Skip to content

Last updated:

Privacy Policy

1. Introduction

This Privacy Policy explains how V. F. S. VERTEXFIN SOLUTIONS LTD, a company incorporated under the laws of the Republic of Cyprus with registration number HE 452567 and registered office at 11, Filippou, Agios Dometios, 2363, Nicosia, Cyprus (“Vertex”, “we”, “us” or “our”), collects, uses, discloses, stores and protects personal data in connection with the website available at https://vertexgroup.tech, including any pages, solution pages, materials, information, contact forms and content made available through that website (“Website”).

This Privacy Policy applies when you:

(a) access or use the Website;

(b) submit information through a contact form or other Website functionality;

(c) communicate with Vertex in relation to the Website, a business enquiry or potential commercial cooperation;

(d) participate in pre-contractual onboarding initiated through or following an enquiry submitted through the Website; or

(e) interact with cookies and similar technologies used on the Website.

For the purposes of Regulation (EU) 2016/679 (“GDPR”) and applicable data protection laws, Vertex acts as the controller in respect of the personal data processed for the purposes described in this Privacy Policy, except where expressly stated otherwise.

This Privacy Policy also applies to personal data processed in connection with business enquiries and pre-contractual onboarding initiated through or following the Website. This may include business contact details and information relating to directors, authorised representatives and ultimate beneficial owners of prospective customers.

This Privacy Policy does not fully describe personal data processed in connection with the provision, implementation, operation or support of Vertex solutions, platforms, software, APIs, integrations or customer-specific services under separate written agreements.

Where Vertex processes personal data on behalf of a customer in connection with such solutions or services, Vertex may act as a processor and the relevant customer may act as the controller. Such processing is governed by the applicable customer agreement, data processing agreement and other relevant documentation and is not fully described in this Privacy Policy.

2. Purpose and data protection principles

This Privacy Policy should be read together with the Website Terms of Use and the Cookie Policy.

When processing personal data as a controller, Vertex complies with the following data protection principles:

(a) personal data is processed lawfully, fairly and transparently;

(b) personal data is collected for specified, explicit and legitimate purposes and is not further processed in a manner incompatible with those purposes;

(c) personal data is adequate, relevant and limited to what is necessary for the purposes for which it is processed;

(d) personal data is accurate and, where necessary, kept up to date;

(e) personal data is retained in an identifiable form for no longer than is necessary for the purposes for which it is processed;

(f) personal data is processed securely, including through appropriate protection against unauthorised or unlawful processing and against accidental loss, destruction or damage; and

(g) Vertex is responsible for, and takes appropriate measures to demonstrate, compliance with applicable data protection requirements.

3. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Website, our personal data processing activities, technical or organisational measures, legal or regulatory requirements, applicable guidance or business operations.

The latest version of this Privacy Policy will be made available on the Website and identified by the “Last updated” date stated at the top of this Privacy Policy.

Where required by applicable data protection law, or where a change materially affects how we process your personal data or your rights, we will take appropriate steps to inform you. This may include posting a notice on the Website or contacting you directly where we have your contact details and it is appropriate to do so.

Where your consent is required for any new or materially different processing activity, we will request your consent before that processing begins.

We encourage you to review this Privacy Policy periodically to remain informed about how we process and protect your personal data.

4. What personal data we collect

Under the GDPR, personal data means any information relating to an identified or identifiable natural person. Information that has been irreversibly anonymised so that an individual is no longer identifiable is not personal data.

We may collect and process the following categories of personal data through or in connection with the Website, business enquiries and pre-contractual onboarding.

(a) Contact and enquiry data

When you contact us through the Website, submit a business enquiry or otherwise communicate with us in relation to the Website, we may collect:

(i) your name;

(ii) your company or organisation name;

(iii) your email address and other contact details;

(iv) your message, comment or enquiry; and

(v) any other information that you choose to provide to us.

Unless specifically requested by Vertex for a stated and lawful purpose, please do not submit through general Website contact forms:

(i) special categories of personal data;

(ii) personal data relating to criminal convictions, offences or related security measures;

(iii) payment card data, bank account credentials or authentication credentials;

(iv) confidential customer or business information that is not necessary for your enquiry;

(v) personal data relating to another individual unless you are authorised to provide it; or

(vi) unlawful content or other information that is not necessary for your enquiry.

