50+ years of risk intelligence.
Infocredit Group has helped organisations make smarter business decisions since 1972.
Your Privacy Matters
Your Data, Our Commitment.
Infocredit Group Ltd (hereinafter referred to as “the Company” or “Infocredit”) engages in the collection, archiving and re-use of data related to individuals or enterprises with the aim to provide business intelligence information to businesses and individuals worldwide, having its main office at 5a Philippou Chatzigeorgiou Str., Nicosia, Cyprus.
This Notice is addressed to natural persons who are current or potential customers of the Company or its clients, officers or beneficiaries of legal entities, persons recorded in the Bankruptcy Registry, or subjects of a debt collecting procedure initiated by us on behalf of any of our clients.
This text aims at providing you with intelligible, transparent and direct information about the processing of your personal data — how we collect and process your personal data in the context of fulfilling our business activities, explaining the procedures that we have in place to safeguard your privacy according to the rules and provisions ascribed by the General Data Protection Regulation (“GDPR”).
Further Processing Notices may be delivered to you at a later stage underlining specific uses of your personal information. This Notice shall apply to all data that we collect in the course of our business and which according to GDPR’s provisions are deemed to be personal data.
Who This Notice Applies To
- Current or potential customers of the Company or its clients
- Officers or beneficiaries of legal entities
- Persons recorded in the Bankruptcy Registry
- Subjects of a debt collection procedure initiated by us on behalf of any of our clients
Information We Collect and How We Use It
Information is collected for the purpose of conducting a business relationship with a said individual, the company he is employed at, or for providing the below solutions:
Within the scope of the provision of our services to our clients, we will come across personal data of individuals who have no direct relationship with us. All data we use are either publicly available and collected from public sources or are provided to us directly by our clients. Through this statement, we inform the said individuals that their data will be collected and processed by the Company for the purpose of executing our obligation to our clients.
Additionally, processing of personal data can occur during other purposes such as contacting companies for promoting the products and services of the Company.
Credit Risk Solutions
Credit risk management is the practice of determining creditworthiness — assessing new and existing customers for their financial health, which can indicate their ability to pay on time. In this scope our clients request information on the financial standing of companies and assessment of the risk associated in trading with the said companies. During the course of this assessment we collect information on the physical entities associated as directors, secretary and shareholders of companies.
The data we collect will include:
- Registration details (Registered Name, Registered Address, Registration Number etc.)
- Director, Secretary and Shareholder information
- Capital (Issued, No. of Shares, Nominal, Value etc.)
- Payment records and Charges (Current and Historic)
- Negative information and bankruptcies
- Financial Statements (when available)
- Credit scoring assessment
- Company operational histories, subsidiaries, affiliates, and lines of business
- Business compliance information from public sources
- Newspaper and media reports
- Bankruptcies information as retrieved from the Official Receiver
Our data originates from:
- Public sector information (e.g. Company Registrars and Official Receiver)
- Governmental and administrative public records
- Organisations providing information directly to us
- Straight from the Data Subject
- Regulatory bodies and law enforcement agencies
- Media sources
Infocredit does not seek to collect any information in relation to a European resident’s race or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, genetic or biometric data.
Regulatory Compliance
In Cyprus and the other jurisdictions in which we operate, laws and regulations are designed to combat money laundering. Broadly, money laundering can arise if a person acquires, retains, transfers, uses or controls the proceeds of a crime or the benefit of a criminal activity. References to money laundering includes references to terrorism.
Our clients are obliged to verify the identity of new and existing clients and may conduct background checks. These may necessitate verification procedures of the identity and good standing of clients, directors, employees, representatives, shareholders, beneficial owners, management, and/or other relevant information, possibly including evidence of the source of funds.
The data we collect may include:
- Relationships as a Director, Secretary and Shareholder
- Relationships of the individual with other physical entities
- Photos
- Negative information of the entity and its related legal entities
- Source of Funds/Wealth if required
- ID/Passport copy
- Company operational histories, subsidiaries, affiliates, and lines of business
- Business information such as memberships in professional bodies
- Newspaper and media reports
- Bankruptcies information as retrieved from official sources
Infocredit does not seek to collect any information in relation to a European resident’s race or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, genetic or biometric data.
