OSTRAI LTD

Privacy Notice

Last updated:

1. ABOUT THIS PRIVACY NOTICE

This Privacy Notice explains how Ostrai Ltd (“OSTRAI”, “we”, “us” or “our”) collects and uses personal data in connection with:

  • our website at ostrai.ai (the “Website”);
  • enquiries and communications with OSTRAI;
  • prospective clients and business leads;
  • professional and business relationships;
  • professional networking, referrals, collaborations and business-development activities;
  • the OSTRAI Briefing;
  • our other public-facing business activities; and
  • data-protection enquiries, rights requests and complaints.

We have structured this Notice so that, for each relevant processing activity, you can understand:

  • the categories of individuals concerned;
  • the categories of personal data involved;
  • where the data comes from;
  • the processing operations we carry out;
  • the purpose of the processing;
  • the legal basis on which we rely;
  • where applicable, the legitimate interest pursued;
  • the categories of recipients to whom the data may be disclosed; and
  • how long the information is retained or the criteria used to determine the retention period.

References in this Notice to the “GDPR” are references to Regulation (EU) 2016/679. Where the UK GDPR applies to processing described in this Notice, references to GDPR requirements should be read as including the corresponding UK GDPR requirements where appropriate.

OTHER OSTRAI PRIVACY NOTICES

This Notice does not govern personal data processed specifically in connection with:

  • a client or service engagement;
  • a regulatory representation mandate;
  • a recruitment process; or
  • an employment, consultancy or other workforce relationship.

Separate privacy information may apply to those activities and will be provided or made available where appropriate.

Where an enquiry or prospective-client relationship develops into a service engagement, processing connected with the provision of those services will be governed by the applicable Client & Service Privacy Notice.

2. WHO WE ARE

The controller responsible for the processing described in this Privacy Notice is:

Ostrai Ltd Registration number: HE 378534

Registered office 33 Konstantinou Palaiologou THE SQUARE, 2nd Floor 6036 Larnaca Cyprus

General enquiries: info@ostrai.ai Telephone: +357 24 323333 Website: ostrai.ai

OSTRAI provides regulatory advisory, compliance, representation, standards, conformity and market-access services in areas including artificial intelligence, privacy and data, cybersecurity and product regulation, and digital regulation.

3. DATA PROTECTION OFFICER

OSTRAI has appointed a Data Protection Officer (“DPO”).

You may contact our DPO about any matter relating to OSTRAI’s processing of your personal data, including:

  • questions about what personal data we process and why;
  • questions about this Privacy Notice;
  • requests to exercise your data-protection rights;
  • access, rectification, erasure, restriction, portability or objection requests;
  • withdrawal of consent;
  • questions or requests relating to direct marketing or the OSTRAI Briefing;
  • questions concerning the disclosure, retention, security or transfer of your personal data;
  • privacy enquiries or concerns; and
  • data-protection complaints.

Email: dpo@ostrai.ai

Postal address:

Data Protection Officer Ostrai Ltd 33 Konstantinou Palaiologou THE SQUARE, 2nd Floor 6036 Larnaca Cyprus

4. UNITED KINGDOM REPRESENTATIVE

Ostrai Ltd has appointed PRIVACY MINDERS (UK) LIMITED as its representative in the United Kingdom under Article 27 UK GDPR.

Individuals in the United Kingdom may contact OSTRAI directly or contact our UK Representative on matters relating to OSTRAI’s processing of their personal data under the UK GDPR.

PRIVACY MINDERS (UK) LIMITED UK Representative under Article 27 UK GDPR 1 Kings Avenue London United Kingdom N21 3NA

Email: ukrep@privacyminders.com

The UK Representative may be addressed, in addition to or instead of Ostrai Ltd, by individuals and by the UK Information Commissioner’s Office on issues relating to processing for the purposes of UK GDPR compliance.

5. WHO THIS PRIVACY NOTICE APPLIES TO

Depending on how you interact with OSTRAI, this Privacy Notice may apply to you if you are:

  • a visitor to the Website;
  • a person who contacts OSTRAI;
  • a prospective client or business lead;
  • a director, officer, employee, adviser or other representative of an organisation;
  • another professional or business contact;
  • a referral or collaboration contact;
  • a person we meet or communicate with through professional networking or events;
  • a person whose professional details are provided to us by another person or organisation;
  • a person whose professional details are obtained from an appropriate publicly accessible source;
  • a person referred to in an enquiry or professional communication;
  • an OSTRAI Briefing subscriber;
  • a former Briefing subscriber or other person who has opted out of marketing; or
  • a person who contacts our DPO or exercises a data-protection right.

Information concerning you in your professional or business capacity may still constitute personal data.

