WEBSITE PRIVACY NOTICE
Notice regarding the personal data collected through C.E.A. CIRCULAR ECONOMY ALLIANCE LTD’s website and related online services.
C.E.A. CIRCULAR ECONOMY ALLIANCE LTD (‘CEA’, ‘we’, ‘our’ or ‘us’) is committed to protecting your personal data and respecting your privacy. We process personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – ‘GDPR’), applicable Cyprus data protection legislation, including Law 125(I)/2018, and other relevant laws. This Privacy Notice explains how we collect, use, store, disclose and otherwise process your personal data when you visit our website or interact with us.
For the purposes of this Privacy Notice, ‘Personal Data’ means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to information such as a name, identification number, location data, online identifier or one or more factors specific to that person.
‘Processing’ means any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, erasure or destruction.
Please read this Privacy Notice carefully. It contains important information about the personal data we collect, how we use it, the legal bases on which we rely, how long we keep it, and the circumstances in which it may be shared. This Privacy Notice supplements any other privacy notices or policies that may apply to specific services and is not intended to override them.
Your use of our website (hereinafter referred to as ‘our Website’, ‘site’, www.circulareconomyalliance.com) does not constitute consent to all processing activities described in this Privacy Notice. Where consent is required by law, we will request it separately and clearly before processing your personal data.
We may update this Privacy Notice from time to time to reflect changes in our activities, legal requirements or industry practices. Any updates will be published on this page and will become effective upon publication unless otherwise stated. We encourage you to review this Privacy Notice periodically.
The Controller
| Company name: | C.E.A. CIRCULAR ECONOMY ALLIANCE LTD |
| Register Number: | HE 413187 |
| Address: |
4 Loui Loizou Street, Latsia 2221, Nicosia, Cyprus |
| E-Mail: | [email protected]. |
Sources Of Personal Data
We may collect personal data directly from you when you:
- Visit our website.
- Complete a contact form.
- Subscribe to newsletters or updates.
- Register for courses, training programmes, events or webinars.
- Apply for membership or partnership opportunities.
- Communicate with us via email, telephone or social media.
- Participate in surveys, consultations or research activities.
- Interact with our learning management systems or other online platforms.
- Use our training, certification, membership, partnership or learning services.
We may also receive limited personal data from third-party service providers, learning platforms, event registration systems, payment processors, social media platforms, business partners and publicly available sources, where permitted by law.
A. THE DATA WE COLLECT AND HOW WE COLLECT IT
Depending on how you interact with CEA, we may collect and process different types of personal data, including the categories described below. Not all categories will apply to every individual.
- Personal Contact Information
Examples include your name, organisation, job title, postal address, email address, telephone number and other contact details you voluntarily provide.
- Account Login Information
Where applicable, this includes information required to access your account or profile, such as login ID, email address, username, password in protected form, and account security information.
Where applicable, we process login credentials and account information necessary to provide access to our learning platforms, member areas or other online services. Passwords are stored in encrypted, hashed or otherwise protected form and are not accessible to CEA personnel.
- Information from a Computer/Mobile Device
We may collect information about the computer, mobile device, or other technology you use to access our websites or applications. This may include your Internet Protocol (IP) address, device type, operating system, browser type and version, language settings, referring website, and the date and time of access. If you access our website through a mobile device, such as a smartphone or tablet, we may also collect, where permitted by law and subject to your consent where required, device identifiers, approximate location information and other similar technical information.
- Information regarding the Use of the Website
When you navigate and interact with our website or electronic communications, we may collect information about your actions, such as pages viewed, links clicked, time spent on pages, content response times, download errors and other usage statistics. This information may be collected through cookies, web beacons and similar technologies. Where required by law, we will only use non-essential cookies, analytics tools or tracking technologies with your prior consent. You can manage your cookie preferences through our cookie consent tool.
- Market Research and Consumer Feedback
Any information you voluntarily provide to us about your experience with our website, services, courses, events, programmes, partnerships or other CEA activities.