(b) Communication data

If you communicate with us by email or other means, we may process information contained in or relating to that communication, including your contact details, the content of the communication, associated metadata and any follow-up correspondence.

(c) Technical data

When you access or use the Website, we may automatically collect technical information, including:

(i) your IP address;

(ii) browser type and version;

(iii) device type and operating system;

(iv) time zone setting and approximate location derived from technical data;

(v) access dates and times;

(vi) referring website or traffic source; and

(vii) other technical information generated through your access to or use of the Website.

(d) Usage data

We may collect information about how visitors use and interact with the Website, including pages visited, time spent on the Website, interactions with Website content, navigation patterns and other Website usage information.

(e) Cookie and analytics data

The Website may use cookies and similar technologies. These may include strictly necessary cookies required for the operation, security and functionality of the Website and, where enabled, analytics cookies, including cookies used in connection with Google Analytics 4.

Analytics cookies are used only where they have been enabled and you have provided any consent required under applicable law. You may manage or withdraw your consent at any time through the cookie banner or cookie settings tool made available on the Website.

Further information about the cookies and similar technologies used on the Website, including their categories, purposes, providers and retention periods, is available in our Cookie Policy.

(f) Business contact data

Where you act on behalf of a company or other organisation, we may process your business contact details, job title, professional role, authority to represent or act on behalf of that organisation and information relating to the relevant business enquiry or potential commercial cooperation.

(g) Onboarding and due diligence data

Where you or the organisation you represent submits a business enquiry or participates in pre-contractual onboarding, we may process personal data relating to the prospective customer’s directors, authorised representatives, signatories, shareholders and ultimate beneficial owners.

Depending on the nature of the prospective relationship and the applicable onboarding requirements, such personal data may include:

(i) name, date and place of birth, nationality and country of residence;

(ii) business and residential contact details;

(iii) job title, professional role and relationship with the prospective customer;

(iv) information concerning authority to represent or act on behalf of the prospective customer;

(v) identification and verification information, including information contained in identification documents;

(vi) information concerning ownership, control and beneficial interests;

(vii) professional, business and regulatory information;

(viii) information obtained through sanctions screening, politically exposed person screening and other compliance checks; and

(ix) personal data contained in corporate documents, ownership records, licences, compliance materials, business descriptions, websites, applications, transaction flow descriptions, payment flow descriptions and other due diligence documentation.

We may obtain such personal data:

(i) directly from you;

(ii) from the prospective customer or its representatives;

(iii) from public registers and other publicly available sources; or

(iv) from third-party due diligence, identity verification, screening, compliance or business information providers.

We may process this personal data for customer assessment, pre-contractual onboarding, know your business checks, ownership and control verification, sanctions screening, politically exposed person screening, internal risk assessment, compliance review, fraud and financial crime prevention, assessment of whether relevant third-party provider requirements can be satisfied and determination of whether Vertex solutions may be made available to the prospective customer.

(h) Special categories of personal data and criminal offence data

Vertex does not request or seek to collect special categories of personal data or personal data relating to criminal convictions, offences or related security measures through general Website contact forms.

Special categories of personal data include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic data, biometric data used for the purpose of uniquely identifying an individual, health data and data concerning an individual’s sex life or sexual orientation.

However, such data may occasionally be contained in information received during onboarding, due diligence, compliance screening or legal and regulatory reviews.

Vertex will process special categories of personal data only where an appropriate legal basis under Article 6 of the GDPR and an applicable condition under Article 9(2) of the GDPR have been identified.

Personal data relating to criminal convictions, offences or related security measures will be processed only where and to the extent that such processing is authorised by applicable Union or Member State law and appropriate safeguards are in place in accordance with Article 10 of the GDPR.

Where such information is provided but is not required or Vertex does not have a lawful basis to process it, Vertex may take reasonable steps to delete it, restrict its further processing or otherwise handle it in accordance with applicable law.

(i) Whether you are required to provide personal data

Providing personal data through general Website contact forms is generally voluntary. However, certain information may be required in order to submit an enquiry, enable us to respond to you, assess proposed commercial cooperation or complete applicable pre-contractual onboarding and due diligence checks.

Where personal data is required, we will indicate this at the relevant point of collection. Depending on the circumstances, certain onboarding information may be necessary to enter into a contract, comply with applicable legal requirements or determine whether Vertex solutions may be made available to the prospective customer.

