Privacy Policy
1. Who we are and how to contact us
BrokTechno is a trading brand of BROKTRADING LTD, a private limited liability company incorporated in the Republic of Cyprus under registration number HE 342927, with registered office at Orfeos Street 2B, Office 201, 1070 Nicosia, Cyprus, VAT number CY10342927L. BrokTechno is a brand, not a separate legal person. Where this policy says “we”, “us” or “BrokTechno”, the legal person responsible is Broktrading Ltd.
Broktrading Ltd is the controller of the personal data described here. Contact us at info@broktechno.com, or by post at the registered office above, marked for the attention of the Data Protection contact.
We have not appointed a Data Protection Officer. Our processing does not meet the conditions in Article 37(1) of the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) that would require one.
2. What this policy covers
It explains how we handle personal data when you visit broktechno.com, send us an enquiry, or deal with us as a prospective or actual client, supplier or partner. It applies to us acting as a controller, meaning we decide why and how the data is used.
It does not cover the systems we build and operate for our clients. When we develop, integrate or host a platform, CRM, client area or any other system for a brokerage, the data inside that system belongs to our client, who is the controller of it. In that role we act as a processor, on the client’s documented instructions and under a separate written data processing agreement. If you are a customer of one of our clients and want to know how your data is used, ask that firm, not us.
3. The personal data we collect
3.1 The enquiry form
The form on our site has six fields. Four are required and two are optional:
| Field | Required | What we do with it |
|---|---|---|
| Name | Yes | Address you properly in our reply |
| Surname | Yes | As above |
| Company | Optional | Understand who is asking, and prepare a relevant answer |
| Email address | Yes | Reply to you. This is the route back, which is why it is required |
| Phone number | Optional | Call you back, if you would rather speak than write. Give it only if you want to be called |
| Message | Yes | Understand what you are asking for |
What happens if you do not provide the required fields. The form will not submit without your name, surname, email address and message, so there is no way to send us an enquiry without them. That is the only consequence: we do not refuse you anything else, and you can always email us directly instead. Company and phone number are genuinely optional. Leaving them blank has no effect on whether or how we reply, and we will not chase you for them.
We ask you not to send special categories of personal data, such as health, political or religious information, through this form. We do not need it and we do not want it. Do not put confidential commercial information in an enquiry either. Use it to start a conversation, not to conduct one.
3.2 Email
If you email us directly, we hold your address, your name as it appears on the message, and whatever you write, together with our reply and any subsequent correspondence.
3.3 Information recorded automatically
Our hosting provider keeps standard server logs of requests to the site: IP address, date and time, the page requested, the referring page, and browser and device type. These are technical records used to keep the site running and protect it from abuse. We run no analytics on this website, and we do not build a profile of you or track you between visits or across other sites.
3.4 Information from an engagement
If your firm engages us, we hold the business contact details and correspondence of the people we work with, and the commercial, contractual, invoicing and due diligence records of the engagement.
4. Why we use it, and our legal basis
We rely on no consent-based processing on this website, because there is nothing here that requires consent. There are no cookies, no analytics and no tracking. See section 5.
| Purpose | Legal basis (GDPR Article 6) | Notes |
|---|---|---|
| Reading your enquiry and replying to it | Article 6(1)(b), steps taken at your request before entering a contract; or Article 6(1)(f), our legitimate interest in answering business enquiries | Only what you chose to type |
| Preparing a proposal and negotiating an engagement | Article 6(1)(b) | |
| Providing, supporting and invoicing our services | Article 6(1)(b); or Article 6(1)(f) where the contract is with your employer rather than you personally | Business contact data of client personnel |
| Keeping the site available, and protecting it from abuse and spam submissions | Article 6(1)(f), our legitimate interest in the security and integrity of our own systems | Server logs |
| Meeting accounting, tax, anti-money-laundering and other statutory duties | Article 6(1)(c), compliance with a legal obligation | Client and supplier records |
| Establishing, exercising or defending legal claims | Article 6(1)(f) |
Where we rely on legitimate interests we have weighed them against your interests and rights and concluded they are not overridden, because the processing covers business contact and technical data only, is what anyone would expect of a business-to-business supplier answering an enquiry, and can be objected to at any time under section 10.