- User- Generated Content
This includes content you choose to create and share with us on third-party social networks or by uploading or submitting it through our website, platforms or other CEA channels. Examples include photos, videos, personal stories, testimonials, comments, case studies, feedback or other similar media or content. Where permitted by law, we may collect, use and, where applicable, publish user-generated content in connection with CEA activities, including events, training programmes, campaigns, website features, community engagement, social media activity, contests or other promotions. Where required by law, we will obtain your consent before publishing or otherwise using such content externally.
- Third Party Social Network Information
Where you interact with CEA through social media platforms such as LinkedIn, Facebook, Instagram or other networks, we may receive information that you choose to make available to us through those platforms, subject to your privacy settings and the privacy policies of the relevant platform provider.
- Payment and Financial Information
Where payments are made for CEA services, courses, events, memberships or other offerings, we may process payment-related information necessary to complete the transaction. CEA does not store complete payment card details. Payment transactions are processed by authorised payment service providers, such as Stripe, in accordance with applicable laws and security standards, including PCI DSS (Payment Card Industry Data Security Standard) where applicable.
- Calls and Recordings
Where you communicate with us by telephone, online meeting platform or similar communication channel, we may process information you provide during that communication. We will only record calls or online meetings where permitted by law and, where required, after informing you in advance.
- Sensitive Personal Data
We do not generally seek to collect or process special categories of personal data, such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data or data concerning sex life or sexual orientation. Where we need to process such data, we will do so only where a valid legal basis under the GDPR applies, such as your explicit consent, compliance with legal obligations, or the establishment, exercise or defence of legal claims.
Personal Data of Children
Our website and services are not directed at children under the age of 14. We do not knowingly collect personal data from children under 14 without appropriate parental or guardian consent, where such consent is required by law. If we become aware that we have collected personal data from a child in circumstances not permitted by law, we will take appropriate steps to delete or anonymise that information.
How we use Cookies/Similar technologies, Log Files and Web Beacons
- Cookies
Cookies are small text files that are placed on your computer or mobile device when you visit a website. They help websites function properly, remember user preferences, improve performance and, where permitted, support analytics or marketing activities. Our Cookie Policy explains the types of cookies we use, their purposes, retention periods and how you can manage your preferences.
- Log Files
We collect information in the form of log files that record website activity and technical information about visits to our website. These records are automatically generated and help us troubleshoot issues, improve performance, maintain security and understand how our website is used.
- Web Beacons
Web beacons (also known as ‘pixel tags’ or ‘tracking pixels’) are small pieces of code that may be included on a website or in an email to collect information about how users interact with content. Information collected through web beacons may include your IP address, browser information and information about how you interact with emails we send to you (for example, whether an email was opened or which links were clicked).
We may use web beacons on our website or in emails we send to you. We may use information collected through web beacons for purposes including website traffic reporting, visitor statistics, email monitoring and reporting, analytics, personalisation and, where applicable, marketing activities. Where required by law, web beacons used for analytics, marketing or similar purposes will only be deployed with your consent.
B. HOW WE USE YOUR PERSONAL DATA
We use personal data only where we have a lawful basis to do so under the GDPR. The purposes for which we process personal data, and the legal bases we rely on, may include the following:
What do we use your Personal Data for?
We may process your personal data for the following purposes:
- To respond to enquiries and communications — Legal basis: legitimate interests or pre-contractual steps.
- To provide access to courses, training programmes, events, webinars, memberships, certifications or other CEA services — Legal basis: performance of a contract or pre-contractual steps.
- To administer user accounts, learning platforms, member areas or online services — Legal basis: performance of a contract and legitimate interests.
- To send newsletters, updates, marketing communications or event invitations — Legal basis: consent, or legitimate interests where permitted by law.
- To manage events, surveys, research activities, consultations or feedback — Legal basis: consent, legitimate interests or performance of a contract, depending on the activity.
- To process payments and maintain financial records — Legal basis: performance of a contract and compliance with legal obligations.
- To improve our website, services, training programmes and communications — Legal basis: legitimate interests and, where required, consent.
- To analyse website use and measure engagement — Legal basis: consent where required for non-essential cookies or analytics technologies.
- To protect the security and integrity of our website, systems and services — Legal basis: legitimate interests and compliance with legal obligations.
- To comply with legal, regulatory, accounting or reporting obligations — Legal basis: legal obligation.
- To establish, exercise or defend legal claims — Legal basis: legitimate interests and legal claims.
