Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when customers use our services. It is intended to be GDPR-compliant and applies to all customers in the area where our services are offered. By using our services, you acknowledge that your personal data may be processed in accordance with this Policy and applicable data protection laws.
1. Scope of This Policy
This Policy applies to all individuals who interact with our services as customers in the relevant area. It covers information collected through service requests, account activity, communications, transactions, support interactions, and related operational processes. It does not apply to third-party services that we do not control, except where those third parties act as processors on our behalf.
2. Data We Collect
We only collect personal data that is necessary for legitimate and specified purposes. Depending on the nature of your interaction with us, we may collect the following categories of information:
- Identity data: name, title, and similar identifying details.
- Contact data: address, email address, telephone number, and communication preferences.
- Transaction data: records of purchases, payments, invoices, and service history.
- Technical data: device type, browser information, log data, IP address, and system identifiers.
- Usage data: information about how services are accessed and used.
- Support data: details you provide when making inquiries, complaints, or support requests.
- Compliance data: records needed to meet legal, regulatory, tax, accounting, or audit obligations.
We do not intentionally collect special category data unless it is required by law, necessary for a specific service, or explicitly provided by you with a valid legal basis. Where such data is processed, we apply enhanced safeguards.
3. How We Use Personal Data
We use personal data for the following purposes:
- to provide and manage our services;
- to process requests, orders, payments, and communications;
- to maintain records and support customer service;
- to improve service quality, reliability, and user experience;
- to monitor and prevent fraud, misuse, and security incidents;
- to comply with legal and regulatory obligations;
- to establish, exercise, or defend legal claims;
- to send operational notices and service-related updates.
We will not use personal data in ways that are incompatible with the original purpose unless we have a lawful basis to do so and have assessed the impact of that further processing.
4. Lawful Basis for Processing
Under GDPR, we rely on one or more of the following lawful bases for processing personal data:
- Contract: processing is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
- Legal obligation: processing is necessary to comply with applicable laws, regulations, tax, or accounting rules.
- Legitimate interests: processing is necessary for our legitimate business interests, such as service improvement, fraud prevention, security, and administrative efficiency, provided these interests are not overridden by your rights and freedoms.
- Consent: where required by law, we may rely on your consent for certain processing activities. You may withdraw consent at any time where consent is the lawful basis.
- Vital interests: in rare cases, processing may be necessary to protect someone’s vital interests.
- Public task: where applicable, processing may be necessary for tasks carried out in the public interest or under official authority.
Where we rely on legitimate interests, we conduct a balancing assessment to ensure that our interests are lawful and do not unfairly impact your privacy.
5. Data Sharing and Processors
We may share personal data with trusted third parties who act as processors on our behalf. These processors only process data according to our instructions and are required to maintain appropriate technical and organizational safeguards.
Typical processor categories may include:
- IT and cloud service providers for storage, system hosting, and infrastructure support;
- payment processors for handling transactions securely;
- customer support tools for managing service requests and communications;
- analytics and reporting providers for service performance monitoring;
- professional advisers such as accountants, auditors, or legal advisers where necessary;
- compliance and security providers for fraud detection, risk management, and incident response.
We may also disclose personal data where required by law, court order, regulatory request, or where necessary to protect our rights, users, employees, or the public. If personal data is transferred outside the relevant jurisdiction, we will ensure appropriate safeguards are in place in line with GDPR requirements, such as standard contractual clauses or equivalent protections.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, reporting, or dispute-resolution requirements. Retention periods are determined by:
- the nature of the data and the purpose of processing;
- contractual obligations;
- legal and regulatory retention requirements;
- limitation periods for legal claims;
- security and audit needs.
When personal data is no longer required, we will securely delete, anonymize, or archive it in accordance with our internal retention procedures and applicable law. In some cases, we may keep limited data for a longer period if required to defend legal claims or comply with statutory obligations.
7. Data Security
We take appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff training, and monitoring of systems and processes. While no system can be guaranteed completely secure, we regularly review our safeguards and update them where appropriate.
8. Your Rights Under GDPR
Subject to legal conditions and limitations, you have the following rights regarding your personal data:
- Right of access: to obtain confirmation of whether we process your data and receive a copy of it;
- Right to rectification: to request correction of inaccurate or incomplete data;
- Right to erasure: to request deletion of your data in certain circumstances;
- Right to restriction: to request limited processing in certain situations;
- Right to data portability: to receive data you provided in a structured, commonly used format and, where feasible, have it transmitted to another controller;
- Right to object: to object to processing based on legitimate interests or direct marketing;
- Right to withdraw consent: where consent is the basis for processing, you may withdraw it at any time;
- Right not to be subject to automated decision-making: to request human intervention where decisions are made solely by automated means and have legal or similarly significant effects.
If you wish to exercise any of these rights, we will respond in accordance with GDPR timeframes and legal requirements. We may need to verify your identity before fulfilling a request. In some cases, certain rights may be limited where necessary to comply with law or protect the rights of others.
9. Data Accuracy and Your Responsibility
We rely on you to provide accurate and up-to-date information. Please notify us of any changes to your personal data so that our records remain correct and complete. Accurate data helps us provide services efficiently, maintain security, and fulfill legal obligations.
10. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate legal grounds and, where required, verifiable parental or guardian consent. If we become aware that personal data has been collected inappropriately, we will take steps to delete or otherwise handle it in accordance with applicable law.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. Any updates will apply from the date they are published or otherwise communicated. We encourage you to review this Policy periodically so that you remain informed about how your personal data is processed.
12. Summary of Key Principles
In summary, we process personal data fairly, lawfully, and transparently. We collect only what is necessary, use it for defined purposes, retain it for no longer than needed, and share it only with authorized processors or where required by law. We also respect your GDPR rights and apply appropriate safeguards to protect your information at every stage of processing.
This Privacy Policy applies to all customers in the area and should be read together with any service-specific terms or notices that may apply.
