1. Who we are
ComplianceSuite is operated by Infocredit Group Ltd ("we", "us", "our"), the data controller for the personal data described in this notice. You can contact our Data Protection Officer using the details in section 11.
2. Personal data we collect
- Identification & contact data — name, work email, job title, company, phone number, country.
- Marketing data — your communication preferences, responses to surveys, content you download.
- Technical data — IP address, device and browser type, pages visited, referrer URL, timestamps.
- Account & usage data (platform users only) — login identifiers, role, audit-log entries, configuration changes.
- Customer data processed on behalf of clients — handled as a processor under our Data Processing Agreement, not under this notice.
3. Purposes & legal basis (GDPR Art. 6)
- Responding to demo requests and sales enquiries — Art. 6(1)(b) steps prior to entering a contract.
- Providing and securing the platform — Art. 6(1)(b) contract performance and Art. 6(1)(f) legitimate interests (security, fraud prevention).
- Direct marketing of similar services to existing customers — Art. 6(1)(f) legitimate interests, with an opt-out in every message.
- Marketing to non-customers — Art. 6(1)(a) consent (PECR / ePrivacy where applicable).
- Compliance with legal obligations (tax, AML, regulator requests) — Art. 6(1)(c).
4. Cookies & similar technologies
We use strictly necessary cookies by default and request your consent for analytics and marketing cookies via our consent banner. See our Cookie Notice for the full list and how to change your preferences at any time.
5. Recipients of your data
- Group entities of Infocredit Group on a need-to-know basis.
- Vetted sub-processors providing hosting, email, analytics, CRM and support — listed in our DPA.
- Auditors, legal advisors, regulators and law-enforcement bodies, where required.
6. International transfers
Where personal data is transferred outside the EEA / UK, we rely on the European Commission's adequacy decisions, the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses (SCCs) with supplementary measures, including encryption in transit and at rest.
7. Retention
- Marketing leads — up to 24 months from last interaction.
- Customer records — duration of the contract + 7 years (AML/audit).
- Server logs — 12 months.
- Cookie consent records — 24 months.
8. Your rights
Under the GDPR and UK GDPR you have the right to:
- Access, rectify or erase your personal data.
- Restrict or object to processing, including direct marketing.
- Receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your supervisory authority (e.g. the ICO in the UK or the Office of the Commissioner for Personal Data Protection in Cyprus).
To exercise any right, email our Data Protection Officer at dpo@infocreditgroup.com. We respond within one month.
9. Security
We maintain ISO/IEC 27001, ISO 9001 and ISO 22301 certified management systems. Technical and organisational measures include encryption, role-based access control, continuous monitoring, vulnerability management and annual penetration testing.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or via a prominent notice on this site at least 30 days before they take effect.
11. Contact — Data Protection Officer
Infocredit Group Ltd · Data Protection Officer
- Address: Philippou Hadjigeorgiou 5A, Acropolis, Nicosia 2006, Cyprus
- Telephone: +357 22 398 000
- Email: dpo@infocreditgroup.com
Working hours: Monday – Thursday 08:30–17:30 · Friday 08:30–14:30 (EET).
