Effective date [PUBLICATION DATE]
This Privacy Policy explains how P&M PERKS & MORE LTD uses personal data when you visit perksandmore.com, contact us, apply as an employer or merchant, request employee access, join the Personal Access Waitlist, or use the Perks+More platform and associated mobile application where available.
1. Who is responsible for your data
P&M PERKS & MORE LTD is a company incorporated in the Republic of Cyprus under registration number HE 497384. Our registered office is 118 Ellados, 3041 Limassol, Cyprus. We operate under the Perks+More brand.
Privacy enquiries and requests: [PRIVACY EMAIL]. General support: [SUPPORT EMAIL]. You may also write to our registered office, marked for the attention of the Privacy Contact.
We act as a data controller when we decide why and how to use personal data for our website, business enquiries, membership service, security and communications. Your employer separately controls its employment records and decisions about eligibility. Merchants separately control information they collect for their own sales and services.
If we handle particular employee records solely on an employer's documented instructions, we act as its processor for that activity. The employer's privacy notice and our data processing agreement govern that instructed processing. Our role depends on the activity, rather than the label given to the overall relationship.
2. Personal data we use
The information we use depends on your relationship with us and the features you use. It can include:
- Contact and enquiry details, such as your name, email address, telephone number, company, job role, message and correspondence with us.
Employer and merchant application details, including representative details, business information, billing contacts, proposed offers and documents needed to assess an application. Business information is personal data where it identifies an individual, including a sole trader.
Membership information, such as your name, account identifier, email address, employer affiliation, invitation and verification status, access permissions and login credentials or authentication records.
Benefit activity, such as saved offers, preferences, redemption requests, merchant and offer identifiers, validation results and related timestamps, where the relevant feature is used.
Employee access requests and waitlist details, including your contact details, employer name, interest in membership and the choices you make about receiving updates or sharing your identity with your employer.
Technical information, such as IP address, browser and device information, security logs, session identifiers, error records and information collected through cookies or similar technologies.
Records of terms acceptance, privacy choices, consent, withdrawal and requests to exercise your rights.
Fields marked as required are needed to respond to your request, assess an application or provide the requested feature. If you do not provide them, we may be unable to complete that action. Optional marketing and tracking choices do not determine your eligibility for core membership.
Please do not send identity documents, medical information, payment card details or other sensitive information unless we specifically request it through an appropriate process. We do not require your employer to provide salary, performance or medical records to establish ordinary membership eligibility.
3. Where information comes from
We receive information directly from you, from authorised representatives of employers and merchants, and from your use of our services. A participating employer may provide the information needed to invite you, confirm eligibility or end access. A merchant may provide information needed to validate an offer or investigate a redemption problem.
We may check business representative information against the business website or public company registers when assessing an application. We do not treat the publication of an email address as consent to receive marketing.
When we first contact you using details supplied by your employer or another source, we identify that source and provide this notice. Where GDPR Article 14 applies, we provide the required information within its applicable time limits, ordinarily at first contact and no later than one month after obtaining the data, or by the first disclosure if earlier.
4. Why we use data and our legal bases
Enquiries and business applications
We use contact, company and correspondence details to answer questions, review applications, arrange discussions and administer employer and merchant relationships. Our basis is legitimate interests in responding to requests and operating those relationships under GDPR Article 6(1)(f). Where you personally enter a contract with us, or ask us to take steps towards one, necessary processing instead relies on Article 6(1)(b). An employer's contract does not, by itself, make each employee a party to that contract.
Member accounts and benefits
We use membership, authentication and necessary benefit activity data to provide the member service you request, manage access and validate offers. Where this is necessary to perform our member agreement with you, we rely on Article 6(1)(b). Before you activate an account, processing that we determine for eligibility checks or an employer invitation relies on our legitimate interests in securely providing an employer-sponsored benefit, subject to your rights. Processing solely on an employer's instructions follows that employer's lawful basis.
Security and service administration
We use technical records and relevant account activity to detect misuse, maintain service reliability, resolve support issues and protect accounts. We rely on legitimate interests in operating a secure and reliable service. This basis does not replace any consent required for access to information on your device. Essential account, security and service messages are separate from marketing.
Employee access requests
We use the details you submit to respond to your request and assess interest at your workplace. Our basis is legitimate interests in handling that request. We use demand information without identifying you when approaching an employer. We ask for your separate consent before identifying you to your employer as someone who requested Perks+More.
Personal Access Waitlist and marketing
We rely on consent under Article 6(1)(a) to send the personal membership availability updates you request. Separate consent covers general news, offers or other promotional messages. Joining the waitlist does not subscribe you to general marketing or create a paid membership. You can withdraw consent through the unsubscribe option or by contacting us.
Optional analytics and advertising
Where enabled, optional analytics, advertising and similar tracking rely on your prior consent. The Cookie Policy and Cookie Settings explain the technologies, purposes, providers and choices that apply. We do not treat continued browsing as consent.
Legal obligations and claims
We retain and disclose information required by applicable accounting, tax or other legal duties under Article 6(1)(c). Necessary processing to establish, exercise or defend legal claims relies on legitimate interests, unless a specific legal duty applies. We limit the data and retention to the relevant obligation or claim.
When we rely on legitimate interests, we assess the purpose, necessity and effect on your rights. You may ask about that assessment and object to the processing. Where consent applies, refusal or withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. What employers and merchants can see
An authorised employer administrator can access the membership information needed to administer its employees' access, such as names, work email addresses, invitation or activation status and eligibility. Reports about benefit use are provided at an aggregated level that does not identify individual employees. We do not give employers individual browsing histories or itemised personal purchase histories as part of standard reporting.
