PRIVACY POLICY
Last Updated: 7 September 2026
1. Introduction
F&A GRAND AUDITING AND CONSULTING LIMITED ("F&A Grand Auditing", "we", "us" or "our") respects the privacy and personal data of its clients, prospective clients, business contacts, employees, job applicants, suppliers, website visitors and other persons whose personal data may be processed in the course of our professional activities.
This Privacy Policy explains how we collect, use, store, disclose and otherwise process personal data and describes the rights available to individuals in relation to their personal data.
We process personal data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data Law of 2018, Law 125(I)/2018, as amended or replaced from time to time, and other applicable data protection and privacy legislation.
This Privacy Policy applies both to personal data collected through our website atwww.grandauditing.com and to personal data processed in connection with our professional and business activities.
2. Who We Are
The controller responsible for the processing described in this Privacy Policy is:
F&A GRAND AUDITING AND CONSULTING LIMITEDRegistration No.: HE 6778865 Prodromou StreetNikaia Building, 4th Floor, Office 402Strovolos, 2063 NicosiaCyprus
Telephone: +357 22 660102Email: contact@grandauditing.com
F&A Grand Auditing has not appointed a Data Protection Officer. Any enquiries concerning this Privacy Policy, the processing of personal data or the exercise of data protection rights should therefore be addressed to us at contact@grandauditing.com.
3. Scope of this Privacy Policy
As a firm providing audit, assurance, accounting, taxation, corporate administration, IFRS, consulting, financial advisory and related professional services, we may process personal data concerning a wide range of individuals.
This may include:
individual clients and prospective clients;
directors, officers, shareholders, ultimate beneficial owners, partners, employees and representatives of corporate clients and prospective clients;
employees, customers, suppliers, creditors, debtors and other persons whose information forms part of the records of our clients;
persons whose personal data are contained in financial statements, accounting records, payroll information, audit evidence, corporate records or other documentation provided to us in the course of an engagement;
business contacts and representatives of suppliers, professional advisers and other organisations;
persons communicating with us or making enquiries;
visitors to our website;
persons subscribing to newsletters or other communications where such services are offered;
job applicants and prospective employees;
employees and other persons visiting our premises; and
any other individual whose personal data we lawfully receive or process in connection with our professional or business activities.
Because of the nature of audit, accounting and other professional services, we may process personal data concerning persons with whom we have no direct relationship. For example, a corporate client may provide us with information concerning its employees, directors, shareholders, customers or suppliers as part of an audit or accounting engagement.
4. Our Role as Controller or Processor
For most of the processing described in this Privacy Policy, F&A Grand Auditing determines the purposes and means of processing personal data and therefore acts as an independent data controller.
This will generally be the case where we process personal data for purposes including:
providing regulated or professional services;
carrying out audits;
complying with legal, regulatory and professional obligations;
conducting client acceptance, independence, conflict, anti-money laundering and other compliance procedures;
managing our professional relationships;
administering our business; and
protecting our legal rights and interests.
In certain engagements, however, we may process personal data solely on documented instructions from a client and act as a data processor on behalf of that client.
Where we act as a processor, the relevant client remains responsible as controller for providing any required privacy information to the individuals concerned, and our processing will be governed by the applicable engagement terms and, where required, a data processing agreement.
5. Personal Data We May Collect
The personal data we process depends on the nature of our relationship with you and the services concerned.
5.1 Identification and contact information
This may include:
full name;
residential or business address;
email address;
telephone number;
date and place of birth;
nationality;
identity card or passport information;
signatures;
photographs contained in identification documents; and
other identification or verification information.
5.2 Business and professional information
This may include:
employer or business;
job title and professional role;
directorships and other appointments;
shareholdings and ownership interests;
professional qualifications;
business relationships;
correspondence;
information concerning business activities and transactions; and
information regarding relationships with companies, trusts, partnerships or other entities.
5.3 Financial, accounting and taxation information
Depending on the services being provided, we may process:
bank and payment details;
financial statements and accounting records;
invoices, receipts and transactional records;
income, assets and liabilities;
tax identification and taxation information;
VAT information;
payroll and employment-related financial information;
pension and social insurance information;
investment and ownership information;
loan and financing information; and
other financial information relevant to our professional engagement.
