Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when individuals use our services. It applies to all customers in the area and is intended to comply with the General Data Protection Regulation (GDPR) and applicable data protection laws. By engaging with our services, customers acknowledge that their personal data may be processed in accordance with this Policy.
1. Data Controller and Scope
For the purposes of data protection law, the organization providing the services is the data controller in relation to personal data collected directly from customers or generated through the use of services. This Policy applies to personal data relating to identified or identifiable natural persons, including data provided by customers, data collected automatically through service interactions, and data received from trusted service partners where permitted by law.
This Policy is designed to ensure that personal data is handled fairly, transparently, and securely. It covers the full lifecycle of data processing, including collection, use, storage, disclosure, retention, and deletion.
2. Personal Data We Collect
We may collect the following categories of personal data:
- Identity data: name, title, and similar identifying details.
- Contact data: postal address, email address, and telephone number.
- Account and transaction data: service preferences, order history, payment-related records, and billing information.
- Technical data: device type, IP address, browser type, operating system, and usage logs.
- Communication data: records of correspondence, inquiries, complaints, and feedback.
- Usage data: pages or features accessed, time spent, interactions, and system events.
We generally do not seek to collect special category data unless required by law or provided voluntarily and lawfully by the individual. Where such data is processed, additional safeguards will be applied.
3. How We Collect Personal Data
Personal data may be collected directly from customers when they submit forms, create accounts, request services, complete transactions, communicate with us, or otherwise interact with our staff or systems. We may also collect data automatically through technical means such as logs, cookies, or similar technologies, where permitted by law and subject to any required consent preferences.
In some cases, personal data may be received from third parties such as service providers, payment processors, fraud prevention partners, or public sources. Where this occurs, we take reasonable steps to ensure that the information is collected and shared lawfully.
4. Purposes of Processing
We process personal data only where necessary for specific and legitimate purposes, including:
- providing, managing, and improving our services;
- processing transactions and administering accounts;
- communicating with customers regarding service matters;
- responding to inquiries, complaints, and support requests;
- maintaining security, preventing fraud, and detecting misuse;
- fulfilling legal, regulatory, accounting, and reporting obligations;
- analyzing service performance and improving customer experience;
- sending essential administrative notices.
Where permitted, we may also process data for internal business administration and record-keeping. We will not use personal data in ways that are incompatible with the original purpose for which it was collected unless we have a lawful basis to do so and the change is compatible with GDPR requirements.
5. Lawful Basis for Processing
We rely on one or more of the following lawful bases under GDPR:
- Contract: processing is necessary to perform a contract with the customer or to take steps at the customer’s request before entering into a contract.
- Legal obligation: processing is necessary to comply with a legal or regulatory requirement.
- Legitimate interests: processing is necessary for our legitimate business interests, provided those interests are not overridden by the individual’s rights and freedoms.
- Consent: processing is based on freely given, specific, informed, and unambiguous consent where required by law.
Where we rely on consent, individuals may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal. If we rely on legitimate interests, we will assess and balance those interests against the impact on the individual.
6. Sharing and Processors
We may share personal data with processors acting on our behalf, but only where they are contractually bound to process data in accordance with our instructions and GDPR requirements. Processors may provide services such as:
- information technology and system hosting;
- data storage and backup;
- payment processing;
- customer support tools;
- analytics and reporting;
- security and fraud prevention services;
- professional advisory services, where relevant.
We may also disclose personal data where required by law, court order, or lawful request from a public authority. Any third party receiving personal data must protect it appropriately and use it only for the authorized purpose. Where data is transferred outside the European Economic Area, appropriate safeguards will be implemented in accordance with GDPR, such as standard contractual clauses or equivalent lawful transfer mechanisms.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to meet legal, accounting, tax, contractual, and regulatory obligations. Retention periods may vary depending on the type of data, the purpose of processing, and applicable legal requirements.
In general, we keep data for the duration of the customer relationship and for a reasonable period afterward to address queries, manage claims, and comply with legal obligations. Once data is no longer required, it will be securely deleted, anonymized, or archived where appropriate. When determining retention, we consider the volume, nature, and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, and the specific legal obligations applicable to the data.
8. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption where appropriate, secure storage, staff training, and regular review of security practices. Although no system can be guaranteed as completely secure, we take reasonable steps to reduce risk and respond promptly to any suspected security incident.
9. User Rights Under GDPR
Individuals whose personal data we process have rights under GDPR, subject to legal limits and exemptions. These rights include:
- Right of access: to obtain confirmation about whether personal data is being processed and to receive a copy of that data.
- Right to rectification: to correct inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data in certain circumstances, also known as the right to be forgotten.
- Right to restriction: to limit processing in certain situations.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and to transmit it to another controller where applicable.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: to withdraw consent at any time where processing is based on consent.
Individuals also have the right not to be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects, except where permitted by law.
Exercising Rights
Requests to exercise data protection rights should be made through the channels provided by the organization. We may need to verify identity before responding to ensure that personal data is disclosed only to the correct person. We will respond within the time limits required by GDPR, typically within one month, unless an extension is permitted due to complexity or volume of requests.
10. Complaints and Supervision
If an individual believes that personal data has been handled unlawfully, they may raise a concern with the organization responsible for the processing. They also have the right to lodge a complaint with the relevant data protection supervisory authority. We encourage individuals to contact us first where possible so that concerns can be reviewed and addressed promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or technical changes. Any updated version will apply from the date it becomes effective. Continued use of the services after changes take effect indicates acceptance of the revised Policy, to the extent permitted by law. We recommend reviewing this Policy periodically to remain informed about how personal data is processed.
By using our services, customers in the area acknowledge that they have read and understood this Privacy Policy.
