GDPR & Privacy Policy
Introduction
This Policy, aims to inform you as to how “ΙSN INTERNATIONAL SCHOOL OF NICOSIALTD” (hereinafter referred to as the “ISN”, “we”, “us” and “our”), collects andprocesses information about you, and in particular, your personal data. We herebyassure you that this GDPR & Privacy Policy (“Policy”) fully respects and complies with
the EU Regulation 679/2016 (“Regulation or GDPR”) and the relevant Law125 / I / 2018 of the Republic of Cyprus.
Useful Definitions
Personal Data is any information relating to an identified or identifiable natural person (that is the ‘data subject’); an identifiable natural person is one whocan be identified, directly or indirectly, indicatively by reference toaninformation or set of information.
Personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.
Controller is the natural or legal person, public authority, agency or other bodywhich, alone or jointly with others, determines the purposes and means of theprocessing of personal data.
Processor is a natural or legal person, public authority, agency or other bodywhich processes personal data on behalf of the controller.
Processing is any operation or set of operations which is performed on personal data or on sets of personal data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Third party is a natural or legal person, public authority, agency or body other than the Data Subject, the Controller, the Processor and persons who, under the direct authority of the Controller or the Processor, are authorisedtoprocess personal data.
The Controller
In those cases where we, as a legal entity, process personal data determiningthe
purposes and means of the processing, the Controller is the legal person: ΙSNINTERNATIONAL SCHOOL OF NICOSIA LTD, address 19 Atlantidos St., Lakatamia, Nicosia 2306, Cyprus, tel: +357 22 780 527 & +357 22 592 900, email: info@isnschool-cy.ac.
Principles we adhere to
At ISN, we are committed to and adhering to the following Principles of processingpersonal data in accordance with Article 5 of the GDPR. The personal data is:
processed lawfully, fairly and in a transparent manner in relation to the data subject (principle of ‘lawfulness, fairness and transparency’);
collected for specified, explicit and legitimate purposes and not further processedinamanner that is incompatible with those purposes (principle of ‘purpose limitation’);
adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed (principle of ‘data minimisation’);
accurate and, where necessary, kept up to date; we take every reasonable steptoensure that personal data that is inaccurate, having regard to the purposes for whichit is processed, erased or rectified without delay (principle of ‘accuracy’);
kept in a form which permits identification of data subjects for no longer thanit isnecessary or as required by relevant Laws (principle of ‘storage limitation’);
processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures (principle of ‘integrity and confidentiality’).
Finally, we are able to demonstrate compliance with the aforementioned principles(principle of ‘accountability’).
Collection of Personal Data
We, as the Controller, collect Personal Data from you in the following cases:
When you contact us directly or by phone or electronically (e.g., through our webpageand/or e-mail, or through our Social Media accounts, etc.), in order to be informedregarding our services or ask relevant information;
If you receive our services, if you cooperate with us, or if you are involved in eventsrelated to the offer of our services;
If you fill in any of our documents;
When your personal data is disclosed to us by third parties – partners or collaboratorsunder contracts or agreements;
When you are connected to our Wi-Fi;
When you visit our webpage or our premises where a legal CCTV systemis inoperation for security purposes;
When you are an employment candidate;
When you are one of our employees.
Minors’ Personal Data
We process minors’ personal data, only under verifiable parental or custodian consent.
Categories of Data Subjects
The categories of data subjects include:
Individuals interested in our services;
Persons receiving services or related to the delivery of our services
Natural persons related to and employees of our professional collaborators andother legal persons cooperating with us;
Natural persons involved in projects we participate to;
Candidates for employment;
Our employees.
Specific Personal Data we may collect about you
Data from the following categories of personal information about you, may becollected and processed per case when we are the Controller, in order to serve thepurpose of the data collection and in accordance with the relevant legal basis asdescribed in this Policy:
Identification and contact details of our students and parents / custodians andpersons you may indicate as authorised to pick up the student (name, surname, address, telephone or fax numbers, emails, relationship);
Occupational information (occupation, position);
Information related to terms of agreements (yours and/ or persons involved) suchus
identification card or passport or ARC number, terms, signatures and amounts;
Payment and transaction details (IBAN, account number, tax number, desired payment method, terms of payment);
Personal data required for the proper performance of our services; such informationrequired is specified in documents we provide you in the beginning of our professional relationship and annually;
Incident investigation data, such as incident details, data of persons involvedor related information;
Client history (satisfaction, transaction details, claims, problems, terms) andinformation related to assessing persons and situations;
Apps / websites / social media related data (cookies, full name or nickname, information you publicly disclose and comments on social media, or email attachments);
Your picture when attending our events, or when your photo is uploaded on our social media or website and of course in both cases under your consent;
Your icon when you pass through areas legally recorded of our CCTV system;
Data referred in your Curriculum Vitae such as data related to studies, competenciesand previous working experience when you apply for employment or other formof cooperation.
