Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when we provide our services. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and related data protection laws. We are committed to handling personal data lawfully, fairly, and transparently.
1. Scope of This Policy
This Privacy Policy applies to personal data processed in connection with our services, communications, transactions, and any related interactions. It covers data collected from customers, prospective customers, website users, and individuals acting on behalf of a business or organization. Where we process personal data jointly with others, we do so in a way that respects applicable data protection obligations.
2. Data We Collect
We may collect and process the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: postal address, email address, and telephone number.
- Account data: login details, account preferences, and service settings.
- Transaction data: information relating to purchases, invoices, payments, and service history.
- Technical data: IP address, device information, browser type, operating system, and usage logs.
- Communication data: messages, feedback, complaints, and correspondence history.
- Marketing data: preferences for receiving communications and responses to campaigns.
- Any other data you provide when you interact with us, request support, or use our services.
We generally collect personal data directly from you. In some cases, we may receive data from service providers, business partners, payment processors, or publicly available sources where permitted by law.
3. How We Use Personal Data
We use personal data only for lawful and specific purposes. These purposes may include:
- providing and managing our services;
- processing orders, payments, and related administrative activities;
- creating and maintaining customer records;
- responding to inquiries and providing support;
- customizing and improving our services;
- meeting legal, tax, accounting, and regulatory obligations;
- protecting against fraud, misuse, or security incidents;
- sending service messages or relevant updates;
- sending marketing communications where permitted and where you have not opted out;
- establishing, exercising, or defending legal claims.
We do not use personal data in ways that are incompatible with the purposes for which it was collected, unless we have a lawful basis to do so.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing personal data. Depending on the context, we rely on one or more of the following bases:
Contract
We process personal data where it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes providing services, managing accounts, and processing payments.
Legal Obligation
We may process personal data where needed to comply with a legal obligation, such as tax, accounting, consumer protection, anti-fraud, or other regulatory requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Legitimate interests may include improving services, securing systems, preventing fraud, and managing business operations. Where required, we perform a balancing assessment to ensure this basis is appropriate.
Consent
We may rely on your consent for certain activities, such as sending optional marketing communications or placing non-essential cookies where applicable. Where consent is used, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Data Sharing and Processors
We may share personal data with trusted third parties that assist us in operating our services. These third parties act as processors or, in some cases, independent controllers. We only share data when necessary and under appropriate contractual and security safeguards.
Processors may include:
- IT and hosting service providers;
- payment service providers;
- customer support tools and communication platforms;
- analytics and performance monitoring providers;
- professional advisors such as accountants, auditors, and legal counsel;
- delivery, logistics, or fulfillment partners where relevant;
- fraud prevention and security service providers.
Where processors handle personal data on our behalf, they are required to process it only in accordance with our instructions, maintain confidentiality, implement appropriate security measures, and comply with GDPR obligations.
We may also disclose personal data if required by law, court order, or valid request from a public authority, or where necessary to protect our rights, users, or others.
6. International Transfers
If personal data is transferred outside the European Economic Area or the United Kingdom, we ensure that appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other legally recognized mechanisms designed to protect your personal data to an equivalent standard.
7. Retention of Personal Data
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, including compliance with legal, accounting, or reporting obligations. Retention periods depend on the nature of the data, the purpose of processing, and any applicable legal requirements.
In general, we consider the following factors when determining retention periods:
- the duration of our relationship with you;
- whether data is needed to provide services or support;
- statutory limitation periods for legal claims;
- tax, audit, and regulatory retention obligations;
- whether deletion is requested and legally permissible.
When personal data is no longer needed, we will securely delete, anonymize, or archive it in accordance with our retention practices.
8. Security of Personal Data
We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, disclosure, or destruction. These measures may include access controls, encryption where appropriate, secure storage, staff training, and regular review of our security practices. While no system is completely secure, we take reasonable steps to reduce risks and protect your information.
9. Your Rights Under GDPR
Subject to legal limitations, you have the following rights in relation to your personal data:
- Right of access – to obtain confirmation and a copy of your personal data.
- Right to rectification – to correct inaccurate or incomplete data.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restriction – to request that processing be limited in certain cases.
- Right to data portability – to receive data you provided in a structured, commonly used format and, where feasible, have it transmitted to another controller.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
- Right not to be subject to automated decision-making – including profiling, where applicable and legally relevant.
You may also have the right to lodge a complaint with your local data protection authority if you believe your rights have been infringed. We encourage you to raise concerns so we can address them promptly and fairly.
10. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate legal basis or required authorization. If we become aware that personal data has been collected in breach of this Policy, we will take steps to remove it where required by law.
11. Cookies and Similar Technologies
Where applicable, we may use cookies and similar technologies to support essential functions, improve performance, and understand how our services are used. Non-essential cookies are used only where permitted and, when required, with your consent. You can manage cookie preferences through your browser settings or other available controls.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any revised version will apply from the date it is published or otherwise communicated, as appropriate. We encourage you to review this Policy periodically so that you remain informed about how we process personal data.
13. Our Commitment
We are committed to respecting privacy, minimizing data collection, and processing personal data in a way that is lawful, fair, and transparent. We aim to use only the information necessary to deliver our services effectively and to protect the rights of all individuals whose data we process. Where we rely on third-party processors, we require them to uphold equivalent standards of protection.
This Privacy Policy applies to all customers in the area and governs our handling of personal data in connection with the services we provide.
