// PRIVACY POLICY //
Last updated June 01, 2026

VAD ALLIANCE DISTRIBUTION LTD (“VAD Alliance”, “the Company”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose and safeguard personal data that we obtain through our website at https://alliance-distribution.ai (the “Website”), through the contact, consultation, webinar and event registration forms and the marketing campaigns made available on or in connection with the Website, and through any related correspondence with us.

We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), the Cyprus Law Providing for the Protection of Natural Persons with Regard to the Processing of Personal Data and for the Free Movement of Such Data (Law 125(I)/2018), and any other applicable data protection legislation. Please read this Privacy Policy carefully. By using the Website or submitting your personal data to us, you acknowledge that you have read and understood this Policy.


1.  WHO WE ARE (DATA CONTROLLER)

For the purposes of the GDPR and applicable Cyprus data protection law, the data controller responsible for your personal data is:
VAD ALLIANCE DISTRIBUTION LTD
Registration number: HE 477478
Registered office: Agias Faneromenis, 143–145, Patsias Court, Flat/Office 201, 6031 Larnaca, Cyprus
E-mail: sales@alliance-distribution.ai

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. You may nevertheless contact us in relation to any data protection matter using the details above.


2.  SCOPE OF THIS POLICY

VAD Alliance is a value-added distributor of cybersecurity software and related solutions, operating with resellers, channel partners and business (B2B) end-users across Eastern Europe, the Caucasus and Central Asia.
The Website operates principally as an informational and business-development resource for current and prospective partners and end-users.

This Policy applies to the personal data we process about: visitors to the Website; individuals who complete a contact, consultation, webinar or event registration form; individuals who interact with our promotional campaigns, including lead-generation forms hosted on social media platforms such as Facebook; and representatives of our partners, resellers, vendors and customers.
This Policy does not apply to the practices of third parties that we do not own or control, including the vendors whose products we distribute and the operators of any third-party websites or platforms that may be linked from the Website.


3.  DEFINITIONS

Unless otherwise stated, terms used in this Policy have the meaning given to them in the GDPR. In particular:
“Controller” means the party that determines the purposes and means of the processing of personal data. “Data subject” means the identified or identifiable natural person to whom the personal data relates. “EEA” means the European Economic Area. “Personal data” means any information relating to an identified or identifiable natural person. “Processing” means any operation performed on personal data, such as collection, storage, use, disclosure or erasure. “Processor” means a party that processes personal data on behalf of, and under the instructions of, the controller.


4.  PERSONAL DATA WE COLLECT

4.1  Information you provide to us
When you complete a form on the Website (for example, a consultation or contact request, or a webinar or event registration), submit a form distributed through our promotional campaigns, or otherwise communicate with us, we collect the personal data you choose to provide. Depending on the form, this may include: first name and last name; business (work) e-mail address; telephone number; company or organisation name; job title or position; country; your preferred method of contact (for example, e-mail, telephone or messenger); and any other information you include in the body of your message or enquiry.

4.2  Information we collect automatically
When you visit or interact with the Website, we and our service providers automatically collect certain technical and usage information through cookies and similar technologies, server log files and analytics tools. This may include: your IP address and approximate (city/country-level) location; device type, operating system, and browser type and settings; the pages and content you view, links you click, and the dates and times of your visit; referring and exit pages and website navigation paths; and other diagnostic and traffic data. Further information about the cookies and similar technologies we use is set out in Section 6 (Cookies and Similar Technologies).

4.3  Information we receive from third parties
We may receive personal data about you from third parties, including: social media and advertising platforms (such as Meta/Facebook), where you submit a form or otherwise engage with our campaigns or pages on those platforms; analytics and advertising service providers; and publicly available or professional business sources, where you act in a business capacity. Where we receive your data from a social media platform, that platform processes your personal data in accordance with its own privacy policy, over which we have no control.

4.4  Special categories of data
We do not intentionally collect special categories of personal data (such as data revealing health, racial or ethnic origin, political opinions or religious beliefs) through the Website. Please do not submit such information to us.


5.  HOW WE USE YOUR PERSONAL DATA AND OUR LEGAL BASES

We process your personal data only where we have a lawful basis to do so under Article 6 GDPR. The table below sets out the purposes for which we process personal data and the corresponding legal basis.

