Last Updated: 8 September 2026
PdAudit Chartered Accountants (“PdAudit”, “we”, “us” or “our”) is committed to protecting the privacy and personal data of our clients, prospective clients, website visitors, business contacts and other individuals whose personal data we process.
This Privacy Policy explains how we collect, use, disclose, retain and protect personal data when you:
-
visit or use our website, pdaudit.com;
-
submit an enquiry or contact form;
-
request information about our services;
-
communicate with us by email or telephone;
-
become or act on behalf of a client;
-
interact with us through social media;
-
submit information through Facebook or Instagram lead-generation forms;
-
communicate with us in connection with our accounting, audit, tax, corporate or advisory services; or
-
otherwise interact with PdAudit.
PdAudit processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), applicable Cyprus data protection legislation and other applicable legal, regulatory and professional requirements.
The GDPR requires organisations to process personal data lawfully, fairly and transparently and to observe principles including purpose limitation, data minimisation, accuracy, storage limitation, security and accountability.
1. Data Controller
The data controller responsible for your personal data is:
PdAudit Chartered Accountants
61, Griva Digeni Street
A&V Court, Office 301
3101 Limassol
Cyprus
Telephone: +357 25 828 233
General Email: [email protected]
Data Protection Contact
For privacy and data protection matters, please contact:
Data Protection Contact: PdAudit Chartered Accountants
Email: [email protected]
Important: The email address above should be verified before this Privacy Policy is published.
2. What Is Personal Data?
Personal data means information relating to an identified or identifiable living individual.
This can include information such as a person’s name, email address, telephone number, identification information, IP address and online identifiers. Information relating to an individual in a professional or business context may also constitute personal data.
3. Personal Data We Collect
Depending on how you interact with PdAudit and the services you request, we may collect the following categories of personal data.
3.1 Contact and identification information
This may include:
-
Name and surname;
-
Email address;
-
Telephone or mobile number;
-
Business or company name;
-
Job title or professional position;
-
Business address;
-
Other contact information.
3.2 Information provided through enquiries
When you contact us or submit a form, we may collect:
-
The information contained in your enquiry;
-
Details of the services you are interested in;
-
Information regarding your business or organisation;
-
Information you voluntarily provide in free-text fields;
-
Information necessary to arrange a consultation or follow-up.
3.3 Client and professional-service information
Where you engage PdAudit to provide accounting, audit, tax, corporate or advisory services, we may process additional personal data necessary to provide those services.
Depending on the particular engagement, this may include:
-
Client identification information;
-
Contact details;
-
Company and shareholder information;
-
Director and beneficial-owner information;
-
Financial and accounting information;
-
Tax-related information;
-
Transaction and business information;
-
Employment and payroll-related information;
-
Information contained in accounting records and supporting documents;
-
Information required for audit and assurance work;
-
Information required for anti-money laundering (“AML”) and know-your-customer (“KYC”) obligations;
-
Information required by applicable professional, regulatory or legal requirements.
The exact categories of information processed will depend on the services provided and the circumstances of each engagement.
3.4 Website and technical information
When you use our website, certain information may be collected automatically, including:
-
IP address;
-
Browser type and version;
-
Operating system;
-
Device type;
-
Date and time of access;
-
Pages visited;
-
Referring website;
-
Technical logs;
-
Cookie identifiers;
-
Security and fraud-prevention information.
Some technical information may constitute personal data where it can identify or be reasonably linked to an individual.
4. How We Collect Personal Data
We may collect personal data from:
-
Our website, pdaudit.com;
-
Contact forms;
-
Enquiry forms;
-
Consultation request forms;
-
Email;
-
Telephone;
-
Meetings and consultations;
-
Existing clients;
-
Prospective clients;
-
Authorised representatives;
-
Business contacts;
-
Professional networks;
-
Facebook and Instagram;
-
Meta lead-generation forms;
-
Marketing campaigns;
-
Other third-party platforms or service providers;
-
Publicly available sources, where legally permitted.
Where personal data is obtained from a source other than the individual, we will comply with the applicable transparency requirements under the GDPR. The GDPR generally requires individuals to be informed about the source of their personal data where the information was not collected directly from them.
5. Purposes for Which We Use Personal Data
We may process personal data for the following purposes.
5.1 Responding to enquiries
We use information provided through our website, email, telephone or other channels to:
-
Respond to questions;
-
Provide requested information;
-
Respond to service enquiries;
-
Contact prospective clients;
-
Arrange meetings;
-
Arrange consultations;
-
Provide quotations or proposals;
-
Follow up on enquiries.
