Skip to content

GDPR Commitment

How a company working between the EU and North Cyprus honours European data-protection standards in full.

Last updated

Our clients are overwhelmingly EU and UK residents, so we hold ourselves to the EU General Data Protection Regulation as our working standard everywhere, including in North Cyprus, where the transaction side of our work takes place. This page explains what that commitment means in practice, beyond the reassuring acronym.

One standard, everywhere we work

The GDPR applies to us directly because we offer services to people in the EU. Rather than maintaining two regimes, we apply the GDPR’s rules to every client relationship regardless of where the client lives or where the property sits. The same consent standards, the same rights, the same retention limits.

Practically, that means data minimisation (we collect what the work needs and no more), purpose limitation (data given for a viewing is not repurposed for marketing), and privacy by default in every system we introduce.

Your rights, honoured in full

Every GDPR right applies to your data with us: access, rectification, erasure, portability, objection and restriction. Requests go to hello@ordently.com, are answered within one month, and cost nothing.

The one honest limit: transaction records that property and tax law oblige us to keep cannot be erased before their statutory retention period ends. We will always tell you exactly which records those are and when the period expires.

  • Access, rectification and erasure
  • Portability in a machine readable format
  • Objection to legitimate interest processing and all marketing
  • Restriction while any dispute is resolved
  • Complaint to your national supervisory authority

Transfers to North Cyprus, handled honestly

A property purchase in North Cyprus necessarily moves some of your data outside the EEA, to your lawyer there, to the seller or developer, and to authorities processing the permission application. North Cyprus has no EU adequacy decision, so we rely on the GDPR’s safeguards for such transfers: contractual protections with recipients and, where those cannot bind an authority, your explicit informed consent for the specific transfer the transaction requires.

We keep the moving data to the minimum the transaction genuinely needs, we tell you before each category of recipient receives anything, and everything not needed for the purchase stays on our EEA systems.

Before any document leaves the EEA for your transaction, you will know what is moving, to whom, and why. No exceptions.

Our processors and security measures

Every service provider that touches personal data, including hosting and email, operates under a data processing agreement, and we prefer providers based in the EEA wherever the market allows. The current processor list is available on request.

Technically: connections to the site are encrypted, access follows roles so colleagues see only what their work requires, and transaction documents are held separately from marketing tools.

If something ever goes wrong

If a personal-data breach ever posed a risk to your rights, we would notify the competent supervisory authority within seventy-two hours and affected individuals without undue delay, in plain language, with an honest account of what happened and what we are doing about it.

You always retain the right to complain to your national data-protection authority, which in Germany is your Landesdatenschutzbehörde, whether or not you raise the matter with us first. We would appreciate the chance to fix things, but it is a preference, not a condition.

Frequently asked

Does the GDPR really apply to a company working in North Cyprus?
Yes. The GDPR follows the people whose data is processed, not the property. Because we offer services to EU residents, the regulation applies to us directly, and we apply it as our single standard everywhere rather than maintaining a weaker parallel regime.
Who is your data protection contact?
Data protection questions go to hello@ordently.com and are read by the people responsible for the topic. Given our size we are not required to appoint a formal DPO, but the responsibility is assigned and taken seriously.

Questions about this policy?

A person, not a form letter, reads and answers every message. We are happy to explain any part of this page in plain language.

Write to us