Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected. It applies to all customers in the area and is intended to be consistent with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our services, you acknowledge that your personal data may be processed as described below.
1. Data We Collect
We collect only the personal data necessary for the purposes described in this policy. The categories of data we may collect include:
- Identification data: name, title, and similar details needed to identify you.
- Contact data: address, email address, telephone number, and communication preferences.
- Transaction data: records of purchases, payments, invoices, and service history.
- Technical data: device information, IP address, browser type, language, and system logs.
- Usage data: information about how services are accessed and used.
- Preference data: choices relating to service settings, marketing, and user experience.
We do not intentionally collect special category data unless it is required for a lawful purpose and permitted by law. If such data is provided, it will be handled with additional safeguards and only where strictly necessary.
2. How We Use Personal Data
Personal data may be used for the following purposes:
- To provide and manage our services.
- To process transactions and maintain records.
- To communicate with customers about service matters.
- To improve service quality, performance, and functionality.
- To detect and prevent fraud, misuse, and security incidents.
- To comply with legal and regulatory obligations.
- To send marketing communications where permitted and appropriately consented to.
We process personal data in a way that is lawful, fair, and transparent, and only for specified, explicit, and legitimate purposes.
3. Lawful Basis for Processing
Under GDPR, we rely on one or more of the following lawful bases to process personal data:
3.1 Performance of a Contract
We process data when it is necessary to enter into or perform a contract with you, including providing requested services, handling payments, and managing account-related matters.
3.2 Legal Obligation
We may process data to comply with legal duties, such as tax, accounting, consumer protection, anti-fraud, or record-keeping requirements.
3.3 Legitimate Interests
We may process data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. These interests may include service improvement, security monitoring, fraud prevention, and internal administration.
3.4 Consent
Where required by law, we will rely on your consent, such as for certain marketing activities or non-essential cookies and similar technologies. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
3.5 Vital Interests and Public Interest
In limited cases, we may process data where necessary to protect vital interests or to perform tasks carried out in the public interest, where applicable law permits.
4. Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting obligations. Retention periods depend on the nature of the data and the context of processing.
In determining the appropriate retention period, we consider:
- The amount, nature, and sensitivity of the data.
- The potential risk of harm from unauthorized use or disclosure.
- The purposes of processing and whether they can be achieved by other means.
- Applicable legal requirements and limitation periods.
When data is no longer required, it will be securely deleted, anonymized, or archived in accordance with applicable law. Where records must be retained, they will be stored only for the minimum period necessary and protected by appropriate technical and organizational measures.
5. Sharing and Processors
We may share personal data with trusted third parties acting as processors or, in some cases, independent controllers. Processors are engaged only where they provide sufficient guarantees to implement appropriate safeguards and process data under a written contract.
Examples of processors may include:
- IT hosting and cloud service providers.
- Payment processing providers.
- Customer support and communication service providers.
- Analytics, security, and fraud prevention providers.
- Document storage and backup service providers.
Where processors act on our behalf, they may only process personal data according to our instructions and for the agreed purposes. They are required to protect data, maintain confidentiality, and implement suitable security controls.
We may also disclose personal data where required by law, to respond to lawful requests, to enforce rights, or to protect the rights, property, or safety of individuals and organizations.
6. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with comparable protections, appropriate safeguards will be used. These may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms recognized under GDPR. We will take steps to ensure that transferred data remains protected to a standard consistent with applicable law.
7. Data Security
We use reasonable and appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, misuse, alteration, or disclosure. These measures may include access controls, encryption, authentication procedures, monitoring, and staff confidentiality obligations.
While no system can be guaranteed as completely secure, we regularly review our safeguards and update them where necessary to reduce risks and maintain a high level of protection.
8. User Rights Under GDPR
Subject to applicable conditions and exceptions, you have the following rights in relation to your personal data:
- Right of access: to request confirmation of whether your data is being processed and to obtain a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limited processing in specific situations.
- Right to data portability: to receive data in a structured, commonly used, machine-readable format and to request transfer where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
- Right to lodge a complaint: to raise concerns with the relevant supervisory authority.
To help protect privacy, we may need to verify your identity before responding to a rights request. Requests will be handled within the time limits required by law, usually within one month, unless the request is complex or numerous.
9. Children’s Data
Our services are not directed to children where parental authorization is required by law. We do not knowingly collect personal data from children without appropriate consent or another valid lawful basis. If we become aware that such data has been collected in error, we will take steps to delete it or obtain the necessary authorization where permitted.
10. Automated Decision-Making
We do not use solely automated decision-making that produces legal or similarly significant effects unless permitted by law and accompanied by suitable safeguards. If such processing is introduced, you will be informed about the logic involved, the significance of the processing, and your available rights.
11. Updates to This Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or technical changes. The latest version will apply from the time it is made available. Material changes will be communicated in an appropriate manner. We encourage you to review this policy periodically to stay informed about how your data is handled.
12. General Principles
We are committed to processing personal data in accordance with the core GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. We also maintain accountability by keeping internal records and reviewing our data handling practices.
By using our services, you understand that this Privacy Policy applies to all customers in the area and describes the basis on which personal data may be processed. We aim to treat all personal data with care and respect, using only what is necessary for legitimate and lawful purposes.
In summary, this policy sets out what data we collect, why we collect it, how long we keep it, who may process it on our behalf, and what rights you can exercise regarding your personal data. We are committed to protecting privacy and handling information responsibly.