6. HOW AND WHY WE PROCESS PERSONAL DATA

6.1 OPERATING AND SECURING THE WEBSITE

Data subjects
Visitors to the Website.
Categories of personal data
IP address; date and time of access; requested page or resource; browser, device and operating-system information; request and response information; technical, application, diagnostic and security log information; other technical information required to deliver and protect the Website.
Source
Generated when your device communicates with the Website and its hosting and infrastructure services.
Processing operations
Collection, transmission, logging, consultation, technical analysis, security monitoring, temporary storage and deletion.
Purpose
To deliver the Website; maintain its availability, integrity and security; troubleshoot technical problems; detect abnormal, malicious or unauthorised activity; investigate security incidents; and protect OSTRAI’s information systems.
Legal basis
Article 6(1)(f) GDPR — legitimate interests.
Legitimate interests
Operating a secure and reliable Website; maintaining business continuity; protecting OSTRAI’s systems and Website users; and preventing and investigating misuse and security incidents.
Categories of recipients
Website hosting and infrastructure providers; Website security and technical-support providers where access is necessary; authorised OSTRAI personnel.
Retention
Technical Website logs are retained for the period configured by the hosting provider. Under Clever Cloud’s standard configuration, application logs are retained for approximately 7 days. Information relating to a specific technical or security incident may be retained for longer where necessary for investigation, remediation, evidential or legal purposes.

OSTRAI does not use Website access logs to create individual marketing profiles.

6.2 ENQUIRIES FROM INDIVIDUALS SEEKING SERVICES FOR THEMSELVES

Data subjects
Individuals who contact OSTRAI about potentially obtaining services in their own capacity.
Categories of personal data
Name; email address; telephone number where provided; content of the enquiry; information and documents submitted; subsequent communications and correspondence.
Source
Directly from you.
Processing operations
Collection, recording, review, internal routing, correspondence, consultation, storage and eventual deletion or archival where justified. Relevant information may be recorded in our CRM, email or document systems.
Purpose
To understand your request; communicate with you; assess whether OSTRAI can provide the requested service; and take steps requested by you before a possible engagement.
Legal basis
Article 6(1)(b) GDPR, to the extent processing is objectively necessary to take steps at your request before entering into a contract with you.
Categories of recipients
Website/form infrastructure providers where applicable; CRM and business-relationship management providers; business email, cloud-productivity and document-storage providers; authorised OSTRAI personnel; limited administrative-support providers where necessary; professional advisers where their involvement is required.
Retention
We retain the information while the enquiry is being considered and for as long as it remains reasonably necessary for legitimate follow-up and management of the prospective relationship. If no engagement or continuing professional relationship develops, inactive records are periodically reviewed and are deleted or anonymised when they are no longer reasonably required. If an engagement is established, relevant information becomes subject to the privacy and retention arrangements applicable to the engagement.

6.3 GENERAL ENQUIRIES AND OTHER COMMUNICATIONS

Data subjects
People who contact OSTRAI for reasons other than seeking pre-contractual steps concerning a contract with them personally.
Categories of personal data
Name; contact information; organisation and professional role where relevant; content of the communication; correspondence history; information voluntarily supplied.
Source
Directly from you.
Processing operations
Collection, recording, review, internal routing, communication, storage and deletion or archival where appropriate.
Purpose
To receive, understand and respond to your communication and maintain an appropriate business record of it.
Legal basis
Article 6(1)(f) GDPR — legitimate interests.
Legitimate interests
Receiving and responding appropriately to communications concerning OSTRAI and administering our business and professional relationships.
Categories of recipients
Business email, cloud-productivity and document-storage providers; CRM providers where the communication is relevant to an ongoing or prospective professional relationship; authorised OSTRAI personnel; limited administrative-support providers where necessary.
Retention
For as long as the communication remains reasonably relevant to its purpose, the professional or business relationship, legitimate business-record requirements, or the establishment, exercise or defence of legal claims. Older records are subject to periodic review.

6.4 REPRESENTATIVES OF ORGANISATIONS

Data subjects
Directors, officers, employees, advisers and other representatives of organisations.
Categories of personal data
Name; organisation; job title or professional role; business email address; business telephone number where supplied; content of enquiries and correspondence; meeting and communication history; contextual information concerning the organisation and professional relationship.
Source
Directly from you and, where relevant, from the organisation you represent.
Processing operations
Collection, recording, CRM organisation, review, correspondence, scheduling, internal consultation, storage, updating and eventual deletion or archival.
Purpose
To communicate with your organisation; respond to enquiries; assess potential relationships and engagements; arrange and administer professional communications; and maintain appropriate relationship records.
Legal basis
Article 6(1)(f) GDPR — legitimate interests.
Legitimate interests
Conducting and developing OSTRAI’s business; communicating with organisations; assessing potential engagements; maintaining professional relationships; and maintaining accurate business records.
Categories of recipients
CRM and business-relationship management providers; business email, cloud-productivity, collaboration and document-storage providers; authorised OSTRAI personnel; limited administrative-support providers where required; relevant professional advisers.
Retention
For as long as the professional or business relationship remains active or the information continues to be reasonably relevant to the relationship, collaboration, referral, networking, business-development or legitimate business-record purposes for which it is held. Older records are periodically reviewed and are updated, deleted, anonymised or otherwise removed from active use when they are no longer reasonably required.

We do not rely on Article 6(1)(b) merely because an organisation that you represent may enter into a contract with OSTRAI.