Purpose
Personal data used
Legal basis
Responding to your enquiries, consultation and contact requests, and providing the information or assistance you request
Identification and contact details, company details, content of your enquiry
Steps taken at your request prior to entering into a contract (Art. 6(1)(b)); our legitimate interests in responding to and managing enquiries (Art. 6(1)(f))
Registering you for, administering and delivering webinars, events and related materials
Identification and contact details, company details, registration data
Performance of the service you requested (Art. 6(1)(b)); your consent where required (Art. 6(1)(a))
Sending you marketing communications about our solutions, vendors, webinars and events
Identification and contact details, company details, engagement data
Your consent (Art. 6(1)(a)); our legitimate interests in marketing similar solutions to existing business customers (Art. 6(1)(f))
Establishing and managing relationships with our partners, resellers, vendors and customers
Identification and contact details, company details, correspondence
Performance of a contract (Art. 6(1)(b)); our legitimate interests in conducting and developing our business (Art. 6(1)(f))
Operating, maintaining, securing and improving the Website, and preventing fraud and misuse
Technical and usage data, log files
Our legitimate interests in the security, integrity and proper functioning of the Website (Art. 6(1)(f))
Using analytics, measurement and advertising cookies and similar technologies
Technical and usage data, cookie identifiers
Your consent (Art. 6(1)(a))
Complying with our legal, regulatory, accounting and tax obligations
Relevant identification, transactional and correspondence data
Compliance with a legal obligation (Art. 6(1)(c))
Establishing, exercising or defending legal claims
Relevant personal data
Our legitimate interests in protecting our legal rights (Art. 6(1)(f))

Where we rely on your consent, you may withdraw it at any time as described in Section 11. Where we rely on our legitimate interests, you may object to the processing as described in Section 11, and we have carried out a balancing assessment to ensure that those interests are not overridden by your interests, rights and freedoms.


6.  COOKIES AND SIMILAR TECHNOLOGIES

The Website uses cookies and similar technologies. Cookies are small text files placed on your device that allow a website to function, to recognise your device and to collect information about your use of the site. We use the following categories of cookies and similar technologies:

Category
Purpose
Example of providers
Strictly necessary
Required for the Website to function and to be delivered securely; these cannot be switched off in our systems
Webflow (hosting ,content delivery); Cloudflare (security,rate-limiting)
Functional
Enable enhanced functionality and personalisation, such as remembering your preferences
Webflow
Analytics/performance
Help us understand how visitors use the Website so that we can measure and improve its performance
Google Analytics (via Google Tag Manager)
Establishing and managing relationships with our partners, resellers, vendors and customers
Identification and contact details, company details, correspondence
Performance of a contract (Art. 6(1)(b)); our legitimate interests in conducting and developing our business (Art. 6(1)(f))
Marketing/advertising
Used to deliver and measure the relevance of advertising and to support our campaigns, including on social media
Meta/Facebook (Meta Pixel); embedded media providers (YouTube, Embedly)

Strictly necessary cookies are used on the basis of our legitimate interests in operating and securing the Website. All other cookies are used only with your prior consent, which you may give, decline or withdraw at any time through the cookie consent banner.
You can also control and delete cookies through your browser settings. Please note that if you disable certain cookies, some features of the Website may not function properly. For a detailed and up-to-date list of the cookies we use, please see our Cookie Policy.


7.  DISCLOSURE OF YOUR PERSONAL DATA

We do not sell or rent your personal data.
We may disclose your personal data to the following categories of recipients:
– service providers and processors who process personal data on our behalf and under our instructions, including providers of website hosting and content delivery, analytics, advertising and social media tools, e-mail, marketing and webinar platforms, customer relationship management, and IT and security services – such providers are bound by written agreements that comply with Article 28 GDPR;
– our affiliated and group companies, where relevant to the purposes described in this Policy; professional advisers, including legal, accounting, audit and insurance advisers;
– vendors and partners, where necessary to respond to your enquiry or to administer a partner or customer relationship that you have requested;
– public authorities, regulators, courts and law-enforcement bodies, where we are required to do so by law or in order to protect our legal rights;
– and acquirers or successors, in connection with any merger, acquisition, reorganisation or sale of assets, subject to appropriate confidentiality safeguards.

The principal service providers we currently use include Webflow (website hosting and content delivery), Cloudflare (content delivery and website security), Google (analytics and tag management) and Meta (advertising and lead generation).  


8.  INTERNATIONAL DATA TRANSFERS

Some of our service providers are located outside the EEA, including in the United States (for example, Webflow, Cloudflare).
Where we transfer personal data outside the EEA, we ensure that an appropriate level of protection is in place by relying on one or more of the following safeguards:
– a European Commission adequacy decision in respect of the recipient country or framework, including the EU–U.S. Data Privacy Framework where the recipient is certified under it;
– or the European Commission’s Standard Contractual Clauses, together with any supplementary technical and organisational measures that may be required.

