Grigoris Aivazidis
Lawyer and International Tax Adviser
Cyprus Bar Association Registration No. 7940
Original publication: 13 June 2023
Last substantive legal review: 21 July 2026
Jurisdiction: Republic of Cyprus and European Union
Website terms and conditions establish the rules governing access to a website and, where applicable, the contract between the operator and its users or customers. They can address accounts, acceptable use, orders, payments, subscriptions, intellectual property, user content, suspension, liability and dispute resolution.
Not every informational website is legally required to publish a document bearing that exact title. However, a business that sells products, licenses software, accepts bookings, operates subscriptions, hosts user content or creates customer accounts will normally need properly tailored contractual terms. Separate legal obligations may also require trader information, consumer information, privacy notices and valid cookie controls.
Terms are effective only when they match the website that users actually experience. The words, checkout design, consent controls, cancellation process and technical data flows must operate coherently. This guide explains what that means for Cyprus businesses serving local or international users.
Well-drafted terms create an organised legal framework for the online relationship. They identify who operates the website, the services being offered, who may use them and the conduct that is prohibited. When the website concludes contracts, the terms should explain when an order is accepted, what the customer receives and how payment, performance, cancellation and termination work.
They also protect valuable business assets. Copyright, trade marks, software, databases, photographs, designs and written content can be reserved to the operator or licensed on defined conditions. If users upload material, the terms should state what rights they grant, what standards apply and when content may be removed.
Liability clauses can allocate risk, but they must be drafted within the limits imposed by applicable law. A provision declaring that the operator has no liability for anything is unlikely to provide the protection its author expects. The clause should address the actual service, foreseeable risks, available remedies, mandatory consumer protections and the type of loss that may lawfully be limited.
Governing-law and jurisdiction clauses can improve predictability, especially in international business. They do not automatically displace mandatory rules protecting consumers in their country of residence. Cross-border businesses should identify where they actively market and whether another jurisdiction requires local consumer information or contractual wording.
Terms are therefore part of operational risk management. Their value comes from translating the business model into clear rules that can be implemented by the website, customer-support team and payment process.
Website Terms and Conditions. These govern permitted use and, where relevant, transactions between the operator and the user. They can cover accounts, orders, payments, subscriptions, intellectual property, user conduct and termination.
Privacy Policy. This explains how personal data is collected and used, the relevant legal bases, recipients, retention, transfers and individual rights. It serves a different purpose from contractual terms. The AVZ Law Office Privacy Policy illustrates the role of a separate privacy notice.
Cookie Policy and consent interface. The policy explains the cookies and similar technologies in use. The consent interface records the user’s choices. The two must reflect the website’s real technical behaviour.
Refund, cancellation and withdrawal information. An online trader should explain the applicable process, time limits, exceptions and consequences. These provisions may sit within the main terms or in a clearly incorporated policy, but the customer journey must present mandatory information before the contract is concluded.
Acceptable Use Policy. SaaS products, platforms, networks and services exposed to misuse may require detailed rules on unlawful content, security, automated access, interference, scraping, spam and prohibited commercial activity.
Legal Notice. This identifies the website operator and contains important notices about the status and purpose of the website. It does not replace transactional terms. AVZ’s own Legal Notice is maintained as a separate document for that reason.
The correct document set depends on what the website does, what technology it uses, what users can submit and where the business markets its services. Combining unrelated documents into one generic policy can make each obligation harder to understand and implement.
AEPD Decision PS/00482/2021
Jimbo Networks S.L., 18 April 2022
The Jimbo Networks decision demonstrates that publishing legal documents is not enough. A regulator may examine whether the website’s actual operation matches what its privacy and cookie policies promise. If analytics or advertising cookies activate before consent, or users cannot reject them as easily as they accept them, carefully written policies cannot cure the technical failure.
A compliant website protects more than the business against penalties. It strengthens customer confidence, supports responsible growth and prevents weaknesses from becoming more expensive as the business expands. Legal drafting, consent mechanisms, online forms and the website’s real data flows must operate as one coherent system.