6.5 PROFESSIONAL CONTACTS, REFERRALS, NETWORKING AND COLLABORATION CONTACTS

Data subjects
Professional contacts, referral contacts, potential collaborators and other business contacts.
Categories of personal data
Name; organisation; professional role; business contact information; information contained on a business card or professional profile; source and context of the relationship; relevant correspondence; meeting or relationship notes.
Source
Directly from you; through professional meetings or events; your organisation; an introducer or other business contact; or an appropriate publicly accessible professional source.
Processing operations
Collection, recording, CRM organisation, consultation, correspondence, updating and retention of relationship history.
Purpose
To establish, maintain and develop genuine professional relationships; manage collaborations, referrals and networking relationships; and maintain appropriate records of previous professional interactions.
Legal basis
Article 6(1)(f) GDPR — legitimate interests.
Legitimate interests
Maintaining and developing OSTRAI’s professional network, collaborations, referral relationships and legitimate business relationships.
Categories of recipients
CRM and relationship-management providers; business email, cloud-productivity and document-storage providers; authorised OSTRAI personnel; limited administrative-support providers where necessary.
Retention
For as long as the professional relationship remains current or the information continues to be reasonably relevant to collaboration, referrals, networking, relationship management or other legitimate professional purposes. The mere passage of time does not automatically end a genuine professional relationship. Older records are periodically reviewed for continued relevance and accuracy.

OSTRAI does not automatically add professional contacts to the OSTRAI Briefing solely because it possesses their contact information.

6.6 PROSPECTIVE CLIENTS AND BUSINESS LEADS

Data subjects
Persons who have expressed an interest in OSTRAI’s services or with whom OSTRAI has had a genuine prospective-business interaction.
Categories of personal data
Name; organisation; professional role; business contact details; nature and source of enquiry or lead; correspondence; proposals and related business-development information; relevant relationship history.
Source
Directly from you; your organisation; a professional introduction; a referral; an appropriate business interaction; or an appropriate publicly available professional source.
Processing operations
Collection, CRM recording, review, correspondence, legitimate follow-up, relationship management, updating and deletion.
Purpose
To respond to prospective-business enquiries, maintain a record of genuine prospective relationships and conduct proportionate business-development follow-up.
Legal basis
Article 6(1)(f) GDPR — legitimate interests, except where Article 6(1)(b) applies to pre-contractual steps requested by an individual personally.
Legitimate interests
Developing OSTRAI’s business, responding to genuine expressions of interest and managing prospective professional relationships.
Categories of recipients
CRM and relationship-management providers; business email and cloud-productivity providers; authorised OSTRAI personnel.
Retention
Prospect information is retained while it remains reasonably relevant to a genuine prospective relationship or legitimate follow-up. In determining whether an inactive prospect record should continue to be retained, we consider the nature and context of the original interaction, the time since the last substantive interaction, whether the individual has indicated continuing interest, whether a genuine professional relationship continues, and whether the information has another legitimate business-record or legal purpose. Records that are no longer reasonably relevant are deleted or anonymised.

Where direct marketing is sent electronically, OSTRAI also complies with applicable electronic-communications and direct-marketing requirements.

6.7 INDIVIDUALS REFERRED TO IN COMMUNICATIONS FROM OTHER PEOPLE

Data subjects
Individuals whose information appears in an enquiry, introduction or other professional communication sent to OSTRAI by another person.
Categories of personal data
Name; organisation; professional role; professional contact details where supplied; and contextual information contained in the communication.
Source
The person or organisation communicating with OSTRAI.
Processing operations
Receipt, review, consultation, use in understanding or responding to the communication, storage and deletion where no longer relevant.
Purpose
To understand the communication and its context, respond appropriately and maintain an accurate record where relevant.
Legal basis
Article 6(1)(f) GDPR — legitimate interests.
Legitimate interests
Receiving, understanding and responding to legitimate professional communications and maintaining appropriate business records.
Categories of recipients
Business email and document-storage providers; CRM providers where relevant; authorised OSTRAI personnel.
Retention
Normally follows the retention criteria applicable to the underlying enquiry, correspondence or professional relationship.

7. CRM AND PROFESSIONAL RELATIONSHIP MANAGEMENT

OSTRAI uses a CRM system to organise professional contacts, enquiries, prospective relationships, communications and relationship history.

Where appropriate business mailboxes are connected to our CRM, relevant business email communications may be synchronised with the CRM so that authorised personnel can maintain an organised and accurate record of professional interactions.

Data subjects
Professional contacts, prospective clients, organisational representatives and other people whose professional interactions with OSTRAI are appropriately recorded in the CRM.
Categories of personal data
Name; professional contact information; organisation and role; relevant communication metadata and content; enquiry and relationship history; business-development information; subscription status where applicable.
Source
Direct interactions with OSTRAI; Microsoft 365 business communications; OSTRAI relationship records.
Processing operations
Recording, synchronisation, organisation, linking contacts to organisations and communications, consultation, updating and deletion. The CRM may use automated functionality to assist with functions such as organisation, relationship intelligence or summarisation.
Purpose
To maintain coherent professional and business records; support continuity of professional relationships; organise enquiries and prospective relationships; and allow authorised personnel to understand relevant previous interactions.
Legal basis
Article 6(1)(f) GDPR — legitimate interests.
Legitimate interests
Efficient and accurate administration of OSTRAI’s professional relationships and business communications.
Categories of recipients
CRM and business-relationship management provider and its authorised subprocessors; authorised OSTRAI personnel.
Retention
CRM information follows the retention criteria applicable to the underlying relationship and purpose. Information is not retained merely because the CRM technically permits indefinite storage.

Automated CRM functionality is used to assist OSTRAI personnel. It is not used by OSTRAI to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning individuals.