If you do not provide the required personal data, we may be unable to process or respond to your enquiry, continue the onboarding process, assess the proposed commercial relationship or make the relevant Vertex solution available to the prospective customer.

Unless otherwise stated at the relevant point of collection, providing personal data through the Website is not a statutory or contractual requirement.

(j) Personal data obtained from other sources

Where we obtain personal data about you from a source other than you, we will provide you with the information required under applicable data protection law by providing you with a copy of or a link to this Privacy Policy, or by other appropriate means.

We will provide such information within a reasonable period after obtaining the personal data and, where required, no later than one month after obtaining it. Where the personal data is used to communicate with you or is disclosed to another recipient, we will provide the relevant information no later than the time of our first communication with you or the first disclosure, as applicable.

This requirement may not apply where you already have the relevant information or where another exemption under applicable data protection law applies.

5. Legal bases for processing your personal data

We process personal data only where we have identified an appropriate lawful basis under applicable data protection laws, including Article 6 of the GDPR.

The applicable legal basis depends on the purpose, nature and circumstances of the relevant processing activity. We may rely on the following legal bases.

(a) Consent

We may process your personal data where you have given us consent to do so.

This applies, where required by applicable law, to the use of non-essential cookies and similar technologies, including analytics cookies used in connection with Google Analytics 4.

You may withdraw your consent at any time through the cookie settings tool made available on the Website or by using another withdrawal method described when your consent is requested.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

(b) Steps prior to entering into a contract

We may process your personal data where this is necessary to take steps at your request before entering into a contract with you personally.

This may apply, for example, where you request information about Vertex solutions or discuss potential commercial cooperation in circumstances where you would be a party to the proposed contract.

This legal basis does not generally apply solely because you act as a director, employee, authorised representative, signatory, shareholder or ultimate beneficial owner of a company or other organisation that may enter into a contract with Vertex.

(c) Legitimate interests

We may process personal data where this is necessary for the legitimate interests pursued by Vertex or a third party, provided that those interests are not overridden by your interests, rights or freedoms.

Depending on the relevant processing activity, our legitimate interests may include:

(i) operating, administering, maintaining and protecting the Website;

(ii) responding to business enquiries and managing business communications;

(iii) developing and managing relationships with prospective customers, partners, suppliers and other business contacts;

(iv) assessing proposed commercial cooperation and determining whether Vertex solutions may be made available to a prospective customer;

(v) verifying the identity, role, authority, ownership and control of persons connected with a prospective customer;

(vi) conducting proportionate know your business checks, sanctions screening, politically exposed person screening, fraud prevention, financial crime prevention, compliance reviews and internal risk assessments, where such processing is not required by a specific legal obligation;

(vii) satisfying proportionate due diligence and risk-management requirements of relevant third-party providers;

(viii) ensuring the security and integrity of the Website, systems, communications and business operations;

(ix) understanding and improving Website performance, content, functionality and visitor experience using data that may lawfully be processed without consent;

(x) maintaining appropriate business, legal, technical, security, compliance and audit records;

(xi) establishing, exercising or defending legal claims and protecting the legal and commercial interests of Vertex; and

(xii) evaluating, negotiating, completing and implementing an actual or proposed merger, acquisition, investment, financing, restructuring, sale, transfer or other corporate transaction involving all or part of our business or assets.

Where we rely on legitimate interests, we assess whether the processing is necessary and proportionate and whether your interests, rights or freedoms override the interests pursued.

(d) Legal obligation

We may process personal data where this is necessary to comply with a specific legal or regulatory obligation applicable to Vertex.

This may include compliance with applicable corporate, accounting, tax, record-keeping, sanctions or reporting requirements and responding to legally binding requests, orders or decisions issued by competent authorities, courts, regulators or other public bodies.

We will rely on this legal basis for onboarding, due diligence, sanctions screening or other compliance activities only where a specific legal obligation applicable to Vertex requires the relevant processing.

(e) Performance of a contract

Where we have entered into a contract with you personally, we may process your personal data where this is necessary to perform that contract or exercise rights arising under it.

Where a contract is entered into with a company or other organisation that you represent, the processing of your business contact details and related communications will generally be based on our legitimate interests rather than the performance of a contract with you personally.

(f) Special categories of personal data and criminal offence data

Where we process special categories of personal data, we will identify both an appropriate legal basis under Article 6 of the GDPR and an applicable condition under Article 9(2) of the GDPR.

