1. Controller and contact
B2SHIFT LTD (trading as B2Shift) is the website operator and data controller. Postal address: Petsokatalytous, Paphos, 8577, Cyprus. Email: [email protected].
Privacy enquiries and data-rights requests can be sent to [email protected]. We have not appointed a data protection officer because our current processing does not require one.
2. Data we collect
- Enquiry and audit data you submit: name, work email, company, website, country, business type, current tools, process description, urgency and message language.
- Communications and project records: messages, meeting notes, proposals and information needed to respond to or deliver an agreed service.
- Limited technical and security data generated when the site is requested, such as IP address, timestamp, user agent, requested URL and abuse-prevention records. Exact infrastructure logs depend on the production hosting provider.
- A first-party language preference cookie when you choose a language. If — and only if — you accept analytics in the cookie banner, Google Analytics 4 records aggregate usage such as pages viewed, approximate location derived from IP, referrer, device and browser. Declining means the analytics scripts are never loaded. See our cookie notice for the exact storage used and how to withdraw.
3. Purposes and legal bases
- To answer an enquiry, prepare an audit or take steps toward a contract — GDPR Article 6(1)(b).
- To deliver and administer an agreed service — GDPR Article 6(1)(b).
- To secure the website, prevent spam, diagnose failures and maintain proportionate business records — our legitimate interests under Article 6(1)(f), balanced against your rights.
- To comply with accounting, tax, legal and regulatory obligations — Article 6(1)(c).
- To measure website usage with Google Analytics — your consent, given in the cookie banner and withdrawable at any time through Cookie settings in the footer, GDPR Article 6(1)(a). No analytics storage is placed before that consent.
4. Recipients and processors
We disclose personal data only as needed to providers that host the website, deliver email, protect the service, measure website usage once you have consented to analytics, or support an automation workflow configured for the enquiry; to professional advisers bound by confidentiality; and to public authorities where law requires it. Providers act under appropriate contractual and confidentiality obligations. We do not sell personal data or share it for third-party advertising.
5. International transfers
We prefer EEA processing where practical. If a provider processes data outside the EEA, we use a lawful transfer mechanism where required, such as an adequacy decision or the European Commission standard contractual clauses, together with supplementary safeguards appropriate to the risk. You may ask for information about safeguards relevant to your data.
6. Retention
- Enquiries that do not become projects: normally up to 12 months after the last substantive contact.
- Client, contract and invoice records: for the engagement and then for the period required by applicable accounting, tax and limitation rules.
- Security and abuse-prevention logs: only for the shortest period reasonably needed for investigation and service security.
- A minimal suppression or request record may be retained where necessary to respect an objection or deletion request.
7. Your rights
Depending on the circumstances, you may request access, rectification, erasure, restriction or portability, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. We may need to verify your identity before acting. You may also complain to the Office of the Commissioner for Personal Data Protection in Cyprus or another competent EEA supervisory authority.
- Cyprus supervisory authority: dataprotection.gov.cy
- Requests: [email protected]
8. Required data and automated decisions
Fields marked as required are needed to assess and answer your request. Without them we may be unable to respond. The website does not make decisions producing legal or similarly significant effects solely by automated means.
9. Security, children and changes
We apply proportionate access controls, validation, rate limiting and provider safeguards, but no internet transmission is risk-free. The service is intended for business users and not directed to children. We will update this notice when our providers or processing change and show the revision date on this page.
آخری بار اپ ڈیٹ کیا گیا۔: 29 August 2026