5.2 Providing professional services
Where PdAudit is engaged to provide professional services, we process personal data as necessary to provide:
-
Accounting services;
-
Audit and assurance services;
-
Tax services;
-
Corporate services;
-
Advisory services;
-
Other professional services requested by the client.
5.3 Client administration
We may process personal data for:
-
Client onboarding;
-
Client identification;
-
Maintaining client records;
-
Managing professional engagements;
-
Communications;
-
Billing and invoicing;
-
Account administration;
-
Service delivery;
-
Quality control;
-
Internal administration.
5.4 AML, KYC and regulatory compliance
As an accounting and audit practice, PdAudit may be required to collect and retain information to comply with applicable legal and professional obligations.
This may include information required for:
-
Customer/client due diligence;
-
Identification and verification;
-
Beneficial ownership verification;
-
Anti-money laundering requirements;
-
Counter-terrorist financing requirements;
-
Regulatory reporting;
-
Professional obligations;
-
Fraud prevention and detection;
-
Other statutory or regulatory requirements.
Where processing is required by law, we do not rely on consent as the legal basis for that processing.
5.5 Business management and security
We may process personal data to:
-
Manage our business;
-
Maintain appropriate records;
-
Protect our systems and website;
-
Detect and prevent fraud;
-
Maintain information security;
-
Investigate security incidents;
-
Establish, exercise or defend legal claims;
-
Protect our rights and property.
5.6 Marketing
Where permitted by applicable law, we may use personal data to send information about:
-
PdAudit services;
-
Business updates;
-
Events;
-
News;
-
Publications;
-
Other relevant professional information.
Where consent is required, we will obtain appropriate consent before sending such communications.
You may unsubscribe from marketing communications at any time.
6. Legal Bases for Processing
Depending on the circumstances, PdAudit may rely on one or more of the following legal bases under Article 6 of the GDPR.
6.1 Consent
We may process personal data where you have given valid consent.
This may apply to certain marketing activities, cookies or other optional processing activities.
Consent must be freely given, specific, informed and unambiguous. You may withdraw consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
6.2 Contract
Processing may be necessary to:
-
Enter into a contract;
-
Perform a contract;
-
Provide professional services;
-
Manage the client relationship;
-
Take steps at your request before entering into a contract.
6.3 Legal obligation
PdAudit may process personal data where necessary to comply with applicable legal or regulatory obligations.
This may include accounting, taxation, audit, AML/KYC, regulatory, professional and record-keeping requirements.
6.4 Legitimate interests
We may process personal data where necessary for our legitimate interests, provided that those interests are not overridden by your rights and freedoms.
Examples may include:
-
Managing our business;
-
Responding to business enquiries;
-
Managing client relationships;
-
Maintaining business records;
-
Information security;
-
Fraud prevention;
-
Network and system security;
-
Protecting our legal rights;
-
Managing prospective-client relationships;
-
Certain business-to-business marketing activities where legally permitted.
Where we rely on legitimate interests, we consider the nature of the processing and its impact on individuals.
7. Special Categories of Personal Data
PdAudit generally seeks to avoid collecting unnecessary special-category personal data through its website.
However, in connection with professional services, legal obligations or specific client engagements, we may encounter or process information that falls within the special categories of personal data under Article 9 of the GDPR.
Where such processing occurs, PdAudit will ensure that an applicable legal condition under the GDPR permits the processing.
Individuals should therefore avoid submitting sensitive personal information through general website contact forms unless it is specifically requested or necessary.
8. Who May Receive Personal Data
We may disclose personal data to appropriate recipients where necessary for the purposes described in this Privacy Policy and where a valid legal basis exists.
These may include:
-
PdAudit employees and authorised personnel;
-
Professional advisers;
-
Lawyers and legal advisers;
-
Auditors and other professional advisers;
-
IT service providers;
-
Website hosting providers;
-
Cloud service providers;
-
Email providers;
-
CRM and business-management providers;
-
Accounting and financial systems;
-
Cybersecurity providers;
-
Website and analytics providers;
-
Marketing and advertising providers;
-
Meta Platforms and related companies;
-
Google and related service providers where Google services are used;
-
Government authorities;
-
Regulatory authorities;
-
Professional bodies;
-
Banks and payment providers where applicable;
-
Law enforcement authorities where legally required.
Where a third party processes personal data on behalf of PdAudit, we will seek to ensure that appropriate contractual and data protection safeguards are in place.
9. Meta, Facebook and Instagram Lead Generation
PdAudit may use Meta advertising services, including Facebook and Instagram Lead Ads, to generate enquiries.