Where we process personal data relating to criminal convictions, offences or related security measures, we will do so only where authorised by applicable Union or Member State law and subject to appropriate safeguards in accordance with Article 10 of the GDPR.

In connection with pre-contractual onboarding, the applicable legal basis will depend on the individual concerned and the purpose of the processing. In particular:

(i) legitimate interests will generally apply to personal data relating to directors, authorised representatives, signatories, shareholders and ultimate beneficial owners of a prospective corporate customer;

(ii) steps prior to entering into a contract may apply where the individual is personally expected to become a party to the contract and the processing is necessary to take steps at that individual’s request; and

(iii) legal obligation will apply only where a specific legal or regulatory requirement applicable to Vertex requires the relevant processing.

6. Purposes for which we process your personal data

We may process personal data collected through or in connection with the Website, business enquiries and pre-contractual onboarding for the following purposes:

(a) to operate, administer, maintain and protect the Website;

(b) to receive, review and respond to enquiries, messages and requests submitted through the Website or otherwise sent to Vertex;

(c) to communicate with prospective customers, partners, suppliers and other business contacts;

(d) to assess proposed commercial cooperation, solution enquiries and other business requests;

(e) to determine whether a prospective customer may be accepted and whether Vertex solutions may be made available to that prospective customer;

(f) to conduct pre-contractual onboarding, know your business checks, identity and authority verification, ownership and control verification, sanctions screening, politically exposed person screening, fraud and financial crime prevention, internal risk assessment and compliance review;

(g) to assess whether relevant third-party provider requirements can be satisfied;

(h) to manage and retain appropriate records of Website-related communications, business enquiries, onboarding activities and commercial discussions;

(i) to ensure the security and integrity of the Website, systems and communications and to prevent unauthorised access, misuse, fraud, cyber incidents and other unlawful or harmful activity;

(j) to monitor, analyse and improve the Website, its content, functionality, performance and visitor experience, where permitted by applicable law;

(k) to manage cookie preferences and, where the required consent has been given, use analytics cookies and similar technologies, including Google Analytics 4;

(l) to comply with applicable legal and regulatory obligations;

(m) to respond to legally binding requests, orders or decisions issued by competent authorities, courts, regulators or other public bodies;

(n) to establish, exercise or defend legal claims and protect the rights, property and legitimate interests of Vertex;

(o) to maintain appropriate business, legal, technical, security, compliance and audit records; and

(p) to evaluate, negotiate, complete and implement an actual or proposed merger, acquisition, investment, financing, restructuring, sale, transfer or other corporate transaction involving all or part of our business or assets.

The purposes listed above do not mean that every category of personal data will be processed for every purpose. We process only the personal data that is necessary and proportionate for the relevant purpose.

We will use personal data only for the purposes for which it was collected, unless we reasonably determine that further processing is compatible with the original purpose and permitted by applicable law.

If we intend to process personal data for an unrelated purpose, we will provide the information required by applicable data protection law before that processing begins and, where necessary, obtain your consent.

Except for business enquiries and pre-contractual onboarding described in this Privacy Policy, personal data processed in connection with customer onboarding, Vertex solutions, solution operations, integrations, APIs, platforms or customer-specific services may be subject to separate customer agreements, data processing agreements, solution-specific terms or other applicable documentation.

7. Disclosures of your personal data

We may disclose your personal data to third parties where this is necessary for the purposes described in this Privacy Policy, where required or permitted by applicable law or where we have another lawful basis to do so.

Depending on the relevant processing activity, we may disclose personal data to the following categories of recipients:

(a) website hosting, cloud infrastructure, information technology, cybersecurity and technical support providers that help us operate, maintain, secure and support the Website and our related systems;

(b) analytics providers, including Google Analytics 4, where the relevant analytics cookies or similar technologies are enabled with your consent;

(c) email, communication, customer relationship management, document management and business administration providers that help us receive, manage and respond to enquiries and communications;

(d) affiliated or related companies operating separate websites, solutions or services referenced on the Website, where this is necessary to respond to or route your enquiry, manage business communications, assess proposed commercial cooperation or direct you to the appropriate entity, website, solution or service;

(e) professional advisers, including lawyers, auditors, accountants, consultants and insurers, where this is necessary for legal, compliance, audit, insurance, business or risk-management purposes;

(f) competent authorities, regulators, courts, law enforcement bodies and other public authorities, where disclosure is required by applicable law, necessary to comply with a legally binding request, order or decision, or necessary to establish, exercise or defend legal claims;

(g) prospective or actual buyers, investors, successors, financing parties, professional advisers and other relevant participants in connection with an actual or proposed merger, acquisition, investment, financing, restructuring, sale, transfer or other corporate transaction involving all or part of our business or assets; and

(h) identity verification, due diligence, screening, compliance, fraud prevention and business information providers that support onboarding checks, ownership and control verification, sanctions screening, politically exposed person screening, internal risk assessment, compliance review and business verification.

