Last updated: 25 September 2026
This Privacy Policy explains how Vimetco PLC, with its registered office at 18 Navarinou Street, Navarino Business Centre, 1100 Nicosia, Cyprus (“Vimetco”, “we”, “us”) processes personal data collected through this website, in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and the applicable law of the Republic of Cyprus. Vimetco is the controller of this data.
1. Personal data we collect
- Contact form: your name, company, email address, phone number, the department you select, the subject and the content of your message.
- Shareholders area: your username, name and email address, your password (stored only in encrypted, hashed form) and a record of your sign-ins and document downloads (date, time and IP address).
- Technical data: IP address, browser type and the date and time of access, recorded in the server logs for security purposes.
2. Purposes of processing
- to answer your enquiries and forward them to the right department;
- to give registered shareholders access to the documents published in the shareholders area;
- to keep the website secure and prevent misuse;
- to comply with our legal obligations.
3. Legal grounds
We process personal data on the basis of Article 6(1) GDPR: to take steps at your request (point b), to comply with legal obligations (point c), for our legitimate interests in communicating with shareholders and investors and in securing the website (point f) and, where we ask for it, on the basis of your consent (point a), which you may withdraw at any time.
4. Recipients and transfers
Your data may be disclosed, strictly as needed, to our hosting provider (acting as a processor under a written agreement), to companies of the Vimetco Group when this is necessary to answer your request, to our professional advisers and to public authorities where required by law. We do not sell personal data. If data has to be transferred outside the European Economic Area, we do so only with appropriate safeguards, such as an adequacy decision of the European Commission or standard contractual clauses.
5. Security
We use appropriate technical and organisational measures to protect personal data, including encrypted connections (HTTPS), restricted access, hashed passwords and storage of shareholder documents outside the public web directory.
6. Retention
We keep personal data only for as long as necessary for the purposes above: correspondence generally for no longer than three years after our last exchange, shareholder accounts for as long as access to the shareholders area is needed, and security logs for a limited period — unless a longer period is required by law.
7. Cookies
Information about the cookies used on this website is available in our Cookie Policy.
8. Your rights
You have the right to access your personal data, to have it rectified or erased, to restrict or object to its processing, to data portability and to withdraw your consent at any time. You also have the right to lodge a complaint with the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy).
9. Contact
To exercise your rights or for any question about this policy, please use our contact form (department “Management”) or write to us at the registered office address above.
10. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always published on this page, with the date of the last update shown at the top.
