Privacy Policy
GDPR-Aligned Data Protection Notice
How Psyconsult Ltd collects, uses, stores and protects your personal information — in line with the General Data Protection Regulation (GDPR) and Cyprus data protection law.
1. Introduction
The purpose of this Privacy Policy is to describe clearly what information Psyconsult Ltd collects about you when you engage with our assessment services, events, website and assessment platforms, how we use and process that data, who we may share it with, and how you can exercise your rights in relation to it.
Psyconsult Ltd is based in Cyprus and complies with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data (Law 125(I)/2018), which together regulate the processing of personal data in Cyprus and across the European Economic Area. Where we process personal data of individuals located outside the EEA, we aim to meet equivalent obligations under comparable data-protection frameworks.
In line with the GDPR, we process all personal data in accordance with the principles for lawful processing:
- Lawfulness, fairness and transparency — we process information lawfully, fairly and in a way you can understand.
- Purpose limitation — we collect personal data for specific, explicit and legitimate purposes.
- Data minimisation — we collect only the data that is adequate, relevant and necessary for those purposes.
- Accuracy — we take reasonable steps to keep personal data accurate and up to date.
- Storage limitation — we keep personal data only for as long as necessary.
- Integrity and confidentiality — we use appropriate technical and organisational measures to keep personal data secure.
- Accountability — we take responsibility for how we process your personal data and can demonstrate our compliance.
2. The Information We Collect
Depending on the service you engage with, we may collect and process the following categories of personal data:
- Name and surname
- Contact details (email address and, where relevant, telephone number)
- Biographical information (sex, age or age range, level of education, ethnicity, first language, country of origin)
- Employment or occupational information
- Assessment responses and the results derived from them
- Facial images, where Facial Validation is used to support un-proctored, remotely administered assessments
- Technical information relating to your use of our websites and assessment platforms (for example, IP address, browser type and session information)
Where we process special categories of personal data under Article 9 of the GDPR (such as information relating to ethnicity or biometric data) we do so only where we have a clear legal basis, typically your explicit consent or another condition permitted under Article 9.
3. How We Obtain Your Information & Why We Process It
We collect only the information necessary to deliver psychometric, skills, 360-degree and other online assessments — and to generate the reports our clients use to make informed people decisions. Your personal data typically reaches us in one of the following ways:
- Our client (for example, a prospective employer or training provider) supplies us with your details so that we can set up your personalised assessment invitation.
- You provide information directly, through a form before starting an assessment or exercise, or as part of your responses during the assessment.
- We capture assessment data automatically as you work through the assessment — for example, your responses to items, time taken and, where enabled, Facial Validation signals.
Where we specifically collect biographical information, we will ask for your consent. You can choose not to provide this information, and where a response is required a "Rather Not Say" option is always available.
Facial Validation is an optional, advanced add-on feature designed to enhance the security and validity of un-proctored, remotely administered assessments. It uses a combination of artificial intelligence (AI) and common hardware available to most end-users. Facial Validation is not the same as facial recognition — it is used to confirm the integrity of the assessment session, not to identify you against external databases.
We store and process your data in order to provide a service to our clients. Your data and responses may be used to:
- Identify you and your responses to the client who supplied your information to us.
- Generate reports describing your personality, abilities, skills or performance.
- Produce feedback reports for you summarising the information provided to the client.
- Support the improvement and validation of our assessments (typically in anonymised form).
Our clients may use these reports for selection, development or succession planning within their organisations. They act as independent controllers and are responsible for processing your personal data in line with their own obligations under the GDPR and any other applicable data-protection laws.
Under the GDPR, the lawful bases on which we rely for processing your personal data include:
- Your consent — given specifically and freely, typically at the point of data collection (Article 6(1)(a)).
- Performance of a contract — where processing is necessary to deliver the assessment services requested by you or our client (Article 6(1)(b)).
- Legitimate interests — where processing is necessary for our legitimate interests (or those of our client), balanced against your rights and freedoms (Article 6(1)(f)).
- Legal obligation — where processing is required by law (Article 6(1)(c)).
- Where applicable, the specific conditions for processing special categories of personal data under Article 9 of the GDPR.
4. How We Store & Protect Your Information
Your personal data is stored securely. We take appropriate technical and organisational security measures to protect it against loss, damage and unauthorised or unlawful access — in line with Article 32 of the GDPR. These measures include, among others, access controls, encryption in transit, segregated environments, activity logging and ongoing staff training on responsible data handling.
We retain personal data only for as long as is necessary for the purpose it was collected, or as required by law. As a general rule, personal data associated with assessment data is anonymised after a period of 18 months, at our discretion, unless a longer retention period is agreed with our client or required by law.
Cross-border transfers. Some of our assessment platforms and service providers may be hosted outside the European Economic Area. Where personal data is transferred outside the EEA, we do so only on a basis permitted under Chapter V of the GDPR — typically where the European Commission has issued an adequacy decision in respect of the recipient country, or where appropriate safeguards such as Standard Contractual Clauses are in place.
5. Your Rights Under the GDPR
As a data subject under the GDPR you have the following rights:
- Right of access — you may request confirmation of whether we hold personal data about you and a copy of that data.
- Right to rectification — you may request that we correct inaccurate or incomplete information.
- Right to erasure — you may request that we delete personal data that is no longer required for the purpose it was collected.
- Right to restriction of processing — you may request that we limit how we process your personal data in certain circumstances.
- Right to object — you may object, on grounds relating to your particular situation, to the processing of your personal data.
- Right to withdraw consent — where we process your personal data on the basis of consent, you may withdraw that consent at any time. This will not affect the lawfulness of processing carried out before the withdrawal.
- Right to data portability — where technically feasible, you may request that certain personal data be transferred to you or another party.
- Right to lodge a complaint — you may complain to the Office of the Commissioner for Personal Data Protection if you believe your data has been processed unlawfully.
You are not required to pay any charge for exercising your rights. We will respond to a request within the time periods required by the GDPR, typically within one month.
6. How to Contact Us
If you have any questions about this Privacy Policy, or if you would like to exercise any of your rights under the GDPR, please contact us:
7. How to Lodge a Complaint
If you have any concerns about how we have handled your personal data, please contact us first so we can try to resolve the matter.
If you remain unhappy, you have the right to lodge a complaint with the supervisory authority in Cyprus, the Office of the Commissioner for Personal Data Protection:
Office of the Commissioner for Personal Data Protection
Nicosia, Cyprus
Email: commissioner@dataprotection.gov.cy
Website: dataprotection.gov.cy
8. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, in applicable law or in our data-handling practices. The effective date at the top of this page indicates when the current version took effect.