top of page

Privacy Policy
 

At ELSA M. SAVVA LLC, we recognize the importance of privacy and are committed to protecting the personal data entrusted to us. This Privacy Notice explains how ELSA M. SAVVA LLC, a law firm incorporated in the Republic of Cyprus under registration number HE 497354, together with its affiliates and subsidiaries where applicable (the “Firm”, “we”, “us” or “our”), collects, uses, stores and discloses personal data and explains the rights available to individuals in relation to that data.

For the purposes of this Privacy Notice, the Firm acts as a data controller and processes personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”) and applicable Cyprus data protection legislation.

How We Collect Your Personal Data

 

We may collect personal data about you in a number of ways, including:

  • directly from you;

  • from your company, or another organization with which you are associated;

  • from agents, professional advisers, intermediaries and custodians of your assets;

  • through correspondence and communications with us, whether in writing, by telephone, email, through our website or by other digital means;

  • when you complete, or we complete on your behalf, client onboarding, application, KYC or due diligence documentation;

  • from publicly available sources and third-party databases, particularly where background, compliance or due diligence checks are required; and

  • through information provided when you meet members of the Firm at meetings, conferences, events or other professional engagements.

Where appropriate and permitted by law, communications with us may be monitored, recorded or retained.

Personal Data We Collect

Depending on the nature of our relationship with you and the services being provided, we may collect and process:

  • your name and contact details, including your residential or business address, job title, email address and telephone number;

  • identification and biographical information, including your date of birth, tax identification number, passport or national identity card details, country of domicile and/or nationality, together with copies of relevant documentation;

  • financial information, including income, expenditure, assets and liabilities, source of wealth and bank account details;

  • reference letters, information concerning politically exposed person status, FATCA and CRS information and authentication information such as signatures;

  • information concerning your objectives and reasons for engaging our services;

  • information concerning your employment, education, family or personal circumstances and interests, where relevant to the services being provided;

  • information required to assess money laundering, sanctions, reputational or other compliance risks; and

  • technical information collected when you use our website, including your IP address, login information, browser version, device information and time zone.

  • How and Why We Process Your Personal Data

We process personal data only where we have a lawful basis for doing so under applicable data protection law.

 

Performance of a Contract

We may process your personal data where processing is necessary for the performance of a services agreement to which you are a party or in order to take steps at your request before entering into such an agreement.

This may include processing your personal data:

  • to prepare proposals concerning the services we may provide;

  • to provide legal, advisory or other services agreed with you;

  • to manage our professional relationship with you;

  • to respond to complaints, queries or feedback; and

  • for other purposes for which you provide information to us in connection with our services.

In connection with these purposes, we may disclose personal data to:

  • your agents, advisers, intermediaries and asset custodians;

  • third-party service providers engaged to assist us in delivering our services, including affiliated companies where applicable;

  • professional advisers, including lawyers, accountants and IT professionals;

  • debt collection agencies where necessary to recover amounts owed to us;

  • courts, regulatory bodies, governmental authorities and other competent public authorities where required or appropriate in connection with our services or under applicable law; and

  • other third parties or professional intermediaries to whom we introduce you, where appropriate.

 

Legitimate Interests

We may also process personal data where this is necessary for our legitimate interests, or those of a third party, provided that those interests are not overridden by your rights and interests.

Such processing may include:

  • communicating with you about our services;

  • training our personnel and monitoring professional performance;

  • administering and managing the Firm;

  • recovering amounts owed to us;

  • maintaining appropriate business records and archives;

  • conducting statistical or internal business analysis; and

  • obtaining professional advice concerning our rights and obligations.

Where necessary for these purposes, we may disclose information to our advisers, agents and to third parties and their advisers in connection with a proposed acquisition or transfer of all or part of our business.

 

Consent

Where processing is based on your consent, such consent will be freely given for the relevant purpose.

You may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before your withdrawal was received.

 

Compliance with Legal Obligations

We may process personal data where necessary to comply with legal, regulatory and professional obligations applicable to the Firm.

This includes:

  • compliance with anti-money laundering and counter-terrorist financing requirements;

  • client identification, verification and due diligence;

  • compliance with tax, regulatory and reporting obligations; and

  • responding to lawful requests, orders or requirements of courts, regulators, law enforcement bodies and other competent authorities.