8. OSTRAI BRIEFING

8.1 SUBSCRIBING TO AND RECEIVING THE BRIEFING

Data subjects
OSTRAI Briefing subscribers.
Categories of personal data
Email address; subscription date and time; subscription source/page; version of the subscription wording; confirmation status; confirmation date/time; active subscription status.
Source
Directly from you and generated through the subscription process.
Processing operations
Collection; recording of subscription request; double-opt-in confirmation; addition to the mailing list; distribution of the Briefing; updating and deletion.
Purpose
To register and verify your subscription and send you the OSTRAI Briefing.
Legal basis
Article 6(1)(a) GDPR — consent.
Categories of recipients
Email distribution and subscription-management providers; authorised OSTRAI personnel.
Retention
Active subscriber information is retained for as long as you remain subscribed.

The OSTRAI Briefing may contain:

  • regulatory intelligence and regulatory developments;
  • OSTRAI Insights and publications;
  • events and speaking activities;
  • developments in OSTRAI’s services;
  • OSTRAI business and organisational developments; and
  • selected news relating to related entities.

Ostrai Ltd is the controller of the OSTRAI Briefing subscriber list.

Related entities do not independently receive the subscriber list for their own marketing merely because their activities may be mentioned in the Briefing.

Subscription is voluntary.

We do not automatically subscribe you because you:

  • become a client;
  • submit an enquiry;
  • are entered into our CRM;
  • exchange contact details with us;
  • attend an event; or
  • otherwise become a professional contact.

8.2 RECORDING BRIEFING STATUS IN OUR CRM

Once a subscription has been confirmed, OSTRAI may record the fact of that subscription in its CRM.

Data subjects
Confirmed OSTRAI Briefing subscribers.
Categories of personal data
Contact identifier/email address; confirmed subscription status; subscription date/source; subsequent unsubscribe status/date.
Source
Confirmed subscription record.
Processing operations
Matching with an existing contact or creating an appropriate record; recording and updating subscription status; consultation by authorised personnel.
Purpose
To maintain accurate and consistent records of OSTRAI’s interactions with professional contacts and ensure subscription and opt-out status is accurately reflected.
Legal basis
Article 6(1)(f) GDPR — legitimate interests.
Legitimate interests
Maintaining accurate relationship and communication records and avoiding inconsistent or duplicate subscription information.
Categories of recipients
CRM and relationship-management provider; authorised OSTRAI personnel.
Retention
Follows the retention criteria applicable to the professional contact record, while any opt-out information is retained as necessary to respect the person’s marketing preference.

Recording the fact that you subscribed to the Briefing does not convert your consent to receive the Briefing into consent for unrelated marketing communications.

OSTRAI does not use individual Briefing open or click information to build individual engagement or interest profiles or automatically score subscribers as sales leads.

Where the Briefing platform generates aggregate campaign statistics, OSTRAI configures the service so that open and click information is not associated with individual subscribers.

8.3 EVIDENCE OF CONSENT

Where OSTRAI relies on consent for the Briefing, we retain evidence necessary to demonstrate that consent was obtained.

This may include:

  • the email address concerned;
  • the subscription date and source;
  • the consent wording/version;
  • confirmation date where double opt-in is used;
  • subscription status; and
  • subsequent withdrawal information.
Processing operations
Recording, storing, retrieving and retaining evidence relating to consent and withdrawal.
Purpose
To demonstrate that consent was obtained and administered in accordance with applicable data-protection and electronic-marketing requirements.
Legal basis
Article 6(1)(c) GDPR, insofar as retention is necessary to demonstrate compliance with applicable consent and accountability requirements.
Categories of recipients
Email subscription-management providers; authorised OSTRAI personnel; supervisory or judicial authorities where disclosure is legally required.
Retention
For the subscription period and afterwards for the period reasonably necessary to establish and demonstrate the consent and its subsequent withdrawal, taking account of applicable regulatory and limitation periods.

8.4 UNSUBSCRIBING

You may withdraw your Briefing consent at any time:

You are not required to give a reason.

Processing operations
Recording the withdrawal; removing the address from active distribution; updating relevant systems.
Purpose
To give effect to withdrawal of consent or an objection to direct marketing and stop Briefing communications.
Legal basis
Article 6(1)(c) GDPR — compliance with applicable legal obligations concerning withdrawal of consent and direct-marketing objections.
Categories of recipients
Email distribution/subscription-management providers; CRM provider where status is synchronised; authorised OSTRAI personnel.

The operational unsubscribe record is retained as necessary to implement the request and establish the fact and date of withdrawal.

8.5 SUPPRESSION RECORDS

Following an unsubscribe or direct-marketing objection, OSTRAI may retain a minimal suppression record.

Categories of personal data
Email address or another minimal suppression identifier; opt-out status; date of opt-out.
Source
Generated from the unsubscribe or objection.
Processing operations
Retention on a suppression list and matching against future proposed distribution records.
Purpose
To ensure that you are not inadvertently re-added to the Briefing or contacted again for the marketing purpose to which you objected.
Legal basis
Article 6(1)(f) GDPR — legitimate interests.
Legitimate interests
Maintaining effective suppression controls and respecting your marketing choice.
Categories of recipients
Email subscription-management providers; CRM provider where suppression status is recorded; authorised OSTRAI personnel.
Retention
For as long as the relevant marketing activity continues and the minimal information remains reasonably necessary to prevent accidental re-contact.

