Executive Summary: Shraga 18 LTD provides structured customer operations and support services. We take your privacy seriously. We only collect personal data necessary to provide our services, communicate with you, and maintain secure website operations. We never sell personal data to third parties.
1. Data Controller Information
Shraga 18 LTD operates as the Data Controller for personal data collected through this website and through direct communications regarding our services.
Company Name: Shraga 18 LTD
Registration: Republic of Cyprus
Email: [email protected] / [email protected]
Website: www.shraga18.com
When providing outsourced customer support and operations services on behalf of our enterprise clients, Shraga 18 LTD operates primarily as a Data Processor under a formal Data Processing Agreement (DPA) executed with the relevant client (the Data Controller).
2. Information We Collect
We collect personal information depending on the nature of your interaction with us:
A. Information You Voluntarily Provide
- Contact & Inquiry Details: Full name, professional email address, phone number, organization name, job title, and details provided when submitting our contact form or communicating via email.
- Business Relationship Data: Account setup information, billing and invoicing contacts, signed agreements, and meeting notes during client consultations.
B. Automatically Collected Information (Technical Data)
- Device & Network Details: IP address, device type, operating system, browser type and version, language settings, and referring URL.
- Usage Information: Pages viewed, time spent on specific sections, navigation patterns, and click timestamps, recorded to ensure platform stability and prevent malicious traffic.
C. Data Handled in Customer Support Operations
In our role as an operational partner, we process customer tickets, live chat transcripts, email communications, and administrative records on client systems. Such processing strictly adheres to client-specified access controls, retention periods, and security baselines.
3. Legal Bases for Processing
Under Article 6 of the General Data Protection Regulation (GDPR), we process personal data only when an established legal basis applies:
- Contract Performance (Art. 6(1)(b)): To review prospective partnership requirements, prepare service proposals, execute agreements, and deliver contracted customer operations.
- Legitimate Interests (Art. 6(1)(f)): To maintain the security, performance, and integrity of our IT infrastructure, prevent fraudulent inquiries, and manage normal corporate business relationships.
- Consent (Art. 6(1)(a)): For optional website analytics or specific communication channels where prior consent has been explicitly granted. You may withdraw consent at any time.
- Legal Obligation (Art. 6(1)(c)): To comply with statutory financial, taxation, audit, or corporate reporting requirements under Cyprus and EU law.
4. How We Use Personal Data
Personal data is used exclusively for legitimate business and operational purposes, including:
- Evaluating your support requirements and delivering tailored operational proposals.
- Administering client communications, scheduling kickoff meetings, and managing service transitions.
- Ensuring the technical availability, resilience, and security of our online presence.
- Fulfilling legal, regulatory, and corporate accounting obligations.
We do not perform automated decision-making or profiling that produces legal or similarly significant effects on individuals.
5. Data Sharing & Third-Party Processors
We do not sell, rent, or trade your personal information. We only disclose personal information to trusted third-party providers under strict contractual confidentiality and data protection terms:
- Hosting & Infrastructure Providers: Secure web servers, firewall providers, and database hosting located within the European Economic Area (EEA) or compliant jurisdictions.
- Communication & Helpdesk Tools: Secure corporate email systems, document management suites, and CRM/ticketing environments used to manage business correspondence.
- Professional Advisers & Authorities: Legal counsel, chartered accountants, and regulatory authorities where required by applicable laws or legal proceedings.
6. International Data Transfers
Shraga 18 LTD processes personal data predominantly within Cyprus and the European Economic Area (EEA). If technical infrastructure or service partners process data outside the EEA in countries without an adequacy decision, we ensure equivalent protection through approved safeguards, including EU Standard Contractual Clauses (SCCs) and supplementary technical security measures.
7. Data Retention Periods
We retain personal information only for as long as necessary to fulfill the operational, legal, and contractual objectives for which it was originally collected:
- Inquiry Records: General contact form inquiries that do not result in a commercial contract are typically deleted or anonymized within 12 months.
- Client Commercial Records: Data relating to active client engagements is retained for the duration of the agreement plus statutory retention periods (typically up to 7 years for financial and tax audit compliance).
- Technical Logs: Server access and firewall logs are retained for a rolling period of 30 to 90 days for cybersecurity and audit purposes.
8. Your Rights Under GDPR
If you reside within the European Economic Area or the United Kingdom, you possess defined statutory rights regarding your personal information:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request that inaccurate or incomplete information be corrected.
- Right to Erasure ("Right to be Forgotten"): You can request deletion of your personal data where retention is no longer legally justified.
- Right to Restriction: You can request that we pause processing while a dispute or verification is underway.
- Right to Data Portability: You can receive personal data you provided in a structured, commonly used machine-readable format.
- Right to Object: You can object to processing founded on our legitimate business interests.
- Right to Withdraw Consent: Where processing relies on consent, you may withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, please email us at [email protected]. We will respond promptly within one calendar month in accordance with statutory guidelines.
You also have the right to lodge a complaint with the relevant data protection authority, such as the Office of the Commissioner for Personal Data Protection in Cyprus (www.dataprotection.gov.cy) or your local national supervisory body.
9. Technical & Operational Security
We implement multi-layered technical and organizational security measures to protect personal data against unauthorized access, loss, alteration, or disclosure. These measures include TLS 1.3 encryption in transit, strict role-based access limitations, strong authentication requirements, continuous system patch management, and employee confidentiality agreements.
10. Updates to This Privacy Notice
We review and update this Privacy Notice periodically to reflect changes in our operational procedures, technologies, or applicable legal standards. When modifications are made, the "Effective Date" at the top of this notice will be revised accordingly.
11. Contact & Inquiries
For any questions, requests, or privacy concerns regarding this notice or our data handling practices, please contact our team:
Shraga 18 LTD
Attn: Data Privacy & Compliance
Email: [email protected]
General Inquiries: [email protected]
Website: Contact Us