Privacy policy

Last updated: 14 June 2026

This policy explains what personal data Sixteen Pillars collects, why, how it is handled, and the rights you have over it. It is written to be read, not to be hidden behind. If anything here is unclear, contact us using the details at the end.

Who we are

Sixteen Pillars (“we”, “us”) is an enterprise technology consultancy operating from Cyprus. For the purposes of the EU General Data Protection Regulation (GDPR) and the Cyprus data protection law, the data controller is Richard King, Christou Samara, Larnaca, CYPRUS.

For any question about this policy or your personal data, contact: richardking@sixteenpillars.com

What this policy covers

This policy applies to personal data we process through this website, our enquiry and booking channels, any online assessment or diagnostic tools we make available, and our client engagements. It does not apply to third-party websites we link to, which operate their own policies.

The personal data we collect

Information you provide

  • Enquiries and bookings. When you contact us or book a conversation, we collect your name, email address, and anything you choose to tell us about your business, your role, and your technology situation.
  • Assessment and diagnostic tools. Where we offer an online assessment, we collect the answers you submit — typically your role, sector, organisation size, and a description of your technology situation — along with the contact details you provide.
  • Client engagement data. When we work with you, we process the information needed to deliver the engagement. This is governed by the engagement agreement and any separate data processing terms.

Information collected automatically

Like most websites, our hosting and security infrastructure records technical information such as IP address, browser type, and pages visited, for security, diagnostics, and to keep the site working. Cookies and similar technologies are handled separately and described in our Cookie Policy; you control non-essential cookies through the consent banner.

Why we process your data, and our lawful basis

  • To respond to your enquiry and arrange a conversation — on the basis of taking steps at your request prior to entering a contract (Article 6(1)(b)), or our legitimate interest in responding to people who contact us (Article 6(1)(f)).
  • To generate the assessment you requested — on the basis of steps taken at your request prior to a possible engagement, or our legitimate interest in providing the tool you chose to use.
  • To deliver our services — performance of our contract with you or your organisation (Article 6(1)(b)).
  • To keep our systems secure and our records accurate — our legitimate interests (Article 6(1)(f)).
  • To meet legal and regulatory obligations — compliance with a legal obligation (Article 6(1)(c)).

We do not use your contact details to send marketing unless you have asked us to. Where we rely on legitimate interests, we have considered your rights and do not process data in ways you would not reasonably expect.

Artificial intelligence and automated processing

Some of our tools use artificial intelligence — specifically large language models — to turn the information you submit into a tailored assessment or summary. We are deliberate about how this works, and the following applies wherever AI is involved in processing your data.

  • Data minimisation. We send the AI only what is needed to produce the output. Direct identifiers such as your name, email address, and company name are removed before your responses are processed by the AI — the data is pseudonymised, so the model works on the substance of your situation, not on who you are.
  • Our AI provider is a processor. We use a reputable AI provider that acts strictly on our instructions under a data processing agreement. Your data is not used to train the provider’s models, and we use zero-data-retention processing where it is available, meaning the provider does not retain your inputs after generating the response.
  • No solely automated decisions. AI output is advisory. It does not, by itself, make any decision that produces a legal effect or similarly significant effect for you. Any assessment is reviewed by a person before it informs a conversation or recommendation. You can ask for human involvement, express your view, or contest any output that concerns you.
  • Purpose limitation. Information you submit to a tool is used to produce the assessment you requested and to follow up with you about it. It is not repurposed for unrelated uses.

Who we share data with

We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract and on our instructions. These fall into the following categories:

  • Website hosting and security — the infrastructure that runs this site.
  • Email, calendar, and booking — the systems used to correspond with you and schedule conversations.
  • Email delivery — the service used to send transactional email reliably.
  • Artificial intelligence processing — the AI provider described above, where you use a tool that involves AI.

We may also disclose data where required by law, regulation, or a valid legal request, or to establish, exercise, or defend legal claims. A current list of the specific providers we use is available on request.

International transfers

Some of our providers process data outside the European Economic Area, including in the United States. Where that happens, the transfer is protected by an appropriate safeguard recognised under the GDPR — typically the European Commission’s Standard Contractual Clauses, or an adequacy decision where one applies. You can request details of the safeguards in place.

How long we keep it

We keep personal data only as long as needed for the purpose it was collected, or as required by law. Enquiry and assessment data is retained while we are in contact and for a reasonable period afterwards in case you return; client engagement data is retained for the duration of the engagement and the period required for legal, tax, and professional obligations. After that, it is deleted or anonymised.

How we protect it

Security is a design property of how we operate, not an afterthought. We apply appropriate technical and organisational measures — access controls, encryption in transit, data minimisation, and supplier due diligence — proportionate to the data involved.

Your rights

Under the GDPR you have the right to access your personal data; to have it corrected or erased; to restrict or object to its processing; to data portability; and, where we rely on consent, to withdraw that consent at any time. To exercise any of these, contact us at richardking@sixteenpillars.com. We will respond within the time the law allows.

If you are not satisfied with how we have handled your data, you have the right to complain to the Cyprus supervisory authority, the Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy), or to the data protection authority in your own country.

Children

Our services and this website are directed at organisations and the people who run them, not at children. We do not knowingly collect personal data from anyone under 18.

Changes to this policy

We may update this policy as our services or obligations change. The date at the top shows when it was last revised. Material changes will be reflected here before they take effect.

Contact

Questions about this policy or your personal data: richardking@sixteenpillars.com, or write to Richard King, Sixteen Pillars, Cristou Samara, Larnaca, Cyprus.

