Privacy Policy
1. Scope and Application
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area where our services are offered, and it is intended to meet the requirements of the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our services, customers acknowledge that their personal data may be processed in the ways described in this policy.
This policy is designed to provide clear information about our data practices and your rights. We are committed to handling personal data fairly, lawfully, and transparently. We only process personal data where we have a valid legal basis and only for specified, legitimate purposes.
2. Data We Collect
We may collect and process the following categories of personal data, depending on how you interact with us:
- Identity information, such as name, title, and similar identifiers.
- Contact information, such as address, email address, and telephone number.
- Transaction information, such as records of services purchased, payments made, and related billing details.
- Account information, such as login details, preferences, and settings.
- Communication data, such as messages, feedback, complaints, and correspondence.
- Technical data, such as device type, IP address, browser type, and usage logs.
- Usage data, such as interactions with our services, pages viewed, and feature usage.
- Preference data, such as marketing choices and service preferences.
We do not intentionally collect special categories of personal data unless this is necessary for a specific lawful purpose and permitted by law. If such data is ever processed, it will be handled with additional safeguards.
3. How We Use Personal Data
We use personal data only for defined purposes, including:
- Providing and administering our services.
- Processing transactions and maintaining records.
- Managing customer accounts and requests.
- Communicating service-related notices and updates.
- Improving our services, systems, and customer experience.
- Meeting legal, regulatory, tax, accounting, and reporting obligations.
- Detecting, investigating, and preventing fraud, security incidents, and misuse.
- Carrying out internal administration and business operations.
We only process data in a way that is compatible with these purposes. Where we need to use data for a new purpose, we will assess whether that purpose is compatible with the original collection purpose or whether a new lawful basis is required.
4. Lawful Basis for Processing
Under GDPR, we process personal data only when we have a lawful basis. Depending on the context, our lawful bases may include:
4.1 Performance of a Contract
We process personal data where it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract. This may include managing accounts, providing services, and processing payments.
4.2 Legal Obligation
We may process personal data where necessary to comply with legal and regulatory obligations. This may include accounting, tax, consumer law, fraud prevention, and record-keeping obligations.
4.3 Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Examples include maintaining service security, improving our operations, and managing internal administration. When we rely on legitimate interests, we carry out an assessment to ensure that your privacy rights are protected.
4.4 Consent
In limited situations, we may rely on your consent, for example for certain marketing activities or optional processing. Where consent is used as the lawful basis, you have the right to withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing before the withdrawal.
5. Data Sharing and Processors
We may share personal data with trusted third parties that act as processors or, in some cases, independent controllers. Processors only process personal data on our documented instructions and are required to keep it secure and confidential. We use contractual safeguards to ensure that such parties meet GDPR standards.
Categories of processors may include:
- IT and hosting providers that support data storage, system operations, and infrastructure.
- Payment service providers that facilitate secure payment processing.
- Customer support tools that help us manage queries and service requests.
- Analytics providers that assist in understanding how services are used.
- Professional advisers, such as legal, accounting, or audit service providers.
- Security and fraud prevention providers that help protect systems and users.
Where personal data is transferred outside the European Economic Area, we will ensure that appropriate safeguards are in place, such as an adequacy decision or standard contractual clauses, as required by GDPR. We only transfer data when necessary and with proper protection.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including meeting legal, accounting, tax, contractual, and operational requirements. Retention periods vary depending on the type of data and the purpose of processing.
In determining retention periods, we consider:
- the amount, nature, and sensitivity of the data;
- the potential risk of harm from unauthorized use or disclosure;
- the purposes of processing and whether those purposes can be achieved through other means; and
- legal or regulatory retention obligations.
When personal data is no longer needed, we will securely delete, anonymize, or otherwise dispose of it in line with our retention practices. If deletion is not immediately possible due to legal or technical reasons, the data will be securely isolated and protected until deletion becomes feasible.
7. Data Security
We implement appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, unlawful use, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff training, and ongoing security monitoring.
No system can be guaranteed to be completely secure, but we continually review and improve our safeguards to reduce risk. Access to personal data is limited to persons who need it for legitimate business purposes and are subject to confidentiality obligations.
8. Your Rights Under GDPR
Subject to legal conditions and exemptions, you have the following rights regarding your personal data:
- Right of access to obtain confirmation of whether we process your data and receive a copy of it.
- Right to rectification to correct inaccurate or incomplete data.
- Right to erasure in certain circumstances, also known as the right to be forgotten.
- Right to restriction of processing in certain cases.
- Right to data portability to receive data you have provided in a structured, commonly used, machine-readable format, where applicable.
- Right to object to processing based on legitimate interests or to direct marketing.
- Right to withdraw consent where processing relies on consent.
- Right not to be subject to solely automated decision-making that produces legal or similarly significant effects, where applicable.
You may also have the right to lodge a complaint with a supervisory authority if you believe your data has been processed unlawfully. We encourage you to raise concerns with us first so we can address them promptly.
9. Children’s Data
Our services are not intended for children unless explicitly stated otherwise. We do not knowingly collect personal data from children in a way that would violate applicable law. If we become aware that such data has been collected without appropriate authorization or consent, we will take steps to delete it or seek a lawful basis for continued processing.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updated version will apply from the date it is made effective. We recommend reviewing this policy periodically to stay informed about how we protect personal data.
11. Principles We Follow
Our data protection approach is based on key GDPR principles, including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability. These principles guide how we collect and use data and how we design our internal controls.
We aim to collect only the data that is necessary, keep it only as long as required, and ensure it is handled responsibly. Where possible, we use anonymization or pseudonymization to reduce privacy risks.
12. Final Statement
This Privacy Policy applies to all customers in the area and sets out the standards we follow when processing personal data. By using our services, you acknowledge that you have read and understood this policy. We are committed to respecting your privacy rights and processing your personal data in a lawful, transparent, and secure manner.
