Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when services are provided to customers in the relevant area. It applies to all customers in area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and related privacy laws. By using our services, customers acknowledge that their personal data may be processed as described in this Policy.
1. Data We Collect
We collect only the personal data that is necessary for the purposes described in this Policy. Depending on the nature of our relationship with customers, we may collect the following categories of data:
- Identity data: name, title, and basic identification details.
- Contact data: postal address, billing address, email address, and telephone number.
- Account data: account identifiers, login details, and preferences.
- Transaction data: details about purchases, orders, payments, and related records.
- Communication data: correspondence, support requests, and feedback.
- Technical data: device information, log data, browser type, IP address, and usage information.
- Compliance data: records needed to meet legal, tax, accounting, and regulatory obligations.
We do not intentionally collect special category data unless it is necessary and lawful to do so. If such data is ever processed, it will be handled in accordance with GDPR safeguards and only where a valid legal basis applies.
2. How We Use Personal Data
Personal data is processed for specific, explicit, and legitimate purposes. These purposes include:
- providing and delivering services;
- managing customer accounts and customer relationships;
- processing payments and keeping transaction records;
- responding to enquiries and support requests;
- maintaining security, fraud prevention, and service integrity;
- meeting legal, tax, accounting, and regulatory requirements;
- improving services, operations, and customer experience;
- sending service-related notices and important updates;
- establishing, exercising, or defending legal claims.
We do not process personal data in a manner that is incompatible with these purposes.
3. Lawful Basis for Processing
We only process personal data where GDPR provides a lawful basis. Depending on the context, our lawful bases may include:
3.1 Performance of a Contract
We process data where it is necessary to enter into or perform a contract with a customer, including managing accounts, delivering services, and handling payments.
3.2 Legal Obligation
We process data where required to comply with laws and regulations, including tax, accounting, anti-fraud, and record-keeping obligations.
3.3 Legitimate Interests
We may process personal data where necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not overridden by the rights and freedoms of the individual. Legitimate interests may include improving services, maintaining security, preventing fraud, and managing business operations.
3.4 Consent
Where consent is required, we will rely on freely given, specific, informed, and unambiguous consent. Individuals may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
3.5 Vital Interests and Public Task
In limited cases, processing may be necessary to protect vital interests or to carry out a task in the public interest, where applicable.
4. Sharing and Processors
We may share personal data with third parties only where necessary and lawful. Some third parties act as processors on our behalf and process data under our instructions. These may include:
- payment service providers;
- IT and cloud service providers;
- customer support and communication tools;
- analytics, security, and monitoring services;
- professional advisers such as accountants, auditors, and legal advisers;
- public authorities, regulators, or law enforcement where required by law.
All processors are required to provide appropriate technical and organisational measures to safeguard personal data. They may only process data for the purposes specified in our instructions and are required to keep it confidential. Where personal data is transferred outside the applicable jurisdiction, appropriate safeguards will be used in accordance with GDPR requirements, such as standard contractual clauses or equivalent protections.
5. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, or reporting requirements. The retention period depends on the type of data, the reason for processing, and any legal obligations that apply.
In general:
- account and transaction records are retained for the period needed to administer the relationship and satisfy financial record obligations;
- communication records are retained for a reasonable period to handle enquiries, disputes, and service matters;
- technical and security logs are retained for limited periods unless longer retention is needed for investigation or compliance;
- data processed on the basis of consent is retained until consent is withdrawn or the data is no longer needed.
When personal data is no longer required, it is securely deleted, anonymised, or otherwise disposed of in a lawful and safe manner.
6. Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures may include access controls, encryption where appropriate, secure storage, staff training, and regular review of security practices.
No system is completely secure, but we take reasonable steps to reduce risks and maintain the confidentiality, integrity, and availability of personal data.
7. User Rights Under GDPR
Individuals whose personal data is processed under this Policy have rights under GDPR. Subject to legal limitations, these rights may include:
- Right of access: to request confirmation and a copy of the personal data held about them.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limited processing in certain situations.
- Right to data portability: to receive personal data in a structured, commonly used format and, where applicable, have it transferred to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time.
- Right not to be subject to automated decision-making: to avoid decisions based solely on automated processing where such decisions have legal or similarly significant effects, except where permitted by law.
We will respond to rights requests within the timeframe required by law and may request information to verify identity before acting on a request. This is done to protect personal data from unauthorised access.
8. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate legal basis and, where required, verifiable parental consent. If we become aware that data has been collected inappropriately, we will take steps to delete it or otherwise process it in compliance with applicable law.
9. Complaints and Supervisory Authority
If an individual believes that personal data has been processed unlawfully, they may raise a concern with us and may also have the right to lodge a complaint with the relevant supervisory authority. We encourage individuals to first review this Policy and exercise their rights where appropriate.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or the way data is processed. Any updated version will apply from the date it takes effect. We encourage customers to review this Policy periodically to remain informed about how personal data is handled.
11. Scope of This Policy
This Privacy Policy applies to all customers in area and governs the processing of personal data in connection with the services provided to them. By maintaining a customer relationship or using the services, individuals acknowledge that personal data may be processed in accordance with this Policy and applicable GDPR requirements.
In summary, we process personal data fairly, lawfully, and transparently; collect only what is needed; retain data only as long as necessary; use processors under strict controls; and respect the rights of individuals under GDPR.