Last updated: 14 June 2026

This policy explains what personal data Sixteen Pillars collects, why, how it is handled, and the rights you have over it. It is written to be read, not to be hidden behind. If anything here is unclear, contact us using the details at the end.

Who we are

Sixteen Pillars (“we”, “us”) is an enterprise technology consultancy operating from Cyprus. For the purposes of the EU General Data Protection Regulation (GDPR) and the Cyprus data protection law, the data controller is Richard King, Sixteen Pillars, Christou Samara, Larnaca, CYPRUS.

For any question about this policy or your personal data, contact richardking@sixteenpillars.com.

What this policy covers

This policy applies to personal data we process through this website, our enquiry and booking channels, any online assessment or diagnostic tools we make available, and our client engagements. It does not apply to third-party websites we link to, which operate their own policies.

The personal data we collect

Information you provide

  • Enquiries and bookings. When you contact us or book a conversation, we collect your name, email address, and anything you choose to tell us about your business, your role, and your technology situation.
  • Assessment and diagnostic tools. Where we offer an online assessment, we collect the answers you submit — typically your role, sector, organisation size, and a description of your technology situation — along with the contact details you provide.
  • Client engagement data. When we work with you, we process the information needed to deliver the engagement. This is governed by the engagement agreement and any separate data processing terms.

Information collected automatically

Like most websites, our hosting and security infrastructure records technical information such as IP address, browser type, and pages visited, for security, diagnostics, and to keep the site working. Cookies and similar technologies are handled separately and described in our Cookie Policy; you control non-essential cookies through the consent banner.

Why we process your data, and our lawful basis

  • To respond to your enquiry and arrange a conversation — on the basis of taking steps at your request prior to entering a contract (Article 6(1)(b)), or our legitimate interest in responding to people who contact us (Article 6(1)(f)).
  • To generate the assessment you requested — on the basis of steps taken at your request prior to a possible engagement, or our legitimate interest in providing the tool you chose to use.
  • To deliver our services — performance of our contract with you or your organisation (Article 6(1)(b)).
  • To keep our systems secure and our records accurate — our legitimate interests (Article 6(1)(f)).
  • To meet legal and regulatory obligations — compliance with a legal obligation (Article 6(1)(c)).

We do not use your contact details to send marketing unless you have asked us to. Where we rely on legitimate interests, we have considered your rights and do not process data in ways you would not reasonably expect.

Artificial intelligence and automated processing

Some of our tools use artificial intelligence — specifically large language models — to turn the information you submit into a tailored assessment or summary. We are deliberate about how this works, and the following applies wherever AI is involved in processing your data.

  • Data minimisation. We send the AI only what is needed to produce the output. Direct identifiers such as your name, email address, and company name are removed before your responses are processed by the AI — the data is pseudonymised, so the model works on the substance of your situation, not on who you are.
  • Our AI provider is a processor. We use a reputable AI provider that acts strictly on our instructions under a data processing agreement. Your data is not used to train the provider’s models, and we use zero-data-retention processing where it is available, meaning the provider does not retain your inputs after generating the response.
  • No solely automated decisions. AI output is advisory. It does not, by itself, make any decision that produces a legal effect or similarly significant effect for you. Any assessment is reviewed by a person before it informs a conversation or recommendation. You can ask for human involvement, express your view, or contest any output that concerns you.
  • Purpose limitation. Information you submit to a tool is used to produce the assessment you requested and to follow up with you about it. It is not repurposed for unrelated uses.

Who we share data with

We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract and on our instructions. These fall into the following categories:

  • Website hosting and security — the infrastructure that runs this site.
  • Email, calendar, and booking — the systems used to correspond with you and schedule conversations.
  • Email delivery — the service used to send transactional email reliably.
  • Artificial intelligence processing — the AI provider described above, where you use a tool that involves AI.

We may also disclose data where required by law, regulation, or a valid legal request, or to establish, exercise, or defend legal claims. A current list of the specific providers we use is available on request.

International transfers

Some of our providers process data outside the European Economic Area, including in the United States. Where that happens, the transfer is protected by an appropriate safeguard recognised under the GDPR — typically the European Commission’s Standard Contractual Clauses, or an adequacy decision where one applies. You can request details of the safeguards in place.

How long we keep it

We keep personal data only as long as needed for the purpose it was collected, or as required by law. Enquiry and assessment data is retained while we are in contact and for a reasonable period afterwards in case you return; client engagement data is retained for the duration of the engagement and the period required for legal, tax, and professional obligations. After that, it is deleted or anonymised.

How we protect it

Security is a design property of how we operate, not an afterthought. We apply appropriate technical and organisational measures — access controls, encryption in transit, data minimisation, and supplier due diligence — proportionate to the data involved.

Your rights

Under the GDPR you have the right to access your personal data; to have it corrected or erased; to restrict or object to its processing; to data portability; and, where we rely on consent, to withdraw that consent at any time. To exercise any of these, contact us at richardking@sixteenpillars.com. We will respond within the time the law allows.

If you are not satisfied with how we have handled your data, you have the right to complain to the Cyprus supervisory authority, the Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy), or to the data protection authority in your own country.

Children

Our services and this website are directed at organisations and the people who run them, not at children. We do not knowingly collect personal data from anyone under 18.

Changes to this policy

We may update this policy as our services or obligations change. The date at the top shows when it was last revised. Material changes will be reflected here before they take effect.

Contact

Questions about this policy or your personal data: richardking@sixteenpillars.com, or write to Richard King, Sixteen Pillars, Christou Samara, Larnaca, CYPRUS.