Privacy Policy
Last updated: 28.05.2026
PK Headway Solutions Ltd respects your privacy and is committed to protecting personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (the GDPR) and applicable Cyprus data protection laws.
This Privacy Policy explains how we handle personal data in connection with the website https://pkheadwaysolutions.com/ and any business communication with us.
1. Controller and Company info
For the purposes of the GDPR, the data controller is PK Headway Solutions Ltd. The Company acts as data controller only in respect of personal data voluntarily provided to the Company and processed for business, contractual, administrative or legal purposes.
| Company | PK Headway Solutions Ltd |
| Registration number | HE 434139 |
| Registered address | Anastasiou Sioukri, 1, THEMIS COURT, Floor 4, Flat/Office 402, 3105, Limassol, Cyprus |
| [email protected] | |
| Website | https://pkheadwaysolutions.com/ |
2. Website visitors
You may visit the Website without creating an account, registering, submitting personal data or providing any information to us.
We do not collect, hold, analyse, track, profile or store personal data from ordinary Website visitors through the Website.
The only technical service relevant to access to the Website is Cloudflare or a similar infrastructure/security provider. Cloudflare may process limited technical information through its own infrastructure where this is necessary for security, traffic management, availability and protection against malicious activity.
We do not use Cloudflare technical information for marketing, advertising, analytics, behavioural tracking or profiling.
3. Cookies and similar technologies
Cookies are small text files that may be placed on a user's device when visiting a website. They may be used for security, functionality, analytics, advertising or tracking, depending on the website.
The Website does not have cookies.
| Technology | Status |
|---|---|
| Analytics cookies | Not used |
| Marketing cookies | Not used |
| Advertising cookies | Not used |
| Remarketing cookies | Not used |
| Behavioural profiling cookies | Not used |
| Tracking pixels or web beacons | Not used |
Cloudflare may, depending on its technical configuration, security settings, traffic conditions or security checks, theoretically place strictly necessary technical/security cookies. If such cookies are ever used, they would be used only for Website protection and operation, and not for analytics, marketing, advertising, behavioural tracking, profiling or remarketing.
| Possible cookie | Purpose |
|---|---|
| __cf_bm | May be used by Cloudflare Bot Management to identify and block automated malicious traffic. |
| cf_clearance | May be used where a visitor completes a CAPTCHA, JavaScript challenge or similar security check. |
| __cflb | May be used for Cloudflare Load Balancing to route users to the same origin server and maintain stable access. |
| _cfuvid | May be used to distinguish users sharing the same IP address, such as users on public Wi-Fi or shared networks. |
If any non-essential cookies or similar technologies are introduced in the future, this Privacy Policy will be updated and, where required by law, consent will be requested before such technologies are used.
4. Information voluntarily provided to us
We only process personal data where it is voluntarily provided to us, for example when you contact us by email, through the Website or through another business communication channel.
| Information | Examples and use |
|---|---|
| Contact details | Name, email address, telephone number, company name, position or role. Used for business and contractual communication. |
| Message content | Information included in an enquiry, email or other communication. Used for responding to the matter raised. |
| Business records | Business correspondence and communication records. Used for administration, contractual records and legal protection. |
We use voluntarily provided information only for business, contractual, administrative and related legal purposes. We do not sell, rent, trade or use personal data for advertising, profiling, behavioural tracking or remarketing.
5. Purpose and legal basis
| Purpose | Legal basis |
|---|---|
| Business communication: responding to enquiries, messages and business communications. | Legitimate interests |
| Contractual matters: discussing, preparing, performing or managing contractual or business relationships. | Contract or pre-contractual steps |
| Business administration: maintaining appropriate business correspondence and records. | Legitimate interests |
| Legal and regulatory matters: complying with legal obligations and protecting legal rights. | Legal obligation or legitimate interests |
| Consent-based processing: only where consent is specifically required by law. | Consent |
6. Sharing of personal data
We do not sell, rent or trade personal data. We do not share personal data with third parties unless this is necessary for contractual, business, administrative, legal or regulatory purposes.
| Recipient | Reason for sharing |
|---|---|
| Personnel and contractors | Where involved in the relevant business matter. |
| Clients, partners, suppliers or contractors | Where necessary for a business or contractual relationship. |
| Professional advisers | For legal, accounting, tax or compliance advice. |
| Public authorities, regulators or courts | Where required by law or necessary to protect legal rights. |
Any sharing is limited to what is necessary for the relevant purpose.
7. Storage and location of data
Personal data voluntarily provided to us is processed and kept within the European Economic Area (EEA).
We do not intentionally transfer personal data voluntarily provided to us outside the EEA. If a transfer outside the EEA becomes necessary in the future, it will be carried out only where lawful and subject to appropriate safeguards under the GDPR.
Cloudflare or similar infrastructure/security providers may process limited technical information through their own infrastructure where necessary for Website security, traffic management and technical operation.
8. Retention
We keep personal data only for as long as necessary for the purpose for which it was provided.
| Information | Retention approach |
|---|---|
| Business enquiries and correspondence | Kept for as long as necessary to manage the relevant business relationship, respond to communications, comply with contractual or legal obligations, or protect legal interests. |
| Legal, tax, accounting or dispute records | Kept for the period required or permitted by applicable law. |
When personal data is no longer required, we will delete it, anonymise it or restrict access to it where appropriate.
9. Sensitive personal data and security
We do not request or intentionally collect sensitive personal data, including health data, biometric data, political opinions, religious beliefs, trade union membership, criminal record data or similar information. Please do not send sensitive personal data to us by email, through the Website or by any other communication channel.
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, disclosure or destruction. Access to personal data is limited to persons who need such access for the purposes described in this Privacy Policy.
10. Your rights under GDPR
Subject to the GDPR and applicable law, you may have the following rights in relation to your personal data.
| Right | Meaning |
|---|---|
| Access | You may request access to your personal data. |
| Rectification | You may request correction of inaccurate or incomplete personal data. |
| Erasure | You may request deletion of your personal data in certain circumstances. |
| Restriction and objection | You may request restriction of processing or object to processing based on legitimate interests. |
| Portability | You may request data portability where applicable. |
| Withdrawal of consent | Where processing is based on consent, you may withdraw consent at any time. |
To exercise your rights, please contact us at [email protected]. We may request additional information to verify your identity before processing your request.
11. Complaints
If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with the competent data protection supervisory authority. In Cyprus, the competent authority is the Office of the Commissioner for Personal Data Protection.
You may also contact us first at [email protected] so that we can try to address your concern directly.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business, Website, technical configuration, service providers or legal requirements. The updated version will be published on the Website with a new “Last updated” date.
13. Contact us
For questions about this Privacy Policy or the way we process personal data, please contact us using the details below.
| Company | PK Headway Solutions Ltd |
| Registration number | HE 434139 |
| Registered address | Anastasiou Sioukri, 1, THEMIS COURT, Floor 4, Flat/Office 402, 3105, Limassol, Cyprus |
| [email protected] | |
| Website | https://pkheadwaysolutions.com/ |
© 2026 PK Headway Solutions Ltd. All rights reserved.
Unauthorised use, copying, reproduction, distribution, modification, publication or any other infringement of the Website content, intellectual property rights, copyrights, trademarks, materials or other protected rights of PK Headway Solutions Ltd may result in legal consequences in accordance with applicable law.