We also collect and process as the Processor on behalf of Governmental Bodiespersonal data defined by the Institutional Framework. You are been informedregarding those personal data required, through our initial communicationandthrough documents we have set in place.
It is noted that we collect some more kind of personal data about our employees; theyare informed through documents, manuals, policies and procedures and informationinternally provided.
Purposes of Processing & the Legal Bases of Data Processing
The processing of personal data as the Controller, is based on one of the “legal bases” as referred to in Article 6 and Article 9 in case of special categories of personal dataof the GDPR.
The legal bases on which the collection and processing of personal data is based-inmost of the cases- are, the consent, the compliance in performing our contractual obligations, the compliance with our legal and statutory obligations, andthe
safeguarding our legitimate interests. In the case of special categories of personal data, the explicit consent and the necessity to protect the vital interests of the datasubject or of another natural person where the data subject is physically or legallyincapable of giving consent. The legal basis, on which the processing of your personal data is based, is as follows for each processing purpose:
Consent: when you communicate with us directly or indirectly as interested inour services, when you are interested in working with us, when you fill in our documents, when we inform you about our services in the context of our promotions, whenyoumake a complaint or statement or when assessing us, when participating in our events, when you visit our social media accounts, when you are connected to our wirelessnetwork, when you give us your business card.
Commitment to perform our contractual obligations: when you have agreedtoreceive our services, when you are our employee or collaborator, during the payment of our liabilities or when we are contacting you in the framework of a contract.
Compliance with our legal obligations: to comply with our legal obligations to all sortsof authorities such as labour law, regulatory authorities, tax, accounting, auditing, judicial authorities and agencies or in connection with our contractual obligations or during payment of our liabilities.
Safeguarding our legitimate interests: to improve our services, or when investigatingand managing any potential incident, to receive our payment, to safeguardour premises, or for the assessment of persons and situations.
Our employees are informed about the processing purposes and the legal bases under specific documents internally.
Retention of Data Period
We store personal data for as long as it is required by the respective processingpurpose and any other permitted linked purpose.
Data collected on the basis of contractual and legal obligations shall be retainedafter the expiry of the contractual and legal obligations as provided by the relevant institutional framework.
Personal Data included in offers that does not lead to a cooperation agreement iskept for 24 months.
The content of proposals including your personal data is being stored as long as legal requirements dictate or relevant directions / requirements by National or Europeanrelevant bodies or auditing authorities both in cases where the project is approvedor not approved.
Cookies are stored depending on their nature as you may be informed in our cookiespolicy.
Personal data you disclose to us as candidates are stored for 12 months.
Data that may be needed for our legitimate interests as the Controller shall be kept until the reason for storing such data ceases.
The CCTV recorded data are retained 15 days and then they are destroyedbyoverwrite.
Specifically, the data we process based on your consent (as an example for marketing), is kept from obtaining the consent until it is revoked or there is no longer needtostore it.
Information that is no longer necessary is securely destroyed or anonymised.
How we ensure the security of Personal Data
We have received reasonable organisational and technical measures to protect thepersonal data we collect, and in particular any specific categories of personal data. Wefollow international standards and practices to ensure the security of our networks. We ensure you that your personal data is processed securely and legally, by adheringto policies and developing and implementing procedures in accordance withthepurposes and legal bases of processing. For example, the following security measuresare used to protect personal data against unauthorised use or any other formof unauthorised processing:
Access to personal data is restricted to a limited number of authorised employeesunder a need to know basis, and the necessary data transfer is done by secureprocedures.
Our employees are bound to confidentiality clauses through proper contracts andagreements, with limited classified access to the necessary data only.
We select trusted collaborators who are bound in writing, in accordance with Article28 of the Regulation, with the same obligations regarding the protection of personal data. We reserve the right to audit them in accordance with Article 28 (3) (h).
In our ICT systems used for the processing of personal data, all technical measures aretaken to prevent loss, unauthorised access or other illegal processing.
In addition, access to these ICT systems is monitored on a permanent basis in order todetect and prevent illegal use at an early stage. Although the transfer of data throughthe Internet or a web site cannot be guaranteed to be protected fromcyberattacks, we work to maintain physical, electronic and procedural security measures to protect your data.
Some of the security measures we take are not announced for obvious reasons.
To whom the Data may be disclosed
We take measures to ensure that the recipients of personal data are kept toaminimum. The personal data we process is disclosed to third parties, provided that thelegality of such disclosure is fully justified. Specific personal data fromthose welawfully process as the Controller, may be accessed (or disclosed) on a case-by-casebasis by:
Any relating supervisory authority within its role;
Any public or judicial authority where required by law or judicial decision.
The accountant and financial controller of the company, for necessary data accordingrequirement (financial, employment, contracts and other controls), under confidentiality.