5.4 Compliance, KYC and regulatory information
Where required for client acceptance, anti-money laundering, sanctions, regulatory or professional compliance purposes, we may process:
identification and verification documents;
information concerning ultimate beneficial ownership and control;
source of funds and source of wealth information;
information concerning politically exposed persons;
sanctions and watchlist screening results;
information obtained from corporate and public registries;
information concerning business activities and relationships;
information required for risk assessments and client due diligence; and
other information required under applicable legal, regulatory or professional obligations.
5.5 Information processed in connection with professional services
Clients may provide us with personal data concerning other individuals where such information is relevant to the services we have been engaged to provide.
Such information may include, amongst other things:
employee and payroll records;
accounting and financial records;
customer and supplier information;
corporate records;
contracts and correspondence;
transaction information;
audit evidence;
tax documentation;
information regarding directors, shareholders and beneficial owners; and
other information contained within documents, systems or records made available to us.
The precise nature and extent of this information will vary according to the particular engagement.
5.6 Website and enquiry information
When you visit our website or contact us through it, we may collect information such as:
your name;
email address;
telephone number;
company or organisation;
information included in your message or enquiry;
IP address;
browser and device information;
website usage and technical information; and
cookie and similar technology information.
Further information regarding our use of cookies is available in our Cookie Policy.
5.7 Recruitment information
Where you apply for employment or otherwise express an interest in working with us, we may collect:
your name;
telephone number;
email address;
curriculum vitae;
cover letter;
education and qualifications;
employment history;
professional experience;
references;
skills and professional memberships;
information provided during interviews or recruitment communications; and
any other information voluntarily provided as part of your application.
Please do not provide special-category personal data or other information that is not relevant to your application unless specifically requested or necessary.
5.8 CCTV information
CCTV systems operate at our premises for security, safety and property-protection purposes.
Where you enter an area covered by CCTV, images of you and information concerning your presence at our premises may be recorded.
Appropriate notices are displayed where CCTV monitoring takes place.
6. Special Categories of Personal Data and Criminal-Offence Data
Due to the nature of some professional engagements, information supplied to us may occasionally contain special categories of personal data, such as information concerning health, racial or ethnic origin, religious beliefs, trade union membership or other information subject to enhanced protection under the GDPR.
We do not ordinarily seek to collect such information unless it is relevant and necessary for a legitimate professional or legal purpose.
Where special categories of personal data are processed, we will do so only where a lawful basis under the GDPR exists, including, where applicable, where processing is necessary:
to comply with obligations or exercise rights under employment or social protection law;
for the establishment, exercise or defence of legal claims;
for reasons of substantial public interest recognised by applicable law;
pursuant to another applicable legal provision; or
on the basis of explicit consent where consent is appropriate.
Information relating to criminal convictions or offences will only be processed where such processing is permitted or required by applicable law.
7. How We Obtain Personal Data
We may obtain personal data from a number of sources.
7.1 Directly from you
You may provide information to us when you:
become or seek to become a client;
correspond or communicate with us;
attend a meeting;
submit documentation;
make an enquiry through our website;
apply for employment;
subscribe to communications;
visit our premises; or
otherwise interact with us.
7.2 From our clients
Our clients frequently provide information relating to other individuals where this is necessary for the services we provide.
For example, during an audit we may receive information relating to the client's employees, directors, shareholders, customers, suppliers and other individuals.
7.3 From public and official sources
We may obtain information from:
the Registrar of Companies;
tax and governmental authorities;
court and public records;
regulatory or professional bodies;
publicly accessible databases;
company websites;
sanctions and politically exposed persons lists; and
other lawful public sources.
7.4 From third parties
We may also receive information from:
banks and financial institutions;
professional advisers;
auditors and accountants;
lawyers;
corporate service providers;
regulators and governmental bodies;
compliance and screening providers;
employers;
business partners;
references provided in connection with recruitment; and
other third parties where appropriate and lawful.
8. Why We Process Personal Data and Our Legal Bases
We only process personal data where there is a lawful basis for doing so.
Depending on the circumstances, we may process personal data for the following purposes.
8.1 Providing professional services
We process personal data where necessary to:
provide audit and assurance services;
provide bookkeeping and accounting services;
prepare financial statements;
provide taxation and VAT services;
provide IFRS-related services;
provide corporate administration services;
provide consulting and advisory services;
communicate with clients concerning engagements;
obtain information required to perform our services; and
manage and complete professional assignments.
Depending on the particular circumstances, processing may be based upon:
performance of a contract or steps taken at your request before entering into a contract;
compliance with a legal obligation; or
our legitimate interests in providing and administering professional services.
