Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with our services. It applies to all customers in the area, regardless of how they access or use the service. We are committed to processing personal data in accordance with the General Data Protection Regulation (GDPR) and applicable local data protection laws.
1. Scope of this Policy
This Policy applies to personal data relating to customers, prospective customers, users, and any other individuals whose information we process in the course of providing services. It covers data collected online, offline, and through any other interaction where personal data is provided or generated. By using our services, you acknowledge that your personal data may be processed as described in this Policy.
2. Data We Collect
We may collect the following categories of personal data:
- Identity data: name, surname, username, and similar identifiers.
- Contact data: address, email address, telephone number, and other communication details.
- Account data: login credentials, profile information, preferences, and settings.
- Transaction data: records of purchases, payments, refunds, and related billing information.
- Technical data: IP address, device type, browser type, operating system, and access logs.
- Usage data: information about how you interact with our services, pages visited, and features used.
- Communication data: correspondence, enquiries, feedback, complaints, and support requests.
- Marketing data: preferences for receiving promotional content and communication choices.
We do not intentionally collect special categories of personal data unless it is necessary, lawful, and explicitly provided by you or otherwise permitted under GDPR. If such data is processed, it will be handled with enhanced protection and only when a valid legal basis applies.
3. How We Collect Personal Data
We collect data directly from you when you:
- create or update an account;
- place an order or request a service;
- communicate with us by any means;
- complete forms or surveys;
- subscribe to notifications or marketing;
- browse or use our services, where technical and usage data may be collected automatically.
We may also receive information from third parties, such as payment providers, service partners, or publicly available sources, where this is lawful and necessary for the purposes described in this Policy.
4. Purposes of Processing
We process personal data only for specific, legitimate purposes, including:
- providing and managing our services;
- processing transactions and payments;
- maintaining account functionality and security;
- responding to requests and providing customer support;
- monitoring and improving service performance;
- meeting legal, regulatory, and tax obligations;
- detecting and preventing fraud, misuse, or unauthorized access;
- sending marketing communications where permitted and not objected to;
- administering internal reporting, audits, and business operations.
We ensure that data is not used in a manner that is incompatible with the original purpose for which it was collected, unless we have a lawful basis to do so.
5. Lawful Basis for Processing
Under GDPR, we rely on one or more of the following lawful bases when processing personal data:
- Performance of a contract: when processing is necessary to provide services, manage accounts, or fulfill obligations to you.
- Legal obligation: when processing is required to comply with applicable laws, accounting rules, tax obligations, or lawful requests from authorities.
- Legitimate interests: when processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include service improvement, fraud prevention, and administrative functions.
- Consent: where you have given clear, informed, and freely given consent, for example for certain marketing activities or optional data uses.
Where we rely on legitimate interests, we carry out a balancing assessment to ensure your privacy rights are protected. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing based on consent before withdrawal.
6. Sharing and Processors
We may share personal data with trusted third parties that act as data processors or independent controllers, depending on the circumstances and the nature of the service provided. Processors may include:
- IT and hosting providers;
- payment service providers;
- customer support and communications tools;
- analytics and performance monitoring providers;
- professional advisers, such as accountants or legal advisers;
- security and fraud prevention partners;
- delivery, logistics, or operational service partners, where relevant.
When we use processors, we ensure that they process data only on our documented instructions, maintain appropriate security measures, and are subject to contractual obligations that meet GDPR requirements. We do not allow processors to use personal data for their own unrelated purposes.
We may also disclose personal data if required by law, to protect our rights, to enforce agreements, or to respond to lawful requests from public authorities.
7. International Transfers
If personal data is transferred outside the European Economic Area, we will take appropriate safeguards to ensure an adequate level of protection. These safeguards may include adequacy decisions, standard contractual clauses, or other legally recognized transfer mechanisms. We apply these measures to ensure your data remains protected regardless of where it is processed.
8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, reporting, and compliance requirements. Retention periods vary depending on the type of data and the context of processing.
- Account and service data: kept for the duration of the relationship and for a reasonable period thereafter.
- Transaction and billing records: retained for the periods required by tax and financial regulations.
- Support communications: retained as needed to manage enquiries, resolve disputes, and improve service quality.
- Marketing data: retained until you withdraw consent or object, where applicable.
- Technical and security logs: retained for limited periods necessary for security, diagnostics, and system integrity.
When data is no longer needed, we will delete, anonymize, or securely archive it in accordance with our retention practices and legal obligations.
9. Data Security
We use appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption, authentication procedures, monitoring, and staff confidentiality obligations. While no system can be guaranteed to be completely secure, we take reasonable and proportionate steps to safeguard your information.
10. Your Rights Under GDPR
You have certain rights in relation to your personal data, subject to applicable legal limitations. These rights include:
- Right of access: to request confirmation of whether we process your data and obtain a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restrict processing: to request that we limit processing in specific situations.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and, where feasible, have it transferred to another controller.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
- Right not to be subject to solely automated decisions: to the extent such decisions have legal or similarly significant effects.
If you exercise any of these rights, we may need to verify your identity before responding. We will respond within the time limits required by law, and in any event in a fair and transparent manner.
11. Complaints and Supervisory Authorities
If you believe that your data protection rights have been violated, you may lodge a complaint with the relevant supervisory authority in your jurisdiction. We encourage you to raise concerns so we can address them promptly and appropriately.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updated version will apply from the date it becomes effective. We encourage you to review this Policy periodically to stay informed about how we protect your personal data.
Summary of Key Principles
We collect only the data needed to provide services, operate securely, and meet legal obligations. We process personal data on a valid lawful basis, share it only with appropriate processors or where legally required, retain it for limited periods, and respect your GDPR rights. This Policy applies to all customers in the area and is designed to ensure transparent, fair, and secure handling of personal data.
