Governance

Data Policy

Our privacy policy explains your rights. This data policy is the operational layer beneath it: the systems that hold your data, who inside the company can see it, how long it stays, and what happens if something goes wrong.

Last updated 1 August 2026 · Arvora Developments Ltd

1. Principles we work to

Every process is designed around five commitments.

  • Collect the minimum. If a field does not change how we advise you, we do not ask for it.
  • One purpose at a time. Data given for a viewing is not repurposed into advertising without consent.
  • Named ownership. Each system has an internal owner accountable for access and retention.
  • Delete by default. Retention periods are set when a system is adopted, not improvised later.
  • Human review. Automated scoring may order our follow-up, but a person always makes the decision.

2. Categories of data we hold

Enquiry and lead records, marketing subscription records, reservation and contract files, supplier and contractor records, and aggregated website analytics. Special category data is not collected. Payment card data is never stored by us — banks and payment providers handle it directly.

3. Systems and processors

Each processor is engaged under a data processing agreement, holds only the fields it needs, and is reviewed annually.

  • CRM and lead routing: enquiry contact details, interest and pipeline notes, accessible to the sales team.
  • Transactional email: delivery of confirmations and document links triggered by your actions.
  • Newsletter and market updates: email address, language and consent state, used only while you remain subscribed.
  • Tag management and analytics: pseudonymised usage data, with IP truncation where supported.
  • Advertising measurement: hashed identifiers used to attribute campaigns, sent only with consent.
  • Hosting, database and storage: the platform that runs this site and stores submitted enquiries.

4. Access control

Access is granted by role, not by seniority. Sales staff see the enquiries assigned to them, finance sees transaction records, and administrators hold system-level access under individual accounts with multi-factor authentication. Access is reviewed quarterly and revoked on the day a person leaves.

5. Retention schedule

Website analytics are retained in pseudonymised form for 14 months. Unconverted enquiries are deleted or anonymised 24 months after last contact. Marketing records end at unsubscribe, with a minimal suppression entry retained. Reservation, contract, tax and anti-money-laundering records are retained for the statutory periods applicable in Cyprus, then destroyed securely.

6. International transfers

Some providers operate outside the European Economic Area. In those cases we rely on an adequacy decision or the European Commission's standard contractual clauses, together with encryption in transit and at rest, and we record the transfer basis in our processor register.

7. Security measures

Encrypted connections across the site and all internal tools, least-privilege database policies, environment-isolated credentials, secrets held outside application code, logging of administrative actions, and regular dependency and configuration reviews.

8. Incident response

Suspected incidents are triaged the same day. If a personal data breach is likely to present a risk, we notify the Office of the Commissioner for Personal Data Protection within 72 hours of becoming aware and inform affected individuals directly where the risk is high, describing what happened, what data was involved and what we are doing about it.

9. Requests and escalation

Data subject requests, processor questions and security reports should be sent to info@arvora.com.cy. Reports are acknowledged within two working days.