The advocate, for whatever data is required in legal cases, under confidentiality.
Professional collaborators under specific Data Processing or Non-Disclosureagreements.
Partner banks (of the company, the staff or affiliates and suppliers), only for payment related data.
Territorial Scope
The personal data we collect is processed within the European Economic Area (EEA).
Your rights as a Data Subject and how you can exercise them
You have the right to be informed, the right of consent where this is the legal basis for the processing, the right of access to your personal data, the rights of rectificationanderasure, the right to restriction of processing, the right to data portability, the right toobject. If the processing is based on your consent, you may withdraw it at any time.
The right to be informed is exercised through this privacy and personal dataprotection notification. In some cases, it is also mentioned in documents – forms weare using. The right for consent is defined per case; we have set the proper documents to receive consent when this is the case.
We inform you that we are not using software of decision making solely basedonautomated processing including profiling.
Right of access: you have the right to obtain from us confirmation as to whether or not your personal data is being processed as well as other relevant information, and, where that is the case, access to your personal data.
Right of rectification: you have the right of rectification of your inaccurate personal data as well as to have incomplete personal data completed by providingasupplementary statement.
Note: Since it is not possible for us to be aware of any changes to your personal dataif you do not inform us, please help us keep your information accurate by informingusof any changes to your personal information we do process.
Right to erasure (‘right to be forgotten’); we have to answer such right when:
your personal data is no longer necessary in relation to the purposes for whichwecollected it;
withdraw your consent on which the processing is based and where there is no other legal basis for the processing;
your personal data has been unlawfully processed;
your personal data has to be erased for compliance with a legal obligation we aresubject to;
your personal data has been collected in relation to the offer of information societyservices.
We reserve the right to refuse this right if the processing is necessary for compliancewith any legal obligation, we are subject to, or for reasons of public interest, or for thefoundation and exercise or support of our legal claims (according to Article 17 § 3).
Right to restriction of processing; you have the right to restriction of processingwhen:
you contest the accuracy of your personal data for a period enabling us to verify theaccuracy of the personal data;
the processing is unlawful and you oppose the erasure of the personal data andrequest the restriction of their use instead;
we no longer need your personal data for the purposes of the processing, but it isrequired by you for the establishment, exercise or defence of legal claims;
you objected to processing pending the verification whether our legitimate groundsoverride those of yours.
Right to data portability: You have the right to receive your data in a structured, commonly used and machine-readable format and under an explicit request suchdatato be transferred to both you and another natural or legal person who will process it under the provisions of Article 20 of the GDPR.
Right to object: you have the right to object to the processing of your data at anytime when the reason for the processing relates to direct marketing.
In the event that you make such request in a written or electronic formregardinganyof the above rights, we will assess your request and respond within one month of itsreceipt, either for its satisfaction or to provide you with objective reasons preventingit from being satisfied, or, given the complexity of the request and the number of requests at the given time, request an extension of response for a further two months period (according to Article 12.3 of the Regulation).
The exercise of your rights is free of charge. Where requests from you are manifestlyun founded or excessive, in particular because of their repetitive character, we may refuse to answer or charge you an administrative fee.
If you are dissatisfied with the use of your data by us, or our response after exercising your rights, you have the right to lodge a complaint with a supervisory authority.
Personal Data Breach
In the event of a breach of the security and integrity of the personal data processed, we will take the following measures (in accordance with Article 33 and 34 of theRegulation in case we are the Controller) and we will:
Assess it in order to implement the appropriate procedures needed to limit the breach; Examine the extent of the breach and the sensitivity of the data included; Evaluate the risk and its impact on your rights and freedoms;
Endeavour to reduce as much as possible the damage that is or may be caused;
Notify within a time limit of 72 hours of becoming aware of the breach, the National Personal Data Protection Authority, if required;
Assess the impact on your privacy and take appropriate measures to prevent the repeating of the incident.
In the event we are the Processor, we will inform the Controller as soon as possible.
Links to other Websites
Our Website may contain links to other websites that are not operated or controlledby us. If you click on a third-party link, you will be directed to that third-party site. We recommend that you review the Privacy Policy for each site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices
of any third-party sites or services.
Contact details with the National Data Protection Authority
Cyprus Personal Data Protection Authority, 1 Iasonos Street, 1082 Nicosia, telephone+357.22818456, e-mail: commissioner@dataprotection.gov.cy.
Contact us
If at any time you want to contact us or make a request regarding your rights or any other matter relating to the protection of personal data you may contact us: address19 Atlantidos St., Lakatamia, Nicosia 2306, Cyprus, tel: +357 22 780 527 &+35722592 900, email: info@isnschool-cy.ac.
Policy Update
This policy is effective from 16.01.2025 and will be reviewed when there is a significant change. This review will be available onour website, with a note of the effective date.