Unsubscribing from the OSTRAI Briefing does not prevent OSTRAI from sending genuinely necessary service, contractual, regulatory or other non-marketing communications.

9. DATA-PROTECTION ENQUIRIES, RIGHTS REQUESTS AND COMPLAINTS

Data subjects
Individuals contacting our DPO, exercising a data-protection right or raising a privacy concern or complaint.
Categories of personal data
Name and contact information; request, enquiry or complaint content; personal data relevant to the matter; correspondence; limited identity-verification information where necessary; handling, investigation and response records.
Source
Directly from you and, where required, relevant OSTRAI records and systems.
Processing operations
Collection, registration, verification where necessary, search and retrieval, assessment, communication, disclosure where legally required, storage and deletion.
Purpose
To respond to privacy enquiries; facilitate and respond to data-subject rights; investigate privacy concerns and complaints; and demonstrate compliance with applicable law.
Legal basis
Article 6(1)(c) GDPR — compliance with legal obligations.
Categories of recipients
Business email, cloud-productivity and document-storage providers; relevant record-management providers; our DPO and authorised personnel; professional advisers where necessary; supervisory authorities or courts where legally required.
Retention
For the period reasonably necessary to demonstrate proper handling of the matter and to address any related regulatory, complaint or legal issues.

We do not routinely request identity documents where identity can reasonably be verified by less intrusive means.

10. COOKIES, ANALYTICS AND SIMILAR TECHNOLOGIES

At the date of this Privacy Notice, OSTRAI does not use optional Website analytics, behavioural advertising or visitor-identification technologies.

In particular, at launch we do not use:

  • Google Analytics;
  • advertising cookies;
  • cross-site behavioural advertising;
  • individual Website behavioural profiles; or
  • company/visitor-identification tools.

The Website may use technical functionality necessary to deliver, secure or operate the Website.

Our separate Cookies & Tracking Notice explains the cookies and similar technologies actually used on the Website, including their provider, purpose, duration and whether they are necessary or optional.

If OSTRAI introduces optional analytics, advertising or other non-essential tracking technologies in future, the processing will be assessed and the relevant privacy information updated before the technology is enabled.

Where consent is required, the relevant technology will not be activated before valid consent has been obtained.

11. RECIPIENTS OF PERSONAL DATA

11.1 CATEGORIES OF RECIPIENTS

Depending on the processing activity, personal data may be disclosed to:

  • website hosting, infrastructure and security providers used to deliver and secure the Website;
  • CRM and professional relationship-management providers used to organise professional contacts, enquiries and communications;
  • business email, cloud-productivity, collaboration and document-storage providers used for email, documents and internal collaboration;
  • email distribution and subscription-management providers used for the OSTRAI Briefing;
  • limited administrative and business-support providers where access is necessary to perform a particular support function for OSTRAI;
  • professional advisers, including legal, accounting, audit, insurance or other advisers where access is appropriately required;
  • competent regulatory, supervisory, judicial or law-enforcement authorities, where disclosure is required or permitted under applicable law; and
  • other recipients where you have directed or requested disclosure or another lawful basis applies.

OSTRAI does not sell personal data.

OSTRAI does not provide the OSTRAI Briefing subscriber list to third parties for their independent marketing purposes.

12. PRINCIPAL SERVICE PROVIDERS

Articles 13 and 14 GDPR permit controllers to identify either recipients or categories of recipients.

OSTRAI uses the specific recipient categories above and, for additional transparency, identifies below the principal recurring providers selected directly by OSTRAI.

This section does not reproduce every technical subprocessor used by those providers.

12.1 CLEVER CLOUD

OSTRAI uses Clever Cloud for Website hosting and infrastructure.

The Website is configured to be hosted in France.

Clever Cloud may process Website requests, IP addresses and technical/security log information necessary to host and deliver the Website.

12.2 MICROSOFT 365

OSTRAI uses Microsoft 365, including:

  • Exchange Online;
  • Exchange Online Protection;
  • Microsoft Teams;
  • OneDrive for Business; and
  • SharePoint,

for business email, communications, collaboration, productivity and document storage.

According to the data-residency information applicable to OSTRAI’s Microsoft 365 tenant, the Current Geography and Committed Geography for Exchange Online, Exchange Online Protection, Microsoft Teams, OneDrive and SharePoint are European Union/EFTA.

Microsoft’s Product Terms commitment applicable to OSTRAI’s tenant further states that certain Microsoft 365 Core Online Services Customer Data is stored at rest in Cyprus.

These data-residency commitments concern the relevant data-at-rest arrangements and should not be understood as meaning that every processing operation or every form of support or access necessarily takes place exclusively in Cyprus.

12.3 ATTIO

OSTRAI uses Attio as its CRM and professional relationship-management provider.

Attio may process:

  • professional contact details;
  • organisation and role information;
  • enquiries and relationship information;
  • relevant business communications where mailboxes are connected to the CRM; and
  • subscription or opt-out status where relevant.

Attio has confirmed to OSTRAI that its primary CRM infrastructure is hosted on Google Cloud Platform in the European Union and that CRM data and synchronised email content are stored within the EU.

