Privacy Policy

Last updated: 15/07/2025

1. Introduction

Marilena Shambarta – Advocates & Legal Consultants (the ‘Law Firm’) is committed to protect your privacy and ensure that all personal data are processed in accordance with the EU General Data Protection Regulation (the ‘GDPR’) and applicable Cyprus laws.
References to “we”, “us” and “our” refer to the Law Firm; “you” and “your” refer to any individual providing personal data to us.

This privacy policy (the ‘Privacy Policy’) was last updated on 15/07/2025. We may update this privacy policy from time to time. All updates will appear on our website at www.marilenashambarta.com.

You are encouraged to review the Privacy Policy periodically, to stay informed about how we protect your information along with our general terms and conditions, which provide further information on confidentiality.

This Privacy Policy does not apply to any third-party websites that may have links to our own website (www.marilenashambarta.com).

2. Scope

This Policy explains how we collect, use, share, and protect personal data obtained directly from you or via third parties, and outlines your rights regarding such data. It also describes how you can access, correct, transfer, or delete your personal information.

3. Collection of Personal Data

Most of the information we collect comes directly from you, but we may also collect information from other sources, always in compliance with legal requirements:

  1. From public sources, such as the Registrar of Companies or the Land Registry;
  2. From third parties, such as sanctions screening providers or client due diligence providers;
  3. From third parties with your consent, such as your bank, financial institution, your employer, accountant or professional body; and
  4. Automatically through our website, where we use cookies and similar technologies.

We collect personal information in the following circumstances:

  • When you contact us for legal advice or services;
  • When you submit an enquiry through our website or by email;
  • When you provide or offer goods or services to us.

4. Types of Data We Collect

Depending on the context, we may collect:

  • Personal details: name, telephone, address, e-mail address, job title, date of birth;
  • Identification details: ID or passport number;
  • Financial details: bank account or billing information;
  • Service-related information: instructions, communications, or payments;
  • Sensitive data: e.g. health information, processed only with your explicit consent and in full compliance with the GDPR and only for the purpose of providing relevant legal services;
  • Financial details: source of your funds, employment and salary details, bank account details, if these are relevant and necessary to the services we are providing to you;
  • Details of family members, if these are relevant and necessary to the services we are providing to you;
  • Audio recordings, e.g. calls;
  • Video recordings, e.g. of virtual meetings.

5. Purpose and Legal Basis

We process personal data to:

  • Provide legal, insolvency, corporate, or administrative services;
  • Respond to enquiries or requests;
  • Comply with professional, legal and regulatory obligations (including anti–money laundering laws) that apply to our business, e.g. rules issued by our professional regulator;
  • Protect or exercise our legal rights;
  • Conduct checks to identify our clients and verify their identity;
  • Screen for financial and other sanctions or embargoes; and
  • Fulfil any other legitimate purpose for which the data were provided.

Processing is based on one or more of the following:

  • Performance or preparation of a contract with you;
  • Compliance with a legal obligation;
  • Our legitimate interests, provided these do not override your rights;
  • Your explicit consent (where applicable);
  • Establishment, exercise, or defence of legal claims.

6. Sharing Personal Data

We may share your information:

  • Where required by law, regulation, or court order;
  • With your express consent or instruction;
  • With professional collaborators or third party service providers acting on our behalf such as other lawyers, accountants, auditors, banks, IT and insurers.

In any case, we shall only share your personal information once we are satisfied that our collaborators and outsourcing providers have taken appropriate measures to protect your personal data. In such cases, the recipients of the information will be bound by confidentiality obligations.

7. Personal Data of Third Parties

If you provide data about another individual, you must ensure you have the authority to do so and that the person concerned has been informed of this Privacy Policy and their data protection rights.

8. Cookies

Our website uses cookies to enhance functionality and improve your browsing experience. You can disable cookies through your browser settings; however, some features may not work properly if cookies are blocked.

9. Data Retention

We will not keep your personal data for longer than we need it for the purpose for which it was collected or as required by law.

Generally, we will keep your personal data for at least seven years from the conclusion of your matter, or longer where required by law, regulation, or professional obligations. However, different retention periods apply for different types of personal data and for different services. After the relevant period, data are securely deleted unless otherwise required or requested.

10. Data Security

We are committed to protecting the personal information provided to us; to this end, we have implemented information security policies, rules and technical measures to protect the personal information data under our control from unauthorised access, improper use and/or disclosure, unauthorised modification and/or unlawful destruction and/or accidental loss.

11. Your Rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request deletion of your data when no longer necessary;
  • Restrict or object to data processing;
  • Request transfer of your data to another controller;
  • Withdraw consent at any time, where processing is lawfully based on consent. You may withdraw consent by contacting us at msh@marilenashambarta.com. Withdrawing consent will not affect the lawfulness of our use of your personal data in reliance on that consent before it was withdrawn.
  • Right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus: https://www.dataprotection.gov.cy/dataprotection/dataprotection.nsf/home_el/home_el?opendocument

How to Contact Us

You can contact us by post, email, or telephone if you have any questions about this Privacy Policy or the information we hold about you, or if you wish to exercise your rights under data protection law or make a complaint.

Our contact details are shown below:

88 Archbishop Makarios III, Office 103,
P.C. 2224, Latsia, Nicosia, Cyprus
msh@marilenashambarta.com
(+357) 99 44 61 50

Search