Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with services provided to customers in the area. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and applicable data protection laws. By using the services, you acknowledge that your personal data may be processed as described in this Policy.
1. Data We Collect
We may collect personal data directly from you, automatically through your use of our services, and from limited third-party sources where permitted by law. The categories of data we may process include:
- Identity data such as your name, username, and similar identifiers.
- Contact data such as address, email address, or telephone number.
- Transaction data such as records of purchases, payments, or service requests.
- Technical data such as device type, browser type, IP address, and usage logs.
- Profile data such as preferences, settings, and feedback.
- Communication data such as information you provide in enquiries or support interactions.
We do not intentionally collect special category data unless it is necessary and a valid legal basis applies. Where such data is provided, it will be handled with appropriate safeguards and only as required by law.
2. How We Use Personal Data
We process personal data for the following purposes:
- to provide and operate our services;
- to manage accounts, orders, and customer relationships;
- to process transactions and maintain records;
- to improve services, functionality, and user experience;
- to protect against fraud, misuse, and security incidents;
- to comply with legal, regulatory, and contractual obligations;
- to communicate important updates, notices, or service-related messages.
We only use your personal data in ways that are fair, lawful, and transparent.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process personal data. Depending on the context, we may rely on one or more of the following:
Performance of a Contract
We process personal data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
Legal Obligation
We process personal data where needed to comply with legal obligations, including tax, accounting, consumer protection, and data protection requirements.
Legitimate Interests
We may process personal data for our legitimate interests, provided those interests are not overridden by your rights and freedoms. This may include service improvement, fraud prevention, network and information security, and internal administration.
Consent
In some cases, we rely on your consent. Where consent is used, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests or Public Interest
In rare cases, we may process personal data to protect vital interests or where processing is necessary for public interest reasons or official functions, as permitted by applicable law.
4. Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, reporting, and dispute-resolution requirements. The retention period depends on the nature of the data and the purpose of processing.
In determining retention periods, we consider:
- the amount, nature, and sensitivity of the data;
- the potential risk of harm from unauthorized use or disclosure;
- the purposes of processing and whether they can be achieved by other means;
- legal and regulatory obligations that require retention;
- the need to establish, exercise, or defend legal claims.
When personal data is no longer needed, it will be securely deleted, anonymized, or otherwise disposed of in a lawful manner.
5. Sharing and Processors
We may share personal data with trusted third parties that act as processors or, in limited cases, as independent controllers. Processors only process personal data on our instructions and are required to keep it confidential and secure.
Examples of processors may include:
- payment service providers;
- IT hosting and infrastructure providers;
- software and analytics providers;
- customer support and communication service providers;
- professional advisers assisting with legal, accounting, or compliance matters.
Where personal data is transferred outside the European Economic Area or to countries without an adequacy decision, we will ensure appropriate safeguards are in place, such as standard contractual clauses or equivalent lawful transfer mechanisms.
We may also disclose personal data where required to comply with law, enforce agreements, protect rights, or respond to lawful requests from public authorities.
6. Data Security
We implement appropriate technical and organizational measures designed to protect personal data against accidental loss, unauthorized access, misuse, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff training, and regular reviews of security practices.
While we take reasonable steps to safeguard data, no system is completely secure. We therefore encourage users to exercise caution when sharing information and to use strong credentials where applicable.
7. Your Rights Under GDPR
As a data subject, you have several rights concerning your personal data. Subject to legal limits and verification of your identity, you may exercise the following rights:
- Right of access – to request confirmation of whether your data is being processed and obtain a copy of it.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of your data in certain circumstances, sometimes called the right to be forgotten.
- Right to restriction – to request limited processing in specific situations.
- Right to data portability – to receive certain data in a structured, commonly used, machine-readable format and transmit it to another controller where feasible.
- Right to object – to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent – where processing relies on consent, you may withdraw it at any time.
- Rights related to automated decision-making – to not be subject to decisions based solely on automated processing where such decisions produce legal or similarly significant effects, except where permitted by law.
We will respond to rights requests in accordance with GDPR and may request additional information to verify identity or clarify the request. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act, as permitted by law.
8. Children’s Data
Our services are not directed to children under the age required by applicable law for consent to data processing. We do not knowingly collect personal data from children without appropriate authorization. If we become aware that such data has been collected unlawfully, we will take steps to delete it as soon as reasonably possible.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any revised version will apply once it becomes effective. We encourage customers in the area to review this Policy periodically to remain informed about how personal data is handled.
10. General Statement
This Privacy Policy applies to all customers in the area. It is intended to provide a clear and transparent explanation of how personal data is processed in compliance with GDPR principles, including lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
By using the services, you confirm that you have read and understood this Policy and that you acknowledge the processing of your personal data as described above.
