Policy 01
Data Protection & GDPR
Our two roles: controller and processor
WinguSuite (Innova – WinguSuite, Rightcom Telecoms (Cyprus) Ltd) protects personal data in line with Regulation (EU) 2016/679 (the GDPR). We act in two roles. When customers place mail, contacts and messages into the WinguSuite platform, the customer is the controller and we are the processor, handling that data only on the customer’s documented instructions under a Data Processing Agreement. Separately, we are the controller of the data we collect to run our own business — website enquiries, trial and support requests, supplier contacts and staff records.
Data protection principles
We apply the Article 5 principles to all personal data we process: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.
Lawful bases
As a controller we rely on contract, legitimate interests, consent (for non-essential cookies and optional marketing) and legal obligation. When we process customer data through the platform, the lawful basis is the customer’s responsibility as controller.
Your rights
- Be informed, and access the data we hold about you.
- Rectify inaccurate data, and erase data where the law allows.
- Restrict or object to processing, including direct marketing.
- Data portability in a machine-readable format.
- Withdraw consent at any time, where processing relies on consent.
- Complain to a supervisory authority — for us, the Hellenic Data Protection Authority (www.dpa.gr).
Security & hosting
The platform is hosted at the Lamda Hellix data centre (ISO 9001, ISO/IEC 27001, SOC). We apply encryption in transit, AES-256 encrypted backups (Acronis Cyber Protect Cloud and Veeam), endpoint detection and response (Acronis EDR/MDR), network segmentation, multi-factor authentication and least-privilege access.
Breaches
Where we are the controller and a breach is likely to risk individuals’ rights, we notify the supervisory authority without undue delay and, where feasible, within 72 hours. Where we are the processor, we notify the affected customer without undue delay. Report a suspected breach to the Data Protection Officer, Michael Sariklis, at [email protected].
Contact
Data Protection Officer: Michael Sariklis — [email protected]. General: [email protected]. A full signed Data Protection & GDPR Compliance Policy is available to customers on request.