Privacy Policy
Last updated: June 30, 2026
This Privacy Policy explains how Eraikey Labs Ltd ("Eraikey", "we", "us" or "our") collects and uses personal data when you visit our website, contact us, schedule a call, request a proposal, or use our professional services. For the purposes of applicable data protection laws, Eraikey Labs Ltd is the controller of the personal data described in this Privacy Policy. You can contact us at legal@eraikey.com. This Privacy Policy is provided for transparency. We do not rely on your general consent to this Privacy Policy as the legal basis for all processing. Where consent is required, we will request it separately.Personal information that we collect includes:
- Identifiers, such as your name, username or similar identifier, title;
- Contact information, such as your postal address and electronic mail address;
- Business information, such as your company name, role, project name, and information you provide when requesting a proposal or audit.
- Correspondence, such as information you provide when you correspond with us;
- Scheduling information, such as information you provide when booking a call through Calendly.
- Financial information, such as tax identification numbers, bank account information;
- Transaction information, such as details about purchases and invoice details;
When you visit our website, our infrastructure providers may process limited technical information, such as IP address, request metadata, browser information, and security-related logs, as necessary to deliver, secure, and operate the website. We do not use this information to identify visitors, create user profiles, or conduct marketing analytics.
Where we collect your data
We collect information from you when you:
- request a quote via our Contact form;
- request a call via our Calendly link;
- correspond directly with us through electronic mail, social media or other means of communication;
- enter into an engagement, statement of work, or other agreement with us;
- visit our website, where technical information may be processed by our website infrastructure providers.
How we use that information
We process your data to:
- manage our business relationship with you, including:
- to communicate with you and manage your requests in relation to our services, including proposals and invoices.
- to carry out our obligations arising from any contracts entered between you and us, including statements of work, retainers, audit agreements, or other engagement documents;
- To allow you to provide feedback, when you agree to do so.
- comply with applicable legal or regulatory obligations, which includes anti-fraud and anti-money laundering measures.
- protect our website, systems, services, clients, and business from spam, abuse, unauthorized access, and security threats.
Legal bases for processing
We process personal data on the following legal bases:
- Steps prior to entering into a contract and performance of a contract, when we respond to inquiries, prepare proposals, deliver services, manage retainers, and issue invoices.
- Legitimate interests, including operating our website, responding to business inquiries, protecting our systems, preventing abuse, and managing client relationships.
- Legal obligations, including accounting, tax, sanctions, anti-fraud, and other compliance obligations.
- Consent, where we specifically ask for it, such as for optional feedback, marketing communications, or non-essential cookies.
Who has access to your personal data
We may share personal data with the following categories of recipients:
- Service providers that help us operate our website and business, including Calendly for appointment scheduling, Cloudflare for website delivery, performance and security, and Amazon Web Services for email delivery through AWS SES.
- Professional advisers, including accountants, lawyers, auditors, insurers, and banks, where necessary for our business operations.
- If we are required to do so by law or legal process;
- To law enforcement authorities or other government officials pursuant to lawful request;
- To protect our property, services, and legal rights;
- To a prospective buyer, in the event of a merger or sale, or other transfer of all or part of our business.
Cookies and similar technologies
Our website may use strictly necessary technical and security cookies, including cookies set by Cloudflare when needed for website security, bot mitigation, traffic management, or similar purposes. These cookies are used to operate and protect the website.
If we use analytics, marketing, or other non-essential cookies in the future, we will update this Privacy Policy and, where required, request your consent.
How long do we keep your data?
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy and in accordance with our legal, accounting, tax, security, and dispute-resolution obligations. In general:
- business inquiries and proposal-related correspondence that do not result in an engagement are generally kept for up to 24 months after our last meaningful contact with you, unless we need to keep them longer to resolve a dispute, protect our legal rights, or comply with law.
- if an inquiry results in an engagement, relevant correspondence, proposal materials, statements of work, contracts, deliverables, billing records, tax records, and accounting records are generally kept for the duration of the engagement and then for at least six years from the end of the relevant financial or tax period, or longer where required by applicable law or necessary to establish, exercise, or defend legal claims;
- scheduling records, including information processed through Calendly, are generally kept for up to 12 months after the scheduled meeting, unless the meeting relates to an ongoing or potential engagement, in which case the information may be retained with the related business records;
- technical and security logs are generally kept for up to 90 days, unless a longer period is needed to investigate abuse, fraud, security incidents, service integrity issues, or legal claims;
- optional feedback, testimonials, or marketing-related communications are kept until you withdraw consent or object, or until they are no longer needed for the purpose for which they were collected.
Security of your data
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful access, disclosure, alteration, loss, or destruction, taking into account the nature, scope, and purposes of our processing and the risks involved. While we work to protect personal data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children
Our website and services are intended for business users and are not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
Your data protection rights
These include:
- the right to request access to your personal data.
- the right to request portability of your personal data to permit you to transmit that personal data to other organizations.
- the right to request that we amend data you believe to be incomplete or inaccurate.
- the right to request that we restrict or stop the processing of your personal data, in some limited circumstances.
- the right to object to processing based on our legitimate interests, in some circumstances.
- the right to withdraw consent where we rely on consent.
- the right to request that we delete your personal data, in some limited circumstances.
- the right to lodge a complaint with your local data protection authority. If you are based in Cyprus, your local supervisory authority is the Office of the Commissioner for Personal Data Protection (Γραφείο Επιτρόπου Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), which you can contact at commissioner@dataprotection.gov.cy. If you are located in another EU/EEA country, you may also contact your local data protection authority.