Sanayi Bölgesi, Nicosia, Cyprus
Επαληθευμένη Εφαρμογή OEM & Aftermarket View full catalog →
Επαληθευμένη Εφαρμογή OEM & Aftermarket View full catalog →

Απευθείας αρχείο κατηγορίας χωρίς υποκατηγορίες.

Προβολή Προϊόντων
Επαληθευμένη Εφαρμογή OEM & Aftermarket View full catalog →
Επαληθευμένη Εφαρμογή OEM & Aftermarket View full catalog →
Επαληθευμένη Εφαρμογή OEM & Aftermarket View full catalog →
Επαληθευμένη Εφαρμογή OEM & Aftermarket View full catalog →
M Ali Zeirbani Trading Ltd © 2026

Συμμόρφωση GDPR & Δικαιώματα Δεδομένων

Ολοκληρωμένες πληροφορίες σχετικά με τα πρότυπα προστασίας δεδομένων βάσει του Κανονισμού (ΕΕ) 2016/679.

REGULATION (EU) 2016/679 (GDPR) COMPLIANCE PROTOCOL
LAST REVISED: AUGUST 2026

01. Regulatory Framework & Territorial Scope

This document sets forth the comprehensive data protection protocols, operational standards, and compliance mechanisms implemented by M Ali Zeirbani Trading Ltd (trading as Lord of BMW), a limited liability company duly incorporated under the laws of the Republic of Cyprus under Department of Registrar of Companies Registration Number HE429180, having its registered operational seat and primary automotive parts fulfillment center situated in Nicosia, Cyprus.

In our capacity as a specialized international distributor and technical retailer of automotive parts, OEM replacement components, high-performance aftermarket assemblies, and precision diagnostic hardware specifically engineered for BMW marque vehicles, we are committed to maintaining the highest benchmarks of data integrity, transparency, and consumer privacy. All data operations executed across our website, localized domains, application programming interfaces (APIs), and physical dispatch infrastructure strictly adhere to the mandatory provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation, hereinafter referred to as "GDPR"), as well as the national implementation framework governed by the Cyprus Law on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of Such Data (Law 125(I)/2018).

The territorial scope of this policy applies without distinction to all natural persons residing within the European Economic Area (EEA), the United Kingdom, and third-country international jurisdictions who access our digital catalog, initiate technical fitment inquiries, register commercial or retail customer accounts, or execute purchase orders for automotive equipment.

02. Core Principles of Data Protection

Lord of BMW embeds the core principles of data protection by design and data protection by default into every layer of our technological stack and supply chain workflows. In compliance with Article 5 of the GDPR, we guarantee that all personal data is:

  • Processed Lawfully, Fairly, and Transparently: Data processing operations are conducted with complete operational clarity, supported by an explicit lawful basis, and free from misleading or hidden automated extraction practices.
  • Subject to Explicit Purpose Limitation: Information gathered during browsing, pre-sale fitment consultations, checkout execution, or post-sale warranty support is utilized solely for stated, legitimate commercial and operational purposes and never repurposed for unauthorized secondary processing.
  • Governed by Data Minimisation: We restrict our data collection protocols strictly to information elements directly essential for automotive component compatibility verification, payment processing, fraud prevention, and freight delivery.
  • Maintained for Accuracy: Reasonable engineering and operational measures are deployed to ensure that customer records, vehicle specifications, and shipping details remain accurate and updated upon notification.
  • Bound by Storage Limitation: Identifiable customer data is retained only for the temporal duration strictly necessary to satisfy warranty terms, tax obligations, and statutory requirements.
  • Protected by Technical Integrity and Confidentiality: All digital assets, transaction ledgers, and database instances are protected against accidental loss, unauthorized destruction, alteration, or unlawful access via enterprise encryption standards.

03. Lawful Bases for Processing E-Commerce Transactions

Under Article 6 of the GDPR, every instance of personal data processing conducted by M Ali Zeirbani Trading Ltd is substantiated by an explicit, verifiable legal ground. In the context of our specialized automotive parts catalog, data processing is categorized under four primary lawful bases:

1. Performance of a Contract (Article 6(1)(b) GDPR): When you place an order for BMW parts, request an express freight quote, or commission a custom part acquisition, processing your personal identifiers (full legal name, billing and physical delivery addresses, telephone contact, and vehicle fitment parameters) is legally necessary to fulfill our contractual obligations to fabricate, package, insure, dispatch, and track your consignment.