We disclose only the personal data that is reasonably necessary for the relevant purpose and, where appropriate, take steps to ensure that the recipient is authorised to receive and process that personal data.

Where a recipient processes personal data on our behalf as a processor, we enter into appropriate data processing arrangements and require the recipient to process the personal data only on our documented instructions, implement appropriate technical and organisational measures and comply with applicable data protection requirements.

Some recipients may process personal data as independent controllers in respect of their own processing activities. This may apply, for example, to professional advisers, public authorities and certain analytics, screening, compliance or technology providers. Where a recipient acts as an independent controller, its processing may be subject to its own privacy notice, legal obligations and data protection responsibilities.

We do not sell your personal data.

8. International transfers

Vertex is established in Cyprus. However, some of the recipients described in this Privacy Policy may be located outside the European Economic Area or may access personal data from a country outside the European Economic Area.

Where personal data is transferred outside the European Economic Area, we will ensure that the transfer is made in accordance with applicable data protection laws and that an appropriate transfer mechanism or other lawful basis for the transfer is in place.

Depending on the relevant transfer, we may rely on:

(a) an adequacy decision adopted by the European Commission in respect of the relevant country, territory, sector or international organisation;

(b) standard contractual clauses approved by the European Commission, together with any supplementary contractual, technical or organisational measures required in the circumstances;

(c) binding corporate rules or another appropriate safeguard permitted under Article 46 of the GDPR, where applicable; or

(d) a derogation permitted under Article 49 of the GDPR, where the conditions for that derogation are satisfied in the specific circumstances.

Where required, we will assess the circumstances of the transfer, including the laws and practices applicable in the recipient country, and implement supplementary contractual, technical or organisational measures designed to protect the transferred personal data.

You may contact us using the contact details provided in this Privacy Policy if you would like further information about the transfer mechanisms or safeguards applicable to transfers of your personal data, including information about how to obtain a copy of the relevant safeguards where available.

9. Data security

We have implemented appropriate technical and organisational measures designed to ensure a level of security appropriate to the risks associated with the processing of personal data and to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access and other unlawful processing.

Access to personal data is limited to personnel, contractors, service providers and other authorised persons who require such access for the performance of their duties or for the purposes described in this Privacy Policy. Such persons are subject to appropriate confidentiality, security or contractual data protection obligations.

Where a service provider processes personal data on our behalf as a processor, we require that provider to implement appropriate technical and organisational measures and to process the personal data in accordance with our documented instructions and applicable data protection laws.

We maintain procedures for identifying, assessing, managing and responding to suspected personal data breaches.

Where Vertex acts as the controller, we will notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Where a personal data breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, unless an exception under applicable data protection law applies.

The transmission of information over the internet, including by email and through online forms, is not completely secure. Although we take appropriate measures to protect personal data, no method of internet transmission or electronic storage can be guaranteed to be entirely secure. This does not affect our obligations under applicable data protection laws.

10. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by applicable law.

When determining an appropriate retention period, we consider:

(a) the nature, amount and sensitivity of the personal data;

(b) the purposes for which the personal data is processed and whether those purposes can be achieved by other means;

(c) the nature and duration of our relationship with you or the organisation you represent;

(d) the risks associated with unauthorised use or disclosure of the personal data;

(e) applicable legal, regulatory, accounting, tax, audit, compliance and record-keeping requirements;

(f) relevant limitation periods and the need to establish, exercise or defend legal claims; and

(g) documented retention requirements connected with relevant third-party provider arrangements, only to the extent that continued retention remains necessary, proportionate and lawful.

