Privacy Notice
Version 1.0
Last updated: 27.08.2026
1. Introduction
PRESERVE FUTURE MANAGEMENT LIMITED (“we”, “us”, “our”) is the data controller responsible for the processing of your personal data. This Privacy Notice explains how we collect, use, and share your personal data when you use our services, which consist of coaching and informational and practical support for individuals, parents and mothers, delivered individually or in groups. For a more detailed description of our services, please refer to our Terms and Conditions.
2. Identity and contact details of the Data Controller:
Company Name: PRESERVE FUTURE MANAGEMENT LIMITED
Registered address: Kinyra, 1, Kinyras Tower, 3rd floor, Flat/Office 301, Agios Andreas, 1102, Nicosia, Cyprus
Email: support@pfm.company
Telephone: +357 25 056416
3. Personal Data We Collect
We only collect the information necessary to provide our services, run our business, comply with our legal obligations and communicate with you.
We typically collect personal data that you provide directly to us, including, where relevant:
-
Contact information (name, surname, email, phone number) and age, to book a service, communicate with you and ensure eligibility for our services.
-
Information related to sessions or coaching activities and information you share with us in the course of using our services.
-
Scheduling and booking details;
-
Payment information such as transaction details (e.g., the amount paid for services offered), payment method (e.g. Revolut, bank transfer etc.), payment confirmation or receipts (e.g., whether the payment was successful or failed); We do not collect or store sensitive payment information, such as credit card or bank account details; all payments are processed securely by third-party providers.
-
Any information you provide in forms, online surveys, or other communications, including through any complaints you may have.
In the context of providing our services, including coaching sessions, brief notes may be taken to support the services. These notes, if taken, serve solely as an aide-mémoire and are not a verbatim record of the session.
Any such session notes are:
-
Hand-written or electronic (e.g., in digital formats or environments, such as common note-taking or document storage tools, where access is controlled by the user);
-
Coded and pseudonymised so they cannot be readily linked to an identifiable individual;
-
Stored securely and accessed only by the coach and only where such storage is necessary for the coaching relationship/process.
These notes are not shared with third parties and are retained only for as long as necessary to support the coaching relationship and effective delivery of the service, in accordance with GDPR data minimisation and storage limitation principles. Where notes are no longer required, they will be securely destroyed at the end of a session or at the conclusion of the coaching process.
We collect only the data necessary for the provision of our services and to meet our legal and contractual obligations.
4. Group sessions confidentiality
Some of our coaching services are delivered in a group setting. In these sessions, personal data you share may be visible or audible to other participants. We encourage you to only share information you are comfortable disclosing and to avoid sharing any personal data about others that you are not authorized to disclose, including sensitive or special category data. While we take all reasonable steps to protect your data, we cannot control what other participants choose to share, either during or after the session, and we are not responsible for any disclosures made by them.
5. How we collect your data
We collect personal data about you in several ways, including when you provide it directly to us (for example, when filling out booking forms, attending our services, completing forms or submitting information through our website, or communicating with us via email or phone), when brief notes are taken to support the delivery of our services, and when you voluntarily provide information relevant to the use of our services. We do not collect data from third parties about you without your knowledge or consent.
6. Special Category Data
In the context of providing our services, we do not intentionally request or require special category personal data, as defined by the GDPR This includes data revealing:
-
racial or ethnic origin;
-
political opinions;
-
religious or philosophical beliefs;
-
trade union membership;
-
genetic or biometric data (for uniquely identifying a natural person),
-
health data, or
-
data concerning a person’s sex life or sexual orientation.
Clients are not required to disclose any special category personal data and are encouraged not to provide such information unless they deem it directly relevant to the coaching process/use of our services. Any disclosure of special category data is entirely at the client’s discretion.
If any special category data is voluntarily disclosed:
-
It will be processed only with the client’s explicit consent and strictly for the purpose of providing our services, to the extent that such processing is necessary and in compliance with the GDPR requirements.
-
Clients may withdraw consent at any time, in which case processing of the data will immediately cease, and the data will be securely deleted. Coaching sessions and/or relevant services may continue based on the remaining available information.
Notwithstanding the above, there may be exceptional circumstances where the processing of special category data is permitted under GDPR without explicit consent. This may include situations such as:
-
Where it is necessary for the protection of life or in emergency situations, such as to ensure the safety or well-being of the client or others where the data subject is not able to give consent (e.g., in cases where there is a serious risk to health or life).
-
Where required by applicable law or where there are other legal obligations (e.g., if required by a court order or other legal requirements).
-
Where the processing is necessary for the establishment, exercise, or defense of legal claims.
