EliconStart a project →

Privacy Policy

Last updated: 6 August 2026. Version 2.0.

This policy explains what personal data Elicon collects through elicon.io, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (GDPR) as applied in the Republic of Cyprus, together with the Cyprus Protection of Natural Persons with Regard to the Processing of Personal Data and for the Free Movement of Such Data Law of 2018 (Law 125(I)/2018).

We have tried to write it in plain language. Where a term has a specific legal meaning under the GDPR — "controller", "processor", "personal data", "processing" — it carries that meaning here.

1. Who we are

Elicon ("Elicon", "we", "us", "our") is a software studio established in the Republic of Cyprus and is the data controller for the personal data described in this policy.

We have not appointed a Data Protection Officer, because we are not required to under Article 37 GDPR: our core activities do not consist of large-scale regular and systematic monitoring of individuals, nor of large-scale processing of special categories of data. Privacy enquiries are handled at the email address above.

2. Scope of this policy

This policy covers personal data processed through:

  • the elicon.io website, including the enquiry form;
  • email correspondence with us at addresses published on this site;
  • our web server's access logs.

It does not cover personal data we process on behalf of our clients when delivering services. In those engagements the client is normally the controller and Elicon acts as a processor under a separate written agreement, including a data processing agreement where Article 28 GDPR requires one. Section 12 says more about this.

It also does not cover third-party websites we link to, which have their own policies.

3. What we collect, and why

3.1 Information you give us through the enquiry form

When you submit the enquiry form on this site, we process:

FieldRequiredWhy we need it
NameYesTo address you correctly in our reply
Email addressYesTo reply to you; it is the only channel we use
CompanyNoTo understand the context of your enquiry
MessageYesTo understand what you are asking for
Project stageYesTo assess whether we are a fit
Budget indicationYesTo assess whether we are a fit
TimelineYesTo assess whether we can meet it

The form also contains a hidden field that is invisible to human visitors and is used solely to detect automated spam submissions. If it is filled in, the submission is rejected and nothing is sent to us.

Please do not include special categories of personal data (Article 9 GDPR — health data, biometric data, political opinions, religious beliefs, trade union membership, sexual orientation, and similar), or other people's personal data, in the free-text message field. We do not need it to answer an enquiry.

3.2 Information we collect automatically

Web server access logs. Our web server records standard technical information about requests: IP address, date and time, requested URL, HTTP status code, referrer and user agent string. This is ordinary server operation and is used for security, abuse prevention and diagnosing faults.

Short-term rate limiting. To prevent abuse of the enquiry form, the server keeps a count of recent submissions per IP address in memory only, for a rolling window of 60 seconds. This data is never written to disk, never combined with any other record, and is discarded automatically.

3.3 Information you send us by email

If you email us, we process the content of your message, your email address, and any information you choose to include, for as long as needed to deal with the matter and as described in section 6.

3.4 What we do not collect

  • No cookies. This site sets no cookies of any kind — not necessary, not functional, not analytical, not advertising. There is no cookie banner because there is nothing to consent to.
  • No browser storage. We do not use localStorage, sessionStorage or similar technologies to store information on your device.
  • No analytics. We run no analytics or measurement product on this site — no Google Analytics, no Plausible, no Matomo, no server-side product analytics.
  • No advertising, tracking pixels, retargeting, or fingerprinting.
  • No third-party requests. Fonts and images are served from our own infrastructure. Loading this site does not cause your browser to contact any CDN, font service, tag manager or social network.
  • No social media plug-ins. Links to our social profiles are plain hyperlinks and load nothing until you click them.
  • No account system. There is nothing to register for, so we hold no credentials.
  • No purchase of personal data, and no enrichment of your details from third-party data brokers.

4. Legal bases for processing

We rely on the following legal bases under Article 6(1) GDPR:

ProcessingLegal basis
Responding to your enquiryArticle 6(1)(b) — steps taken at your request prior to entering a contract; and where no contract is contemplated, Article 6(1)(f) legitimate interests in responding to business correspondence
Email correspondenceArticle 6(1)(b) or Article 6(1)(f) as above
Server access logs and rate limitingArticle 6(1)(f) — our legitimate interest in keeping the site secure, available and free from abuse
Retaining enquiry records after the conversation endsArticle 6(1)(f) — our legitimate interest in maintaining a record of business discussions and in establishing, exercising or defending legal claims
Keeping accounting records for engagementsArticle 6(1)(c) — compliance with Cyprus tax and accounting law

Where we rely on legitimate interests, we have considered whether those interests are overridden by your interests or fundamental rights, and concluded that they are not, because the processing is limited, expected in a business context, and involves no profiling or marketing. You may object to legitimate-interest processing at any time — see section 7.

We do not rely on consent for anything on this site, and we do not send marketing email. If we ever introduce marketing communications, they will be opt-in and separately consented to.

5. Who we share personal data with

We do not sell personal data. We do not share it for anyone else's marketing. We do not disclose it to third parties except as set out here.

Processors acting on our instructions:

RecipientPurposeLocation
Resend (Plus Five Five, Inc.)Transactional email delivery — the enquiry form's contents are transmitted through Resend to reach our mailboxUnited States
Our hosting providerOperating the server on which elicon.io runsDisclosed on request
Our email providerThe mailbox in which we receive and store enquiriesDisclosed on request

Each processor is bound by a contract meeting the requirements of Article 28 GDPR and may process personal data only on our documented instructions. We will identify the specific providers we use, and the countries in which they process personal data, on request — write to us at the email address in section 1.