- To manage and administer our organisation, maintain records, conduct internal reporting, governance, auditing, business planning and operational activities — Legal basis: legitimate interests and, where applicable, legal obligations.
- We reserve the right, if you have more than one CEA account, to combine these accounts into a single account. We also use your personal data to manage and operate our communications, IT and security systems.
Opting Out
You may withdraw your consent to receive marketing communications at any time by using the unsubscribe link in our emails or by contacting us directly. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal. Where we send communications based on legitimate interests, you may object to receiving such communications at any time.
C. DATA RETENTION
We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide our services, comply with legal, accounting or reporting obligations, resolve disputes, enforce agreements, maintain security, and establish, exercise or defend legal claims.
We may retain personal data for a longer period where required by law, where there is an ongoing relationship with you, where we reasonably believe there is a prospect of a complaint, dispute or legal claim, or where retention is otherwise necessary for the purposes described in this Privacy Notice.
In some circumstances, you may ask us to delete your personal data. Please see the ‘Your Legal Rights’ section below for further information.
In other circumstances, we may anonymise personal data so that it can no longer be associated with you. We may use anonymised information for research, statistical, reporting or business analysis purposes indefinitely.
Typical retention periods may include:
- Website enquiries and contact form submissions: up to 24 months after the last interaction, unless a longer period is required.
- Newsletter and marketing records: until you unsubscribe or withdraw consent, plus a limited period to maintain suppression records and ensure that we do not contact you again for marketing purposes.
- Course, training, certification, event and membership records: for the duration of your participation or relationship with CEA and for a reasonable period thereafter to administer the relevant service, verify participation or certification, respond to enquiries and comply with legal obligations.
- Payment, accounting and tax records: for the period required under applicable law.
- Website analytics and cookie data: in accordance with our Cookie Policy and cookie consent settings.
- Legal claims and dispute-related records: for the applicable limitation period and any additional period reasonably necessary to manage, establish, exercise or defend the claim.
After the relevant retention period expires, we will delete, destroy or anonymise the personal data, unless continued retention is required or permitted by law.
D. WHEN WE MAY DISCLOSE YOUR PERSONAL INFORMATION
We may share your personal data with selected third parties where necessary for the purposes described in this Privacy Notice and where we have a lawful basis to do so.
- Service Providers
These are external organisations that support our operations, including website hosting and maintenance providers, learning management systems, certification platforms, email communication providers, payment processors, analytics providers, social media management tools, professional advisers and other business support services. Service providers and their authorised personnel may process your personal data on our behalf only for the specific tasks they are required to perform in accordance with our instructions and are required to keep your personal data confidential and secure.
Where required by law, you may request further information regarding the categories of recipients with whom we share personal data.
- Third Party Providers (where applicable)
We do not sell your personal data to third parties for their own marketing purposes. Where we share personal data with third parties acting as independent controllers, we will do so only where permitted by law, for example where you have given consent, where the sharing is necessary for the provision of a service, or where we are legally required to do so.
- Third-Party Recipients
We may disclose personal data to courts, regulators, public authorities, law enforcement bodies, professional advisers or other third parties where necessary to comply with legal obligations, protect our rights, or establish, exercise or defend legal claims.
Disclosure, Storage and/or Transfer of your Personal Data
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. However, information that you choose to share publicly, including through third-party social media platforms, may be accessible to others depending on the settings and policies of those platforms.
- Persons who can access your personal data
Your personal data may be accessed by authorised CEA employees, contractors, representatives or service providers only where necessary for the purposes described in this Privacy Notice.
- Operational measures
We store personal data in systems and operational environments that apply appropriate security measures designed to protect against unauthorised access, disclosure, alteration or destruction.
- Transfer of your personal data
Your personal data may be transferred to, accessed from or stored in countries outside the European Economic Area (EEA), including where our service providers or their systems are located outside the EEA. Where such transfers take place, we will ensure that appropriate safeguards are in place, such as an adequacy decision by the European Commission, Standard Contractual Clauses approved by the European Commission, or another lawful transfer mechanism under applicable data protection laws.
Where required by law, further information regarding international transfers and the safeguards applied may be obtained by contacting us.
