62px
62px
Document · GDPR-compliant

Policy privacy

How 62px processes personal data of clients and website visitors. Complies with GDPR (EU 2016/679) and Cyprus Data Protection Law No. 125(I)/2018.

Last updated: April 27, 2026

1. Who is the data controller?

Data Controller - 62px (Cyprus Limited Company), registered at: Limassol, Cyprus.

Contact email for privacy inquiries: privacy@62px.com. Main contact for business matters: info@62px.com.

2. What data do we collect?

  • Contact form details - Name, email, phone/Telegram, task description. Collected only when you fill out application forms on the website.
  • Website analytics — IP address (anonymized), browser type, OS, referral source. Via Google Analytics 4 with your consent (cookie banner)
  • Cookies — Cookie techniques for site operation (theme, language), analytical cookies (only with consent)
  • Communications — Email, Telegram, WhatsApp communication on inquiry.

3. Processing purposes

  • Contact you upon request (application, brief, cost estimate)
  • Prepare a proposal and contract
  • Fulfil contractual obligations (if a contract is in place)
  • Improve website performance through anonymous analytics
  • Comply with legal requirements (accounting, Cyprus taxes)

4. Legal grounds

  • Consent (GDPR Article 6(1)(a)) - for analytics and marketing cookies
  • Contractual obligations (Article 6(1)(b)) - Processing customer data to perform work
  • Legal interests (Article 6(1)(f)) - Processing application forms prior to contract conclusion
  • Legal obligations (Article 6(1)(c)) - storage of accounting records on demand by the tax authority

5. Storage terms

  • Application form data - 3 years, if no contract is concluded; plus 6 years (Cyprus accounting requirements) if a contract was signed.
  • Analytics — 14 months (Google Analytics standard)
  • Server logs — 30 days
  • Communications — as relevant to the project + 1 year

6. To whom we transfer data

We do not sell your data to third parties. We use the following data processors, with whom we have signed a DPA:

  • Google LLC — Google Analytics, Google Workspace for email
  • Cloudflare, DigitalOcean — Hosting and CDN (servers in EU)
  • Stripe, JCC, Revolut — Payment processing (if paying online)
  • Cyprus accountant — for tax reporting (only financial data)

7. Data transfer outside the EU

Most of the data is stored in the EU (Germany, Netherlands). If services processing outside the EU are used (Google Analytics, Cloudflare US), this is done on the basis of Standard Contractual Clauses (SCC) approved by the European Commission.

8. Your rights

According to GDPR, you have the right to:

  • Access to data (Article 15) — request a copy of your data
  • Correction (Art. 16) — correct incorrect data
  • Removal (Article 17, "right to be forgotten") - remove data if there is no legal basis for storage
  • Processing limitation (Article 18) — suspend processing
  • Adaptability (Article 20) — obtain data in a machine-readable format
  • Objection (Article 21) — against processing based on legitimate interests
  • Consent given (Art. 7(3)) - at any time via the cookie banner
  • Complaint to the supervisory authority — Cyprus Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy)

For the implementation of rights, write to: privacy@62px.com. We'll respond within 30 days (standard GDPR).

9. Cookies on the site

We use three types of cookies:

  • Technical (required) — for website work (theme, language, cookie consent). Do not require consent. Stored locally (localStorage), not sent to our servers
  • Analytics — Google Analytics 4 to understand user behaviour. Only with your consent
  • marketing- — as long as we're not using it

Manage consents at any time through the cookie banner (automatically opens on first visit).

10. Security

We implement technical and organizational protection measures:

  • HTTPS (TLS 1.3) for all requests
  • Hosting in EU with server-level encryption
  • Two-factor authentication for admin access
  • Regular backups (encrypted)
  • Employee access restriction based on the need-to-know principle
  • Notification of data breach within 72 hours in accordance with GDPR

11. Children

The site is not intended for individuals under 16 years old. We do not intentionally collect personal data from children. If you are a parent or guardian and believe your child has provided us with information, contact us to have it removed.

12. Changes in policy

We can update this policy to reflect changes in our processes or legal requirements. The date of the last update is stated at the top of this document. For significant changes, we will notify via email (if you are a client) or a banner on the site.

13. Contacts

Privacy questions: privacy@62px.com

General questions: info@62px.com

Telegram: @px62

Cyprus regulatory body: Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy)