Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when services are provided to customers in the relevant area. This policy applies to all customers in the area and is intended to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR).
1. Introduction
We are committed to respecting privacy and protecting personal information. We process personal data in a lawful, fair, and transparent manner. This policy describes what data we collect, the purposes for which we use it, the legal bases relied upon, how long we retain it, the third parties that may process it on our behalf, and the rights available to individuals under data protection law.
By using our services, customers acknowledge that their personal data may be processed as described in this policy.
2. Data We Collect
We collect only the personal data necessary for our operations. The types of data we may process include:
- Identity data such as name, title, and similar identifiers.
- Contact data such as postal address, email address, and telephone number.
- Account and transaction data such as service records, purchase history, billing details, and payment status.
- Technical data such as device type, browser information, IP address, log files, and usage patterns.
- Communication data such as inquiries, complaints, requests, and correspondence.
- Preference data such as service choices, consent settings, and marketing preferences.
We do not intentionally collect special category data unless it is necessary and permitted by law, and where this occurs, additional safeguards will be applied.
3. How We Use Personal Data
Personal data may be used for the following purposes:
- To provide, operate, and maintain our services.
- To manage customer accounts and records.
- To process transactions, payments, and refunds.
- To communicate service updates, confirmations, and support responses.
- To improve service performance, reliability, and user experience.
- To detect, prevent, and investigate fraud, abuse, or security incidents.
- To comply with legal and regulatory obligations.
- To send marketing communications where permitted and where consent is required or a valid opt-out mechanism is available.
We only use personal data for purposes that are compatible with the reason it was collected.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. Depending on the context, we may rely on one or more of the following:
- Contract: Processing is necessary to enter into or perform a contract with a customer, including the provision of services and related support.
- Legal obligation: Processing is necessary to comply with legal, tax, accounting, consumer, or other regulatory requirements.
- Legitimate interests: Processing is necessary for our legitimate business interests, provided those interests are not overridden by the individual’s rights and freedoms. This may include maintaining service security, preventing fraud, and improving operations.
- Consent: Where required by law, we rely on consent for specific processing activities, such as certain marketing communications or non-essential cookies where applicable. Consent may be withdrawn at any time.
- Vital interests: In rare circumstances, processing may be necessary to protect an individual’s vital interests.
When we rely on consent, it will be freely given, specific, informed, and unambiguous.
5. Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, reporting, and operational requirements. Retention periods depend on the type of information and the reason for processing.
- Data used to provide services is retained for the duration of the customer relationship and for a reasonable period afterward.
- Financial and tax records are retained for the period required by applicable law.
- Support communications and service records may be retained to manage ongoing service issues, maintain records, and improve service quality.
- Where processing is based on consent, data may be retained until consent is withdrawn or the data is no longer needed.
When personal data is no longer required, we will delete it, anonymize it, or securely archive it in line with our retention practices and legal obligations.
6. Processors and Data Sharing
We may share personal data with trusted third-party service providers who process data on our behalf as processors. These providers are subject to contractual obligations to protect personal data and to process it only in accordance with our instructions.
Processors may include:
- IT hosting and infrastructure providers.
- Payment processing services.
- Customer support and communication tools.
- Analytics and performance monitoring providers.
- Professional advisors such as legal, audit, or accounting services, where relevant.
We may also disclose personal data to authorities, regulators, courts, or law enforcement where required by law or necessary to protect legal rights, safety, or security.
We do not sell personal data. Any sharing is limited to what is necessary for legitimate business operations, legal compliance, or the delivery of services.
7. International Transfers
If personal data is transferred outside the country or region where it was collected, we will ensure appropriate safeguards are in place. These safeguards may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms recognized under GDPR. We take reasonable steps to ensure that transferred data remains protected and handled in a manner consistent with this policy.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and regular review of security procedures.
While we strive to protect personal data, no system can be guaranteed to be completely secure.
9. Your Rights Under GDPR
Individuals whose personal data we process have rights under GDPR, subject to certain conditions and exceptions. These rights include:
- Right of access: to obtain confirmation of whether we process personal data and to request a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limited processing in specific situations.
- Right to data portability: to receive personal data in a structured, commonly used, machine-readable format and, where feasible, have it transmitted to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: to withdraw consent at any time where processing relies on consent.
- Right not to be subject to automated decision-making: to object to decisions based solely on automated processing in circumstances where this right applies.
Requests will be handled in accordance with applicable law, and we may need to verify identity before responding. Where a request cannot be fulfilled, we will explain the reason.
10. Children’s Data
Our services are not directed to children unless expressly stated otherwise. If we become aware that personal data has been collected from a child without the required authorization or lawful basis, we will take appropriate steps to delete or protect that information as required by law.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service offerings. Any updated version will apply from the date it is made effective. We encourage customers to review this policy periodically to stay informed about how personal data is processed.
12. Final Statement
We are committed to handling personal data responsibly, transparently, and in compliance with applicable law. This policy applies to all customers in the area and is intended to provide a clear explanation of our privacy practices. By continuing to use our services, individuals acknowledge the terms described in this policy.