Skip to content
StageacrossGroup
Start a Conversation
← Back to home

Privacy Policy

In accordance with Regulation (EU) 2016/679 (GDPR)

This Privacy Policy explains how Stageacross Group Ltd ("we", "us", "the company") processes personal data when you visit this website or contact us. We are committed to protecting your privacy and handling your data transparently and lawfully.

1. Controller identity

Controller
Stageacross Group Ltd
Registered office
Androkleous 7, 1060 Nicosia, Cyprus
Registration number
HE 488138
VAT / Tax number
CY60344778P
Director
Martin Goger
Email
hello [ät] stageacross.com

2. Contact details for data protection matters

For any question relating to this policy or to the processing of your personal data, please contact us at hello [ät] stageacross.com. We have not appointed a separate Data Protection Officer, as we are not legally required to do so; data protection enquiries are handled by the company's management.

3. What data we collect through this website

We process the following categories of personal data:

  • Contact form data — the name, email address, company/brand (optional) and message content you choose to submit.
  • Consent record — confirmation that you agreed to the privacy consent statement, together with the time of submission.
  • Server log data — technical information automatically transmitted by your browser (see Section 8).
  • Spam-protection data — minimal technical values generated by our spam-protection mechanism (see Section 9).

We do not knowingly collect special categories of personal data through this website, and you should not submit such data in the contact form.

4. Purposes of processing

  • To receive, review and respond to enquiries submitted through the contact form or by email.
  • To operate, secure and maintain the technical availability of the website.
  • To prevent abuse, spam and automated submissions.
  • To comply with legal obligations where applicable.

5. Legal basis under the GDPR

  • Article 6(1)(a) — consent: for processing the personal data you submit via the contact form, based on the consent checkbox.
  • Article 6(1)(b) — pre-contractual steps: where your enquiry concerns entering into a potential service relationship.
  • Article 6(1)(f) — legitimate interests: for website security, spam prevention and the proper technical operation of the site. Our legitimate interest is the safe and reliable provision of the website.
  • Article 6(1)(c) — legal obligation: where we are required to retain certain records by law.

6. Retention period

We keep contact enquiry data only for as long as necessary to handle your request and any resulting correspondence. If no business relationship arises, enquiry data is generally deleted within 12 months, unless a longer period is required to comply with legal retention obligations. Server log data is retained for a short period for security purposes (typically up to 30 days) and then deleted or anonymised.

7. Recipients and processors

Your data may be processed on our behalf by service providers acting as processors under Article 28 GDPR — for example our website hosting provider and email provider. Such providers process data only on our documented instructions and under appropriate data-processing agreements. We do not transfer your personal data to third parties for their own purposes. Where a processor is located outside the European Economic Area, we ensure an adequate level of protection through appropriate safeguards such as Standard Contractual Clauses.

8. Server log files

When you access this website, our hosting infrastructure may automatically record technical data such as the requesting IP address, date and time of access, the page requested, the referring URL, and browser/operating-system information. This data is processed on the basis of Article 6(1)(f) GDPR for the purpose of ensuring security, stability and correct functioning of the website. It is not used to identify individuals and is not combined with other data.

9. Spam protection

To protect the contact form against automated abuse, we use a privacy-friendly, self-hosted proof-of-work mechanism and a hidden "honeypot" field. This approach does not set tracking cookies, does not profile you and does not transmit your data to third-party advertising services such as external CAPTCHA providers. Only minimal technical values needed to validate a genuine submission are processed, on the basis of Article 6(1)(f) GDPR.

10. Contact form processing

When you submit the contact form, the information you provide is used solely to process and respond to your enquiry. Providing your name, email and message is necessary to respond; the company/brand field is optional. You may withdraw your consent at any time with future effect by emailing hello [ät] stageacross.com; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

11. Cookies and analytics

This website uses only strictly necessary functionality and does not set marketing or tracking cookies by default. We do not use external analytics or advertising trackers. Should analytics be introduced in future, it will require your prior consent and will be documented in our Cookie Policy.

12. No sale of personal data

We do not sell, rent or trade your personal data. We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

13. Your rights

Under the GDPR, you have the right to:

  • Access — obtain confirmation of whether we process your data and a copy of it (Art. 15).
  • Rectification — have inaccurate or incomplete data corrected (Art. 16).
  • Erasure — request deletion of your data where applicable (Art. 17).
  • Restriction — request restriction of processing in certain cases (Art. 18).
  • Objection — object to processing based on legitimate interests (Art. 21).
  • Data portability — receive your data in a structured, machine-readable format (Art. 20).
  • Withdraw consent — at any time, with effect for the future (Art. 7(3)).

To exercise any of these rights, contact us at hello [ät] stageacross.com.

14. Complaint to a supervisory authority

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent authority in Cyprus is the Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy). You may also contact the supervisory authority in your country of residence or place of the alleged infringement.

15. Updates to this policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. The current version is always available on this page.

© 2026 Stageacross Group Ltd · Cyprus Legal Notice Privacy Policy Cookie Policy