8.2 Client acceptance, KYC, AML and regulatory compliance
We may process information in order to:
identify and verify clients and relevant persons;
establish ultimate beneficial ownership;
conduct anti-money laundering and counter-terrorist financing checks;
conduct sanctions and politically exposed person screening;
perform client risk assessments;
perform conflict and independence checks;
determine whether we can accept or continue an engagement;
maintain records required by law; and
comply with obligations imposed upon us by regulators, professional bodies or applicable professional standards.
Processing is generally necessary for compliance with our legal and regulatory obligations and, where appropriate, for our legitimate interests in ensuring that we conduct our business lawfully, ethically and in accordance with applicable professional standards.
8.3 Business administration
We may process personal data to:
administer client relationships;
manage contracts and engagements;
issue invoices and collect payments;
maintain accounting and tax records;
operate and secure our IT systems;
manage suppliers and service providers;
maintain internal records;
carry out quality-control procedures;
manage risk;
maintain insurance coverage;
obtain professional advice;
handle complaints and disputes; and
manage and develop our business.
Such processing may be necessary for the performance of a contract, compliance with legal obligations or our legitimate interests in properly administering and protecting our business.
8.4 Legal and professional obligations
We may process or retain information where necessary to comply with:
applicable laws and regulations;
audit and accounting requirements;
tax requirements;
anti-money laundering and counter-terrorist financing requirements;
sanctions obligations;
court orders or legal proceedings;
requests from competent governmental, regulatory or law-enforcement authorities;
professional standards;
regulatory inspections;
quality reviews; and
other obligations applicable to an accounting and auditing firm.
The legal basis for such processing is generally compliance with a legal obligation and, where applicable, our legitimate interests in complying with professional requirements and protecting the integrity of our services.
8.5 Website enquiries and communications
Where you contact us through our website, by email, telephone or otherwise, we process your information to:
respond to your enquiry;
provide information you have requested;
determine whether we may be able to provide services to you;
arrange consultations or meetings; and
maintain appropriate records of our correspondence.
The processing is based on steps taken at your request before entering into a contract and/or our legitimate interests in responding to enquiries and managing potential business relationships.
8.6 Recruitment
We process information submitted by applicants in order to:
assess applications;
communicate with applicants;
evaluate experience, skills and suitability;
conduct interviews;
obtain references where appropriate;
make recruitment decisions; and
take steps necessary to enter into an employment relationship where an applicant is successful.
The processing is based principally on taking steps at the applicant's request prior to entering into an employment contract and our legitimate interests in recruiting suitable personnel.
Unless a longer period is necessary due to legal proceedings or another lawful reason, information relating to unsuccessful applicants may be retained for up to two (2) years following the conclusion of the relevant recruitment process so that we may consider the applicant for suitable future employment opportunities.
Applicants may request that we delete their information before the end of this period, subject to any legal or legitimate requirement for us to retain particular records.
8.7 Security and CCTV
We use CCTV at our premises for purposes including:
protecting employees and visitors;
safeguarding our premises and property;
preventing and investigating unauthorised access, theft, damage or other security incidents; and
supporting the establishment, exercise or defence of legal claims where necessary.
CCTV processing is based upon our legitimate interests in maintaining the safety and security of our premises, personnel, visitors, information and property.
8.8 Marketing and newsletters
We may from time to time provide newsletters, tax updates, professional insights, invitations, information concerning our services or other business communications.
Where applicable law requires prior consent for electronic direct marketing, we will only send such communications where the recipient has provided the required consent.
Where permitted by applicable law, we may also send communications concerning our own similar services to existing clients whose contact details were obtained in connection with our services, provided that the recipient was given an appropriate opportunity to object.
You may unsubscribe or object to direct marketing communications at any time by:
using the unsubscribe facility included in the relevant communication; or
contacting us at contact@grandauditing.com.
We will not use consent as a condition for receiving professional services where the processing concerned is not necessary for those services.
8.9 Establishing and protecting legal rights
We may process personal data where necessary to:
obtain legal advice;
establish, exercise or defend legal claims;
respond to disputes;
investigate suspected wrongdoing;
enforce contractual rights; or
protect our business, personnel and professional interests.
This processing is based on our legitimate interests and, where relevant, the establishment, exercise or defence of legal claims.
