Privacy Policy

How Cyprus Motors & Marine handles personal data.

This notice explains what personal data we collect, why we use it, how long we keep it, who we share it with, and the rights available to people who use the CMM marketplace, editorial products, enquiries and deal alerts.

Last updated: April 25, 2026

Who we are

Cyprus Motors & Marine operates a marketplace and editorial platform for cars, leasing and marine inventory in Cyprus. In GDPR terms, Cyprus Motors & Marine acts as the controller for personal data we collect through our public website, user accounts, enquiries, concierge requests, deal alerts and related communications.

This policy applies to information collected through the CMM website, account flows, contact forms, lead and concierge enquiries, deal alerts, and related communications with buyers, readers, partners and prospective partners.

What we collect

The exact data we process depends on how you use the platform. We may collect:

  • Identity and account data such as name, email address, sign-in identifiers, locale, and account preferences.
  • Enquiry and concierge data such as budget, district, timeline, vehicle or vessel preferences, notes, contact method, phone number and WhatsApp number where provided.
  • Deal alert and watchlist data such as saved vehicles, alert filters, districts, preferred makes, fuel types and notification email.
  • Communication data such as messages you send us, support requests, and responses to follow-up questions.
  • Usage and device data such as IP address, browser information, pages viewed, approximate device or session identifiers, consent choices and security logs.
  • Partner or business-contact data where someone enquires about working with CMM as a commercial partner.

We also process listing and market data from public or partner sources in order to run the marketplace and editorial products. Where a listing contains personal data, we aim to minimise exposure and display public-market information in line with our product rules.

How we receive personal data

We receive personal data directly from you when you fill in forms, register an account, save listings, set a deal alert, submit an enquiry or contact us. We also receive technical and authentication data from the systems that support sign-in, hosting, analytics, consent management, security and customer communication.

How we use data and our legal bases

We only use personal data where we have a valid legal basis under the GDPR. Depending on the context, that basis may be contract, steps taken at your request before contract, legitimate interests, consent, or legal obligation.

  • To provide the marketplace and account features. This includes sign-in, watchlists, profile settings, enquiry routing, deal alerts and account security. Legal basis: contract or steps at your request.
  • To route and manage enquiries. If you ask for a quote, concierge search or partner contact, we use your details to match you with relevant providers and to manage lead status. Legal basis: steps at your request and legitimate interests in operating the platform.
  • To publish and improve editorial and market-intelligence products. We use aggregated marketplace data, platform analytics and operational reporting to understand demand, pricing and site performance. Legal basis: legitimate interests, and consent where a tool requires cookie consent.
  • To send operational communications. This includes enquiry updates, account notices, security messages and deal-alert emails you have asked to receive. Legal basis: contract, steps at your request, or legitimate interests.
  • To prevent abuse and keep the platform secure. We log technical events, investigate misuse, enforce rate limits, and maintain audit trails. Legal basis: legitimate interests and legal obligations where relevant.
  • To comply with law, accounting and tax obligations. Legal basis: legal obligation.
  • To send marketing or non-essential analytics. Where required by applicable law, we rely on consent for non-essential cookies and comparable tracking technologies.

Who we share data with

We do not sell personal data. We share it only where needed to run the service, comply with law, or fulfil a request you have made.

  • Relevant sellers, lessors, brokers or partners. If you submit an enquiry, request a concierge search, or otherwise ask to be connected, we may share the information needed to handle that request with one or more vetted partners.
  • Service providers acting on our behalf. The processors currently in use are:
    • Clerk — user authentication, sessions and account security.
    • Supabase — the PostgreSQL database holding accounts, enquiries and listings.
    • Sanity — the content management system behind our editorial pages.
    • PostHog (EU hosting) — product analytics, loaded only where you have accepted analytics cookies.
    • Cloudflare R2 — storage and delivery of listing images and documents.
    • Resend — transactional email such as enquiry confirmations and deal alerts.
    • Twilio — WhatsApp and SMS messages where you have asked to be contacted that way.
    • Google reCAPTCHA — spam and abuse prevention on our forms.
    • Stripe — payment infrastructure. Integrated for future partner billing but dormant: no payments are processed today, and buyers are never charged.
    • Vercel — hosting for this website. Processes IP addresses and request data in the course of serving pages.
    • Railway — hosting for our API and background workers. Enquiry submissions, including the contact details you provide, pass through it.
    • Upstash — Redis used for rate limiting and background job queues. Holds short-lived keys derived from IP addresses.
    We do not currently use Sentry, BetterStack or any other error-monitoring or uptime provider. If we add a processor, this list is updated before it goes live.
  • Professional advisers and authorities. We may disclose data where reasonably necessary for legal advice, claims, fraud prevention, regulatory compliance or law-enforcement requests.

International transfers

CMM is designed around EU data residency where possible. If personal data is transferred outside the EEA, we will rely on an appropriate safeguard such as an adequacy decision, standard contractual clauses, or another transfer mechanism recognised by applicable law.

How long we keep data

We keep personal data only for as long as necessary for the purpose it was collected, plus any period needed for legal, tax, dispute or security reasons. Current platform-level retention decisions reflected in the product requirements include:

  • User accounts: up to 2 years after inactivity, unless a longer period is needed for a live relationship, unresolved issue or legal obligation.
  • Leads and enquiries: up to 3 years to manage enquiries, disputes, reporting and partner operations.
  • Raw listing snapshots: 90 days before archive to cold storage for market-intelligence and operational purposes.
  • Security and audit logs: retained for as long as reasonably necessary to investigate incidents and maintain accountability, and in some cases longer where the platform must keep permanent audit history.
  • Deal alerts: until you unsubscribe, delete the alert, or the alert becomes inactive under our retention rules.

Cookies and similar technologies

We use cookies and comparable technologies for essential site functions — sign-in, session continuity, spam prevention and storing your cookie choice — and, if you accept them, for product analytics through PostHog. PostHog is not loaded at all unless you press Accept on the cookie banner, and session or screen recording is switched off. We run no advertising or ad-tech cookies.

Analytics events carry counts and yes/no flags about form completion, never your name, email address, phone number or free-text notes. Please read our Cookies Policy for the full list and for how to withdraw consent.

Your rights

Depending on the circumstances, you may have the right to request access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. You also have the right not to be subject to a decision based solely on automated processing where the GDPR gives that protection.

We will normally respond within one month. If a request is especially complex, the GDPR may permit an extension of up to two further months, in which case we will explain why.

Contact and complaints

For privacy questions or rights requests, contact us at privacy@cyprus-motors-marine.com. If you believe your data has been handled unlawfully, you can also complain to Commissioner for Personal Data Protection (Cyprus).

We may update this notice from time to time as the platform, legal requirements or processing activities change. Material changes will be reflected on this page together with an updated revision date.