Grigoris Aivazidis
Lawyer and International Tax Adviser
Cyprus Bar Association
International Compliance Association
A business website that only publishes information may still require rules on intellectual property, acceptable use, reliance on content, third-party links and enquiries. Regulated professions should ensure that descriptions of services, credentials, communications and disclaimers comply with their professional rules.
A disclaimer should be accurate. It cannot convert individual advice into general information after a professional has actually accepted instructions or provided a tailored opinion.
Online stores require detailed pre-contract information about the trader, goods or services, total price, delivery, payment, complaint handling, cancellation and withdrawal. The wording must match the checkout, order confirmation and returns process.
Bookings may involve deposits, rescheduling, no-show rules, supplier terms and time-sensitive services. A cancellation clause should distinguish the customer’s contractual rights from mandatory statutory rights.
Software and subscription terms should address the licence granted, authorised users, technical restrictions, billing cycles, automatic renewal, cancellation, availability, support, updates, data handling, suspension and termination. If a service level is promised, the measurement method and remedy should be clear.
Users should understand what happens to their data and account when the service ends. Export periods, deletion schedules and continuing payment obligations should not be left to assumption.
A marketplace must explain whether it is the seller, an intermediary or a venue connecting third parties. The terms should allocate responsibility for listings, payment, fulfilment, refunds, disputes and user verification without misleading consumers about who their contracting party is.
Platforms hosting third-party content may also need moderation, notice, appeal and transparency processes. Where the service falls within the Digital Services Act, its terms and operational procedures should be reviewed against the duties applicable to that category of intermediary service. The Act does not apply to every ordinary business website.
Websites that permit reviews, comments, images, videos or other submissions need standards governing unlawful content, intellectual-property infringement, privacy, impersonation, harassment and manipulation. The licence granted by a user should be no broader than the service reasonably requires.
Moderation powers should be described clearly, but the published process must also be workable. A policy promising a response or appeal that the business cannot administer creates its own risk.
A Cyprus governing-law clause is not a universal solution. The business should review where customers are located, which markets it directs advertising toward, whether local consumer rights apply and whether the product is restricted in a particular jurisdiction. Foreign-law advice may be required for markets presenting material exposure.
The terms should state the legal name, contact details and relevant registration information of the operator. They should explain any age or eligibility restrictions and when the user becomes contractually bound.
For online sales, the sequence between placing an order, receiving an automated acknowledgement and final acceptance matters. The terms should distinguish each step and remain consistent with the confirmation emails.
Account holders should protect credentials and report suspected misuse. The terms can prohibit unlawful activity, security interference, automated abuse and conduct that damages the service or other users. Suspension rights should be proportionate and linked to identifiable grounds.
Customers should see the total price and relevant charges before committing. Subscription terms should state the billing interval, renewal mechanism, notice required for cancellation and consequences of failed payment. Additional payments should not be created through pre-selected options.
The operator should reserve ownership of its brand, website and original content while explaining the limited permission granted to users. Software terms should define the licence scope, prohibited exploitation and treatment of updates. User-content provisions should identify ownership and the licence needed to host, display or distribute submissions.
The terms should describe the service honestly. Availability exclusions, maintenance rights and warranty language must be appropriate to the product and applicable law. Liability provisions should distinguish between business and consumer users where their rights differ.
Termination provisions should explain the grounds, notice, access consequences and treatment of data or outstanding payments. A change clause should not grant unlimited power to alter a contract without notice. The terms should state the governing law, dispute process and competent forum without attempting to remove mandatory rights.
The Cyprus Consumer Protection Law 112(I)/2021 regulates contracts between traders and consumers, including distance contracts for goods, services, digital content and digital services. Before a consumer becomes bound, the trader may need to provide information concerning its identity, the main characteristics, total price, payment, performance, complaint handling and withdrawal rights.
