Last updated: 23 September 2026
This Privacy Policy explains how TRIANMAR LTD, trading as IdealSense (“IdealSense”, “we”, “us”, “our”) collects and uses personal data when you visit idealsense.com.cy, buy from our online shop, or contact us. We process personal data in accordance with the EU General Data Protection Regulation 2016/679 (“GDPR”) and the Cyprus Law 125(I)/2018 on the protection of personal data.
1. Who is responsible for your data
The data controller is:
TRIANMAR LTD, trading as IdealSense (Ideal Sense Rejuvenation Center)
Kyriakou Matsi & Rodou 11, 1086 Nicosia, Cyprus
Email: idealsense@cytanet.com.cy · Phone: +357 22 526 333
We are not required to appoint a Data Protection Officer. For any question about this policy or your personal data, contact us at the email address above.
2. What data we collect, why, and on what legal basis
| Purpose | Personal data | Legal basis |
|---|---|---|
| Processing and delivering your order, including store pickup | Name, billing and delivery address, email address, phone number, products ordered, order notes | Performance of a contract (Art. 6(1)(b) GDPR) |
| Taking payment | You enter your card or wallet details directly with our payment provider. We receive only a payment reference, the card type and last four digits, and the result of the payment and fraud checks | Performance of a contract; our legitimate interest in preventing payment fraud (Art. 6(1)(f)) |
| Invoicing, accounting and tax | Order and payment records | Legal obligation (Art. 6(1)(c)) |
| Your customer account (optional) | Name, email address, password (stored encrypted), saved addresses, order history, wishlist | Performance of a contract |
| Customer service | Messages you send us and the order details needed to answer them | Performance of a contract, or our legitimate interest in answering your enquiries |
| Product reviews | Name, rating and review text (published); email address (not published) | Your consent, given when you submit a review |
| Keeping the website secure and working | IP address, browser and device information, pages requested, date and time, login attempts | Our legitimate interest in operating a secure website |
| Order attribution statistics (only if you accept marketing cookies) | How you reached our website (referring site, campaign codes), device type, number of pages viewed — stored with your order | Your consent |
| Establishing or defending legal claims | The records relevant to the claim | Our legitimate interest |
Where we rely on legitimate interests, we have balanced them against your rights. You can object at any time (see section 6).
Is providing data mandatory? We need your name, address, email and phone number to fulfil an order — our courier requires a phone number for delivery. Without them we cannot accept your order. Everything else, such as an account or a product review, is optional.
3. Who we share your data with
We share personal data only with the service providers we need to run our shop, and only as much as they need:
- Payments — WooPayments by WooCommerce, powered by Stripe. They process your payment and run fraud checks. If you pay with Apple Pay or Google Pay, Apple or Google also process your data under their own privacy policies.
- Delivery — ACS Courier (Cyprus) receives your name, delivery address and phone number to deliver your parcel.
- IT service providers — companies that host, secure and maintain our website and email, acting only on our instructions.
- Embedded content — the map on our contact page comes from an outside provider and loads only if you accept marketing cookies. Our Cookie Policy names the outside services our pages use.
- Advisers and authorities — our accountants, auditors and lawyers; tax authorities, courts or police where the law requires it.
If you would like the names of the companies we use, ask us and we will tell you.
We do not sell your personal data, and we do not use it for automated decisions that have legal or similarly significant effects on you. Our payment provider screens payments automatically for fraud and may decline one; if that happens, contact us and a person will review it.
4. Transfers outside the European Economic Area
Some of these providers, such as our payment providers and some IT service providers, may process data in the United States or other countries outside the EEA. When they do, the transfer is protected either by a European Commission adequacy decision — such as the EU–U.S. Data Privacy Framework for certified companies — or by the European Commission’s Standard Contractual Clauses. You can ask us for more information about these safeguards.
5. How long we keep your data
| Data | How long |
|---|---|
| Orders, invoices and payment records | 6 years from the end of the tax year in which the order was placed, as required by Cyprus tax law; then deleted or anonymised |
| Incomplete checkouts (basket details entered but not paid) | Deleted automatically, normally within 1 day |
| Unpaid, failed or cancelled orders | Up to 3 months |
| Customer account | Until you close it. Accounts with no login or order for 3 years may be deleted (your orders are kept for the period above) |
| Customer service correspondence | Up to 2 years after your request has been resolved |
| Product reviews | For as long as the product is listed, or until you ask us to remove your review |
| Security logs | Normally up to 90 days, longer only if needed to investigate an incident |
| Cookies | See our Cookie Policy |
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data, where there is no legal reason for us to keep it;
- restrict our processing in certain circumstances;
- data portability — receive the data you gave us in a machine-readable format;
- object to processing based on our legitimate interests, and at any time to direct marketing;
- withdraw your consent at any time, without affecting processing that took place before.
To exercise any of these rights, see Your Data Rights (GDPR) or email idealsense@cytanet.com.cy. We will answer within one month. This is free of charge. We may ask you to confirm your identity first.
Right to complain. If you believe we have not handled your data lawfully, you can lodge a complaint with the Commissioner for Personal Data Protection of Cyprus: Iasonos 1, 1082 Nicosia (P.O. Box 23378, 1682 Nicosia) · +357 22 818456 · commissioner@dataprotection.gov.cy · www.dataprotection.gov.cy. We would appreciate the chance to resolve your concern first, so please contact us.
7. Children
Our website and shop are not directed at children under 14, and we do not knowingly collect personal data from them.
8. How we protect your data
Our website is encrypted (HTTPS). Access to our website’s administration is restricted to authorised staff and secured with two-factor authentication. Card details are entered directly with our payment provider and are never stored on our website. We keep our software up to date and monitor the website for attacks. We will never ask you for your password or your full card details by email, phone or message. If you receive a request like this that seems to come from us, do not reply, and let us know.
9. Cookies
We use cookies and similar technologies. Functional cookies, which the shop needs to work, are always active. Marketing cookies and Google Maps are only used with your consent. See our Cookie Policy for details, and use Cookie settings at the bottom of any page to change your choices.
10. Changes to this policy
We may update this policy, for example when we add a new service. The date at the top shows when it last changed. If we make significant changes, we will highlight them on our website.