Other disclosures. We may disclose personal data where we are legally required to do so — for example in response to a lawful order from a court or competent authority — or where necessary to establish, exercise or defend legal claims. We may also disclose it to our professional advisers (lawyers, accountants, auditors) under a duty of confidentiality. If Elicon's business is transferred to another entity, personal data may transfer with it; you would be informed before that took effect.

6. International transfers

Some of our processors are established outside the European Economic Area, notably in the United States. Where personal data is transferred outside the EEA, we rely on the safeguards permitted by Chapter V GDPR — principally the European Commission's Standard Contractual Clauses under Article 46(2)(c), supplemented where appropriate by the EU–US Data Privacy Framework where the recipient is certified under it.

You may request a copy of the safeguards applying to a specific transfer by writing to us at the email address in section 1.

7. How long we keep personal data

We keep personal data only as long as we need it, and then delete it.

DataRetention
Rate-limiting counters60 seconds, in memory only
Web server access logsNo longer than 90 days
Enquiries that do not lead to an engagementUp to 24 months from last contact, then deleted
Enquiries that lead to an engagementFor the duration of the engagement, then as below
Contracts and engagement correspondence6 years after the engagement ends, to establish, exercise or defend legal claims
Accounting and tax records6 years, as required by Cyprus tax legislation

The enquiry form does not write to any database on this website. Its contents exist as an email in our mailbox, and the retention periods above apply to that email.

Where a retention period has expired, data is deleted or irreversibly anonymised at the next routine review.

8. Your rights

Under the GDPR you have the following rights in relation to personal data we hold about you. They are not absolute, and some apply only in particular circumstances.

  • Right of access (Article 15). To be told whether we process your personal data and, if so, to receive a copy of it together with information about how we use it.
  • Right to rectification (Article 16). To have inaccurate personal data corrected and incomplete data completed.
  • Right to erasure (Article 17). To have personal data deleted where it is no longer necessary, where you withdraw consent that we relied on, where you object and there is no overriding ground, or where it has been processed unlawfully.
  • Right to restriction (Article 18). To have processing limited while a dispute about accuracy or our legitimate grounds is resolved.
  • Right to data portability (Article 20). Where processing is based on consent or on a contract and carried out by automated means, to receive your data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
  • Right to object (Article 21). To object at any time to processing based on our legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is for legal claims. Where processing is for direct marketing, your objection is absolute and we will stop immediately.
  • Right to withdraw consent (Article 7(3)). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
  • Right not to be subject to automated decision-making (Article 22). See section 11 — we do not carry out automated decision-making producing legal or similarly significant effects.

How to exercise them

Email [email protected] describing what you want. We may ask for information to confirm your identity, so that we do not disclose personal data to the wrong person. We will respond within one month of receiving your request. Where a request is complex or you have made several, we may extend that period by up to two further months and will tell you why within the first month.

Exercising these rights is free. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if that ever arises.

9. Complaints

If you believe we have handled your personal data unlawfully, please tell us first — we would rather fix it. You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.

The supervisory authority for Cyprus is:

Office of the Commissioner for Personal Data Protection 1 Iasonos Street, 1082 Nicosia, Cyprus www.dataprotection.gov.cy

10. Security

We take appropriate technical and organisational measures under Article 32 GDPR, proportionate to the risk. For this website these include:

  • Encryption in transit. The site is served over HTTPS with modern TLS; HTTP requests are redirected to HTTPS.
  • Data minimisation. The enquiry form collects the minimum needed to reply, and the website stores no personal data in a database of its own.
  • Abuse controls. Rate limiting per IP address and a hidden anti-spam field on the enquiry form.
  • Input validation. Submissions are validated against a strict schema server-side, and malformed input is rejected rather than processed.
  • Access control. Access to the mailbox receiving enquiries and to the server is limited to personnel who need it, and protected by strong authentication.
  • Secret management. API credentials are held in server-side environment configuration and are never exposed to the browser.
  • Patching. Dependencies and server software are kept up to date.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Commissioner within 72 hours as required by Article 33, and will notify you directly where Article 34 requires it.

11. Automated decision-making and profiling

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. Enquiries are read and answered by a person.

12. Artificial intelligence, agents, and how we work

Elicon builds AI systems and uses AI tooling in its own delivery work. Because that is unusual enough to be worth stating plainly:

  • We do not feed enquiry-form submissions or your correspondence into third-party AI services for training or for any other purpose. Your enquiry is read by a person.
  • No personal data collected through this website is used to train any machine learning model, ours or anyone else's.
  • In client engagements, any use of AI tooling on client data is governed by the engagement contract and the data processing agreement, which specify what may be processed, by which sub-processors, and under what safeguards. Where we act as a processor, we act only on the client's documented instructions.
  • Where we use AI-assisted tooling to write software, that is an internal engineering practice; it does not change who has access to your personal data or where it is processed.

13. Children

This site is directed at businesses and is not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

14. Links to other sites

This site links to third-party websites, including source-code repositories and social media profiles. We are not responsible for their content or their privacy practices, and this policy does not apply to them. Read their policies before providing personal data.

15. Changes to this policy

We may update this policy to reflect changes in how we operate or in the law. The version number and date at the top of the page will change. Where a change materially affects how we process your personal data, we will take reasonable steps to bring it to your attention. Continued use of the site after a change takes effect indicates that you are aware of the current version.

16. Contact

Questions about this policy or about how we handle personal data:

Email: [email protected]