Consumers generally have 14 days to withdraw from a qualifying distance contract without giving a reason, subject to the statutory rules and exceptions. The starting point depends on whether the contract concerns goods or services. If the trader fails to give the required withdrawal information, the withdrawal period can be extended by up to 12 months.
A consumer may ask for a service to begin during the withdrawal period, but the request and information process must satisfy the statutory conditions. For digital content not supplied on a tangible medium, loss of the withdrawal right depends on prior express consent, commencement of performance and acknowledgement of that consequence.
A checkbox reading only “I agree to the terms” may not capture every distinct consent or acknowledgement required for immediate digital performance. Additional payments also require express consent. Pre-ticked boxes or default additions can expose the trader to repayment claims and enforcement.
A clause choosing Cyprus law can provide contractual certainty, but it cannot deprive a consumer of mandatory protection that applies under the relevant conflict-of-law and consumer rules. Businesses directing activity to several countries should assess the markets they actually serve.
Refunds, cancellation, withdrawal forms and customer-support responses should follow the published terms. A clause is of limited value if the interface prevents the customer from exercising the right described in it.
The business should be able to show that the user had a reasonable opportunity to read the relevant terms before becoming bound and took an appropriate affirmative step. A clickwrap process usually presents the terms through a clear link beside an unchecked box or button requiring active agreement.
A footer link that users can ignore, sometimes called browsewrap, provides weaker evidence of notice and assent for a transaction. The strength of any process depends on the design, wording, timing and surrounding facts.
The acceptance record should identify the user or transaction, date and time, version of the terms and wording displayed at the point of consent. The business should preserve earlier versions and be able to reproduce the document accepted.
Material clauses should not be hidden in dense text or contradicted by the checkout. Automatic renewal, significant exclusions, withdrawal consequences and recurring charges deserve clear presentation. Mobile users must receive an equally accessible process.
Contractual acceptance does not automatically create a lawful basis for every use of personal data. The General Data Protection Regulation requires controllers to identify appropriate legal bases and provide the information required by Articles 13 or 14. Consent is only one possible basis and must meet the Regulation’s standards where it is relied upon.
The privacy notice should describe the real data journey, including forms, accounts, payments, support tools, analytics, advertising, embedded media and international transfers. A generic statement that data may be used for any business purpose is not a substitute for specific information.
Non-essential cookies and similar technologies should not be activated before valid consent where consent is required. The Cyprus Data Protection Commissioner’s cookie guidance explains that consent requires an affirmative action. Continuing to browse or scroll is not enough.
Users should be able to reject non-essential categories without being directed only to browser settings. Withdrawal should be as accessible as acceptance. The cookie policy should identify the technologies actually present, their purposes, providers and relevant duration.
In AEPD Decision PS/00482/2021, the Spanish Data Protection Authority investigated a website operated by Jimbo Networks S.L. The authority found that non-essential cookies, including analytics and third-party technologies, were installed on entry without the necessary consent.
The website did not provide an adequate cookie banner, an effective method to reject non-essential cookies or granular controls. Directing users to browser settings was not treated as an adequate substitute. The privacy information was also outdated and did not satisfy the applicable transparency requirements.
The proposed penalties totalled €15,000. They comprised separate amounts relating to unlawful processing, deficient information and cookie-law infringements. The proceeding ended following acknowledgement of responsibility and voluntary payment of €9,000 after the available reductions.
This is a Spanish decision applying Spanish electronic-communications legislation together with the GDPR. It is not Cyprus case law and does not establish the amount that a Cyprus authority would impose. Its wider EU lesson is nevertheless important. A regulator may test the website itself rather than accepting the published policy at face value.
The legal audit must include technical behaviour. It should test which cookies and scripts load before consent, whether rejection works, whether choices are remembered, whether users can withdraw consent and whether the policy accurately describes every active tool.
The same principle applies beyond cookies. Terms promising a particular cancellation, complaint or deletion process should be supported by an interface and internal procedure capable of delivering it.