Certain Attio functions use automated or AI-assisted functionality to support CRM features such as organisation, relationship intelligence and summarisation.

Such functionality assists OSTRAI personnel and is not used by OSTRAI for solely automated decisions that produce legal or similarly significant effects concerning individuals.

Attio’s data-processing arrangements provide for applicable safeguards where approved subprocessors involve processing outside the EEA, including Standard Contractual Clauses where required.

12.4 BREVO

OSTRAI uses Brevo to administer subscriptions to and distribute the OSTRAI Briefing.

Brevo may process subscriber email addresses, consent and confirmation information, subscription status and unsubscribe/suppression information.

Brevo states that its database-hosting infrastructure is located within the European Union.

OSTRAI configures the Briefing service to use double opt-in and anonymous email tracking.

Individual open and click information is not associated with individual subscribers or used by OSTRAI to build individual engagement or interest profiles. Aggregate campaign statistics may be generated in anonymised form.

12.5 RAPHAEL LEGAL

OSTRAI may receive limited and occasional administrative and operational support from M. Raphael LLC, trading as Raphael Legal, which is a separate legal entity.

Where Raphael Legal processes personal data solely to provide administrative support to OSTRAI, it does so on OSTRAI’s documented instructions and subject to appropriate confidentiality and data-protection arrangements.

Authorised Raphael Legal personnel may, where necessary for the particular support task, have access to limited information such as:

  • professional contact details;
  • administrative correspondence;
  • scheduling or booking information; and
  • other limited information necessary to perform the requested administrative function.

Raphael Legal does not have general access to OSTRAI’s CRM or to the OSTRAI Briefing subscriber database.

Access is limited to what is necessary for the relevant administrative-support activity.

13. INTERNATIONAL TRANSFERS

Some personal data processed under this Notice is stored and processed within the European Economic Area.

In particular:

  • the Website is hosted in France;
  • the Microsoft 365 workloads identified above have a Current and Committed Geography of EU/EFTA, with certain Microsoft 365 Core Online Services Customer Data stored at rest in Cyprus;
  • Attio has confirmed that its primary CRM data and synchronised email content are stored in the EU; and
  • Brevo states that its database-hosting infrastructure is located within the EU.

However, certain service providers or their approved subprocessors may process personal data or permit access from outside the EEA for particular functions.

Where a transfer of personal data outside the EEA is subject to Chapter V GDPR, OSTRAI requires an appropriate transfer mechanism.

Depending on the circumstances, this may include:

  • a European Commission adequacy decision;
  • Standard Contractual Clauses adopted by the European Commission;
  • Binding Corporate Rules or another safeguard recognised under Articles 46 or 47 GDPR; or
  • an Article 49 derogation where the applicable conditions are satisfied.

Where Standard Contractual Clauses are relied upon, supplementary measures are applied where required by applicable law and the circumstances of the transfer.

You may contact dpo@ostrai.ai for further information concerning safeguards relevant to a particular transfer.

14. PERSONAL DATA OBTAINED FROM SOMEONE OTHER THAN YOU

Most personal data covered by this Notice is either:

  • provided directly by you; or
  • generated through your interaction with OSTRAI or the Website.

We may also receive professional personal data from:

  • your employer or organisation;
  • an introducer;
  • another professional or business contact;
  • a referral source;
  • another person making an enquiry;
  • correspondence in which you are identified;
  • professional meetings or events; or
  • appropriate publicly accessible professional sources.

The relevant source is identified in the applicable processing section above.

Where Article 14 GDPR requires us to provide privacy information directly to you because the personal data was obtained from another source, we will provide the required information within the applicable period, including, as appropriate:

  • within one month of obtaining the personal data;
  • at the time of our first communication with you, if earlier; or
  • before the first disclosure to another recipient,

unless an exception under Article 14 GDPR applies.

15. SPECIAL CATEGORIES OF PERSONAL DATA

The Website, general enquiry process, professional contact process and OSTRAI Briefing are not designed to collect special categories of personal data.

Special categories include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade-union membership, genetic data, biometric data used for unique identification, health information and data concerning a person’s sex life or sexual orientation.

Please do not include sensitive personal information in a general enquiry unless it is genuinely necessary to the matter you are raising.

Where special-category personal data is received and processing is necessary, OSTRAI will identify:

  1. an applicable legal basis under Article 6 GDPR; and
  2. an applicable condition under Article 9(2) GDPR.

Where such information is not necessary for the relevant purpose, we will not use it for an unrelated purpose and may delete it.

16. CRIMINAL-CONVICTION AND OFFENCE INFORMATION

The public Website and OSTRAI Briefing are not designed to collect personal data relating to criminal convictions or offences.

Where such information is processed, OSTRAI will do so only where the requirements of Article 10 GDPR and applicable law are satisfied.

Processing carried out in connection with a particular client engagement or regulatory representation mandate may be governed by separate privacy information.

17. IS PROVIDING PERSONAL DATA MANDATORY?

You may access publicly available Website content without providing us with your name, email address or telephone number.

Certain technical information is necessarily processed when your device communicates with the Website.

If you submit an enquiry, you must provide sufficient information for us to understand and respond to it. If the necessary contact or contextual information is not provided, we may be unable to respond or take the steps requested.

