TillMark ENEL

Privacy

How TillMark handles personal data: on this website, in the TillMark till system, and for the websites we build.

1. Who is responsible

TillMark runs this website, the TillMark point-of-sale software and a website-building service for businesses. For people who visit this website, contact us, or buy one of our services, TillMark is the data controller. For the data a shop enters into TillMark about its own customers and staff, that shop is the data controller and TillMark acts as a processor, only on the shop's instructions.

2. Visiting this website and contacting us

When you email, phone or message us, we keep what you send us (your name, contact details and message) so we can reply. This website has no analytics, advertising or tracking tools. It stores only a few small cookies: your language, your sign-in if you use the dashboard, and your cookie choice; Cloudflare, which delivers the site, may add a security cookie that helps block automated attacks. Like any website, our hosting and Cloudflare briefly record technical details of each visit (IP address, browser, time) to keep the site running and secure; we do not use them to identify you. Which cookies we use, and why

When a business buys TillMark or a website from us, we keep the contact and billing details we need to provide the service, send invoices and keep our accounts.

3. What personal data the till system holds

The system stores the following categories of personal data:

  • Staff accounts — display name, username, role, store, optionally an email address (added by a manager and used only to send password-reset emails), and hashed login credentials (PIN and password are never stored in plain text).
  • Customer loyalty records, for customers who opt in — name, email, phone, points balance, and the version and timestamp of the consent notice they were shown. Where a shop browses its customer list, only the name and points balance are shown; email and phone are returned only through an audited, manager-restricted export.
  • Tax-free ("VAT retail export") sales, only where a shop enables that feature — the traveller's name, country of residence, and travel-document (passport) number, recorded on the sale as evidence for the VAT-refund claim. The document number is masked except for its last characters everywhere except the single-sale view the till needs to print the refund form. This data is part of the transaction record and has no erasure path (see retention).
  • Sales and stock transactions — these reference a customer only by an internal id, never by name or contact details, so erasing a customer never has to touch a reported sale.
  • Audit log — which staff member performed a sensitive action, when, and against which store or (by internal id) customer. It never contains email, phone, PIN or password. It exists for accountability (GDPR Art. 30).

No payment card data such as full card numbers, expiry dates or CVVs is received or stored. Card entry belongs to the payment provider. TillMark can retain the terminal approval code, transaction reference and exactly the last four card digits for reconciliation.

4. Why the data is processed, and on what basis

To operate the point of sale: authenticating staff, running the loyalty programme (for opted-in customers), producing receipts and reports, supporting VAT-refund claims where enabled, and maintaining an audit trail. The stated bases are performance of the contract with the shop and a legitimate interest in a secure, auditable system. Loyalty processing for a customer relies on that customer's consent, which is recorded with the notice version and timestamp; withdrawing it stops future points accrual.

Replying to your messages and providing a service you buy from us rest on taking steps at your request and on our contract with you. Keeping this website and our systems secure rests on our legitimate interest. Keeping invoices rests on our legal obligations under Cyprus tax law.

5. Retention

In the till system, nothing is deleted automatically. Sales, receipt and audit records stay in the shop's system, because Cyprus tax law requires shops to keep them for a set period — the shop is responsible for knowing how long, and should confirm it with its accountant. Nightly backups are kept on the hosting server for 3 days, and an encrypted off-site copy of them is kept for 30 days; older backups are deleted. When a shop stops using the service we delete its data on request, and copies in backups disappear within 30 days after that. Because an older backup would bring an erased person back if it were ever restored, we also keep a list of erased record IDs (no names or contact details) and erase those records again straight after any restore. Tax-free traveller data follows the same record-keeping rule and cannot be erased on request.

Emails and messages we receive are kept for as long as we need them to deal with your request and for our business records. Invoices and billing records are kept for as long as Cyprus tax law requires.

6. Your rights

You can ask us for a copy of the personal data we hold about you, and to correct it, delete it, limit how we use it, object to its use, or receive it in a portable format. Where we rely on your consent, you can withdraw it at any time. Contact us using the details below and we will answer within one month. You also have the right to complain to the Commissioner for Personal Data Protection in Cyprus (www.dataprotection.gov.cy).

Customers and staff of a shop that uses TillMark

The system provides built-in tools a shop can use to action a request: a full data export (access / portability), in-place rectification of contact details, and erasure — which scrubs personal data while keeping the internal row so past sales stay intact for fiscal record-keeping. A customer can also withdraw loyalty consent without erasing the record of that consent. A customer should contact the shop they deal with; the shop actions the request.

Staff data is retained on the basis of the employment relationship, which under Cyprus and EU labour law generally requires keeping employment records for a period rather than granting erasure on demand. There is no self-service staff erasure, deliberately.

7. Sharing, sub-processors and transfers

Personal data is not sold. It is shared only with the services needed to run TillMark, and where required by law. Hosting is provided by Oracle Cloud Infrastructure (Amsterdam, Netherlands (EU)). Cloudflare delivers this website and its DNS and forwards emails sent to our contact address. Password-reset emails are sent through Resend from its EU region (Ireland); Resend receives only the recipient's email address and the message.

Cloudflare and Resend are companies based in the United States. Where personal data leaves the EU through them, it is protected by the safeguards those providers use under EU law: the EU-US Data Privacy Framework or the European Commission's standard contractual clauses. The websites we build are hosted in the same way as this one.

8. Websites we build for businesses

For a website we build and host for a business, that business is the data controller for the personal data its visitors send through the site (for example messages or emails to its business address), and we process that data only on the business's instructions: to host the site, deliver its email and make the changes it asks for. Each such website should carry its own privacy notice; we can help write it.

9. Security

Access is role-restricted; credentials are stored only as hashes; sensitive actions are written to the audit log. Two-factor sign-in with an authenticator app is available for the web dashboard. Password-reset links expire after 30 minutes and work once, and a reset signs the person out everywhere. Data is encrypted in transit (TLS), and the off-site backup copy is stored encrypted and is not reachable from the internet.

10. Contact

Privacy enquiries:[email protected]

Last updated: 24 September 2026.