Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in relation to our services. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and applicable data protection laws. Please read this policy carefully to understand how we process personal information and the rights available to you.
1. Scope of This Policy
This policy applies when you interact with our services, make an inquiry, place an order, receive support, or otherwise engage with us. It covers data collected directly from you, data generated through your use of our services, and data received from third parties where permitted by law.
We process personal data only where there is a lawful basis to do so, and we limit processing to what is necessary for the stated purposes. We do not use personal data in ways that are incompatible with those purposes.
2. Personal Data We Collect
Depending on your relationship with us and the services you use, we may collect the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, and telephone number.
- Transaction data: records of purchases, services requested, billing details, and related correspondence.
- Technical data: device type, IP address, browser information, time zone, and usage logs.
- Usage data: interactions with our services, preferences, and service history.
- Communication data: messages, complaints, requests, and feedback.
Where necessary and lawful, we may also collect limited information from publicly available sources or from business partners who are permitted to share it with us. We do not knowingly collect more data than is required for the relevant purpose.
3. How We Use Personal Data
We use personal data for the following purposes:
- to provide and manage our services;
- to process transactions and maintain records;
- to respond to enquiries, requests, and complaints;
- to improve service quality and customer experience;
- to maintain security, prevent fraud, and detect misuse;
- to comply with legal, regulatory, and accounting obligations;
- to send administrative communications related to the service;
- to support internal reporting, analytics, and business operations.
We process personal data only when the processing is necessary and proportionate. If we intend to use your data for a new purpose, we will assess whether that purpose is compatible with the original purpose and whether additional notice or consent is required.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. We may rely on one or more of the following lawful bases:
Consent
Where required, we process personal data based on your consent. This may apply to certain optional communications or specific data uses. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Contract
We process personal data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
Legal Obligation
We process personal data where necessary to comply with laws, court orders, regulatory requirements, tax rules, or other legal obligations.
Legitimate Interests
We may process data where it is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests. Examples include service improvement, fraud prevention, and internal administration. When relying on legitimate interests, we consider the nature of the data, the impact on you, and the safeguards in place.
5. Data Sharing and Processors
We may share personal data with trusted third parties that act as processors or, where applicable, independent controllers. Processors only act on our instructions and are required to protect personal data using appropriate technical and organizational measures.
Categories of processors may include:
- IT and hosting providers;
- payment and billing service providers;
- customer support and communications tools;
- analytics and reporting providers;
- security, fraud prevention, and compliance services;
- professional advisers acting under confidentiality obligations.
Where personal data is transferred outside the European Economic Area, we take steps to ensure an adequate level of protection, such as relying on approved safeguards and transfer mechanisms where required by law. We do not sell personal data.
6. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax, or reporting requirements. Retention periods may vary depending on the type of data, the purpose of processing, and statutory obligations.
In general, we apply the following principles:
- data used to provide services is kept for the duration of the service relationship and a reasonable period afterward;
- financial and contractual records are retained as long as required by law;
- support and correspondence records are kept only as long as needed to resolve issues and maintain accurate records;
- technical logs are retained for security and operational purposes for limited periods.
When data is no longer required, we will delete it, anonymize it, or securely archive it where deletion is not immediately possible. Retention is reviewed periodically to ensure that data is not kept longer than necessary.
7. Data Security
We implement appropriate security measures designed to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption, monitoring, backup procedures, and staff confidentiality obligations.
Although no system can be guaranteed to be completely secure, we work to maintain a security framework that is appropriate to the risk presented by the data we process. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will handle it in accordance with applicable law.
8. Your Rights Under GDPR
Depending on the circumstances, you may have the following rights in relation to your personal data:
- Right of access: to request confirmation of whether we process your data and obtain a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request limited processing in certain situations.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and to request transfer where feasible.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
- Right to lodge a complaint: to raise concerns with a supervisory authority if you believe your rights have been infringed.
We may need to verify your identity before responding to a rights request. Requests will be handled within the time limits required by GDPR unless an extension is permitted by law. Exercising your rights will not usually affect your ability to use our services, unless the requested change makes it impossible for us to provide them.
9. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children where such collection would require parental consent or other special safeguards. If we become aware that personal data has been collected inappropriately, we will take reasonable steps to delete it.
10. Automated Decision-Making
We do not carry out decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals unless such processing is lawful and appropriate safeguards are in place. If we use automated tools for operational purposes, we do so in a manner that is fair, transparent, and limited to the relevant purpose.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or technical changes. Any revised version will apply from the effective date stated in the updated policy. We encourage you to review this policy periodically so that you remain informed about how we process personal data.
12. Summary of Key Points
- We collect only the personal data needed to provide and improve our services.
- We process data on lawful bases such as consent, contract, legal obligation, and legitimate interests.
- We share data only with processors and other third parties where necessary and protected by suitable safeguards.
- We retain personal data only for as long as needed and then delete or anonymize it.
- You have GDPR rights to access, correct, delete, restrict, port, object, and withdraw consent.
This Privacy Policy applies to all customers in the area. By using our services, you acknowledge that your personal data may be processed as described in this policy and in accordance with applicable data protection laws.