9. Our Legitimate Interests
Where we rely upon legitimate interests as a lawful basis, those interests may include:
providing effective professional services;
administering and developing our business;
maintaining relationships with clients and business contacts;
protecting our premises, systems, personnel and information;
preventing fraud, misuse and security incidents;
ensuring compliance with professional standards;
managing risk;
recovering amounts owed to us;
establishing and defending legal rights;
maintaining appropriate business records;
improving our services and operations; and
communicating with existing clients and professional contacts where permitted by law.
We will rely on legitimate interests only where we consider that those interests are not overridden by the rights, freedoms or interests of the individuals concerned.
10. When Providing Personal Data Is Required
In certain circumstances, providing personal data is necessary:
to enter into or perform a contract with us;
to enable us to provide requested professional services;
to comply with our statutory, regulatory or professional obligations;
to complete client-identification and due-diligence requirements; or
to consider an application for employment.
Where required information is not provided, we may be unable to:
accept or continue a client relationship;
provide particular services;
complete a transaction or engagement;
comply with legal or regulatory obligations; or
consider an employment application.
We will inform you where the provision of particular information is mandatory where this is not otherwise apparent from the circumstances.
11. Disclosure of Personal Data
We treat personal data as confidential and do not disclose it except where reasonably necessary, legally required or otherwise permitted by law.
Depending on the circumstances, personal data may be disclosed to the following categories of recipients.
11.1 Governmental, regulatory and professional authorities
Including:
tax authorities;
the Registrar of Companies;
courts and tribunals;
law-enforcement authorities;
governmental departments;
regulatory bodies;
professional bodies;
supervisory or inspection authorities; and
other competent authorities where required or permitted by law.
11.2 Professional advisers
Including lawyers, accountants, auditors, consultants, insurers and other professional advisers where their services are required.
11.3 Technology and service providers
We use a range of third-party technology solutions to support our business operations and the delivery of our professional services.
Depending on the service concerned, personal data may therefore be processed through or made accessible to providers of:
cloud-based productivity and collaboration software, used for email, document management, communication, file sharing and internal collaboration;
cloud-based accounting software, used for bookkeeping, accounting records, financial reporting and related accounting services;
audit and assurance software, used for the preparation, documentation, review and management of audit and assurance engagements;
AML, KYC and sanctions screening software, used for customer due diligence, identity verification, anti-money laundering checks, politically exposed person screening and sanctions screening;
payroll and workforce management software, used for payroll processing, employee records and related administrative functions; and
cloud infrastructure, data storage and hosting services, used for data storage, system hosting, backups and other cloud-based infrastructure services.
We may also use other providers that support our website, cybersecurity, communications, banking, payments, document management and general administration.
The extent of personal data made available to any service provider is limited, where reasonably practicable, to what is necessary for the relevant service or function.
Where a third-party provider processes personal data on our behalf as a data processor, we require the provider to process such data in accordance with applicable data protection requirements and appropriate contractual, confidentiality and security obligations.
Certain technology providers may act as independent controllers in respect of limited processing activities for which they determine their own purposes and means of processing. Where applicable, such processing is governed by the provider's own privacy obligations under applicable law.
11.4 Parties connected with professional engagements
Where necessary for a particular engagement and permitted by law, information may be shared with:
the relevant client;
members of a client's corporate group;
other accountants or auditors;
banks and financial institutions;
lawyers and other advisers;
counterparties;
specialists or experts involved in an engagement; and
other persons whom the client has authorised us to contact or to whom disclosure is reasonably necessary for the services concerned.
11.5 Corporate transactions
If our business, or part of it, is subject to a merger, restructuring, acquisition, sale or similar transaction, personal data may be disclosed to appropriate prospective purchasers, advisers and other relevant parties, subject to appropriate confidentiality and legal safeguards.
We do not sell personal data to third parties.
12. International Transfers
Due to the international nature of some of our clients, professional engagements and technology infrastructure, personal data may in certain circumstances be transferred to, stored in, accessed from or otherwise processed in countries outside Cyprus or outside the European Economic Area ("EEA").
This may occur, for example:
where a client or member of its corporate group is located outside the EEA;
where an overseas professional adviser, specialist or service provider is involved;
where information must lawfully be provided to a foreign authority;
where an international engagement requires communication with persons outside the EEA; or
where a cloud, technology, software, hosting, storage or support provider operates infrastructure or provides services from locations outside the EEA.
Where personal data are transferred outside the EEA to a country that has not been recognised by the European Commission as providing an adequate level of data protection, we will use an appropriate transfer mechanism where required by applicable law.
