Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area where our services are offered. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with applicable data protection laws, including the GDPR where relevant.
1. Scope of This Policy
This Policy applies to personal data processed when individuals use our services, interact with our business, or otherwise provide information to us. It covers data collected directly from customers, data generated through service use, and limited data received from third parties where permitted by law. By using our services, customers acknowledge that their personal data may be processed as described in this Policy.
2. Data We Collect
We collect only data that is necessary for specific, legitimate purposes. Depending on the service relationship, this may include:
- Identity information such as name, title, or similar identifiers.
- Contact information such as address, email address, or phone number.
- Account and transaction information such as service records, billing history, payment status, and order details.
- Technical information such as device type, browser type, IP address, log data, and usage patterns.
- Communication data such as messages, inquiries, complaints, feedback, and support requests.
- Preference information such as communication choices or service preferences.
We do not intentionally collect special category data unless it is necessary and permitted by law, and where required, subject to additional safeguards and explicit consent or another valid legal basis.
3. How We Use Personal Data
We use personal data only for lawful and relevant purposes, including:
- Providing and managing our services.
- Processing transactions, payments, and related administration.
- Communicating with customers about service matters, updates, or support.
- Maintaining records, quality control, and internal reporting.
- Detecting, preventing, and investigating fraud, misuse, or security incidents.
- Meeting legal, regulatory, tax, accounting, and compliance obligations.
- Improving service performance, functionality, and customer experience.
Where processing is based on legitimate interests, we ensure that those interests do not override the rights and freedoms of individuals. We may also use data in anonymized or aggregated form, which no longer identifies an individual, for analysis and service improvement.
4. Lawful Basis for Processing
We process personal data only when we have a valid lawful basis under the GDPR or other applicable law. The lawful bases we rely on may include:
- Performance of a contract – when processing is necessary to provide services or take steps at a customer’s request before entering into a contract.
- Legal obligation – when processing is required to comply with applicable laws and regulations.
- Legitimate interests – when processing is necessary for our legitimate business interests, provided these interests are not overridden by the individual’s rights.
- Consent – when a customer has given clear and informed consent for a specific purpose, and where consent is required by law.
Where consent is used, it may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Sharing and Processors
We may share personal data with trusted third parties only when necessary and appropriate. Such parties may act as processors or independent controllers depending on the circumstances. Processors process data on our behalf and are bound by written agreements requiring them to protect personal data and act only on our documented instructions.
Examples of processors may include:
- IT and hosting providers.
- Payment and billing service providers.
- Customer support and communication platform providers.
- Security, analytics, and system maintenance providers.
- Professional advisers, where relevant and lawful.
We may also disclose personal data where required by law, regulation, court order, or lawful request by public authorities. If a transfer of personal data outside the applicable jurisdiction is necessary, we will ensure appropriate safeguards are in place to protect the data in accordance with GDPR requirements, such as standard contractual clauses or other approved mechanisms.
6. Data Retention
We retain personal data only for as long as it is needed for the purposes for which it was collected, or as required by law. Retention periods are determined by several factors, including:
- The nature and sensitivity of the data.
- The purposes for which it is processed.
- Legal, accounting, tax, and regulatory obligations.
- Potential disputes, claims, or enforcement matters.
When data is no longer required, we will delete, anonymize, or securely archive it in accordance with our retention practices. We aim to keep data no longer than necessary, while ensuring compliance with applicable legal requirements.
7. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption where suitable, secure storage, regular monitoring, and staff training. Although no system can be guaranteed completely secure, we work to maintain a level of protection appropriate to the risks involved.
8. User Rights
Subject to applicable law, individuals have a range of rights regarding their personal data. These rights may include:
- Right of access – to request confirmation of whether we process personal data and to obtain a copy of that data.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of personal data in certain circumstances.
- Right to restriction – to request that processing be limited in certain situations.
- Right to data portability – to receive certain data in a structured, commonly used, machine-readable format and to transmit it to another controller where applicable.
- Right to object – to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to withdraw consent – to withdraw consent at any time where processing is based on consent.
- Right to complain – to lodge a complaint with a supervisory authority if an individual believes their data rights have been infringed.
Requests relating to these rights will be assessed in accordance with legal requirements. In some cases, we may need to verify identity before responding, and certain rights may be limited by law or by legitimate grounds for retaining the data.
9. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate legal basis and required authorizations. If we become aware that we have collected data from a child in breach of applicable law, we will take appropriate steps to delete or secure the information as required.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any revised version will apply from the effective date stated in the updated policy. We encourage customers to review this Policy periodically to remain informed about how we protect personal data.
Summary of Key Principles
Lawfulness, fairness, transparency, data minimization, storage limitation, accuracy, integrity, and confidentiality guide our data protection practices. We collect only what is necessary, use it for specified purposes, retain it only as long as needed, and respect the rights of individuals under applicable data protection law.
This Privacy Policy applies to all customers in the area and is intended to provide clear information on how personal data is handled.