7. How We Use Your Data
We typically process personal data for the following purposes:
-
To provide the services you request;
-
To communicate with you regarding sessions, scheduling, or inquiries or process your bookings and provide you with information on our services;
-
Send any resources such as newsletters you have opted and consented to receive;
-
To maintain accurate records and manage bookings efficiently;
-
To comply with applicable legal or tax obligations;
-
To exercise or defend our legal rights, if necessary.
We do not use any automated decision-making or profiling in our coaching services.
We may use your personal data to send you marketing communications about our services, events, or offers, only where you have given your explicit consent. You have the right to withdraw your consent at any time, and we will immediately stop processing your data for marketing purposes upon request.
8. Lawful Basis for Processing
We process personal data in accordance with one or more of the following lawful bases under GDPR. These typically include:
-
Performance of a contract: to provide the services you request or to take steps at your request prior to entering into a contract;
-
Consent: where you have explicitly given permission for specific processing, such as to send you newsletters or resources;
-
Legitimate interests: to manage our business operations, improve our services, and ensure the security of our systems and premises.
-
Legal obligations: where processing is required to comply with applicable laws.
9. Data Sharing
We do not sell or disclose your personal data for marketing purposes. Personal data may be shared only with:
-
Service providers assisting us with bookings, payment processing, or online forms.
-
Professional advisors (e.g., accountants, lawyers, auditors, or insurers) as necessary.
-
Authorities, if required by law, court order, or other legal obligations or where necessary for the exercise or defense of legal claims.
All our service providers and advisors are required to process your data securely and only in accordance with our instructions.
10. International Transfers
Where personal data is transferred or processed outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place in accordance with GDPR and Cyprus law, such as transfers to countries with an adequacy decision by the European Commission, or the use of standard contractual clauses or equivalent legal mechanisms.
11. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, such as providing our services, managing bookings, scheduling, and communicating with you, or for as long as required by applicable law. Once the relevant purpose is achieved, we securely delete the data — unless retention is necessary to comply with legal obligations, or to allow us to exercise or defend legal rights, maintain records for accounting, or meet other legal or regulatory requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
12. Your Rights
Subject to applicable law and any relevant exemptions, you have the following rights regarding your personal data:
-
Access: You may request a copy of the personal data we hold about you.
-
Correction: You may ask us to correct or complete any inaccurate or incomplete personal data concerning you.
-
Deletion: In certain circumstances prescribed by law, you may request that we delete your personal data. We may retain data where we are legally required to do so or for the exercise, establishment or defence of legal claims.
-
Objection: In certain circumstances prescribed by law, you may object to how we process your personal data. However, we may be entitled to continue to process your personal data where we have a legitimate interest or where it is necessary for the establishment, exercise, or defence of legal claims.
-
Restriction: You have the right to request the restriction of processing of your personal data in certain circumstances.
-
Withdrawal of consent: If we rely on your consent to process your personal data, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing based on consent before it was withdrawn, and we will stop processing your data that relied on consent going forward.
-
Data portability: You may request a machine-readable copy of the personal data you have provided to us, where it is processed by automated means and based on your consent or necessary for a contract with you.
-
Automated decision making and profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affect you.
If you wish to exercise any of these rights, please contact us in writing at the email address provided in section 2 of this Privacy Notice.
We work to address all legitimate rights requests within the required legal timeframe. If a request is especially complex, the law may allow us extra time, and we’ll let you know if that’s the case.
13. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, alteration, or disclosure. These measures are regularly reviewed and updated in line with best practices.
14. Lodge a complaint
If you believe that the processing of your personal data violates the GDPR or your rights as a data subject, you have the right to lodge a complaint with a supervisory authority.
In Cyprus, the competent supervisory authority is the Office of the Commissioner for Personal Data Protection. You can contact them at:
-
Address: Kypranoros 15, Nicosia 1061, Cyprus
-
Telephone: +357 22818456
-
Website: https://www.dataprotection.gov.cy
We encourage you to first contact us directly at email: support@pfm.company with any concerns, and we will do our best to resolve the matter promptly.
15. Questions or enquiries
If you have any questions about how we handle your personal data, or about our coaching services, please do not hesitate to contact us by e-mail or telephone using the contact details provided in section 2 of this Privacy Notice. We are happy to provide further information and clarify any concerns you may have. Your enquiry will be handled confidentially and securely.
16. Changes to This Privacy Notice
We may update this privacy notice from time to time to reflect changes in our practices, services, or legal requirements. Where required by law, we will notify you of material changes. The most current version of this Privacy Notice will always be made available at https://www.pfm-serv.com/ and https://drive.google.com/drive/folders/1V6guClGZhZmbQZMqwjaGkvfORKjvQJni?usp=sharing. Please consult this regularly to stay informed about any updates.