GDPR Commitment
How a company working between the EU and North Cyprus honours European data-protection standards in full.
Last updated
Our clients are overwhelmingly EU and UK residents, so we hold ourselves to the EU General Data Protection Regulation as our working standard everywhere, including in North Cyprus, where the transaction side of our work takes place. This page explains what that commitment means in practice, beyond the reassuring acronym.
One standard, everywhere we work
The GDPR applies to us directly because we offer services to people in the EU. Rather than maintaining two regimes, we apply the GDPR’s rules to every client relationship regardless of where the client lives or where the property sits. The same consent standards, the same rights, the same retention limits.
Practically, that means data minimisation (we collect what the work needs and no more), purpose limitation (data given for a viewing is not repurposed for marketing), and privacy by default in every system we introduce.
Your rights, honoured in full
Every GDPR right applies to your data with us: access, rectification, erasure, portability, objection and restriction. Requests go to hello@ordently.com, are answered within one month, and cost nothing.
The one honest limit: transaction records that property and tax law oblige us to keep cannot be erased before their statutory retention period ends. We will always tell you exactly which records those are and when the period expires.
- Access, rectification and erasure
- Portability in a machine readable format
- Objection to legitimate interest processing and all marketing
- Restriction while any dispute is resolved
- Complaint to your national supervisory authority
Transfers to North Cyprus, handled honestly
A property purchase in North Cyprus necessarily moves some of your data outside the EEA, to your lawyer there, to the seller or developer, and to authorities processing the permission application. North Cyprus has no EU adequacy decision, so we rely on the GDPR’s safeguards for such transfers: contractual protections with recipients and, where those cannot bind an authority, your explicit informed consent for the specific transfer the transaction requires.
We keep the moving data to the minimum the transaction genuinely needs, we tell you before each category of recipient receives anything, and everything not needed for the purchase stays on our EEA systems.
Before any document leaves the EEA for your transaction, you will know what is moving, to whom, and why. No exceptions.
Our processors and security measures
Every service provider that touches personal data, including hosting and email, operates under a data processing agreement, and we prefer providers based in the EEA wherever the market allows. The current processor list is available on request.
Technically: connections to the site are encrypted, access follows roles so colleagues see only what their work requires, and transaction documents are held separately from marketing tools.
If something ever goes wrong
If a personal-data breach ever posed a risk to your rights, we would notify the competent supervisory authority within seventy-two hours and affected individuals without undue delay, in plain language, with an honest account of what happened and what we are doing about it.
You always retain the right to complain to your national data-protection authority, which in Germany is your Landesdatenschutzbehörde, whether or not you raise the matter with us first. We would appreciate the chance to fix things, but it is a preference, not a condition.
Frequently asked
Does the GDPR really apply to a company working in North Cyprus?
Who is your data protection contact?
Questions about this policy?
A person, not a form letter, reads and answers every message. We are happy to explain any part of this page in plain language.