Subscription to the OSTRAI Briefing is entirely voluntary.

Where another interaction requires information because of a legal or contractual requirement, the relevant privacy information will explain that requirement and the possible consequences of not providing the information.

18. AUTOMATED PROCESSING AND AI-ASSISTED FUNCTIONALITY

OSTRAI uses certain business software that may incorporate automated or AI-assisted functionality, including within its CRM.

Such functionality may assist authorised personnel with activities such as organising, reviewing or summarising professional and business information.

OSTRAI does not use personal data covered by this Privacy Notice to make decisions based solely on automated processing, including profiling, that produce legal effects concerning an individual or similarly significantly affect them.

At the date of this Notice, OSTRAI does not:

  • use Website activity to create individual advertising profiles;
  • use visitor-identification technology;
  • use individual OSTRAI Briefing engagement to build behavioural profiles;
  • automatically classify Briefing subscribers as sales-qualified leads solely because they have subscribed; or
  • use AI-generated outputs as the sole basis for decisions producing legal or similarly significant effects concerning individuals.

19. RETENTION OF PERSONAL DATA

OSTRAI does not apply one generic retention period to all personal data.

Retention is determined according to the purpose for which the information is held, the nature of the relationship and the continuing necessity of the data.

WEBSITE TECHNICAL DATA

Website application and access logs are normally retained for approximately 7 days, subject to longer retention where information is needed to investigate a specific technical or security incident or satisfy a legal requirement.

ENQUIRIES AND PROSPECTIVE-CLIENT INFORMATION

Information relating to an enquiry or prospective relationship is retained while:

  • the enquiry is being handled;
  • legitimate follow-up remains appropriate;
  • a genuine prospective professional relationship continues; or
  • the information remains reasonably necessary for another legitimate business-record or legal purpose.

Where no engagement or continuing professional relationship develops, inactive prospect information is periodically reviewed and deleted or anonymised when it is no longer reasonably required.

PROFESSIONAL, NETWORKING, REFERRAL AND COLLABORATION CONTACTS

Professional contact and relationship information may be retained for as long as the professional relationship remains active or the information continues to be reasonably relevant to:

  • collaboration;
  • referrals;
  • professional networking;
  • relationship management;
  • legitimate business development; or
  • the maintenance of appropriate professional records.

A genuine professional relationship does not automatically cease to be relevant merely because a particular period of time has elapsed.

Older records are periodically reviewed for continued accuracy and relevance.

BUSINESS CORRESPONDENCE

Business email correspondence and related records may be retained for as long as they remain reasonably relevant to:

  • the purpose of the communication;
  • a professional or business relationship;
  • a prospective or existing engagement;
  • legitimate business-record requirements;
  • applicable legal or regulatory obligations; or
  • the establishment, exercise or defence of legal claims.

Information that no longer serves an identified and justified purpose is subject to deletion, anonymisation or other appropriate restriction or removal from active use.

OSTRAI BRIEFING

Active subscriber information is retained while the individual remains subscribed.

Evidence of consent is retained for the period reasonably necessary to demonstrate that consent was validly obtained and, where applicable, withdrawn.

Minimal suppression information may be retained while necessary to ensure that an unsubscribe or direct-marketing objection continues to be respected.

PRIVACY ENQUIRIES AND RIGHTS REQUESTS

Records concerning privacy enquiries, rights requests or complaints are retained for the period reasonably necessary to:

  • demonstrate proper handling of the matter;
  • comply with accountability requirements; and
  • address any related regulatory, complaint or legal issue.

OTHER CONTINUING RETENTION PURPOSES

Information may be retained for longer where this is necessary to:

  • comply with applicable law;
  • satisfy a binding regulatory or judicial requirement;
  • establish, exercise or defend legal claims;
  • preserve evidence relevant to an actual dispute or investigation; or
  • investigate and document a security incident.

Where the same information is processed for more than one purpose, deletion from one activity does not necessarily require deletion where another separate lawful and continuing purpose justifies its retention.

Following deletion from active systems, residual copies may remain temporarily within secured backup systems until overwritten or deleted in accordance with normal backup cycles.

20. FURTHER USE OF PERSONAL DATA

We process personal data for the purposes for which it was collected.

Where we propose to use personal data for a new purpose, we assess whether:

  • the new purpose is compatible with the original purpose;
  • an existing legal basis continues to apply;
  • a different legal basis is required; and
  • additional transparency information must be provided.

Where applicable law requires information about a new purpose to be provided before further processing begins, we will provide that information before commencing the new processing.

21. SECURITY

OSTRAI implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Depending on the systems and processing involved, these measures include appropriate:

  • identity and access controls;
  • authentication and account-security measures;
  • secure cloud infrastructure;
  • confidentiality and access restrictions;
  • backup and recovery arrangements;
  • security monitoring;
  • processor and supplier due diligence;
  • contractual data-protection requirements; and
  • organisational data-protection and information-security procedures.

Access to personal data is limited according to role and business need.

We require processors acting on our behalf to implement appropriate security measures and comply with applicable contractual confidentiality and data-protection requirements.

We also maintain procedures for managing suspected personal-data breaches.

No electronic transmission or information system can be guaranteed to be completely secure, and this section should not be understood as providing an absolute security guarantee.