This guide was substantively reviewed on 21 July 2026. The official materials relied upon include the Cyprus Electronic Commerce Law 156(I)/2004, the Cyprus Consumer Protection Law 112(I)/2021, the General Data Protection Regulation, the Cyprus Data Protection Commissioner’s cookie guidance, the Digital Services Act where a qualifying intermediary service is involved, and AEPD Decision PS/00482/2021.
The applicable document set and consumer duties depend on the website’s functions, users, target markets and contractual model. A business entering additional jurisdictions should obtain advice on the rules applicable there.
Copied terms often identify the wrong company, currency, governing law or service. They may refer to a payment provider the business does not use, prohibit functions the website actively offers or promise a refund process that does not exist.
Templates also struggle with legal classification. A marketplace may wrongly describe itself as the seller. A subscription may omit renewal information. A digital-content seller may state that every purchase is non-refundable without collecting the consent and acknowledgement relevant to immediate performance.
The greatest weakness is frequently implementation. Terms placed in the footer after payment, pre-selected boxes, unrecorded consent, inaccessible cancellation and outdated cookie tables create a gap between document and reality. That gap is precisely what a legal and technical audit should identify.
This article provides general information about website terms and digital-business compliance in Cyprus and the European Union as at 21 July 2026. It is not legal advice and does not create a lawyer-client relationship. The documents, disclosures, consent process and consumer rights applicable to a website depend on its business model, technology, users, target markets and contractual journey. Obtain advice tailored to the particular website and jurisdictions involved.
Practical answers about legal requirements, online acceptance, privacy, cookies, consumer withdrawal, digital content, liability and updating website documents.
There is no universal rule requiring every informational website to publish a document with that title. However, electronic commerce, consumer, privacy and professional rules may require specific information. Transactional websites normally need clear contractual terms.
Copying creates legal and practical risks. The other website may use a different company, product, jurisdiction, payment process, cancellation model or technology. It may also contain errors or protected text.
Website terms govern use of the site and contractual relations. A privacy policy explains how personal data is processed under data-protection law. One document does not replace the other.
Terms can still be useful for intellectual property, permitted use, reliance on general content and third-party links. The exact need depends on the website’s functions and any regulated services it describes.
They commonly address trader identity, products, prices, payment, delivery, contract formation, complaints, cancellation, withdrawal, returns, intellectual property, liability and governing law. Mandatory information must be presented at the correct time.
A footer link alone may provide weak evidence of notice and acceptance for a transaction. An appropriately designed clickwrap process usually provides stronger evidence because the user takes an affirmative step after receiving access to the terms.
The record should connect the user or transaction with the date, time, accepted version and wording shown. Earlier versions should be preserved so the business can reproduce the terms applying to a dispute.
Consumers generally have a 14-day withdrawal right for qualifying distance contracts, subject to statutory rules and exceptions. Goods, services and digital content do not all follow an identical process.
The withdrawal right for qualifying digital content can be lost only where the statutory conditions are satisfied, including prior express consent to immediate performance and acknowledgement of the consequence. A blanket label may be insufficient.
No clause can safely be assumed to exclude every form of liability. Enforceability depends on the applicable law, customer type, subject matter, drafting and mandatory rights. The clause should allocate risk lawfully and realistically.
Review them when the product, pricing, payment model, subscription process, customer market, technology or law changes. A scheduled annual review is useful, but it does not replace an immediate review after a material business change.
Usually yes. SaaS terms may require licences, service access, support, subscriptions, data exit and security rules. Marketplaces and platforms may require seller roles, payments, content moderation and intermediary-service provisions.
AVZ Law Office drafts and reviews website terms, privacy information, cookie documentation, online customer journeys and supporting policies for Cyprus businesses, founders, e-commerce operators, SaaS providers and digital platforms.
Our wider Private Enterprise practice supports established businesses, while our startup advisory and founder structuring work addresses the legal foundations needed before a digital business scales.