This Privacy Policy explains how TKOCY LTD (“SMSCY”, “we”, “us”, “our”) collects, uses, shares and protects personal data when you visit smscy.com, create an account on the SMSCY platform (including our customer dashboard, API and any mobile application we make available for sending messages through a device connected to your account), or receive a message sent through our platform.

We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (Law 125(I)/2018), and the Regulation of Electronic Communications and Postal Services Law (Law 112(I)/2004), as amended.

1. Who we are

The data controller for the website and for your SMSCY account is:

TKOCY LTD
Panagias Evaggelistrias 89B
4156 Limassol, Cyprus
VAT Number: CY10399700T
Telephone: +357 25253190
Email: info@smscy.com

For any question about this policy or about your personal data, you can contact us at the details above. Please put “Data Protection” in the subject line of your email.

2. Our two roles: controller and processor

Because SMSCY is a messaging platform, we handle personal data in two different capacities:

  • As a controller – for the personal data of website visitors and of the people who register and use an SMSCY account (our “Customers” and their authorised users). Sections 3 to 11 of this policy describe this processing.
  • As a processor – for the personal data of the people our Customers send messages to (the “Recipients”): their phone numbers, names, any custom fields the Customer uploads, the content of messages, and replies. For this data our Customer is the controller and we act only on the Customer’s instructions, under the data processing terms included in our Terms and Conditions. Section 12 explains what this means if you have received a message through SMSCY.

3. Personal data we collect

3.1 Data you give us

  • Account and profile data – name, company name, email address, mobile number, postal address, VAT number, username and password (stored in hashed form), language and time-zone preferences.
  • Billing data – billing address, VAT/tax details, invoices, chosen plan, credit purchases and payment history. Card and bank details are entered directly with our third-party payment providers; we do not store full card numbers on our systems. For offline payments (bank transfer) we record the transaction reference.
  • Contact-form and support data – the name, email, mobile number and message you send us through the contact form, by email or by telephone, and our correspondence with you.
  • Sender ID requests – the sender names you ask us to register and any supporting documents we need to submit to mobile operators.
  • Contacts, groups and templates – the phone books, contact groups, custom fields, blacklists, message templates and campaign settings you create or upload (we process Recipient data in these as a processor – see section 12).

3.2 Data generated by using the platform

  • Message data – the content of messages you send, the recipient numbers, sender ID, sending time, message type (e.g. SMS, Unicode, MMS, OTP), delivery status and operator delivery reports, credits used, and any replies received on two-way numbers or keywords.
  • Usage and log data – IP address, browser and device type, operating system, pages viewed, login dates and times, session history, API calls and API token usage, webhook delivery attempts and failed-login attempts.
  • Security data – two-factor authentication settings and one-time codes, active sessions and devices, and audit records of administrative actions.
  • Connected-device data – if you use a mobile application to send messages through your own device and SIM card, we collect the device identifier, application version, SIM/operator information, connection status, and the messages and delivery statuses processed through that device. Where you enable the relevant features, this may also include incoming messages, USSD responses and call logs from the connected SIM.

3.3 Data from third parties

  • Social sign-in – if you choose to log in with Google, Facebook or a similar provider, we receive your name, email address and profile identifier from that provider.
  • Payment providers – confirmation of payment, the last four digits of your card, and fraud-screening results.
  • Mobile operators and SMS aggregators – delivery reports, number-validity information and operator error codes.

4. Why we use your data and on what legal basis

Purpose Legal basis (GDPR Art. 6)
Creating and managing your account, providing the platform, API and mobile application, routing and delivering your messages, showing delivery reports Performance of a contract (Art. 6(1)(b))
Processing payments, issuing invoices, managing credits and subscriptions, recovering unpaid amounts Performance of a contract; legal obligation (accounting and VAT law)
Registering and verifying sender IDs with mobile operators and regulators Performance of a contract; legal obligation
Keeping traffic and message records required by telecommunications, tax and anti-fraud legislation Legal obligation (Art. 6(1)(c))
Securing the platform: authentication, two-factor codes, session management, spam and fraud detection, blocking abusive traffic, investigating complaints about messages Legitimate interests (Art. 6(1)(f)) in protecting our systems, our Customers, Recipients and mobile networks; legal obligation
Responding to your enquiries and support requests Performance of a contract or steps prior to a contract; legitimate interests
Sending service notices (delivery failures, low credit, invoices, security alerts, changes to terms) Performance of a contract; legitimate interests
Sending our own marketing emails or SMS about SMSCY products to Customers Consent (Art. 6(1)(a)), or our legitimate interest in marketing similar services to existing customers, subject to your right to opt out at any time (Law 112(I)/2004, s.106)
Analysing how the website and platform are used in order to improve them Legitimate interests; consent for non-essential cookies
Establishing, exercising or defending legal claims Legitimate interests

Where we rely on legitimate interests we have balanced those interests against your rights. You may ask us for details of that assessment.

