Effective date: 1 January 2025 · Last updated: 1 January 2025
Paschalı Insurance & Consultants ("we", "us", "our") is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and Cyprus data protection law.
Contents
1. Who we are
Paschalı Insurance & Consultants is a registered insurance intermediary in the Republic of Cyprus, operating as a General & Life Insurance Agency. Our registered office is at Arch. Makariou III, Sotira, Ammochostos 5390, Cyprus.
For the purposes of GDPR, we act as a data controller in relation to the personal data we collect from you as a client or prospective client. In certain circumstances, when we pass data to an insurer for the purpose of arranging cover, we may also act as a data processor on behalf of that insurer.
2. What data we collect
Depending on the type of insurance and the services we provide, we may collect:
- Identity data: name, date of birth, ID number, passport number, nationality
- Contact data: address, phone number, email address
- Financial data: bank details, payment card information, income information
- Underwriting data: health information, occupation, lifestyle details, existing cover
- Policy data: policy numbers, cover details, premium payment history
- Claims data: details of incidents, supporting documents, medical reports
- Technical data: IP address, browser type, pages visited (via cookies)
3. Why we collect it
We process your personal data for the following purposes:
- To assess your insurance needs and recommend suitable products
- To arrange insurance cover with one or more insurers on your behalf
- To administer your policy renewals, amendments, cancellations
- To handle claims made under your policy
- To comply with our legal and regulatory obligations (AML, KYC, tax, ICCS requirements)
- To communicate with you about your policy or our services
- To improve our website and services
4. Legal basis for processing
We rely on the following legal bases under GDPR:
- Contract: processing necessary to arrange and administer your insurance policy
- Legal obligation: processing required to comply with AML, tax and regulatory rules
- Legitimate interests: processing for fraud prevention, claims handling and improving our services
- Consent: for marketing communications and non-essential cookies
- Vital interests: in rare cases involving urgent medical or safety matters
5. Who we share it with
We may share your data with:
- Insurance companies and reinsurers for the purpose of arranging or administering your cover
- Loss adjusters, medical professionals and other experts involved in handling your claim
- Regulatory and law enforcement authorities when legally required
- Professional advisors (auditors, legal, compliance) bound by confidentiality
- IT service providers who support our systems, under strict contractual safeguards
We never sell your personal data. We share only what is necessary, and always under appropriate confidentiality and data protection agreements.
6. How long we keep it
We keep personal data only as long as necessary for the purpose it was collected and to comply with our legal obligations. Typical retention periods:
- Policy records: at least 10 years after the policy ends (statutory requirement)
- Claims records: at least 10 years after settlement
- AML/KYC records: 5–7 years after the business relationship ends
- Marketing preferences: until you withdraw consent
7. Your rights
Under GDPR you have the right to:
- Access request a copy of the personal data we hold about you
- Rectification ask us to correct inaccurate or incomplete data
- Erasure ask us to delete data (subject to legal retention obligations)
- Restriction ask us to limit how we use your data
- Portability request your data in a machine-readable format
- Objection object to processing based on legitimate interests
- Withdraw consent at any time, for processing based on consent
- Lodge a complaint with the Office of the Commissioner for Personal Data Protection (Cyprus)
To exercise any of these rights, contact us at privacy@paschali-insurance.com.cy. We respond within one month of receiving your request.
8. Security
We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. Measures include encrypted storage, access controls, staff training, and regular review of our systems.
9. How to contact us
Data Protection Officer
Paschalı Insurance & Consultants
Arch. Makariou III, Sotira, Ammochostos 5390, Cyprus
Email: privacy@paschali-insurance.com.cy
Tel: +357 PA SCH ALI
This policy may be updated from time to time. The current version is always published on this page.