Business Analyses and Market Research
We may analyse information relating to our business activities, website use, services, courses, events, memberships, enquiries and communications in order to improve our services, understand user needs, evaluate engagement and manage our operations. Where possible, we use aggregated or anonymised information for these purposes. Where personal data is used, we rely on our legitimate interests, provided that those interests are not overridden by your rights and freedoms.
For these purposes, we may process information relating to communications, website usage, service participation, account activity, event participation and other interactions with CEA.
Where you have an account with us, we may use limited account and service usage information to understand how our services are used and to improve user experience. We do not use this information to make decisions that produce legal or similarly significant effects concerning you without appropriate safeguards and a valid legal basis.
Personal data used for business analysis and market research will be retained only for as long as necessary for the relevant purpose, unless it is anonymised, in which case it may be used indefinitely.
E. THIRD PARTIES
Cooperation with Processors, Joint Controllers and Third Parties
We may share personal data with processors, joint controllers or other third parties where necessary for the purposes described in this Privacy Notice and where we have a lawful basis to do so. This may include situations where:
- the disclosure is necessary for the performance of a contract or to take steps prior to entering into a contract;
- you have provided your consent;
- we are required to do so by law or regulatory obligation; or
- the disclosure is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms.
We use selected third-party providers to support our operations, including learning management systems, email communication tools, payment processors, certification platforms, social media management tools, analytics providers and other IT or business support services. Where these providers process personal data on our behalf, they do so only in accordance with our instructions and are required to implement appropriate measures to protect personal data.
- TalentLMS/Epignosis LLC – learning management services. talentlms.com
- Mailchimp/The Rocket Science Group LLC – email marketing and CRM-related services. https://mailchimp.com/features/crm
- Stripe – payment processing services. https://www.stripe.com
- Rustici Software/SCORM-related services – e-learning content and tracking functionality. https://scorm.com/
- Accredible – digital credential and certification services. https://www.accredible.com
- Sprout Social – social media management services. https://app.sproutsocial.com/login
Integration of services and contents of third parties
Our website may include content, tools or services provided by third parties, such as embedded videos, fonts, maps, analytics tools, social media features or other external content (collectively referred to as ‘Content’).
When third-party Content is loaded, the relevant provider may receive technical information such as your IP address, browser information, device information and information about your interaction with the Content. This processing is necessary in order for the Content to be displayed or function correctly.
Some third-party providers may also use cookies, web beacons or similar technologies in connection with their Content. Where required by law, third-party Content that is not strictly necessary will only be loaded after you have provided consent through our cookie consent tool.
For further information about how third-party providers process personal data, please refer to the privacy notices of the relevant providers.
Third-Party Links
Our website may include links to third-party websites, plug-ins or applications. If you click on those links or enable those connections, third parties may collect or process data about you. We do not control third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy notice of every website you visit.
Google Analytics
We may use Google Analytics to understand how visitors interact with our website and to improve functionality, content and user experience. Google Analytics may use cookies or similar technologies to collect information such as IP address, browser type, device information, pages visited, time spent on pages and interactions with website content.
Where required by law, Google Analytics will only be used with your consent. You can manage your preferences through our cookie consent tool. Google’s processing of personal data is subject to Google’s own privacy terms and applicable data processing terms. Further information can be found in Google’s Privacy Policy.
Consent manager
We use Cookiebot or another consent management platform to request, manage and document user choices regarding cookies and similar technologies on our website. Cookiebot is a consent management platform (‘CMP’) that detects and controls all cookies and trackers in use on our website, and automatically manages end-user consent.
The consent management platform allows you to accept, reject or manage different categories of cookies and similar technologies, where applicable.
You can change or withdraw your cookie preferences at any time through the cookie settings tool available on our website.
We process and store your cookie preferences in order to respect and document your choices. The retention period for consent records will depend on the configuration of the consent management platform and applicable legal requirements. At regular intervals (after the user settings have been made), you will be asked again for your consent. The user settings made will then be stored again for this period.
F. YOUR LEGAL RIGHTS
Under certain circumstances, you have rights under data protection laws in relation to your personal data. To exercise any of these rights, please contact us at [email protected] We will respond within the timeframes required under applicable data protection laws.