5. Who we share your data with

We share personal data only where necessary and only with the following categories of recipient:

  • Mobile network operators and SMS aggregators / gateway providers in Cyprus and, where a Recipient’s number is in another country, abroad. They receive the recipient number, sender ID and message content needed to deliver a message.
  • Payment service providers (for example card processors, PayPal and similar) for processing your payments.
  • Hosting, infrastructure and email providers that host our servers, databases, backups and transactional email.
  • Push-notification providers used to wake a connected mobile device when messages are queued for it.
  • Social sign-in providers, if you choose to use them.
  • Professional advisers – accountants, auditors, lawyers and insurers.
  • Public authorities – including the Office of the Commissioner of Electronic Communications and Postal Regulation (OCECPR), the Commissioner for Personal Data Protection, the Tax Department, courts and law-enforcement authorities, where we are legally required to do so or to protect our rights.
  • A buyer or successor in the event of a merger, acquisition or sale of our business, under confidentiality.

We do not sell personal data and we do not share your contact lists with other Customers or with advertisers.

6. International transfers

Our primary systems are located in the European Economic Area. Some of our providers (for example payment processors, push-notification services, or aggregators used to reach numbers outside the EEA) may process data outside the EEA. Where this happens we rely on an adequacy decision of the European Commission or on the Standard Contractual Clauses approved by the Commission, together with additional safeguards where needed. You can request a copy of the relevant safeguards by contacting us.

7. How long we keep your data

  • Account data – for as long as your account is active and for up to 12 months after it is closed, unless a longer period is required by law.
  • Invoices, payments and accounting records – 7 years, as required by Cyprus tax and company law.
  • Message content and delivery records – for the retention period selected in your account settings, and otherwise for a default period of 12 months, after which they are deleted or anonymised. Aggregated, non-identifying statistics may be kept longer.
  • Traffic and log data – up to 12 months for security and troubleshooting, or longer where required by law or needed for an ongoing investigation or legal claim.
  • Contact-form and support correspondence – up to 24 months from our last contact with you.
  • Sender ID registration records – for as long as the sender ID is active and 24 months thereafter.

8. How we protect your data

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit (TLS), hashed passwords, optional two-factor authentication, role-based access for staff, API tokens with configurable permissions, session management with remote logout, logging of administrative access, regular backups, firewalls and malware protection, and contractual confidentiality obligations for staff and providers. No system is completely secure; if we become aware of a personal data breach that is likely to result in a risk to you we will notify the Commissioner for Personal Data Protection and, where required, you, within the time limits set by the GDPR.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data in certain circumstances (for example where it is no longer needed);
  • restrict processing in certain circumstances;
  • data portability – receive the data you provided to us in a structured, commonly used, machine-readable format;
  • object to processing based on our legitimate interests, and to object at any time to direct marketing;
  • withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions; automated spam filtering may temporarily hold a message for human review.

You can exercise most of these rights directly from your account settings (profile, notification preferences, active sessions, data export). For anything else, email info@smscy.com. We will respond within one month, extendable by two further months for complex requests. We may need to verify your identity before acting on a request.

If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the supervisory authority in Cyprus:

Office of the Commissioner for Personal Data Protection
1 Iasonos Street, 1082 Nicosia, Cyprus
P.O. Box 23378, 1682 Nicosia
Tel.: +357 22818456
Website: www.dataprotection.gov.cy

You may also complain to the supervisory authority of the EU Member State where you live or work. We would appreciate the chance to address your concern first.

10. Cookies and similar technologies

Our website and platform use:

  • Strictly necessary cookies – for login sessions, security (including CSRF protection and two-factor authentication), load balancing and remembering your preferences. These do not require consent.
  • Analytics cookies – to understand how visitors use the website so we can improve it. These are set only with your consent, which you can give or withdraw through the cookie banner or your browser settings.

You can block or delete cookies through your browser settings; some parts of the platform will not work without the strictly necessary cookies.

11. Children

SMSCY is a business service. Our website and platform are not directed at, and we do not knowingly collect data from, anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.

12. If you received a message sent through SMSCY

SMSCY provides the technical platform that businesses, organisations and public bodies in Cyprus use to send SMS marketing, alerts, reminders and one-time passwords. The organisation whose name appears as the sender is the controller of your data. It decided to send you the message and is responsible for having a lawful basis to do so – for example your consent, or an existing customer relationship with a clear opt-out, as required by section 106 of Law 112(I)/2004 and the GDPR.

What we do with your data as a processor: we store your number, the message and its delivery status for the sender’s records, route the message to your mobile operator, and record any reply you send to a two-way number or keyword. We do not use Recipient data for our own purposes and we do not sell or share it with other senders.

To stop receiving messages from a sender: reply STOP (or the opt-out keyword given in the message) if one is available, or contact the sender directly using the details in the message. Once a number is opted out it is placed on that sender’s blacklist and cannot be messaged again by that sender through our platform. If you cannot reach the sender, or if you believe a message was sent unlawfully, contact us at info@smscy.com and we will forward your request to the sender and, where appropriate, block the number on our side. You can also complain to the Commissioner for Personal Data Protection (details in section 9) or the Office of the Commissioner of Electronic Communications and Postal Regulation (OCECPR).

13. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top shows when it was last changed. For material changes we will notify account holders by email or a notice in the dashboard before the change takes effect. Continued use of the website or platform after the effective date means the updated policy applies.

14. Contact

TKOCY LTD, Panagias Evaggelistrias 89B, 4156 Limassol, Cyprus · Tel. +357 25253190 · info@smscy.com