DataBackNow Privacy Policy
Effective Date: October 5, 2026
DataBackNow ("we," "our," or "us") operates the website databacknow.com (the "Service").
This Privacy Policy describes how we collect, use, process, share, and protect your personal information when you visit our website, communicate with us, or utilize our physical offline data recovery, data backup/restore, or technical support services.
Because our operations are based in Nicosia, Cyprus, we process all personal data in strict compliance with European data protection standards, specifically the General Data Protection Regulation (GDPR) (EU) 2016/679 and the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data (Law 125(I)/2018).
1. Information We Collect
We collect distinct categories of information depending on how you interact with our website and laboratory services.
A. Information You Provide Directly to Us
- Identity and Contact Data: When you request a quote, book a device pickup, or submit a data recovery ticket, we collect your first name, last name, email address, telephone number, and physical pickup/delivery address.
- Financial and Billing Data: To process invoice payments for diagnostics, delivery, and successful recoveries, we collect necessary payment details (such as bank details, corporate tax identifiers, and transaction histories). Note: We do not directly store credit card numbers on our servers; payments are handled through secure, PCI-compliant third-party payment gateways.
- Customer Support and Communications: Any details, text, or files you provide when communicating with our support team via email, contact forms, or phone calls.
B. Technical and Device Metadata We Collect
- Damaged Media Specifications: To log, track, and diagnose your order, we document the technical specifications of your submitted storage device. This includes the brand, model, serial number, storage capacity, file system type, interface type, and a description of the physical or logical failure.
- Website Usage and Technical Data: When you browse databacknow.com, we automatically log information transmitted by your browser. This includes your Internet Protocol (IP) address, browser type and version, time zone setting, operating system, referral source, page interaction data, and exact timestamps of your visits.
2. The Data We Do NOT Collect or Retain
- No Digital File Uploads: Our website does not provide cloud storage, portal uploads, or digital file hosting. Users cannot upload the contents of their hard drives or files to our website servers.
- No Content Retention (0-Day Retention Policy): While we physically clone and manipulate your storage media in our local laboratory to extract your data, we enforce a strict 0-day retention window. Once the extracted data is transferred to the new return media device and delivered to you, all temporary images, files, and workspace fragments are immediately and permanently destroyed using secure cryptographic erasure standards. We do not retain copies of your recovered files under any circumstances.
3. Legal Basis for Processing Under the GDPR
We only process your personal data when we have a valid legal framework to do so. We rely on the following legal bases:
- Performance of a Contract (Art. 6(1)(b) GDPR): Processing your contact details, address, and device metadata is strictly necessary for us to fulfill our contractual obligations to you—specifically, managing logistics, diagnosing the media, recovering the data, and returning the devices.
- Compliance with a Legal Obligation (Art. 6(1)(c) GDPR): We must process and retain your billing information, tax identifiers, and transaction history to comply with legal statutory obligations under Cyprus tax, VAT, and corporate accounting laws.
- Legitimate Interests (Art. 6(1)(f) GDPR): We process technical website data to protect our infrastructure against cyber attacks, prevent fraud, optimize website performance, and maintain service security.
4. How We Share Your Information
We do not sell, rent, or trade your personal data to third parties for marketing purposes. We only disclose your information to trusted third-party service providers who assist us in operating our business:
- Logistics and Courier Partners: If we utilize independent courier networks instead of our in-house delivery team, we share your name, phone number, and physical address with them solely to facilitate the secure collection and return of your hardware.
- Payment Processors: Your billing information is shared directly with authorized financial institutions and secure payment gateway providers to validate transactions.
- Legal Authorities: We may disclose your information if legally required to do so by the courts or law enforcement authorities within the Republic of Cyprus to comply with legal procedures or protect public safety.
5. Data Security and International Transfers
- Local Storage: All personal data (such as customer accounts and order histories) is stored and processed on secure servers located within the European Economic Area (EEA). Your physical storage media never leaves our secure laboratory facility in Nicosia, Cyprus.
- Technical Safeguards: We implement robust technical and organizational security measures—including SSL/TLS encryption for website traffic, firewalls, strict access controls, and laboratory surveillance—to prevent unauthorized access, alteration, or disclosure of your data.
6. Data Retention Erasure Windows
- Customer Account and Billing Data: We retain your identity, contract, and invoice records for a minimum of 7 years to fulfill legal, tax, and accounting retention mandates under Cyprus legislation.
- Recovered Storage Content: As detailed in our 0-day retention policy, the actual contents recovered from your storage devices are held on our offline laboratory extraction units only until delivery is executed. They are erased instantly (0 days) following project closure.
7. Your Data Protection Rights Under GDPR
As an EEA resident, you possess comprehensive legal rights regarding your personal data. You may exercise these rights at any time:
- Right of Access: You have the right to request clear copies of the personal data we hold about you.
- Right to Rectification: You can request that we immediately correct any inaccurate or incomplete personal information.
- Right to Erasure ("Right to Be Forgotten"): You may request the deletion of your personal data when it is no longer necessary for the purposes it was collected, subject to statutory tax retention laws.
- Right to Restrict or Object to Processing: You have the right to limit how we process your data or object to specific processing activities based on legitimate interests.
- Right to Data Portability: You can request that we transfer your personal data to another organization or directly to you in a structured, machine-readable format.
- Right to Lodge a Complaint: If you believe our processing violates data protection laws, you have the right to file an official complaint with the Cyprus Data Protection Commissioner (Office of the Commissioner for Personal Data Protection).
8. Cookies and Tracking Technologies
Our website uses essential and analytical cookies to maintain session states and analyze generalized traffic patterns. You can configure your internet browser settings to reject all cookies or alert you when a cookie is issued. Restricting essential cookies may impact your ability to use specific interactive features of our booking platform.
9. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any discretion to reflect service changes or legislative updates. Any revisions will be signaled by updating the "Effective Date" at the top of this document. We encourage you to review this page periodically to stay informed about how we protect your privacy.
10. Contact us
If you have any questions, concerns, or wish to formally exercise any of your GDPR data protection rights, please contact our team at:
- E-mail: info@databacknow.com
- Location: Nicosia, Cyprus
Or use our Contact Form.