You are entitled to the following rights:
- Right of access:
You have the right to request confirmation as to whether we process personal data about you and, where applicable, to receive access to that personal data and information about how we process it.
Where your personal data is transferred outside the EEA, you have the right to request information about the safeguards used for that transfer. In this context, you may request to be informed about the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.
This right of access may be restricted to the extent that it is likely to render impossible or seriously impair the achievement of the statistical purposes and the restriction is necessary for the fulfillment of the statistical purposes.
You have the right to receive a copy of the personal data undergoing processing. For additional copies, we may charge a reasonable fee based on administrative costs. If you make the request electronically, the information shall be provided in a commonly used electronic format, unless otherwise specified.
Your right to receive a copy of your personal data must not adversely affect the rights and freedoms of others.
- Right to rectification:
You have the right to ask us to correct inaccurate personal data or complete incomplete personal data.
- Right to restriction of processing:
You may ask us to restrict the processing of your personal data in certain circumstances, for example where you contest its accuracy, object to processing, or where the processing is unlawful but you do not want the data erased.
- Right to erasure:
You have the right to request the erasure of your personal data in certain circumstances. We may refuse or limit erasure where processing is necessary for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims.
- Right to data portability:
Where processing is based on consent or contract and carried out by automated means, you have the right to receive personal data you provided to us in a structured, commonly used and machine-readable format, and to request that we transmit it to another controller where technically feasible.
- Right to object:
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. We will then no longer process the personal data concerning you unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
Where your personal data is processed for direct marketing purposes, you have the right to object at any time. If you object, we will no longer process your personal data for direct marketing purposes.
- Right to revoke your consent:
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
- Automated decisions in individual cases including profiling:
You have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision:
(1) is necessary for the conclusion or performance of a contract between you and the controller,
(2) is permitted by legal provisions of the Union or the Member States to which the controller is subject, and these legal provisions contain appropriate measures to protect your rights and freedoms as well as your legitimate interests; or
(3) is made with your express consent.
However, these decisions may not be based on special categories of personal data under Article 9(1) of the GDPR, unless Article 9(2)(a) or (g) applies and appropriate measures have been taken to protect the rights and freedoms as well as your legitimate interests.
With regard to the cases mentioned in (1) and (3), we take reasonable steps to safeguard the rights and freedoms as well as your legitimate interests, which include at least the right to obtain the intervention of a person on the part of the controller, to express your point of view and to contest the decision.
- Right to complain to a supervisory authority:
Without prejudice to any other administrative or judicial remedy, you have the right to complain with a supervisory authority, in particular in the Member State of your residence, workplace or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority to which the complaint has been submitted will inform the complainant of the status and outcome of the complaint, including the possibility of a judicial remedy under Article 78 GDPR.
No fee is usually required:
You will not usually have to pay a fee to exercise your rights. However, we may charge a reasonable fee or refuse to comply with a request where the request is clearly unfounded, repetitive or excessive.
What may we need from you?
We may request specific information from you to confirm your identity and verify your right to exercise a data protection request. This is a security measure to ensure that personal data is not disclosed to a person who is not entitled to receive it. We may also contact you for further information in order to respond to your request.
Any subject access request must be made in writing to C.E.A. CIRCULAR ECONOMY ALLIANCE LTD, [email protected].
G. CHANGES TO THIS POLICY
If we change how we handle personal data, we will update this Privacy Notice. Historic versions may be obtained by contacting us.
If you have any questions or comments about this policy and our privacy practices, or if you would like to make a complaint regarding our compliance with applicable privacy laws, please contact us as mentioned below.
H. How can you file a complaint?
If you have any complaint or concern about the way we process your personal data, you may contact us directly at [email protected] We will review your complaint and respond as soon as reasonably possible.
You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus. You can find information regarding the filing of complaints on the relevant website (http://www.dataprotection.gov.cy).
I. CONTACT US
Questions, comments and requests regarding this Privacy Notice or our handling of personal data should be addressed to: [email protected]



















































































































