Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, retained, and protected in relation to our services. It applies to all customers in the area and is intended to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our services, customers acknowledge that their personal data may be processed as described in this Policy.
1. Data We Collect
We collect and process only the personal data that is necessary for legitimate business and operational purposes. The types of data we may collect include:
- Identity data such as name, title, or account identifier.
- Contact data such as email address, telephone number, billing address, or delivery address.
- Transaction data such as purchase history, payment status, and service usage records.
- Technical data such as device type, browser type, IP address, and access logs.
- Profile data such as preferences, service selections, and communication choices.
- Correspondence data such as messages, support requests, feedback, and complaints.
We may receive this information directly from customers, through automated technologies, or from third parties where permitted by law. We do not intentionally collect unnecessary data, and we aim to limit collection to what is relevant, adequate, and proportionate.
2. How We Use Personal Data
We process personal data for the following purposes:
- To provide and manage our services.
- To process transactions, invoices, and payments.
- To communicate with customers about service matters, updates, and notices.
- To respond to inquiries, complaints, and support requests.
- To maintain security, prevent fraud, and detect misuse.
- To improve service performance, usability, and quality.
- To comply with legal and regulatory obligations.
- To establish, exercise, or defend legal claims.
Where required, we will ensure that processing is limited to the relevant purpose and carried out in a manner consistent with the principles of lawfulness, fairness, transparency, data minimization, accuracy, storage limitation, integrity, and confidentiality.
3. Lawful Basis for Processing
We process personal data only when we have a valid lawful basis under GDPR. Depending on the context, we rely on one or more of the following bases:
Consent
We may rely on consent when customers have given a clear and informed indication that they agree to the processing of their data for a specific purpose. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
Contract
We process personal data where it is necessary to perform a contract with a customer or to take steps at the customer’s request before entering into a contract. This may include fulfilling orders, providing access to services, or managing accounts.
Legal Obligation
We may process personal data where it is necessary to comply with a legal or regulatory obligation. This can include recordkeeping, tax requirements, fraud prevention, or responding to lawful requests from public authorities.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the rights and freedoms of the customer. Examples include service improvement, security monitoring, and internal administrative purposes. Where legitimate interests are relied upon, we assess the impact on individuals and apply safeguards.
4. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, reporting, or contractual requirements. The retention period depends on the nature of the data, the reason for processing, and any applicable retention obligations.
In general:
- Account and service records are retained while the account remains active and for a reasonable period afterward.
- Financial and transaction records may be retained for longer periods to meet tax and legal obligations.
- Support correspondence may be retained for quality assurance, dispute resolution, or compliance purposes.
- Technical logs may be kept for security, troubleshooting, and operational monitoring.
When data is no longer needed, it will be securely deleted, anonymized, or otherwise irreversibly disposed of in accordance with applicable requirements. Retention is reviewed periodically to ensure that data is not kept longer than necessary.
5. Processors and Third Parties
We may share personal data with trusted third-party service providers acting as processors on our behalf. These processors are authorized to process data only under our instructions and are required to implement appropriate security and confidentiality measures.
Processors may provide services such as:
- IT hosting and infrastructure support
- Payment processing
- Customer support and communication tools
- Security and fraud detection services
- Analytics and performance monitoring
- Document storage and administrative services
We may also disclose personal data where necessary to comply with law, enforce agreements, protect rights, or respond to lawful requests. Any sharing is limited to what is necessary and proportionate. Where data is transferred outside the European Economic Area, appropriate safeguards will be implemented in accordance with GDPR requirements.
6. Security of Personal Data
We use appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures may include access controls, encryption, system monitoring, secure storage, and staff training.
Although no system can be guaranteed completely secure, we maintain reasonable safeguards designed to reduce risk and protect customer information. We also review our security practices regularly and update them as needed.
7. User Rights
Under GDPR, customers have important rights regarding their personal data. Subject to legal limitations and verification requirements, customers may exercise the following rights:
- Right of access – to request confirmation of whether their data is processed and obtain a copy of that data.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of data in certain circumstances.
- Right to restriction – to request limited processing in certain cases.
- Right to data portability – to receive certain data in a structured, commonly used format and transmit it to another controller where applicable.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent.
- Right not to be subject to automated decision-making – including profiling, where such processing has legal or similarly significant effects.
We will respond to rights requests in accordance with GDPR time limits and applicable law. In some cases, we may need to retain certain information despite a request, for example where required to comply with legal obligations or defend legal claims.
8. Children’s Data
Our services are not directed to children where consent from a parent or guardian is required by law. If we become aware that personal data has been collected from a child without appropriate authorization, we will take reasonable steps to delete that information.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updated version will apply from the date it becomes effective. Customers are encouraged to review this Policy periodically to remain informed about how personal data is handled.
10. General Statement
This Privacy Policy applies to all customers in the area. It is intended to provide clear and transparent information about our data processing practices and the rights available to individuals under GDPR. We are committed to handling personal data responsibly, securely, and in accordance with applicable law.
By continuing to use our services, customers acknowledge that they have read and understood this Privacy Policy.
