Privacy Policy
This policy explains what personal data NANOG LTD collects through sonlano.com and in the course of client work, why we hold it, and what you can ask us to do with it.
1. Who we are
NANOG LTD, registration number HE 448256, a company incorporated in the Republic of Cyprus with its registered office at 5, A.G. Leventi, The Leventis Gallery Tower, Fl. 13th, Apt. 1301, 1097 Nicosia, Cyprus, trading as Sonlano, is the data controller for the personal data described here.
Questions about this policy, or about data we hold, go to app@sonlano.com. A named person handles these; we are not large enough to require a statutory Data Protection Officer.
2. Data we collect
We collect only what an enquiry or an engagement actually requires:
- Contact details you send us — name, email address, company, and whatever you choose to write in the body of a message.
- Engagement records — correspondence, meeting notes, invoices and contractual documents relating to a project.
- Technical logs — IP address, browser type, requested page and timestamp, recorded by our hosting provider for security and diagnostics.
We do not run advertising or behavioural tracking on this site, we do not buy contact lists, and we do not ask for special category data. If a client engagement requires access to personal data held in their systems, we act as a processor under a separate written agreement, and that data is governed by the client’s own policy rather than this one.
3. Why we use it
- To answer an enquiry and prepare a scope or proposal.
- To deliver, invoice and support work that has been agreed.
- To keep accounting and tax records that Cyprus law requires us to keep.
- To keep the site available and investigate abuse or technical faults.
4. Legal basis
Under the General Data Protection Regulation (EU) 2016/679 and Cyprus Law 125(I)/2018, we rely on: performance of a contract for engagement data; legitimate interests for responding to enquiries and for keeping our infrastructure secure; and legal obligation for accounting records. Where we rely on legitimate interests, we have considered whether our interest overrides yours and concluded that it does not extend beyond ordinary business correspondence.
5. Who we share it with
We share personal data only with service providers that are necessary to run the business — email and document hosting, cloud infrastructure, accounting, and our auditors — each under a written processing agreement. We do not sell personal data or transfer it to third parties for their own marketing.
Our providers operate within the European Economic Area where that option exists. Where a transfer outside the EEA is unavoidable, it takes place under the European Commission’s Standard Contractual Clauses. We disclose data to a public authority only where a valid legal instrument requires it.
6. How long we keep it
- Enquiries that do not become engagements: 12 months, then deleted.
- Engagement correspondence and project records: 3 years after the engagement ends.
- Invoices and accounting records: 6 years, as required by Cyprus tax legislation.
- Server logs: 90 days.
7. Your rights
You may ask us to give you a copy of the data we hold about you, correct it, delete it, restrict how we use it, or send it to another provider in a machine-readable format. You may also object to processing we carry out on the basis of legitimate interests.
Write to app@sonlano.com. We answer within one month and do not charge for a first request. If you are not satisfied with our answer, you can complain to the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus, or to the supervisory authority in the EU country where you live.
8. Cookies
This site sets no analytics, advertising or profiling cookies. Nothing on sonlano.com requires a consent banner because nothing here tracks you. Should that change, we will ask for consent before setting anything beyond what is strictly necessary, and this section will be updated first.
9. Security
Traffic to this site is encrypted in transit. Internal access to client and enquiry data is limited to the people working on the relevant engagement, protected by multi-factor authentication, and reviewed when someone joins or leaves. Backups are encrypted at rest. If a breach occurs that is likely to affect your rights, we will notify the Commissioner within 72 hours and inform you directly where the regulation requires it.
10. Changes
When this policy changes we publish the new version here with a revised version number and date. Material changes affecting people we already correspond with are sent by email. The version in force is the one published on this page.