Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area and is intended to reflect the requirements of the General Data Protection Regulation (GDPR). By using our services, you acknowledge that you have read this Policy and understand how your information is handled.
1. Scope and Purpose
We are committed to processing personal data lawfully, fairly, and transparently. This Policy describes the categories of information we may collect, the purposes for which we process it, the legal grounds on which we rely, the retention periods applied, the third parties that may process data on our behalf, and the rights available to individuals under applicable data protection law.
Personal data means any information relating to an identified or identifiable natural person. This may include details that identify you directly or indirectly, such as name, contact details, account identifiers, payment-related information, and usage data.
2. Data We Collect
We may collect and process the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, telephone number, or other communication details.
- Account data: login details, preferences, and profile information.
- Transaction data: records of purchases, services requested, payment status, and associated billing information.
- Technical data: device type, browser type, IP address, log data, and similar technical identifiers.
- Usage data: information about how you access and interact with our services.
- Communication data: information provided when you make an inquiry, submit a request, or otherwise correspond with us.
We generally collect data directly from you when you provide it, but we may also receive data from authorised third parties, service providers, or publicly available sources where permitted by law.
3. How We Use Personal Data
We process personal data for the following purposes:
- to provide and manage our services;
- to verify identity and maintain security;
- to process transactions and administer records;
- to communicate with you regarding service-related matters;
- to improve service quality, performance, and user experience;
- to detect, prevent, and investigate fraud, abuse, or misuse;
- to comply with legal, regulatory, and accounting obligations;
- to establish, exercise, or defend legal claims.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. Lawful Basis for Processing
Under GDPR, we must identify a lawful basis for each processing activity. We rely on the following grounds as appropriate:
Performance of a Contract
We process personal data where it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes managing your account, delivering services, and handling transactions.
Legal Obligation
We may process personal data when necessary to comply with legal obligations, including tax, accounting, consumer protection, and other regulatory requirements.
Legitimate Interests
We may process data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. These interests may include service improvement, fraud prevention, network security, internal administration, and limited analytics. When we rely on this basis, we assess whether the processing is proportionate and whether appropriate safeguards are in place.
Consent
In some cases, we rely on your consent, for example for certain optional communications or where required by law. Where consent is used, it must be informed, specific, and freely given. You may withdraw consent at any time.
5. Sharing and Processors
We do not sell personal data. However, we may share personal data with trusted third parties when necessary for the purposes described in this Policy. These parties may act as processors or independent controllers depending on the context.
Typical processors may include:
- hosting and infrastructure providers;
- IT support and maintenance providers;
- payment processing services;
- accounting, audit, or compliance service providers;
- customer support or communications tools;
- analytics or security service providers.
Where a processor acts on our behalf, we require appropriate contractual terms to ensure data is processed only on documented instructions, kept secure, and retained only for the period necessary. We may also disclose personal data to regulators, law enforcement, courts, or other parties where required or permitted by law.
6. International Transfers
If personal data is transferred outside the European Economic Area or the United Kingdom, we will ensure appropriate safeguards are in place. These safeguards may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms designed to protect your data to a standard consistent with GDPR requirements.
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, and for any additional period required by law or justified by a legitimate business need. Retention periods vary depending on the type of data and the purpose of processing.
In general:
- account and service records are retained for the duration of the relationship and for a reasonable period afterward;
- transaction and financial records are retained as required by tax and accounting laws;
- support communications are retained for as long as needed to resolve queries and maintain accurate records;
- technical logs are retained for security, performance, and troubleshooting purposes for limited periods.
When personal data is no longer required, we will delete, anonymise, or securely archive it in line with applicable law and internal retention procedures.
8. Security Measures
We use appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures may include access controls, encryption where appropriate, secure storage, staff training, and procedures for handling suspected incidents. While no system can be guaranteed to be completely secure, we take reasonable steps to reduce risk and maintain data integrity.
9. Your Rights Under GDPR
Depending on the circumstances and subject to applicable law, you may have the following rights:
- Right of access: to request confirmation of whether your data is processed and obtain a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain situations.
- Right to restriction: to request limitation of processing in certain circumstances.
- Right to data portability: to receive data you provided in a structured, commonly used, machine-readable format and, where feasible, have it transmitted to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Rights related to automated decision-making: to not be subject to decisions based solely on automated processing where such decisions have legal or similarly significant effects, unless permitted by law.
Where processing is based on legitimate interests, you may object on grounds relating to your particular situation. We will stop processing unless we can demonstrate compelling legitimate grounds or need the data for legal claims.
You may also have the right to lodge a complaint with a supervisory authority if you believe your data has been processed unlawfully or your rights have been infringed.
10. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children in circumstances where parental or guardian consent is required without obtaining appropriate authorisation. If we become aware that we have collected such data improperly, we will take reasonable steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service arrangements. When we make material changes, we will take appropriate steps to ensure you are informed in a clear and timely manner. The updated version will apply from the effective date stated within the revised policy.
12. General Statement
This Privacy Policy is intended to provide a clear and transparent explanation of our data protection practices. We are committed to respecting privacy, limiting processing to what is necessary, and ensuring that personal data is handled in accordance with GDPR principles such as lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
By using our services, you confirm that you have read and understood this Privacy Policy and that it applies to all customers in the area.