In general:

(a) contact, enquiry and communication data is retained for as long as reasonably necessary to respond to the relevant enquiry, manage related communications and maintain appropriate business records;

(b) business contact data is retained for as long as reasonably necessary to assess, establish or manage the relevant prospective or existing business relationship and related communications;

(c) technical, security and log data is retained for a limited period necessary for Website operation, security monitoring, incident investigation, troubleshooting and record-keeping;

(d) cookie and analytics data is retained for the periods specified in the Cookie Policy and the applicable cookie settings;

(e) onboarding and due diligence data is retained for as long as reasonably necessary to complete the relevant assessment, document the outcome of the onboarding process, satisfy applicable legal and compliance requirements and proportionate, documented requirements connected with relevant third-party provider arrangements, manage related risks and establish, exercise or defend legal claims; and

(f) personal data required for legal, regulatory, accounting, tax, audit, compliance or dispute-related purposes may be retained for the period required or permitted under applicable law.

Personal data may be retained for a longer period where this is necessary in connection with an actual or reasonably anticipated legal claim, investigation, regulatory enquiry or legally binding request.

When personal data is no longer required, we will delete it or irreversibly anonymise it. Where immediate deletion is not technically possible, for example because personal data is contained in a backup system, we will securely restrict access to that personal data and prevent further processing until deletion becomes possible, except where processing is required by applicable law.

Information that has been irreversibly anonymised so that no individual can be identified may be retained and used for statistical, analytical, business or technical purposes.

11. Your legal rights

Subject to the conditions, limitations and exceptions provided under applicable data protection laws, you may have the following rights in relation to your personal data:

(a) the right to request access to your personal data and obtain information about how it is processed;

(b) the right to request correction of inaccurate personal data and completion of incomplete personal data;

(c) the right to request deletion of your personal data;

(d) the right to request restriction of the processing of your personal data;

(e) the right to object to processing based on legitimate interests, including profiling related to such processing;

(f) where personal data is processed for direct marketing purposes, the right to object to that processing at any time;

(g) the right to receive personal data that you have provided to us in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller, where the applicable legal requirements for data portability are satisfied;

(h) the right to withdraw your consent at any time where processing is based on consent; and

(i) the right not to be subject to a decision based solely on automated processing, including profiling, where that decision produces legal effects concerning you or similarly significantly affects you, subject to the exceptions permitted by applicable law.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, you may contact us at mail@vertexgroup.tech.

We may request additional information reasonably necessary to verify your identity and ensure that personal data is not disclosed to an unauthorised person.

We will respond to your request without undue delay and ordinarily within one month of receiving it. Where permitted by applicable law, this period may be extended by up to two additional months due to the complexity or number of requests. If an extension is required, we will inform you within one month of receiving your request and explain the reasons for the extension.

The exercise of your rights is generally free of charge. However, where a request is manifestly unfounded or excessive, in particular because of its repetitive nature, we may charge a reasonable fee or refuse to act on the request, as permitted by applicable law.

You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus. You may alternatively lodge a complaint with another competent supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement.

12. Third-party links and separate services

The Website may contain links or references to third-party websites, platforms, tools, content, materials, resources or services.

If you follow a link to a third-party website or interact with a third-party service, that third party may collect or process personal data about you in accordance with its own privacy notice, terms and practices.

Vertex does not control third-party websites or services and is not responsible for their privacy practices, content or security. We encourage you to review the applicable privacy notice before providing personal data to or interacting with a third-party website or service.

13. Cookies and similar technologies

The Website uses strictly necessary cookies and may use other cookies and similar technologies, including analytics cookies, as described in the Cookie Policy.

Strictly necessary cookies are used for the operation, security and functionality of the Website. They may be placed without your consent only to the extent permitted by applicable law.

Analytics cookies, including cookies used in connection with Google Analytics 4, are used only where they have been enabled and you have provided any consent required under applicable law.

You may manage or withdraw your consent at any time through the cookie banner or cookie settings tool made available on the Website. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Further information about the cookies and similar technologies used on the Website, including their categories, purposes, providers, retention periods and available preference controls, is provided in the Cookie Policy.

14. Automated decision-making

As of the date of this Privacy Policy, Vertex does not use personal data processed for the purposes described in this Privacy Policy to make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

If this changes, we will update this Privacy Policy and provide the information required by applicable data protection laws before carrying out such processing.

15. Contact us

If you have any questions, comments or requests regarding this Privacy Policy or the processing of your personal data, you may contact us at:

V. F. S. VERTEXFIN SOLUTIONS LTD

Registration number: HE 452567

Registered office: 11, Filippou, Agios Dometios, 2363, Nicosia, Cyprus

Email: mail@vertexgroup.tech