If you submit a Meta lead-generation form, information such as:
-
Name;
-
Email address;
-
Telephone number;
-
Company/business name;
-
Information contained in your enquiry;
-
Other information voluntarily provided;
may be transmitted to PdAudit.
We may use this information to:
-
Respond to your enquiry;
-
Contact you;
-
Provide information about our services;
-
Arrange a consultation;
-
Follow up on your request;
-
Manage a prospective client relationship.
Meta may separately process personal data in accordance with its own privacy policies and terms.
Where Meta processes personal data for its own purposes, Meta’s own privacy documentation will also apply.
10. Google reCAPTCHA
Our website uses Google reCAPTCHA to help protect website forms and services from spam, abuse, automated submissions and malicious activity.
reCAPTCHA may collect information about your interaction with the website and your browser/device, including technical information such as IP address and other information necessary to assess whether a request is generated by a human user or automated system.
Google may process information in accordance with its own privacy policy. Google’s current privacy policy explains that Google may collect information about browsers, devices, IP addresses and interactions with Google services.
The use of reCAPTCHA is primarily intended to protect the website and its forms against abuse and fraudulent activity.
Where applicable, information collected through reCAPTCHA may be processed by Google in accordance with Google’s applicable terms and privacy practices.
You can review Google’s privacy information here:
11. Cookies and Similar Technologies
Our website may use cookies and similar technologies.
Cookies may be used for:
-
Essential website functionality;
-
Security;
-
Fraud prevention;
-
Remembering preferences;
-
Website performance;
-
Analytics;
-
Understanding website usage;
-
Marketing;
-
Advertising;
-
Measuring campaign effectiveness.
The categories of cookies may include:
Strictly necessary cookies
These may be required for the website to function correctly or securely.
Functional cookies
These may remember choices and preferences made by visitors.
Analytics cookies
These may help us understand how visitors use our website and improve its performance.
Marketing and advertising cookies
Where used, these technologies may help measure advertising campaigns or provide more relevant advertising.
Third-party technologies
Depending on the website configuration, third-party services may include technologies operated by:
-
Google;
-
Meta;
-
Other analytics providers;
-
Advertising providers;
-
Security providers such as Google reCAPTCHA.
Where applicable law requires consent for non-essential cookies or similar technologies, the relevant technologies will only be activated after the appropriate consent has been obtained.
You may also manage cookies through your browser settings and, where available, our website cookie-consent mechanism.
12. International Data Transfers
Some of the technology, cloud, communications, analytics, security or advertising providers we use may process personal data outside Cyprus or the European Economic Area (“EEA”).
Where personal data is transferred outside the EEA, PdAudit will take appropriate measures to ensure that the transfer complies with the GDPR.
Depending on the circumstances, safeguards may include:
-
An adequacy decision by the European Commission;
-
European Commission Standard Contractual Clauses;
-
Appropriate supplementary safeguards;
-
Other lawful transfer mechanisms recognised under applicable data protection legislation.
The specific location of processing may vary depending on the service providers used by PdAudit.
13. Data Security
PdAudit takes appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss, destruction or unlawful processing.
Measures may include:
-
Access controls;
-
Authentication;
-
Password protection;
-
Encryption where appropriate;
-
Secure communications;
-
Backup and recovery procedures;
-
Malware and endpoint protection;
-
Security monitoring;
-
Access restrictions;
-
Confidentiality obligations;
-
Staff awareness and training;
-
Secure handling of client information;
-
Appropriate supplier and processor controls.
Access to personal data is restricted to persons who require access for legitimate business, professional or legal purposes.
While we take reasonable measures to protect personal data, no electronic transmission or storage system can be guaranteed to be completely secure.
14. Data Retention
PdAudit retains personal data only for as long as reasonably necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by applicable law.
Retention periods may therefore vary depending on the nature of the information.
For example:
Website enquiries
Information relating to general enquiries may be retained for as long as reasonably necessary to respond to the enquiry and manage any resulting business relationship.
Prospective clients
Information relating to prospective clients may be retained for as long as reasonably necessary to manage the prospective business relationship and comply with applicable legal requirements.
Clients
Client records may be retained for periods required by applicable accounting, audit, taxation, AML/KYC, professional, regulatory and legal requirements.
Marketing
Marketing information may be retained while there is a valid legal basis for the relevant marketing activity, or until the individual objects, unsubscribes or withdraws consent, subject to applicable legal requirements.
Website and security logs
Technical and security information may be retained for periods appropriate to security, operational and legal requirements.
When personal data is no longer required, PdAudit will take reasonable steps to securely delete, anonymise or otherwise dispose of it.
