Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area and is designed to comply with the General Data Protection Regulation (GDPR). By using our services, customers acknowledge that their personal data may be processed in accordance with this policy.
1. Data We Collect
We collect only the data that is necessary for lawful, fair, and transparent processing. The categories of data may include the following:
- Identity data such as name, title, and similar identifiers.
- Contact data such as billing address, delivery address, or other communication details.
- Transaction data relating to purchases, service requests, payments, and records of interactions.
- Technical data such as device type, browser information, and log data used to maintain security and performance.
- Usage data showing how services are accessed and used, including preferences and service interactions.
- Communication data where customers choose to send messages, requests, feedback, or complaints.
We do not collect more data than is reasonably necessary for the purposes described in this policy. Where applicable, certain data may be provided directly by customers, automatically generated through service use, or received from third parties acting on behalf of the customer or in support of service delivery.
2. How We Use Personal Data
Personal data is processed for specific, explicit, and legitimate purposes. These include:
- Providing and delivering services requested by customers.
- Managing accounts, orders, billing, and customer relationships.
- Processing payments and maintaining financial records.
- Improving service quality, user experience, and operational efficiency.
- Detecting, preventing, and investigating fraud, misuse, or security incidents.
- Complying with legal obligations and responding to lawful requests.
- Maintaining internal records, audits, and business administration.
We apply the principles of data minimisation, purpose limitation, and storage limitation. Personal data is used only for the purpose for which it was collected unless a compatible lawful basis exists for another use.
3. Lawful Basis for Processing
Under GDPR, every processing activity must have a valid lawful basis. Depending on the context, we may rely on one or more of the following:
Consent
Where required, we process personal data based on freely given, specific, informed, and unambiguous consent. Customers may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Contract
We process data when it is necessary to enter into or perform a contract with a customer, including delivering services, managing payments, and handling customer support.
Legal Obligation
Certain data must be processed to comply with legal and regulatory duties, such as tax, accounting, fraud prevention, and record-keeping requirements.
Legitimate Interests
We may process data where necessary for our legitimate interests, provided those interests are not overridden by the rights and freedoms of the customer. Examples include service improvement, security monitoring, internal analytics, and business administration.
Vital Interests and Public Task
These bases are generally used only in limited circumstances where required to protect life, respond to emergencies, or support a task carried out in the public interest, where applicable.
4. Sharing of Personal Data and Processors
We may share personal data with trusted third parties where necessary for the operation of our services. These recipients may act as processors or independent controllers, depending on the purpose of the sharing.
Processors are engaged only under written agreements that require them to process personal data on our documented instructions, maintain confidentiality, implement appropriate security measures, and assist with GDPR obligations where relevant.
Examples of processors may include:
- IT and cloud hosting providers.
- Payment and billing service providers.
- Customer support and communication platforms.
- Analytics and performance monitoring tools.
- Professional advisers and compliance support services.
We may also disclose data where required by law, to enforce our legal rights, to protect the rights and safety of customers or others, or in connection with a business reorganization, merger, or transfer of assets. Any such transfer will be handled with appropriate safeguards.
5. International Transfers
If personal data is transferred outside the European Economic Area or another protected jurisdiction, we ensure that appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other legally recognized transfer mechanisms. Customers are entitled to understand the basis on which transfers occur where required by law.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, reporting, or dispute-resolution obligations. Retention periods are determined by the nature of the data, the purpose of processing, and applicable legal requirements.
In practice, this means:
- Contract and transaction records may be retained for the duration of the customer relationship and thereafter for the period required by law.
- Support communications may be retained for a reasonable period to resolve inquiries and improve service quality.
- Security logs may be retained for short periods unless a longer retention period is needed to investigate incidents or meet legal obligations.
- Consent-based data will be kept only until consent is withdrawn or the purpose ends, unless another lawful basis applies.
When data is no longer needed, we take appropriate steps to delete, anonymize, or securely archive it in accordance with applicable law and internal retention standards.
7. Data Security
We use appropriate technical and organizational measures to protect personal data from unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff training, and regular review of security practices. While no system can be guaranteed to be completely secure, we take reasonable steps to reduce risk and maintain a level of protection appropriate to the data processed.
8. User Rights Under GDPR
Customers have a number of rights concerning their personal data. Subject to applicable legal conditions and exceptions, these rights include:
- Right of access – to obtain confirmation of whether personal data is being processed and to receive a copy of that data.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of personal data in certain circumstances.
- Right to restriction – to request limitation of processing in specific situations.
- Right to data portability – to receive data in a structured, commonly used, and machine-readable format, where applicable.
- Right to object – to object to processing based on legitimate interests or to direct marketing, where relevant.
- Right to withdraw consent – where processing relies on consent, withdrawal may be made at any time.
- Right not to be subject to solely automated decision-making – including profiling, where this produces legal or similarly significant effects, unless permitted by law.
We may ask for reasonable information to verify identity before responding to a rights request. Requests will be handled within the time limits required by GDPR, generally within one month, subject to lawful extensions in complex cases.
9. Children’s Data
Our services are not intended for children unless specifically stated otherwise. Where we become aware that personal data has been collected from a child in a way that does not comply with applicable law, we will take appropriate steps to address the matter, including deletion where necessary and lawful.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, operational practices, or service requirements. When updates are made, the revised version will apply from the date it takes effect. Customers are encouraged to review this policy periodically to remain informed about how personal data is handled.
11. General Statement
This Privacy Policy applies to all customers in the area. It is intended to provide clear information about how personal data is managed and the protections available under GDPR. By continuing to use the services, customers acknowledge that they have read and understood the practices described in this policy.
Summary of key principles:
- We collect only necessary data.
- We process data on valid lawful bases.
- We retain data only as long as needed.
- We use processors under written safeguards.
- We respect and support user rights.
