Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected when customers use our services in the relevant area. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and related data protection laws. By using our services, customers acknowledge that their personal data may be processed in accordance with this policy.
1. Scope of This Policy
This policy applies to all individuals who are customers in the area and whose personal data is processed in connection with the provision of our services. It covers data collected directly from customers, data received from third parties where permitted, and data generated through service use. It does not apply to personal data processed for purposes outside the scope of our services unless otherwise stated.
2. Data We Collect
We collect only the personal data that is necessary for legitimate business and service purposes. Depending on the nature of the relationship and the services used, we may collect the following categories of data:
- Identity data such as name, title, or similar identifiers.
- Contact data such as billing address, delivery address, or other relevant location details.
- Transaction data such as records of purchases, payments, and service history.
- Technical data such as device information, browser type, log data, and usage patterns.
- Communication data such as messages, requests, complaints, or feedback.
- Preferences data such as settings or choices related to service delivery.
We do not intentionally collect special categories of personal data unless it is required by law or explicitly provided for a specific and lawful purpose. Where such data is processed, we apply additional safeguards as required by GDPR.
3. How We Use Personal Data
We use personal data only for specified, explicit, and legitimate purposes. These purposes include:
- Providing and administering our services.
- Processing payments and managing transactions.
- Communicating service-related information.
- Responding to inquiries, requests, or complaints.
- Maintaining records for operational, accounting, and legal purposes.
- Improving service quality, security, and performance.
- Detecting, preventing, and addressing fraud, misuse, or unauthorized activity.
- Complying with legal obligations and regulatory requirements.
We will not use personal data in ways that are incompatible with the purposes for which it was collected unless we have a lawful basis to do so and, where required, have informed the customer.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing personal data. Depending on the context, our processing may rely on one or more of the following lawful bases:
- Contract: Processing is necessary to perform a contract with the customer or to take steps at the customer’s request before entering into a contract.
- Legal obligation: Processing is necessary to comply with a legal or regulatory obligation.
- Legitimate interests: Processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the customer’s rights and freedoms.
- Consent: In limited situations, processing may be based on the customer’s consent. Where consent is relied upon, it may be withdrawn at any time.
Where we rely on legitimate interests, we assess whether our interests are balanced against the rights of the customer. Where consent is required, it will be freely given, specific, informed, and unambiguous.
5. Sharing Personal Data and Processors
We may share personal data with trusted third parties where necessary for service delivery, legal compliance, security, or operational support. These third parties may act as processors under GDPR, meaning they process personal data on our behalf and under our instructions.
Examples of processors may include:
- Payment service providers.
- IT hosting and cloud infrastructure providers.
- Data storage and backup providers.
- Customer support and communication service providers.
- Analytics and security service providers.
We require processors to implement appropriate technical and organizational measures to protect personal data and to process it only for authorized purposes. We do not allow processors to use personal data for their own independent purposes unless they are acting as separate controllers under a valid legal basis.
We may also disclose personal data where required by law, court order, or lawful request from public authorities, or where disclosure is necessary to protect rights, property, or safety.
6. Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, reporting, or compliance requirements. Retention periods vary depending on the type of data and the purpose of processing.
When determining retention periods, we consider:
- The nature and sensitivity of the data.
- The purpose for which it was collected and processed.
- Legal and regulatory retention obligations.
- Whether the data may be needed to establish, exercise, or defend legal claims.
Once the retention period expires, personal data will be securely deleted, anonymized, or archived in a manner that prevents identification, unless further retention is required by law.
7. Data Security
We apply appropriate technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, monitoring, and staff training. While no system can be guaranteed completely secure, we take reasonable steps to reduce risk and protect customer information.
8. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with equivalent data protection requirements, we will ensure that appropriate safeguards are in place. These safeguards may include standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms permitted under GDPR.
9. User Rights Under GDPR
Customers in the area have rights in relation to their personal data. Subject to applicable legal conditions and exemptions, these rights may include:
- Right of access: To request confirmation of whether personal data is being processed and to obtain a copy of that data.
- Right to rectification: To request correction of inaccurate or incomplete personal data.
- Right to erasure: To request deletion of personal data in certain circumstances.
- Right to restriction: To request limitation of processing in certain situations.
- Right to data portability: To receive certain data in a structured, commonly used, machine-readable format and to request transmission to another controller where feasible.
- Right to object: To object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: To withdraw consent at any time where processing is based on consent.
- Right not to be subject to automated decision-making: To request human intervention where decisions are made solely by automated means and have legal or similarly significant effects.
Customers may also have the right to lodge a complaint with their local data protection authority if they believe their rights have been infringed.
10. Exercising Rights
Requests to exercise data protection rights should be made using the available service channels. We may need to verify identity before responding to a request. We aim to respond within the timeframes required by GDPR and will provide information about any extension if a request is complex or numerous.
Note: Some rights are not absolute and may be limited where processing is necessary to comply with legal obligations, protect the rights of others, or establish, exercise, or defend legal claims.
11. Children’s Data
Our services are not directed at children unless explicitly stated. We do not knowingly collect personal data from children without appropriate authorization where required by law. If we become aware that personal data has been collected in breach of this policy, we will take appropriate steps to delete or secure the data as required.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our processing practices, legal obligations, or service developments. Any revised version will apply from the date it is made effective. Customers are encouraged to review the policy periodically to stay informed about how personal data is protected and used.
Summary of Key Principles
We process personal data lawfully, fairly, and transparently. We collect only what is necessary, use it for defined purposes, retain it for limited periods, share it only with appropriate processors or where legally required, and respect the rights of all customers in the area.
