Privacy Policy

Last updated: 8 August 2026

This Privacy Policy explains how EIROPIAN PARTS LTD ("Europarts", "we", "us" or "our") collects, uses, shares and protects personal data when you visit europarts.cy (the "Website"), create an account, place an order, contact us, subscribe to marketing communications, or otherwise use our services.

We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR"), applicable Cyprus data protection law, and the rules applicable to cookies and similar technologies.

1. Who is responsible for your personal data?

The data controller is:

EIROPIAN PARTS LTD

Registration number: HE458184

Registered address: Spyrou Kyprianou Ave 3, 3070 Agios Georgios, Limassol, Cyprus

Telephone: +357 999 400 70

Website: europarts.cy

You may contact us about privacy or exercise your data protection rights using the contact details above or the Contact Us facility on the Website.

2. What personal data do we collect?

Depending on how you use the Website and our services, we may process the following categories of personal data:

Account and contact information

Your name, email address, telephone number, account details and other information you provide when creating or managing an account.

Order and delivery information

Billing and delivery address, products ordered, order value, order history, delivery details, returns, warranty requests and related correspondence.

Payment and transaction information

Payment method, payment status, transaction references and information needed to process or reconcile a payment. Where a third-party payment provider collects payment-card or other financial details directly, its own privacy terms also apply.

Vehicle and product-search information

Information you provide or select to identify a vehicle or compatible parts, such as make, model, engine, registration-related information or VIN, where applicable.

Customer-service and communications information

Messages, enquiries, support requests, complaints, return or warranty information, and records of our communications with you.

Technical and usage information

IP address, device and browser information, operating system, language, referring URLs, pages viewed, interactions with the Website, timestamps, diagnostic information, security logs and similar technical data.

Marketing and preference information

Your newsletter or marketing preferences, cookie choices and any consent or objection you have communicated to us.

Cookies and similar technologies

Identifiers and information generated through cookies, pixels, tags, local storage and similar technologies, as explained in section 6 below.

We normally collect personal data directly from you, from your use of the Website, and from service providers involved in providing the service you request, such as payment and delivery providers.

3. Why do we use your personal data and what is our legal basis?

We only process personal data where we have a lawful basis under the GDPR.

Purpose Typical data used Legal basis
Create and manage your account Account and contact information Performance of a contract or steps at your request before entering into a contract (Art. 6(1)(b) GDPR)
Process, fulfil and deliver orders Contact, order, delivery and transaction information Performance of a contract (Art. 6(1)(b) GDPR)
Process payments, refunds, returns and warranty requests Contact, order, transaction and support information Performance of a contract (Art. 6(1)(b) GDPR); compliance with legal obligations where applicable (Art. 6(1)(c))
Respond to enquiries and provide customer support Contact and communications information Performance of a contract or steps at your request (Art. 6(1)(b)); legitimate interests in operating customer support where the request is not contractual (Art. 6(1)(f))
Keep records required by tax, accounting, consumer-protection or other laws Order, transaction and relevant customer information Compliance with legal obligations (Art. 6(1)(c) GDPR)
Protect the Website, accounts and transactions; detect fraud, abuse and security incidents Technical, account and transaction information Legitimate interests in protecting our business, customers and IT systems (Art. 6(1)(f) GDPR); legal obligations where applicable (Art. 6(1)(c))
Establish, exercise or defend legal claims Relevant account, order, payment and communications information Legitimate interests in protecting and enforcing legal rights (Art. 6(1)(f) GDPR)
Send newsletters and electronic marketing where consent is required Contact and marketing-preference information Your consent (Art. 6(1)(a) GDPR and applicable electronic-marketing rules)
Measure Website use using non-essential analytics technologies Technical, usage and cookie data Your consent (Art. 6(1)(a) GDPR)
Measure advertising, create audiences or support personalised/targeted advertising using marketing technologies Technical, usage and cookie data Your consent (Art. 6(1)(a) GDPR)

Where we rely on legitimate interests, we consider whether the processing is necessary and whether your rights and interests override our interests. You may object to processing based on legitimate interests as explained in section 10.

Where we ask for consent, providing it is voluntary. You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

We do not treat your acceptance of this Privacy Policy as consent to processing that requires consent.

4. Is providing personal data mandatory?

You may browse much of the Website without providing account or order information. However, information marked as required during registration, checkout, payment, delivery, returns or support is necessary for us to provide the relevant service or comply with applicable law.

If you do not provide information necessary to enter into or perform a contract, we may be unable to create an account, process an order, deliver products, issue a refund or provide the requested service.

Consent to analytics or marketing cookies is not required to purchase products or use the core functionality of the Website.

5. Who receives your personal data?

We may disclose personal data only where necessary and for the purposes described in this Policy, including to:

  • hosting, cloud, IT, cybersecurity and Website-support providers;
  • payment and fraud-prevention providers;
  • couriers, postal operators, logistics and fulfilment providers;
  • customer-support and communications providers;
  • professional advisers such as accountants, auditors, insurers and lawyers;
  • analytics and advertising technology providers, but only where the applicable processing is permitted and, where required, you have given consent;
  • public authorities, regulators, courts or law-enforcement bodies where disclosure is required or permitted by law; and
  • a purchaser, investor or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and data-protection safeguards.

Depending on the service and configuration in use, our analytics and advertising providers may include Google, Meta, Microsoft Clarity and PostHog. These providers may act as our processors, independent controllers or, for particular processing operations, joint controllers, depending on the service concerned and the provider's applicable terms.

We require service providers acting on our behalf to process personal data under appropriate contractual and security obligations.

