Privacy Policy

Data Privacy & Data Processing Notice
Effective: 21 May 2026 · Ioannou & Sharpe LLC


1. Who We Are

Ioannou & Sharpe LLC (“we”, “us”, “the Firm”) is a lawyers’ limited company registered in Cyprus under registration number HE 447364. Our registered office is at P.O. Box 53163, 3301 Limassol, Cyprus.

We are the data controller for the personal data we collect through this website, our client portal, and our client engagement processes.

2. Personal Data We Collect

We collect and process the following categories of personal data:

CategoryExamples
IdentityFull name, date of birth, nationality, passport/ID number, photograph
ContactEmail address, phone number, postal address, WhatsApp number
Corporate & ownershipCompany name, registration number, registered address, directors, shareholders, ultimate beneficial owners, corporate structure
Financial & KYC/AMLSource of funds, source of wealth, bank references, risk assessment outputs, PEP status, sanctions screening results
Legal matter dataInstructions, correspondence, case documents, court filings, advice given
Consent recordsGDPR consent choices (services, marketing, AI processing), timestamps, consent versions
Website & bookingPages visited, appointment details (via our own booking system at cal.ios.cy), browser type, IP address

3. Purposes & Legal Bases

We process your personal data for the following purposes, each under a lawful basis required by the General Data Protection Regulation (GDPR):

PurposeLegal basis (GDPR)
Providing legal services and managing client mattersArt. 6(1)(b) — performance of a contract
Fulfilling AML/CFT obligations under Cyprus Law 188(I)/2007Art. 6(1)(c) — legal obligation · Art. 9(2)(g) — substantial public interest
Regulatory reporting and complianceArt. 6(1)(c) — legal obligation
Client relationship management (including engagement letters and billing)Art. 6(1)(f) — legitimate interest
AI-assisted KYC screening and risk assessmentArt. 6(1)(c) — legal obligation (AML/CFT) · Art. 9(2)(g) — substantial public interest
Sending marketing communications (legal updates, events, service information)Art. 6(1)(a) — consent
Website functionality and appointment bookingArt. 6(1)(f) — legitimate interest

Special categories of data: We may process special category data (e.g., data revealing racial or ethnic origin, political opinions, or criminal offences) where necessary for AML/CFT compliance. This is processed under Article 9(2)(g) of the GDPR (substantial public interest) and the Cyprus Data Protection Law 125(I)/2018.

4. AI-Assisted Processing

As part of our KYC and compliance workflow, your submitted information may be processed using AI-assisted tools to assist with:

  • Risk assessment and due diligence screening
  • Sanctions and PEP screening
  • Document analysis

Human review guarantee: All AI-assisted decisions are subject to human review by a qualified compliance officer before any action is taken. No significant decision affecting your legal rights is made solely by automated means.

5. Recipients of Your Data

We may share your personal data with:

Recipient categoryPurpose
Cyprus regulatory authoritiesAML/CFT reporting and compliance obligations
Sanctions screening providersRegulatory compliance checks
AI processing toolsKYC screening and risk assessment (under our control)
Cloud infrastructure providersHosting, security, and application delivery
CRM systemsClient relationship management
Email and communication platformsSending engagement letters, updates, and marketing

We do not sell your personal data to third parties.

6. International Transfers

Some of our service providers operate outside the European Economic Area (EEA), including in the United States. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission where applicable
  • Encryption in transit and at rest

You may request further details about international transfers by contacting us at info@ios.law.

7. Data Retention

Data typeRetention period
AML/CFT records5 years after end of business relationship (Law 188(I)/2007)
Client matter filesDuration of engagement + applicable limitation period
GDPR consent recordsDuration of processing + 3 years
Marketing consent & communicationsUntil withdrawal of consent
Website booking data12 months after appointment

Where retention is required by law (e.g., AML/CFT), we retain data for the minimum statutory period and delete it promptly thereafter.

8. Your Rights

Under the GDPR and the Cyprus Data Protection Law 125(I)/2018, you have the following rights:

Right of access (Art. 15)

You may request a copy of the personal data we hold about you.

Right to rectification (Art. 16)

You may request correction of inaccurate or incomplete personal data.

Right to erasure (Art. 17)

You may request deletion of your personal data, subject to legal retention obligations (e.g., AML/CFT record-keeping requirements). Where deletion is not possible due to legal obligations, we will restrict further processing instead.

Right to restriction (Art. 18)

You may request that we restrict processing of your data while accuracy or lawfulness is contested.

Right to data portability (Art. 20)

You may request to receive your data in a structured, machine-readable format, where processing is based on consent or contract and carried out by automated means.

Right to object (Art. 21)

You may object to processing based on legitimate interest or for direct marketing purposes.

Right to withdraw consent (Art. 7)

Where processing is based on consent (e.g., marketing communications, AI processing), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Right related to automated decision-making (Art. 22)

You have the right not to be subject to decisions based solely on automated processing that produce legal effects. As stated above, all AI-assisted decisions undergo human review before action is taken.

Exercising your rights: To exercise any of these rights, contact us at info@ios.law. We will respond within 30 days. We may request verification of your identity before fulfilling a request.

9. Cookies & Website Tracking

Our website and portal may use minimal technical cookies necessary for security and functionality (e.g., session tokens, CSRF protection). These cookies do not require consent under Article 5(3) of the ePrivacy Directive.

We do not use advertising trackers, analytics cookies, or third-party tracking pixels. If this changes, we will update this notice and obtain your consent where required.

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of data in transit (TLS) and at rest
  • Access controls limiting data access to authorised personnel
  • Secure infrastructure behind authenticated access layers
  • Regular review of security measures

11. Changes to This Notice

We may update this notice from time to time. The effective date at the top indicates when the current version was published. We will notify you of material changes where required by law.

12. Contact & Complaints

Data controller: Ioannou & Sharpe LLC, P.O. Box 53163, 3301 Limassol, Cyprus
Email: info@ios.law
Phone: 70006333

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Cyprus supervisory authority:

Office of the Commissioner for Personal Data Protection
1-3 Ionos Street, 1080 Nicosia, Cyprus
Website: www.dataprotection.gov.cy