You may request further information about these safeguards, and a copy of the relevant transfer mechanism, by contacting us using the details in Section 1.


9.  DATA RETENTION

We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy any legal, accounting, tax or reporting requirements, and to establish, exercise or defend legal claims.
The criteria we use to determineretention periods include the nature of our relationship with you, the purpose of the processing, and applicable legal limitation and record-keeping periods. Indicative retention periods are set out below.

Category of data
Retention period
Enquiry and consultation data where no business relationship results
12 months from your last contact with us
Marketing and webinar/event data processed on the basis of consent
Until you withdraw consent or object, and in any event reviewed and deleted after 24 months of inactivity
Partner, reseller, vendor and customer relationship data
For the duration of the relationship and for 6 years thereafter
Website technical and cookie data
For the lifespan of the relevant cookie or log entry, generally up to 24 months

When personal data is no longer required, we securely delete or anonymise it.


10.  DATA SECURITY

We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include the encryption of data in transit (for example, TLS), access controls and authentication, the use of reputable service providers bound by confidentiality and security obligations, and the ongoing review of our security practices.

No method of transmission over the internet, or method of electronic storage, is completely secure, and we cannot guarantee absolute security.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority, and you where required, in accordance with the GDPR.


11.  YOUR RIGHTS

Subject to the conditions and exceptions set out in the GDPR, you have the following rights in relation to your personal data: 

(a) the right of access to your personal data and to information about how we process it; 
(b) the right to rectification of inaccurate or incomplete personal data; 
(c) the right to erasure (the “right to be forgotten”) in certain circumstances; 
(d) the right to restriction of processing in certain circumstances; 
(e) the right to data portability, allowing you to receive and reuse your personal data in certain circumstances; 
(f) the right to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing purposes; 
(g) the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you; and 
(h) where processing is based on your consent, the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out before its withdrawal. 

To exercise any of these rights, please contact us using the details in Section 1. We may need to verify your identity before responding. We will respond to your request without undue delay and, in any event, within one month of receipt, although this period may be extended for complex or numerous requests. Exercising your rights is generally free of charge, although we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.


12.  RIGHT TO LODGE A COMPLAINT

If you have any concerns about how we process your personal data, we encourage you to contact us first so that we can address the matter.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.
The supervisory authority in Cyprus is:
Office of the Commissioner for Personal Data Protection
Office address: Kypranoros 15, 1061 Nicosia, Cyprus
Postal address: P.O. Box 23378, 1682 Nicosia, Cyprus
Telephone: +357 22 818 456
E-mail: commissioner@dataprotection.gov.cy
Website: www.dataprotection.gov.cy


13.  MARKETING COMMUNICATIONS

Where you have consented, or where we are otherwise permitted to do so, we may send you marketing communications about our solutions, vendors, webinars and events.
You can opt out of marketing communications at any time by using the unsubscribe link in any marketing e-mail, or by contacting us using the details in Section 1.
Where we send marketing to existing business customers about our own similar solutions, we do so on the basis of our legitimate interests, and you may object at any time. Withdrawing consent or objecting to marketing will not affect any other processing of your personal data.


14.  CHILDREN’S DATA

The Website is intended for business users and is not directed at children. We do not knowingly collect personal data from children. If you believe that we have inadvertently collected personal data from a child, please contact us and we will take appropriate steps to delete it.


15.  THIRD-PARTY LINKS AND SERVICES

The Website may contain links to, and content from, third-party websites, platforms and resources, including vendor websites, social media platforms and embedded media (such as videos hosted on YouTube). We are not responsible for the privacy practices or the content of those third parties. We encourage you to review the privacy policies of any third-party services you access.


16.  AUTOMATED DECISION-MAKING AND PROFILING

We do not make decisions that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing. Where we use analytics or advertising tools that involve limited profiling for measurement or audience-targeting purposes, this is carried out on the basis of your consent and does not have legal or similarly significant effects on you.


17.  CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements or other factors. The “Last updated” date at the top of this Policy indicates when it was last revised. Where changes are material, we will take reasonable steps to bring them to your attention. We encourage you to review this Policy periodically.


18.  HOW TO CONTACT US

If you have any questions, requests or complaints regarding this Privacy Policy or our processing of your personal data, please contact us:

VAD ALLIANCE DISTRIBUTION LTD
Agias Faneromenis, 143–145, Patsias Court, Flat/Office 201, 6031 Larnaca, Cyprus
E-mail: sales@alliance-distribution.ai