Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when services are provided to customers in the relevant area. This Policy applies to all customers in the area and is intended to provide clear information in line with applicable data protection laws, including the GDPR where it applies.
1. Who This Policy Applies To
This Privacy Policy applies to all individuals who use or receive services as customers in the area. It covers personal data processed in connection with inquiries, account creation, transactions, service delivery, support, communication, and related operational activities. By interacting with the service, customers acknowledge that their personal data may be processed in accordance with this Policy.
2. Personal Data We Collect
We may collect and process different categories of personal data depending on the nature of the interaction and the service provided. The information collected may include:
- Identity data such as name, title, or similar identifiers.
- Contact data such as postal address, email address, or phone number.
- Account and service data such as service preferences, purchase history, or communication records.
- Payment and transaction data where needed to complete a transaction or fulfill a service.
- Technical data such as device type, browser type, IP address, and usage logs.
- Communication data including correspondence, support requests, and feedback.
Where permitted by law and necessary for the service, we may also process limited special category data only if a valid legal basis exists. Such information is handled with additional safeguards and only when strictly required.
3. How We Collect Personal Data
Personal data may be collected directly from customers when they submit forms, make requests, place orders, communicate with us, or otherwise interact with the service. Data may also be collected automatically through technical systems, such as logs and analytics tools, to help maintain security, improve performance, and ensure the proper operation of services.
In some cases, personal data may be obtained from third parties, such as service providers, payment handlers, or publicly available sources, where lawful and appropriate. When this happens, we take steps to ensure that the data was collected and shared in compliance with applicable law.
4. Purposes of Processing
We process personal data only for specific and legitimate purposes. These may include:
- providing and managing services;
- processing orders and transactions;
- responding to requests and support issues;
- maintaining records and internal administration;
- improving service quality and user experience;
- protecting against fraud, misuse, and security incidents;
- meeting legal, regulatory, accounting, and tax obligations.
We do not process personal data in a way that is incompatible with these purposes unless required or permitted by law.
5. Lawful Basis for Processing
Where the GDPR applies, personal data will be processed only when we have a lawful basis to do so. Depending on the context, the lawful basis may be one or more of the following:
Contract
We process personal data when it is necessary to perform a contract with a customer or to take steps at the customer’s request before entering into a contract. This includes providing the service, handling orders, or fulfilling related obligations.
Legal Obligation
We may process personal data when necessary to comply with legal or regulatory requirements, such as tax, accounting, consumer protection, fraud prevention, or record-keeping obligations.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the customer’s rights and freedoms. This may include service improvement, security, internal reporting, and preventing misuse. We apply a careful balancing test before relying on this basis.
Consent
In limited cases, we may rely on consent, for example where it is required by law or for optional communications. Where consent is used, it will be specific, informed, and freely given. Customers may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, tax, regulatory, and dispute-resolution requirements. Retention periods may vary depending on the category of data, the nature of the relationship, and the applicable legal obligations.
When personal data is no longer required, it will be securely deleted, anonymized, or otherwise rendered inaccessible. Retention is limited to what is necessary and reviewed periodically to ensure continued justification.
- Service and account records may be retained for the period needed to administer the customer relationship.
- Transaction records may be retained for statutory accounting or tax periods.
- Support communications may be retained to resolve disputes and improve service quality.
7. Processors and Third Parties
We may share personal data with trusted processors and third parties who act on our behalf and under our instructions. These may include providers of hosting, IT support, analytics, customer service systems, payment services, record management, and security tools. Such parties are only given access to the data needed to perform their functions and are bound by contractual obligations regarding confidentiality, security, and lawful processing.
Where a processor is used, we ensure appropriate safeguards are in place, including data processing agreements and, where necessary, additional measures for international transfers. Processors are not permitted to use personal data for their own independent purposes.
We may also disclose personal data where required by law, to protect legal rights, or in connection with investigations, litigation, or regulatory requests.
8. International Transfers
If personal data is transferred outside the relevant jurisdiction or the European Economic Area, we will take appropriate steps to ensure that it remains protected in accordance with applicable data protection law. These steps may include the use of standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms. We assess transfer risks and apply additional safeguards where needed.
9. Data Security
We implement reasonable technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, encryption where appropriate, secure storage, staff training, and monitoring procedures. While no system can be guaranteed completely secure, we work to maintain a level of protection appropriate to the risk.
10. User Rights
Depending on the applicable law and the circumstances of the processing, customers may have the following rights:
- Right of access — to obtain confirmation and a copy of the personal data held about them.
- Right to rectification — to request correction of inaccurate or incomplete data.
- Right to erasure — to request deletion of personal data in certain situations.
- Right to restriction — to request limited processing in specific circumstances.
- Right to data portability — to receive certain data in a structured, commonly used format and transfer it where applicable.
- Right to object — to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to withdraw consent — where processing is based on consent.
- Right to lodge a complaint — with the relevant data protection authority if a customer believes data protection rights have been infringed.
Requests relating to rights will be handled in accordance with applicable law. We may need to verify identity before responding, and some requests may be limited where retention or processing is required by law or where another lawful ground applies.
11. Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on customers unless such processing is lawful, necessary, and subject to appropriate safeguards. If automated decision-making is used in a limited context, customers will be informed where required by law and will have the right to request human review where applicable.
12. Children’s Data
The services are not directed to children unless clearly stated otherwise. We do not knowingly collect personal data from children without appropriate authorization or consent where required by law. If we become aware that data has been collected from a child without a valid basis, we will take steps to remove or protect that information as appropriate.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, business practices, or the nature of the services. Any updated version will apply from the effective date stated in the revised policy. Customers are encouraged to review this Policy periodically to remain informed about how personal data is processed.
14. General Principles
We are committed to processing personal data lawfully, fairly, and transparently. We apply the principles of purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. Only data that is necessary for the stated purposes will be collected and used. We also seek to ensure that personal data remains accurate and up to date, and that it is not kept longer than necessary.
By using the services, customers acknowledge that their personal data may be processed in accordance with this Privacy Policy and applicable data protection law. This Policy applies to all customers in the area and is intended to reflect a privacy-respecting approach to data handling across the full customer relationship.