2. Compliance with Statutory and Legal Obligations (Article 6(1)(c) GDPR): As a registered corporate entity under Cyprus jurisdiction, we are legally mandated by European and Cypriot fiscal statutes (including the Cyprus Value Added Tax Law and corporate accounting regulations) to retain immutable fiscal records, commercial invoices, proof of export documentation, and customs transit declarations for statutory tax audit intervals.

3. Legitimate Commercial Interests (Article 6(1)(f) GDPR): We process select technical and transactional data to advance our legitimate commercial interests, provided such interests are not overridden by your fundamental rights. These activities include real-time fraud mitigation screening on international card transactions, server infrastructure load-balancing, network vulnerability auditing, safeguarding intellectual property, and conducting internal inventory forecasting.

4. Freely Given Consent (Article 6(1)(a) GDPR): Where non-essential analytical cookies, voluntary workshop newsletters, or opt-in marketing broadcasts are concerned, processing is strictly predicated upon your prior, informed, and unambiguous affirmative consent, which may be withdrawn at any time without punitive consequences.

04. Exhaustive Catalog of Data Subject Rights

The GDPR guarantees individuals a robust suite of enforceable rights regarding their personal information. Lord of BMW provides full operational mechanisms to ensure you can exercise any of the following statutory entitlements:

Article 15 — Right of Access: You possess the absolute right to request formal confirmation as to whether personal data concerning you is being processed by our organization. Upon validation, you are entitled to receive a structured copy of your personal data file, alongside exhaustive details regarding the categories of data processed, the specific processing purposes, third-party recipients, and the envisaged retention timeframe.

Article 16 — Right to Rectification: If your contact numbers, delivery addresses, corporate VAT identifiers, or vehicle ownership records are inaccurate or incomplete, you have the right to demand prompt correction or completion of your profile without unwarranted delay.

Article 17 — Right to Erasure ("Right to be Forgotten"): You may request the permanent deletion of your personal records from our active database systems where the data is no longer necessary for the original fulfillment purposes, where you have withdrawn consent, or where you object to processing based on legitimate interests. Please note that statutory fiscal retention mandates (such as tax invoices) may preclude immediate deletion of historic accounting records.

Article 18 — Right to Restriction of Processing: You are entitled to demand the temporary suspension of data processing where you contest data accuracy, where processing is deemed unlawful but you oppose erasure, or where data is required by you for legal claims while an objection verification is pending.

Article 20 — Right to Data Portability: For data provided on the basis of consent or contract and processed via automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV), and to transmit that data to another service provider without hindrance.

Article 21 — Right to Object: You possess the right to object at any time to data processing grounded upon Article 6(1)(f) legitimate interests or direct marketing operations. Upon receiving an objection, we will immediately cease processing unless compelling legitimate grounds overriding your interests are demonstrated.

Article 22 — Automated Decision-Making & Profiling Safeguards: We do not deploy automated decision-making engines or profiling algorithms that produce legal or similarly significant effects regarding your commercial relationship with our platform.

05. Subject Access Request (SAR) Protocol & Timelines

To submit a formal Data Subject Access Request (SAR), exercise a right of rectification, or petition for account erasure, you may submit a written notice to our designated Data Protection Officer via electronic mail at info@lordofbmw.com, or by registered postal correspondence addressed to our headquarters in Nicosia, Cyprus.

Our statutory SAR resolution protocol adheres to the following strict timeline and security rules:

  • Identity Verification: To protect customer confidentiality and prevent fraudulent exfiltration of commercial data, we may require proof of identity (such as matching email authentication, order confirmation tokens, or official identification) prior to disclosing sensitive records.
  • Statutory 30-Day Response Window: All validated SAR inquiries are fulfilled within one calendar month (30 days) of receipt. In cases involving exceptional complexity or voluminous historical requests, this timeframe may be extended by an additional two months in accordance with Article 12(3) GDPR, accompanied by formal notice outlining the grounds for extension.
  • Zero Fee Policy: Data subject requests are fulfilled entirely free of charge. In rare cases where requests are demonstrably unfounded, repetitive, or excessive, we reserve the right to charge a reasonable administrative fee based on direct clerical costs or decline the request.

