Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with the services provided to customers in the applicable area. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR). By using our services, you acknowledge that your personal data may be processed in accordance with this Policy.
1. Who This Policy Applies To
This Policy applies to all customers located in the area where our services are offered, including individuals who visit, register, purchase, communicate, or otherwise interact with our services. It also applies where personal data is collected through forms, email, support interactions, account creation, or service use.
We are committed to handling personal data in a lawful, fair, and transparent manner. We only collect information that is relevant and necessary for the purposes described below.
2. Personal Data We Collect
We may collect the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, telephone number, and other communication details.
- Transaction data: payment-related records, order history, service requests, and billing information.
- Technical data: device information, browser type, operating system, IP address, and usage logs.
- Profile data: preferences, feedback, service interactions, and account settings.
- Communication data: correspondence and records of enquiries or complaints.
We do not intentionally collect special category data unless it is required by law or you choose to provide it for a specific purpose. Where such data is processed, we will apply additional safeguards as required by GDPR.
3. How We Use Personal Data
We use personal data only where permitted by law and for clear purposes. These purposes may include:
- providing and maintaining our services;
- processing requests, transactions, and customer support matters;
- managing accounts and service records;
- improving service quality, performance, and user experience;
- meeting legal, regulatory, tax, accounting, and security obligations;
- communicating important service-related information;
- preventing fraud, misuse, and unauthorized access.
We will not use personal data for purposes that are incompatible with the original reason for collection unless we have a valid lawful basis and, where necessary, provide appropriate notice.
4. Lawful Basis for Processing
Under GDPR, we must identify a lawful basis before processing personal data. Depending on the context, we may rely on one or more of the following:
Contract
We process personal data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract. This may include handling account details, orders, payments, and service delivery.
Legal obligation
We may process personal data when required to comply with legal or regulatory duties, including recordkeeping, financial obligations, fraud prevention, and responding to lawful requests.
Legitimate interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Examples include improving services, securing systems, and managing operational activities.
Consent
Where required, we will rely on your consent. If processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
Vital interests and public task
In limited circumstances, we may process personal data to protect vital interests or where processing is necessary for a task carried out in the public interest, in accordance with applicable law.
5. Data Sharing and Processors
We may share personal data with trusted third parties that assist us in operating our services. These third parties act as processors when they handle data on our behalf and only according to our instructions.
Examples of processors may include:
- IT and cloud hosting providers;
- payment service providers;
- customer service tools and communication platforms;
- security and fraud-prevention services;
- professional advisers, such as accountants or legal advisers, where necessary;
- analytics or maintenance providers supporting system performance.
Where processors are used, we take steps to ensure appropriate data processing agreements are in place, requiring them to protect personal data, process it only on our instructions, and implement suitable technical and organizational measures.
We may also disclose personal data to public authorities, regulators, courts, or law enforcement where required or permitted by law.
6. International Transfers
If personal data is transferred outside the European Economic Area or the United Kingdom, we will ensure that appropriate safeguards are in place. These may include standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms recognized under GDPR.
We assess transfer risks and apply measures designed to protect personal data to a standard consistent with applicable data protection law.
7. Data Retention
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, reporting, or regulatory requirements.
Retention periods are determined by considering:
- the nature and sensitivity of the data;
- the purpose of processing;
- legal or contractual requirements;
- potential disputes or claims;
- security and operational needs.
When personal data is no longer needed, we will delete it, anonymize it, or securely archive it in accordance with applicable law and our retention practices.
8. Security of Personal Data
We use appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff training, and regular security reviews.
While no system is completely risk-free, we aim to maintain a level of security appropriate to the risk posed by the processing of personal data.
9. Your Rights Under GDPR
Depending on your circumstances and the legal basis for processing, you may have the following rights:
- Right of access: to request confirmation of whether we process your data and obtain a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain cases.
- Right to restriction: to request limited processing in specific circumstances.
- Right to data portability: to receive data you provided in a structured, commonly used format, where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent.
- Right not to be subject to automated decision-making: including profiling, where applicable under law.
We may need to verify your identity before responding to a rights request. We will respond within the time limits required by GDPR and explain if any legal exceptions apply.
10. Cookies and Similar Technologies
Where applicable, we may use cookies or similar technologies to support site functionality, improve performance, and understand usage patterns. Where consent is required for non-essential cookies, it will be requested before activation. You may manage browser settings or other available controls to limit cookie use, subject to service limitations.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. The updated version will apply from the date it is published or otherwise communicated. We encourage customers to review this Policy periodically to stay informed about how personal data is handled.
12. General Statement
This Privacy Policy is designed to provide clear information about how we process personal data and the rights available to customers in the area. We are committed to respecting privacy, minimizing data use, and ensuring that personal data is handled with lawfulness, fairness, and transparency. If any provision of this Policy conflicts with applicable data protection law, the law will prevail.
By continuing to use our services, you acknowledge that you have read and understood this Privacy Policy.
