Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when customers use our services. It applies to all customers in the area where our services are offered, and it is designed to reflect the requirements of the General Data Protection Regulation (GDPR). We are committed to handling personal data lawfully, fairly, and transparently.
1. Scope of This Policy
This policy applies to all individuals who interact with our services as customers, including prospective customers, registered users, and any person whose data is processed in connection with a customer account, service request, transaction, or support interaction. The policy covers personal data collected directly from individuals, data provided by third parties acting on behalf of customers, and data generated through the use of our services.
We only process personal data where there is a valid legal basis under GDPR and only for purposes that are necessary, relevant, and proportionate.
2. Data We Collect
We may collect and process the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, phone number, and delivery details.
- Account data: customer identifiers, login details, preferences, and account settings.
- Transaction data: purchase history, payment status, billing records, and service usage records.
- Technical data: IP address, browser type, device identifiers, operating system, and usage logs.
- Communication data: messages, inquiries, complaints, and support correspondence.
- Preference data: marketing choices, service preferences, and consent settings.
We may also process limited special category data only where strictly necessary and where a lawful basis exists under GDPR. In such cases, additional safeguards are applied.
3. How We Use Personal Data
Personal data is used for legitimate and clearly defined purposes, including:
- providing and managing our services;
- processing transactions and fulfilling requests;
- creating and maintaining customer accounts;
- responding to questions, complaints, or service issues;
- ensuring service quality, security, and fraud prevention;
- maintaining records required by law;
- improving our services, processes, and customer experience;
- sending marketing communications where permitted by law and where consent or another lawful basis applies.
We do not use personal data in ways that are incompatible with the purposes for which it was collected unless permitted by law or with appropriate consent.
4. Lawful Basis for Processing
Under GDPR, we process personal data only when there is a valid lawful basis. Depending on the situation, our processing may be based on one or more of the following:
Contract
We process data when it is necessary to enter into or perform a contract with a customer, such as providing services, managing accounts, or fulfilling an order.
Legal Obligation
We may process data to comply with legal and regulatory obligations, including tax, accounting, fraud prevention, and recordkeeping requirements.
Legitimate Interests
We may process data for our legitimate business interests where those interests are not overridden by the rights and freedoms of the individual. Examples include service improvement, security monitoring, internal administration, and limited direct marketing where permitted. A balancing assessment is carried out where required.
Consent
Where consent is required, we will obtain it in a clear and informed manner. Individuals may withdraw consent at any time, and this will not affect the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Task
These bases are used only in exceptional circumstances where necessary for safety or where processing is required in the public interest under applicable law.
5. Data Sharing and Processors
We may share personal data with trusted third-party service providers acting as processors on our behalf. These processors are bound by written agreements and may only process personal data in accordance with our instructions and GDPR requirements.
Processors may include providers of:
- IT hosting and cloud infrastructure;
- payment processing;
- customer support systems;
- analytics and reporting tools;
- security and fraud detection services;
- document storage and archiving services.
We may also disclose personal data where required by law, in response to lawful requests from public authorities, or where necessary to protect rights, property, or safety.
Where data is transferred outside the European Economic Area, appropriate safeguards are used, such as standard contractual clauses or equivalent legal mechanisms, to ensure an adequate level of protection.
6. Retention of Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, reporting, and dispute-resolution requirements. Retention periods vary depending on the type of data and the context of processing.
In general:
- Account and service data are retained for the duration of the customer relationship and for a reasonable period afterward.
- Transaction and financial data are retained for the period required by tax and accounting laws.
- Support and communication records are retained as long as needed to resolve issues and maintain service records.
- Marketing preferences and consent records are retained until the preference changes or consent is withdrawn.
- Security and log data are retained for a limited time unless a longer period is needed for investigation or legal compliance.
When personal data is no longer required, it is securely deleted, anonymized, or otherwise disposed of in a safe and lawful manner.
7. Data Security
We apply appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption, monitoring, backup systems, and staff confidentiality obligations.
Security is a continuous process, and we regularly review our safeguards to keep them appropriate to the risks involved.
8. User Rights Under GDPR
Individuals whose personal data we process have specific rights under GDPR. Subject to legal conditions and exemptions, these rights include:
- Right of access: to obtain confirmation and a copy of personal data being processed.
- Right to rectification: to have inaccurate or incomplete data corrected.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to limit processing in certain situations.
- Right to data portability: to receive data in a structured, commonly used format and transfer it where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent.
- Right not to be subject to automated decision-making: including profiling, where applicable.
Requests relating to these rights will be handled in line with GDPR timelines and requirements. We may need to verify identity before responding to protect privacy and prevent unauthorized access.
9. Children’s Data
Our services are not intended for children unless specifically stated otherwise. Where children’s personal data is processed, we do so only in compliance with applicable law and with appropriate safeguards. If consent is required for a child, it will be obtained from a person authorized to provide it where necessary.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any revised version will apply from the date it becomes effective. Continued use of our services after an update will be interpreted as acknowledgment of the revised policy, where permitted by law.
11. Additional GDPR Information
We aim to ensure that all processing is lawful, fair, and transparent. We limit collection to what is relevant and necessary, keep data accurate and up to date where possible, and retain information only for the time needed. We also take care to process data in a manner that respects individual rights and ensures accountability.
Where individuals exercise their rights, we will review the request carefully and respond in accordance with GDPR obligations. Where we rely on legitimate interests, we will balance those interests against the rights and freedoms of the individual. Where consent is required, it will be requested clearly and can be withdrawn easily.
This Privacy Policy applies to all customers in the area and should be read together with any service-specific terms or notices that may explain additional processing details. If a conflict arises between this policy and mandatory law, applicable law will prevail.
By using our services, customers acknowledge that personal data may be processed as described in this policy and in accordance with applicable data protection law.