15. Your Rights Under the GDPR
Subject to applicable conditions and legal limitations, you may have the following rights.
Right to be informed
You have the right to receive clear information about how your personal data is processed.
Right of access
You may request access to personal data we hold about you and information about how it is processed.
Right to rectification
You may request correction of inaccurate or incomplete personal data.
Right to erasure
In certain circumstances, you may request deletion of your personal data.
This right is not absolute. PdAudit may be required to retain information because of legal, regulatory, professional or other obligations.
Right to restriction
You may request restriction of processing in certain circumstances.
Right to object
You may object to processing based on legitimate interests in certain circumstances.
You also have the right to object to direct marketing.
Right to data portability
Where applicable, you may request personal data you have provided to us in a structured, commonly used and machine-readable format.
Right to withdraw consent
Where processing is based on consent, you may withdraw your consent at any time.
Rights relating to automated decision-making
Where applicable, you may have rights relating to decisions based solely on automated processing, including profiling, where those decisions produce legal or similarly significant effects.
PdAudit does not generally make decisions concerning individuals based solely on automated processing that produce such effects.
The GDPR recognises these rights and specifies the circumstances in which they apply.
16. Exercising Your Data Protection Rights
To exercise your rights or ask questions about how PdAudit processes your personal data, please contact:
Data Protection Contact
PdAudit Chartered Accountants
61, Griva Digeni Street
A&V Court, Office 301
3101 Limassol
Cyprus
Email: [email protected]
Telephone: +357 25 828 233
We may need to verify your identity before responding to certain requests.
We will respond to valid requests within the timeframe required by applicable data protection legislation.
17. Right to Lodge a Complaint
If you believe that PdAudit has processed your personal data in violation of applicable data protection legislation, you have the right to lodge a complaint with the competent supervisory authority.
For Cyprus, the relevant supervisory authority is:
Office of the Commissioner for Personal Data Protection
P.O. Box 23378
1682 Nicosia
Cyprus
Telephone: +357 22 818 456
Email: [email protected]
The Cyprus Data Protection Commissioner is the competent supervisory authority for GDPR matters in Cyprus.
The Commissioner confirms that individuals have the right to lodge a complaint where they consider that processing of their personal data infringes the GDPR.
We encourage you to contact PdAudit first so that we have an opportunity to investigate and address your concern.
18. Third-Party Websites
Our website may contain links to third-party websites, social media platforms or other services.
PdAudit does not control the privacy practices of third-party websites.
When you follow a link to another website, that website’s own privacy policy and terms will apply.
This may include websites and services operated by:
-
Google;
-
Meta/Facebook;
-
Instagram;
-
Other professional, technology or advertising providers.
19. Children’s Privacy
Our website and services are not directed specifically at children.
We do not knowingly seek to collect personal data from children through our website.
If you believe that a child has provided personal data to PdAudit without appropriate authorisation, please contact us.
20. Providing Personal Data
In certain circumstances, providing personal data may be necessary for us to:
-
Respond to an enquiry;
-
Provide requested information;
-
Enter into a contract;
-
Provide professional services;
-
Comply with legal or regulatory obligations;
-
Complete client identification or AML/KYC procedures.
Where particular information is necessary for these purposes, failure to provide it may prevent us from responding to an enquiry, establishing a business relationship or providing the requested services.
Where information is optional, we will indicate this where appropriate.
21. Direct Marketing
Where legally permitted, PdAudit may contact existing clients or prospective clients regarding relevant services, events, publications or professional information.
Where consent is required, PdAudit will obtain appropriate consent before sending the relevant communications.
Every marketing communication will provide an appropriate mechanism to unsubscribe or opt out.
You may also contact us at any time at:
to request that marketing communications stop.
22. Automated Decision-Making and Profiling
PdAudit does not generally use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
If this changes in the future, we will provide the information required under applicable data protection legislation regarding the relevant processing and the rights available to individuals.
23. Changes to This Privacy Policy
PdAudit may update this Privacy Policy from time to time to reflect:
-
Changes to our services;
-
Changes to our website;
-
Changes in technology;
-
Changes to our data-processing activities;
-
Changes in applicable legislation;
-
Changes in regulatory or professional requirements.
The latest version will always be published on this page.
The date at the top of this Privacy Policy indicates when it was most recently updated.
24. Contact Us
If you have questions regarding this Privacy Policy or the processing of your personal data, please contact us.
PdAudit Chartered Accountants
61, Griva Digeni Street
A&V Court, Office 301
3101 Limassol
Cyprus
Telephone: +357 25 828 233
General Email: [email protected]
Data Protection Email: [email protected]
Last Updated: 8 September 2026