Such safeguards may include:
Standard Contractual Clauses approved by the European Commission;
supplementary technical, contractual or organisational measures where appropriate;
another approved contractual or organisational safeguard;
another legally recognised transfer mechanism; or
an applicable derogation under the GDPR where the circumstances permit its use.
Where third-party technology providers are used, we take reasonable steps to ensure that any international processing of personal data is subject to appropriate safeguards as required by applicable data protection law.
You may contact us for further information concerning the safeguards applicable to a particular transfer.
13. Retention of Personal Data
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected or subsequently lawfully processed.
The relevant retention period will depend on factors including:
the nature of the information;
the nature and duration of the relevant client or business relationship;
applicable statutory limitation periods;
tax and accounting record-keeping requirements;
anti-money laundering and customer-due-diligence requirements;
audit and professional record-keeping requirements;
regulatory and professional standards;
the possibility of complaints, disputes or legal proceedings;
applicable contractual requirements; and
the need to establish, exercise or defend legal claims.
Accordingly, different categories of information may be retained for different periods.
Recruitment information
Information concerning unsuccessful job applicants may ordinarily be retained for up to two (2) years after the conclusion of the relevant recruitment process, unless a longer period is required for a specific lawful reason.
CCTV recordings
CCTV recordings are retained only for a limited period proportionate to the security purposes for which they are collected.
Where footage relates to a security incident, accident, investigation, complaint, legal claim or other matter requiring further examination, the relevant footage may be preserved for as long as reasonably necessary to investigate or resolve that matter or comply with a legal obligation.
When personal data are no longer required, we will delete, securely destroy or anonymise them, as appropriate.
14. Security and Confidentiality
We take appropriate technical and organisational measures designed to protect personal data against:
accidental or unlawful destruction;
loss;
alteration;
unauthorised disclosure;
unauthorised access; and
other unlawful forms of processing.
Our business operations make use of cloud-based and specialist third-party technology solutions, including accounting, audit, compliance, payroll, communication, document-management, storage, hosting and backup systems.
Where such providers process personal data on our behalf, we seek to ensure that appropriate data protection, confidentiality and security arrangements apply to the processing concerned.
Depending on the nature of the information and the processing involved, our measures may include:
access controls;
user authentication;
appropriate IT and network security;
secure data storage;
backup arrangements;
access restrictions based on professional responsibilities;
confidentiality obligations;
staff training and awareness;
procedures for handling personal data and security incidents; and
appropriate contractual requirements for service providers.
Access to personal data is restricted to persons who require such access for legitimate professional or business purposes.
As accountants and auditors, we are also subject to professional duties of confidentiality applicable to information received in the course of our professional work.
No system of electronic storage, cloud processing or electronic transmission can be guaranteed to be completely secure. We therefore seek to maintain measures appropriate to the nature and risks of the processing concerned.
15. Cookies and Website Technologies
Our website may use cookies and similar technologies to:
enable essential website functions;
maintain security;
remember preferences;
understand how visitors use our website; and
improve the performance and usability of the website.
Where a cookie or similar technology is not strictly necessary and applicable law requires consent, it will only be used after the required consent has been obtained.
You may manage or withdraw your cookie preferences through the cookie-management facility available on our website.
For more detailed information concerning the cookies and similar technologies used on our website, please refer to our Cookie Policy.
16. Your Rights
Subject to the conditions and limitations provided by applicable law, you have a number of rights concerning your personal data.
16.1 Right of access
You may request confirmation as to whether we process personal data concerning you and, where we do, request access to that personal data and certain information concerning our processing.
16.2 Right to rectification
You may request that inaccurate personal data concerning you be corrected and that incomplete information be completed where appropriate.
16.3 Right to erasure
You may request deletion of your personal data in circumstances where the GDPR provides a right to erasure.
This right is not absolute. For example, we may be required to retain information to comply with legal, regulatory, tax, audit, anti-money laundering or professional obligations or for the establishment, exercise or defence of legal claims.
16.4 Right to restriction of processing
You may request that the processing of your personal data be restricted in circumstances provided by the GDPR.
16.5 Right to data portability
Where processing is based on consent or contract and carried out by automated means, you may, where applicable, request to receive personal data you provided to us in a structured, commonly used and machine-readable format or request its transmission to another controller where technically feasible.
16.6 Right to object
Where we process personal data on the basis of our legitimate interests, you may object to that processing on grounds relating to your particular situation.