6. Cookies and similar technologies

We use cookies and similar technologies such as pixels, tags and local storage. A cookie is a small text file or identifier stored on or accessed from your device. Similar technologies can perform comparable functions without necessarily using a traditional browser cookie.

We use these technologies for the categories below.

Strictly necessary

These technologies are required for functions you explicitly request or for the Website to operate securely, for example session management, shopping-cart functions, account login, security, load balancing and storing your cookie choice.

Where the applicable ePrivacy rules permit strictly necessary storage or access without consent, we do not ask for consent for these technologies.

Analytics

Analytics technologies help us understand how visitors use the Website, measure performance, identify errors and improve the Website. Depending on the production configuration, these may include Google analytics services, Microsoft Clarity and PostHog.

Analytics technologies that are not strictly necessary are disabled until you actively choose to allow Analytics in Cookie Settings.

Marketing

Marketing technologies help us measure advertising campaigns, conversions, build advertising audiences and, where enabled, show or support more relevant advertising. Depending on the production configuration, these may include Meta Pixel and Google advertising technologies.

Marketing technologies are disabled until you actively choose to allow Marketing in Cookie Settings.

Your cookie choices

When the cookie banner is shown, you can:

  • Accept all non-essential technologies;
  • Reject all non-essential technologies; or
  • choose separately whether to allow Analytics and Marketing in Manage preferences.

Strictly necessary technologies remain active where they are required to provide a service you request.

You can change or withdraw your choices at any time by opening Cookie Settings from the Website footer. It must be as easy to withdraw consent as it is to give it.

The current list of cookies and similar technologies, including their provider, purpose, category and storage duration, is available in Cookie Settings. The list reflects the technologies enabled in the current production configuration and may change when services are added, removed or reconfigured.

Withdrawing consent stops future non-essential processing based on that consent. It does not make processing carried out before withdrawal unlawful. You may also delete cookies already stored on your device using your browser settings.

7. International transfers

Some of our service providers or their group companies may process personal data outside Cyprus or the European Economic Area (EEA).

Where personal data is transferred to a country outside the EEA, we use a transfer mechanism permitted by Chapter V of the GDPR, as applicable. This may include an adequacy decision adopted by the European Commission, Standard Contractual Clauses approved by the European Commission together with supplementary measures where necessary, or another lawful transfer mechanism.

You may contact us for further information about the safeguards relevant to a particular transfer.

8. How long do we keep personal data?

We keep personal data only for as long as necessary for the purpose for which it was collected, including to meet legal, accounting, tax, consumer-protection and reporting obligations and to establish, exercise or defend legal claims.

In particular:

  • account information is generally kept while the account remains active and thereafter only for as long as necessary for legal, security or dispute-resolution purposes;
  • order, invoice, payment and transaction records are kept for the period required by applicable tax, accounting, consumer-protection and other laws;
  • support, complaint, return and warranty records are kept for as long as needed to resolve the matter and, where relevant, for an appropriate period afterwards to deal with claims or legal obligations;
  • security and technical logs are kept for a limited period appropriate to security and troubleshooting needs, unless a longer period is necessary to investigate an incident or protect legal rights;
  • marketing contact data is used until you withdraw consent, unsubscribe or object, after which we may keep minimal suppression information to ensure we respect your choice; and
  • cookie and consent information is kept for the relevant cookie/storage duration and for as long as reasonably necessary to record and demonstrate your consent choices.

Where several retention rules apply, we use the longest period that is necessary for the relevant legal or operational purpose. We delete or anonymise personal data when it is no longer required.

9. How do we protect personal data?

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected having regard to the nature of the processing, available technology, implementation costs and the risks to individuals.

No online system can be guaranteed to be completely secure. If we become aware of a personal-data breach, we will assess and handle it in accordance with applicable legal requirements.

10. Your data protection rights

Subject to the conditions and limitations in the GDPR, you may have the right to:

  • access your personal data and receive information about how it is processed;
  • rectify inaccurate personal data and complete incomplete data;
  • erase your personal data in circumstances where the GDPR gives you that right;
  • restrict processing in certain circumstances;
  • receive and transmit certain personal data in a structured, commonly used and machine-readable format (data portability);
  • object at any time to processing based on our legitimate interests, on grounds relating to your particular situation;
  • object at any time to direct marketing, including related profiling; and
  • withdraw consent at any time where processing is based on consent.

To exercise a right, contact us using the details in section 1. We may need information necessary to verify your identity before acting on a request. We will respond within the period required by applicable law.

You also have the right to lodge a complaint with a supervisory authority. In Cyprus, the competent authority is:

Office of the Commissioner for Personal Data Protection

Office address: Kypranoros 15, Nicosia 1061, Cyprus

Postal address: P.O. Box 23378, 1682 Nicosia, Cyprus

Telephone: +357 22818456

Website: dataprotection.gov.cy

You may also lodge a complaint with another competent supervisory authority where the GDPR allows this.

11. Automated decision-making

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, unless we specifically inform you otherwise and provide the information and safeguards required by law.

12. Third-party websites and services

The Website may contain links to third-party websites or services. Their processing of personal data is governed by their own privacy notices, and we recommend reviewing those notices before providing personal data to them.

13. Changes to this Privacy Policy

We may update this Privacy Policy when our services, technologies or legal obligations change. The current version will be published on this page and identified by the Last updated date above.

Where a change materially affects processing based on consent, we will request new consent where required. We will not treat continued use of the Website as consent where the law requires an affirmative choice.

We use cookies for analytics and advertising to improve your experience. See our Privacy Policy.

Your cart

×