We do not send marketing email. If that changes, we will ask for your consent first and this policy will be updated before we do.
5. Cookies
This website sets no cookies. None, of any category, first-party or third-party. There is no consent banner because there is nothing to consent to. Our Cookie Policy sets this out in full, including the one third-party request the site does make, for a typeface.
6. Who we share it with
We do not sell personal data and we do not share it for anyone else’s marketing. We disclose it only to:
- Service providers acting for us, under written contract and only on our instructions: namely Vercel Inc. (website hosting and server logs), Supabase, Inc. (receipt and delivery of contact form submissions) and Microsoft (the corporate mailbox that receives the enquiry), each acting on our instructions under a written contract meeting Article 28 GDPR, together with our accountants.
- Our font provider. The site loads a typeface from a third-party font service, which as a technical consequence of serving the file receives your IP address and browser details. It receives nothing you type.
- Professional advisers, being our lawyers, auditors and insurers, where they need it to advise us.
- Companies in our group, being our parent BTG S.r.l. and affiliated brands, where a specific enquiry or engagement concerns them.
- Public authorities, courts and regulators, where we are legally required to disclose.
- A buyer or successor, if we sell or reorganise the business, subject to equivalent protection.
7. Transfers outside the European Economic Area
We prefer suppliers hosting within the EEA. Where a supplier processes personal data outside it, we transfer only on a basis permitted by Chapter V of the GDPR: an adequacy decision of the European Commission covering the destination country, or the European Commission’s Standard Contractual Clauses with any additional measures a transfer risk assessment shows to be necessary. Ask us and we will tell you which applies to a given supplier.
8. How long we keep it
| Category | Retention |
|---|---|
| Form submissions and email enquiries that do not lead to an engagement | 24 months from the last contact, then deleted |
| Client and supplier contractual records | 6 years from the end of the relationship, covering the limitation period for contractual claims |
| Accounting and tax records | 6 years, as required by Cyprus tax and companies legislation |
| Website server logs | 12 months |
Where a record is needed for a live or anticipated legal claim we keep it until that matter is closed, even if the period above has expired.
9. How we protect it, and automated decisions
We apply technical and organisational measures appropriate to the risk: encryption in transit, access on a need-to-know basis, multi-factor authentication on business systems, logging, supplier due diligence, and written confidentiality obligations on our people. No transmission over the internet is completely secure, and we cannot guarantee the security of anything you send us before it reaches us.
We make no decisions about you producing legal or similarly significant effects by automated means, and we carry out no profiling. Our services are sold to businesses; the site is not directed at children and we do not knowingly collect data from anyone under 18.
10. Your rights
Subject to the conditions and exemptions in the GDPR, you have the right to be told what we hold about you and receive a copy of it, to have inaccurate data corrected and incomplete data completed, to have data deleted where we no longer have good reason to keep it, to have our use restricted while a dispute is resolved, to receive data you gave us in a structured, commonly used, machine-readable format and have it sent to another controller where technically feasible, and to object to processing we base on legitimate interests.
To exercise any of these, email info@broktechno.com. We respond within one month, and will tell you if we need to extend that by up to two further months because the request is complex. There is no fee unless a request is manifestly unfounded or excessive. We may ask for information to confirm your identity first.
11. Complaints
Please raise any concern with us first at info@broktechno.com so we can put it right. You also have the right to complain to the supervisory authority in Cyprus, the Office of the Commissioner for Personal Data Protection, Iasonos 1, 1082 Nicosia, Cyprus, telephone +357 22 818 456, email commissioner@dataprotection.gov.cy, website www.dataprotection.gov.cy. If you live or work in another EEA state you may complain to your local supervisory authority instead.
12. Changes to this policy
We review this policy when our processing changes and at least once a year. The version number and date appear under the title. Where a change materially affects your rights we will bring it to your attention rather than rely on you noticing a new version.
13. Document control
| Controller | Broktrading Ltd, HE 342927, trading as BrokTechno |
|---|---|
| Contact | info@broktechno.com |
| Version | 2.0, replacing version 1.0 of the same date |
| Basis of this version | No cookies anywhere on the site; enquiry form taking name, surname, email and message as required, company and phone number as optional |
| Effective from | 13 August 2026 |
| Next review | 13 August 2027, or on any material change to processing |