GDPR Compliance
Our commitment to the EU General Data Protection Regulation (Regulation (EU) 2016/679) and how to exercise your data subject rights with EuroLexAI.
Last updated · May 2026
1. Data controller
The data controller for personal data processed through EuroLexAI is Infocredit Group Ltd, Filippou Chatzigeorgiou 5a, Nicosia 2006, Cyprus.
Compliance enquiries: compliance@infocreditgroup.com · +357 22 398000
2. Principles we apply
- Lawfulness, fairness and transparency — clear notices and a documented legal basis for every processing activity.
- Purpose limitation — data is used only for the purposes communicated to you.
- Data minimisation — we collect only what is necessary.
- Accuracy — you can correct your data at any time.
- Storage limitation — defined retention periods, then deletion or anonymisation.
- Integrity and confidentiality — encryption, access controls and audit logging.
- Accountability — Records of Processing Activities (ROPA) and Data Protection Impact Assessments (DPIAs) where required.
3. Your rights as a data subject
- Right of access (Art. 15) — a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — correction of inaccurate data.
- Right to erasure (Art. 17) — deletion where conditions are met.
- Right to restrict processing (Art. 18).
- Right to data portability (Art. 20).
- Right to object (Art. 21), including to direct marketing.
- Right not to be subject to solely automated decisions (Art. 22) producing legal or similarly significant effects.
- Right to withdraw consent at any time, without affecting prior lawful processing.
- Right to lodge a complaint with a supervisory authority.
4. How to exercise your rights
Send a written request to compliance@infocreditgroup.com with enough information to verify your identity and the right you wish to exercise. We will respond within one month of receipt, in line with Article 12(3) GDPR. The first response is free of charge.
5. International transfers
Where personal data is transferred outside the European Economic Area, we rely on EU Standard Contractual Clauses (SCCs) and supplementary measures, following the European Data Protection Board's guidance on transfer impact assessments.
6. Data breach notification
We maintain incident response procedures. Where a personal data breach is likely to result in a risk to rights and freedoms, we notify the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus within 72 hours, and affected data subjects without undue delay where the risk is high.
7. Supervisory authority
You can lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus or the supervisory authority of your EU country of residence.
8. Related policies
See the Privacy Policy, Cookie Policy and Terms of Service.