We may continue processing where we demonstrate compelling legitimate grounds which override your interests, rights and freedoms or where processing is required for the establishment, exercise or defence of legal claims.
16.7 Right to object to direct marketing
You have the right to object at any time to the processing of your personal data for direct marketing purposes.
Where you object to direct marketing, we will cease processing your personal data for that purpose.
16.8 Right to withdraw consent
Where processing is based upon your consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
16.9 Rights relating to automated decision-making
F&A Grand Auditing does not currently make decisions producing legal or similarly significant effects concerning individuals solely through automated processing.
If this changes, we will provide the information and safeguards required by applicable law.
17. Exercising Your Rights
To exercise any of your data protection rights, or to make an enquiry concerning the way we process your personal data, please contact:
F&A GRAND AUDITING AND CONSULTING LIMITED
Email: contact@grandauditing.com
Postal address:65 Prodromou StreetNikaia Building, 4th Floor, Office 402Strovolos, 2063 NicosiaCyprus
Please provide sufficient information to enable us to identify you and understand your request.
We may request reasonable proof of identity where necessary to ensure that personal data are not disclosed to an unauthorised person.
We will respond to valid requests within the periods prescribed by applicable data protection law. In accordance with the GDPR, this will ordinarily be within one month of receipt of the request, although this period may be extended where permitted by law due to the complexity or number of requests.
There is normally no charge for exercising your data protection rights. We may, however, charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, particularly because of its repetitive nature, where permitted by the GDPR.
18. Limitations on Data Protection Rights
The rights described above are subject to the conditions, exceptions and restrictions provided by the GDPR and applicable Cyprus or European Union law.
In particular, we may be unable to comply fully with a request where processing or retention of information is necessary:
for compliance with a legal obligation;
for anti-money laundering or regulatory requirements;
for statutory or professional audit requirements;
for taxation or accounting obligations;
for reasons of public interest recognised by law;
to protect the rights and freedoms of another person;
for the establishment, exercise or defence of legal claims; or
where another lawful restriction applies.
Where appropriate and legally permissible, we will explain the reason why a request cannot be fulfilled in whole or in part.
19. Complaints
If you have concerns regarding our processing of your personal data, we encourage you to contact us first at contact@grandauditing.com so that we may consider and address your concerns.
You also have the right to lodge a complaint with the:
Office of the Commissioner for Personal Data Protection of the Republic of Cyprus
or, where applicable under the GDPR, with another competent supervisory authority.
The exercise of your right to lodge a complaint does not affect any other administrative or judicial remedy available to you.
20. Information Concerning Other Persons
Where you provide personal data to us concerning another individual, you should ensure, where required by law and appropriate in the circumstances, that:
you are entitled to provide that information to us;
the information is accurate and relevant; and
the individual has been provided with appropriate information concerning the processing of their personal data.
This does not apply where providing such information would be impossible, would involve disproportionate effort, would seriously impair the purpose of the relevant processing, or where another exemption under applicable law applies.
21. Third-Party Websites
Our website may contain links to websites operated by third parties.
F&A Grand Auditing is not responsible for the privacy practices, content or security of third-party websites. Where you follow a link to another website, you should review the privacy information provided by the operator of that website.
22. Children's Personal Data
Our website and professional services are not directed specifically at children.
We do not knowingly seek to collect children's personal data through our website for marketing or similar purposes.
Personal data relating to children may, however, occasionally form part of records provided to us in connection with legitimate professional services, for example where such information is contained in payroll, taxation, accounting, corporate or other client records.
Where such information is processed, it will be handled in accordance with applicable data protection law and only to the extent necessary for the relevant purpose.
23. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
changes in our services or business activities;
changes in the way we process personal data;
changes in technology or service providers;
changes in applicable law or regulatory guidance; or
improvements to our data protection practices.
The current version will be published on our website and the Last Updated date appearing at the beginning of this Privacy Policy will be amended accordingly.
Where a change materially affects the way we process personal data, we will take appropriate steps to bring the change to the attention of affected individuals where required by law.
24. Contact Us
For questions concerning this Privacy Policy, our processing of personal data or the exercise of your rights, please contact:
F&A GRAND AUDITING AND CONSULTING LIMITEDRegistration No. HE 67788
65 Prodromou StreetNikaia Building, 4th Floor, Office 402Strovolos, 2063 NicosiaCyprus
Telephone: +357 22 660102Email: contact@grandauditing.com