Debt Recovery & Receivables Management
We offer debt collection services and receivables management to our clients where they assign the process of debt collection or receivables management to us. This entails the processing of personal data of the debtors. These personal data are provided by our clients and the processing is limited to the sole purpose of collecting the debt. Additionally, data may be collected straight from the data subject during our contact with them.
| Type of Information | Debtor is Individual | Debtor is Company |
|---|---|---|
| Name and Surname | Yes | Yes |
| Position | No | Yes |
| ID/Passport and ARC Number | Yes | No |
| Address | Yes | Of the Company |
| Contact Numbers | Yes | Business Numbers |
| Yes | Business Email | |
| Client/Claimant | Yes | Yes |
| Amount of the Debt | Yes | Yes |
| Cases/Invoice Number | Yes | Yes |
| Date of Last Payment | Yes | Yes |
| Description of Service | Yes | Yes |
| Other Details Necessary to the execution of the contract | Yes | Yes |
Call Centre
We provide call center services to our clients for Promotion and Customer Service. The personal data are either provided by our clients or retrieved during the communication with a company and are limited to the below:
- Name and Surname
- Position
- Telephone numbers
- Business Email
Infocredit does not seek to collect any information in relation to a European resident’s race or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, genetic or biometric data.
Training
To register as a delegate for an event or training you must complete a registration form. During registration you are required to give your contact information. This information enables us to process and fulfil your enrolment online so that we can contact you about the events and trainings for which you have expressed interest.
- Name
- Address
- Phone number
- Email address
- Company name and position (optional)
Should the training or seminar be HRDA subsidized you will be required to provide more information to HRDA according to their requirements. Infocredit does not seek to collect any sensitive personal data as defined under GDPR.
Other Purpose for Processing Personal Data
We may also use aggregate information and statistics for other purposes. These statistics will not include any information that can be used to identify any individual.
We may automatically collect technical information when you connect to our site that is not personally identifiable. This includes for example the type of Internet Browser you are using, the type of computer operating system and the domain name of the website from which you are linked to our site. Additionally, in case you connect to our system we collect your IP address.
When you register for any of our services, we may require details including:
- Last Name
- First Name
- Company and your position
- VAT Number
- Address details
- Telephone number
- Fax
Lawfulness of Data Processing
Credit Risk Solutions
Necessary for public interest and legitimate interest; based on Article 6(1)(f) GDPR and relevant public-sector information legislation.
Regulatory Compliance
Consent, Legal Obligation, Legitimate Interest of third party
Debt Recovery & Receivables Management
Legitimate interest of third party
Call Centre
Consent, Legitimate interest of third party
Training
Consent
Other purpose for processing personal data
For the fulfilment of a contract
In each transmission to third parties every measure shall be taken beforehand so that only the necessary data shall be transmitted for the implementation of the contract, along with the effective requirements for their legitimate and lawful processing. Exempt are those cases in which the communication of the data is affected due to some legal or statutory obligation.
In cases where it is necessary to communicate your personal data to countries outside the European Union, which do not offer adequate guarantees for the protection of your personal data, our company shall be obliged and hereby undertakes the responsibility to conclude contractual clauses in the form of a Data Transfer Agreement between our Company and the Company to which the data are communicated, in order to safeguard the information transmitted.
Retention Period for Your Personal Data
Due to harmonization with the Regulation, we have determined the time periods for the retention of your personal data, depending on the processing to which they are being subjected. The parameters that have been taken into consideration for the determination of the time periods are your better service, our operational needs, our legal obligations and the safeguarding of our legal interests.
Credit Risk Solutions
5 years from last update; deleted after a further 5 years if not updated. Overall retention does not exceed 10 years.
Regulatory Compliance
3 months after the report was completed and provided to the client. Overall retention does not exceed 4 months.
Debt Recovery & Receivables Management
If collected: anonymised 2 months after collection. If not collected: anonymised 12 months after assignment. Overall retention does not exceed 12 months.
Call Centre
30 days after project finalisation. Overall retention is 2 months.
Training
HRDA documents kept per applicable regulations; trainer data kept for 3 years after last cooperation; other data deleted upon project completion.
Other purpose for processing personal data
Accounting data retained per Tax Legislation; consent-based data retained until consent is withdrawn.
Security Measures
Infocredit applies throughout the data processing procedure the appropriate technical, physical, and administrative security measures for the protection and security of the personal data from loss, misuse, damage or modification, unauthorised access and disclosure, in compliance with article 32 of the GDPR 679/2016, in order to ensure the appropriate security level against those risks.
- ISO 27001/2013 Certification
- Dedicated information security team
- Ongoing infrastructure checks for weaknesses and intrusions
- HTTPS protocols for secure and encrypted client communication
- Firewalls
- Information Security Management System (ISMS)
- Confidentiality clauses in agreements with suppliers and employees
- Adequate training for all employees that handle personal data
Your Reinforced Rights
GDPR rights at a glance.
Our Company has developed a mechanism for the satisfaction of requests concerning your personal data.
Right to access
You have a right to access your data maintained by us and you may at any time obtain a copy thereof provided we possess them in electronic form.