A merchant receives only the information needed for the relevant offer, such as eligibility confirmation, an offer or redemption reference and, where necessary for validation, your displayed name or employer affiliation. The validation screen explains what will be shown before you proceed. Merchants do not receive access to the employer's full employee list through redemption.
If you buy directly from a merchant, that merchant handles its own sales, booking, payment and customer records under its privacy notice. We may share relevant information with it to investigate a complaint you ask us to help resolve.
6. Other recipients
We use service providers for functions such as hosting, technical support, authentication, email delivery, customer support, business administration and, where enabled, consented analytics or advertising. Their access must be limited to their function. Providers acting as processors operate under data protection terms and our documented instructions. Any provider using data for its own purposes must have its role and processing explained in the relevant notice or consent information.
We may disclose necessary information to professional advisers, insurers, competent authorities or courts where lawfully required or necessary to protect legal rights. A proposed business sale or reorganisation may involve limited disclosure under confidentiality and other appropriate safeguards. Any successor's use of data remains subject to applicable data protection law and relevant notice requirements.
We do not sell member contact lists or provide them to merchants for independent marketing. A merchant must obtain its own lawful permission for marketing it sends to you.
7. International transfers
Our processing locations and transfer arrangements are: [INTERNATIONAL TRANSFER DETAILS]. This information covers hosting, backups, support access and other service providers.
Where personal data is transferred outside the European Economic Area, we use an applicable adequacy decision or appropriate safeguards, such as the European Commission's Standard Contractual Clauses, supported by an assessment and additional protections where required. We do not rely on encryption alone as the legal mechanism for a transfer. You can contact our Privacy Contact for information about the relevant safeguard or a copy, with confidential information redacted where appropriate.
8. Cookies and optional device features
Our Cookie Policy explains cookies, local storage and similar website technologies. Cookie Settings lets you accept or reject optional categories and change your choices. Rejecting optional tracking does not prevent basic access to the website or core account functions.
If an available feature needs access to your camera, location or device notifications, we explain the purpose when requesting permission. For example, camera access may support a redemption scan. You can change device permissions in your settings. Device permission does not automatically authorise unrelated advertising or marketing. Any optional feature involving additional data must be explained before you enable it.
We do not use solely automated decisions producing legal or similarly significant effects on you. Routine access checks may prevent login when an account is unverified or no longer eligible. Contact support if you think a restriction is incorrect and request human review. Any future profiling or automated decision feature requiring additional information will be explained before use.
9. How long we keep data
We apply the following retention rules. A specific legal obligation or a documented dispute may require a limited exception for relevant records.
| Data | Retention rule |
|---|---|
| Enquiries and unsuccessful business applications | [ENQUIRY RETENTION] after the last substantive contact or application decision, unless a relationship begins. |
| Personal Access Waitlist | Until you withdraw or [WAITLIST RETENTION] after joining or actively renewing your interest, whichever comes first. |
| Active membership records | While your account is active and needed to provide membership. Following closure, deletion or anonymisation within [ACCOUNT DELETION PERIOD], subject to specific lawful exceptions. |
| Identifiable benefit activity | [ACTIVITY RETENTION] after the event, unless needed for a live support issue, fraud investigation or legal claim. |
| Routine security and technical logs | [LOG RETENTION] from creation, with relevant incident records retained only as needed to resolve and document the incident. |
| Contracts and accounting records | For the applicable statutory period, or the applicable limitation period where necessary for a legal claim. This does not justify keeping unrelated browsing or benefit history. |
| Consent and opt out records | Necessary evidence for the applicable accountability or claims period. A minimal suppression record is kept while needed to ensure you are not contacted against your wishes. |
| Backups | Deleted records leave routine backups within [BACKUP ROTATION PERIOD]. Until then, backups remain restricted and are not used for ordinary business activity. |
Where we act as a processor, the relevant employer's instructions and agreed deletion or return arrangements apply. Properly anonymised statistics that no longer identify an individual may be retained separately.
10. Your rights and choices
Depending on the circumstances, you can request access to your personal data, correction of inaccurate data, deletion, restriction of processing, and portability of data processed automatically on the basis of consent or a contract. You can withdraw consent at any time.
You can object to processing based on legitimate interests because of your particular situation. We will stop unless we demonstrate overriding compelling grounds or need the information for legal claims. You can object to direct marketing at any time, including related profiling. We will stop that marketing.
Send requests to [PRIVACY EMAIL]. We may request proportionate information to verify your identity. We do not routinely require a copy of your identity card. Rights are subject to the conditions and exceptions in applicable law. We normally respond free of charge within one month of receipt. If a permitted extension of up to two further months is necessary because of complexity or the number of requests, we explain the extension and reasons within the first month.
You can complain to the Office of the Commissioner for Personal Data Protection in Cyprus, at commissioner@dataprotection.gov.cy or through the Commissioner's website. You may also contact the supervisory authority in the EEA country where you live or work, or where the alleged infringement occurred. You do not have to contact us before making a complaint.
11. Security and incidents
We use technical and organisational measures appropriate to the risks, including access controls, secure handling of credentials and procedures for responding to incidents. No online service can guarantee absolute security. We notify the relevant authority and affected individuals of personal data breaches where the applicable legal thresholds require notification.
12. Age eligibility
Member accounts and our personal membership waitlist are intended for adults aged 18 and over. This is our service eligibility rule. If you believe we have collected data from a person below that age through these services, contact us so we can assess the situation and take appropriate action.
13. Updates and contact
We update this notice when our processing changes and identify the effective date above. We bring significant changes to your attention through an appropriate channel. A change to this notice does not itself give us consent for a new purpose. Where new consent is required, we ask for it separately.
Privacy Contact, P&M PERKS & MORE LTD, 118 Ellados, 3041 Limassol, Cyprus. Email: [PRIVACY EMAIL].