For these purposes, personal data may be disclosed to our professional advisers, auditors, providers assisting with background or due diligence checks, regulators, law enforcement agencies, courts and other competent authorities where required by law.

Marketing Communications

We may provide you with information concerning our services, legal and commercial developments, newsletters, alerts, invitations to events and other information that we believe may be relevant or of interest to you.

We may communicate with you by email, telephone, post or other appropriate digital channels.

You may object to receiving marketing communications from us at any time by contacting: elsa@nalarislegal.com 

Where marketing communications are based on your consent, you may withdraw that consent at any time by contacting us at the above email address.

International Transfers of Personal Data

In providing our services, we may need to transfer personal data to recipients located outside the European Union.

Where such transfers take place, we will ensure that an appropriate lawful transfer mechanism is in place. This may include:

  • transferring personal data to a country recognized by the European Commission as providing an adequate level of protection;

  • transferring personal data to an eligible recipient in the United States participating in the applicable EU-US Data Privacy Framework;

  • using Standard Contractual Clauses approved by the European Commission or other contractual safeguards providing an appropriate level of data protection; or

  • relying on your explicit consent where permitted by applicable law.

Third parties receiving personal data in connection with the provision of services are permitted to access and use that information only for the relevant purposes and subject to applicable legal and contractual requirements.

Retention of Personal Data

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and for as long as we have a lawful basis or legal obligation to retain it.

In particular:

  • personal data collected for anti-money laundering purposes, including identification, screening and reporting information, may be retained for between five and seven years following termination of our relationship, unless a longer period is required by law or in connection with legal proceedings; and

  • other personal data will generally be retained for a period of seven years following termination of our contractual or other relationship, including where retention is appropriate in connection with potential claims arising from the services provided.

 

Security of Your Personal Data

We take appropriate technical and organizational measures to protect personal data against unauthorized or unlawful access, processing, loss, alteration, disclosure or destruction.

These measures may include encryption, password protection, secure servers and backups, access controls and appropriate physical, electronic and procedural safeguards.

Access to personal data is restricted to officers, employees and other authorized persons who require access for legitimate professional or business purposes and who are subject to appropriate confidentiality obligations.

We also maintain procedures for identifying, assessing and responding to suspected personal data breaches. Where required by applicable law, we will notify affected individuals and/or the relevant supervisory authority.

Agents and Intermediaries

Where you provide personal data to us in your capacity as an agent or intermediary, you are responsible for bringing any relevant privacy notices or policies relating to our services to the attention of the individuals concerned.

You confirm that any personal data provided to us by you or on your behalf has been lawfully collected and disclosed in accordance with applicable data protection legislation.

You must take reasonable steps to ensure that you, your employees, agents and contractors do not provide us with irrelevant or unnecessary personal data and that appropriate physical, technical and organizational safeguards are maintained.

You must notify us without undue delay of any actual or suspected personal data breach that may affect us or the individuals concerned.

Your Rights Under the GDPR

Subject to applicable law and any relevant exemptions, you may have the right to:

  • request access to the personal data we hold about you and obtain a copy;

  • request correction of inaccurate or incomplete personal data;

  • request erasure of your personal data;

  • request restriction of processing;

  • object to certain processing of your personal data;

  • object to receiving direct marketing communications;

  • receive certain personal data you have provided to us in a structured, commonly used and machine-readable format and, where applicable, request its transmission to another controller; and

  • withdraw consent where processing is based on consent.

These rights are not absolute and may be subject to restrictions or exceptions under applicable law.

Data Protection Officer

We have designated a Data Protection Officer (“DPO”) who is responsible for monitoring compliance with this Privacy Notice and applicable data protection legislation and for liaising with relevant supervisory authorities.

Questions concerning this Privacy Notice, the processing of your personal data or the exercise of your data protection rights may be addressed to: elsa@nalarislegal.com 

    

Right to Lodge a Complaint

If you have concerns regarding our processing of your personal data or our compliance with the GDPR or applicable data protection legislation, you may contact our Data Protection Officer at: elsa@nalarislegal.com  

You also have the right to lodge a complaint with the competent supervisory authority.

For matters concerning Cyprus, you may contact the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.

bottom of page