Right to rectification
You may at any stage check and update your personal data, always presenting the necessary documentation and requesting the rectification or completion of inaccurate information.
Right to be forgotten
You have the right to ask for the erasure of data that are no longer necessary in relation to the purposes for which they are processed.
Right to restriction
You have the right of restricting processing where the accuracy of the personal data is contested by you or the processing is unlawful.
Right to object
You may at any time raise objections about the processing of your personal data. Processing shall immediately cease unless the Company can prove legal interest or need for a legal/judicial case.
Right to data portability
You have the right to transfer your personal data to another organization in a legible and commonly used form.
Right to recall consent
You have the right to withdraw your consent at any time, without affecting the legality of processing based on consent before its withdrawal.
Right to launch complaint
You have the right to launch a complaint with the Commissioner for the Protection of Personal Data regarding the processing of your personal data.
Our Use of Cookies
When you view one of our websites, following consent, we may store information on your computer. This information will be in the form of a “Cookie” or similar file and can help us in many ways. For example, cookies allow us to tailor our website to better match your interest and preferences. With most Internet browsers, you can erase cookies from your computer hard drive, block all cookies or receive a warning before a cookie is stored. Please refer to your browser instructions or help screen to learn more about these functions.
Your Consent
If we change our Privacy Notice we will post the changes on this page so that you may be aware of the information we collect and how we use it at all times. Continued use of the service will signify that you agree to any such changes.
Data Protection Responsibilities
For the purposes of this Privacy Notice we act as “data controllers” when we determine the purposes for which and the manner in which any personal data are, or are to be processed. Furthermore, we act as “data processors” when we obtain, record or hold the information or data or carry out any operation or set of operations on the information or data.
Data Protection Officer contact details
A. & E. C. Emilianides, C. Katsaros & Associates LLC
192 Ledras, 3rd Floor,
1011 Nicosia, Cyprus
+357 22 676752
How to Lodge a Complaint
If you have exercised some or all of your rights to data protection and you still feel that your concerns about the way we process your personal data have not been fully addressed by us, you have the right to file a complaint to the Office of the Personal Data Protection Commissioner.
dataprotection.gov.cySustainability & Corporate Responsibility
Infocredit Group Ltd is committed to creating long-term value for all stakeholders by delivering services in a sustainable, transparent, and ethical manner.
As part of our forward-looking strategy, in 2025 Infocredit Group Ltd established a wholly owned subsidiary The Corpro Ltd which will eventually take over all Customer Contact Centre operations and transferred the operations of customer debt collections under Decol Services Ltd where it holds a 50% stake. This structure ensures dedicated focus, fosters innovation and service excellence, offers operational flexibility, and allows the Group to concentrate on strategic growth and development.
Our Vision
“To enhance transparency and trust in day-to-day business transactions, assist our clients in making informed decisions, and remain compliant with evolving regulatory standards.”
Our Commitments
- Achieving excellence in customer and stakeholder satisfaction through continuous improvement
- Embedding Environmental, Social, and Governance (ESG) principles in all aspects of our business
- Protecting the environment and contributing to sustainable development
- Ensuring a safe and healthy workplace that embraces diversity and inclusion
- Maintaining responsible and transparent communication with all stakeholders
- Complying with applicable national and international laws, regulations, and standards
- Providing ongoing training and engagement opportunities to our people
- Safeguarding the confidentiality, integrity, and availability of information and services at all times
How We Deliver
- Understanding and meeting the requirements of all stakeholders
- Diligent risk management
- Setting and monitoring high operational and ethical standards
- Achieving excellence in Information Security through planning, resources, and evaluation
- Ensuring business continuity and service excellence through our specialized operations
- Maintaining effective systems for addressing deviations and implementing corrective measures
- Leveraging new technologies and best practices to improve operations
- Leading and participating in industry related Research and Development projects
We set measurable targets (KPIs) to track our performance, reviewed at least annually, and embedded within our Integrated Management System, aligned with ISO 9001:2015 (Quality Management), ISO 22301:2019 (Business Continuity), ISO 27001:2022 (Information Security), ISO 18295-1:2017 (Customer Contact Centres), and all relevant laws, regulations, and accepted CSR practices.
Top Management is responsible for the design, implementation, and continual improvement of our systems, supported by all employees. Every staff member and external provider has a duty to protect Quality, Occupational Health & Safety, Environment, and Information Security & Business Continuity through their actions. This Policy, approved by the Managing Director, is available to all interested parties and communicated to stakeholders as appropriate, and reviewed regularly to remain relevant as requirements, organizational structures, and business methods evolve.
Updated: September 1st, 2025