06. Automotive Identifiers & VIN Data Governance

Given the technical nature of our business, customers frequently provide specialized vehicle identifiers, including 17-character Vehicle Identification Numbers (VIN), chassis codes (e.g., E46, E92, F30, F80, G20, G80), production build dates, engine designation codes (e.g., S55, S58, B58, N55), and ECU software calibration variants during order placement or compatibility checks.

We treat Vehicle Identification Numbers with rigorous privacy controls. When a VIN is provided to verify parts fitment against official BMW electronic parts catalogs (ETK) and technical databases, the VIN is associated exclusively with your specific sales order to ensure accurate component dispatch and establish warranty records. VIN identifiers are never sold, rented, or shared with third-party behavioral advertising brokers, vehicle history aggregators, or telemetry profiling networks.

07. Data Retention Schedules & Automated Purging

M Ali Zeirbani Trading Ltd maintains defined data retention schedules designed to ensure that personal records are retained no longer than required by legal and commercial necessity:

Data Category Retention Interval Statutory Justification
Tax Invoices & Customs Records 7 Years Cyprus Corporate Tax & VAT Law compliance
Customer Account Profiles Duration of Active Account Contractual performance & service management
Component Warranty Logs 2 to 5 Years Manufacturer defect & liability tracking
Server Access Logs & IP Records 90 Days Cybersecurity, anti-DDoS, and network integrity
Abandoned Cart Sessions 30 Days Automated cleanup of temporary session cache

08. Sub-processors, Logistics Partners & Security Audits

To execute international e-commerce fulfillment, Lord of BMW partners with selected third-party service providers (sub-processors) who operate under strict Data Processing Agreements (DPAs) that enforce confidentiality and GDPR Article 28 compliance:

  • Payment Processors (Stripe, PayPal): Direct payment processing is tokenized directly via PCI-DSS Level 1 compliant gateways. Cardholder numbers never touch or reside upon our web servers.
  • Freight & Courier Carriers (DHL Express, FedEx, Cyprus Post, DPD): Essential delivery details (name, recipient address, phone number for delivery coordination) are securely transmitted via encrypted API integrations solely to complete physical transport and customs clearance.
  • Cloud Hosting & Content Delivery: High-performance server infrastructure and Redis object caching layers deployed within hardened, Tier-4 European data center zones compliant with ISO/IEC 27001 standards.

09. Data Incident & Breach Notification Protocol

In the improbable event of a cybersecurity incident resulting in unauthorized access, accidental alteration, disclosure, or destruction of personal data, Lord of BMW executes an immediate incident response procedure in accordance with Articles 33 and 34 of the GDPR.

Where a breach is deemed to present a risk to individual rights and freedoms, our Data Protection Officer will notify the Office of the Commissioner for Personal Data Protection in Cyprus within 72 hours of becoming aware of the incident. Furthermore, where a breach is likely to result in high risk to affected individuals, we will communicate the nature of the breach, expected consequences, and mitigation measures directly to affected customers without undue delay.

10. Official DPO Contact & Regulatory Escalation

If you have inquiries regarding this GDPR Compliance Policy, wish to file a formal Data Subject Access Request, or seek clarification on our automotive data governance standards, please contact our Data Protection Office directly:

Data Protection Officer — M Ali Zeirbani Trading Ltd
Operating Name: Lord of BMW
Company Registration: HE429180 (Republic of Cyprus)
Address: Sanayi Bölgesi, Nicosia, Cyprus
Electronic Mail: info@lordofbmw.com
Telephone: +90 548 873 8215

Without prejudice to any other administrative or judicial remedy, you have the statutory right under Article 77 of the GDPR to lodge a formal complaint with the competent supervisory authority if you consider that the processing of personal data relating to you infringes the GDPR:

Office of the Commissioner for Personal Data Protection (Cyprus)
15 Kypranoros Street, 1061 Nicosia, Cyprus | P.O. Box 23378, 1682 Nicosia
Website: www.dataprotection.gov.cy | Email: commissioner@dataprotection.gov.cy