22. YOUR DATA-PROTECTION RIGHTS

Depending on the circumstances and the legal basis for processing, you may have the following rights.

ACCESS

You may ask whether OSTRAI processes personal data concerning you and obtain access to that data and the information required under Article 15 GDPR.

RECTIFICATION

You may ask us to correct inaccurate personal data and complete incomplete personal data.

ERASURE

You may ask us to erase your personal data in the circumstances provided by Article 17 GDPR.

This right is not absolute. We may be required or entitled to retain information for another lawful purpose.

RESTRICTION

You may request restriction of processing in the circumstances provided by Article 18 GDPR.

DATA PORTABILITY

Where the requirements of Article 20 GDPR are satisfied, you may have the right to receive certain personal data you provided to us in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller.

OBJECTION

Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation.

Where you object, we will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or processing is required for the establishment, exercise or defence of legal claims.

DIRECT MARKETING

You may object at any time to processing of your personal data for direct-marketing purposes.

Where you object, we will stop processing your personal data for that direct-marketing purpose.

WITHDRAWAL OF CONSENT

Where processing is based on consent, you may withdraw that consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.

For the OSTRAI Briefing, you may withdraw consent using:

AUTOMATED DECISION-MAKING

Where Article 22 GDPR applies, you have rights concerning certain decisions based solely on automated processing.

OSTRAI does not currently carry out such decision-making in relation to the processing described in this Notice.

23. EXERCISING YOUR RIGHTS OR CONTACTING US ABOUT YOUR PERSONAL DATA

For any data-protection matter, including questions, rights requests or privacy concerns, please contact our DPO:

dpo@ostrai.ai

or write to:

Data Protection Officer Ostrai Ltd 33 Konstantinou Palaiologou THE SQUARE, 2nd Floor 6036 Larnaca Cyprus

Individuals in the United Kingdom may alternatively contact:

PRIVACY MINDERS (UK) LIMITED UK Representative under Article 27 UK GDPR 1 Kings Avenue London United Kingdom N21 3NA

Email: ukrep@privacyminders.com

When exercising a right, please provide sufficient information for us to understand:

  • who you are;
  • the right you wish to exercise; and
  • the personal data or processing concerned.

We may request information reasonably necessary to verify your identity where verification is required.

We will not request more identification information than is proportionate.

There is normally no charge for exercising your data-protection rights.

We will respond within the periods required by applicable law.

24. CHILDREN

The Website and OSTRAI’s services are primarily intended for organisations and professional users and are not directed at children.

We do not knowingly use the Website or OSTRAI Briefing to collect personal data from children for marketing purposes.

If you believe that a child has provided personal data to OSTRAI in circumstances that require our attention, please contact our DPO.

25. THIRD-PARTY WEBSITES AND PLATFORMS

The Website may contain links to third-party websites, publications, professional networks or social-media platforms.

Those organisations may independently process personal data under their own privacy information.

For example, where you interact with OSTRAI through LinkedIn, LinkedIn’s processing of your use of its platform is governed by its own privacy arrangements.

Where OSTRAI receives a communication through such a platform and subsequently processes it for OSTRAI’s own purposes, our processing is governed by this Privacy Notice where applicable.

26. COMPLAINTS

If you have any concern regarding OSTRAI’s processing of your personal data, you may contact our DPO at:

dpo@ostrai.ai

This does not affect your right to lodge a complaint with a competent supervisory authority.

EUROPEAN UNION

As Ostrai Ltd is established in Cyprus, you may contact:

Office of the Commissioner for Personal Data Protection 15 Kypranoros Street 1061 Nicosia Cyprus

P.O. Box 23378 1682 Nicosia Cyprus

Telephone: +357 22 818456 Email: commissioner@dataprotection.gov.cy Website: dataprotection.gov.cy

Depending on the circumstances, you may also have the right under Article 77 GDPR to lodge a complaint with another competent supervisory authority, including a supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement.

UNITED KINGDOM

Where the UK GDPR applies, you may lodge a complaint with the Information Commissioner’s Office.

You may also contact OSTRAI’s UK Representative at:

ukrep@privacyminders.com

27. CHANGES TO THIS PRIVACY NOTICE

We keep this Privacy Notice under review.

We may update it where there is a change to:

  • the categories of personal data we process;
  • processing operations;
  • purposes;
  • legal bases or legitimate interests;
  • recipients or service providers;
  • international transfers;
  • retention arrangements;
  • Website functionality;
  • CRM functionality;
  • the OSTRAI Briefing;
  • cookies, analytics or tracking technologies; or
  • applicable legal or regulatory requirements.

The “Last updated” date at the beginning of this Privacy Notice identifies the current version.

Where a change materially affects people whose personal data we already process, we will consider whether additional steps are required to bring the change to their attention rather than relying solely on publication of an updated Website notice.

28. CONTACT DETAILS

DATA PROTECTION OFFICER

Ostrai Ltd 33 Konstantinou Palaiologou THE SQUARE, 2nd Floor 6036 Larnaca Cyprus

Email: dpo@ostrai.ai

UK REPRESENTATIVE

PRIVACY MINDERS (UK) LIMITED 1 Kings Avenue London United Kingdom N21 3NA

Email: ukrep@privacyminders.com

GENERAL ENQUIRIES

Email: info@ostrai.ai Telephone: +357 24 323333