Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, and protected when individuals interact with our services. It applies to all customers in the area where the services are offered, and it is intended to meet the standards required under the General Data Protection Regulation (GDPR). By using the services, customers acknowledge that their personal data may be processed as described in this policy.
1. Data We Collect
We collect only the personal data that is necessary for legitimate and specified purposes. Depending on how a customer interacts with the services, this may include:
- Identity data such as name, title, or user identifier.
- Contact data such as billing address, service address, and communication preferences.
- Transaction data such as records of purchases, service requests, and payment history.
- Technical data such as device type, browser type, IP address, and usage logs.
- Profile data such as preferences, service history, and feedback.
- Communication data such as correspondence and customer support records.
We do not intentionally collect special category data unless it is strictly necessary and permitted by law. If such data is ever required, we will process it only with an appropriate lawful basis and additional safeguards.
2. How We Use Personal Data
Personal data is used for the following purposes:
- To provide and manage services.
- To process payments, transactions, and related administration.
- To communicate with customers about service updates, notices, and support matters.
- To improve service quality, safety, and performance.
- To comply with legal and regulatory obligations.
- To prevent fraud, misuse, and unauthorized access.
We will always ensure that processing is limited to what is relevant and necessary for the stated purpose. Where possible, we use aggregated or pseudonymized data to reduce privacy risks.
3. Lawful Basis for Processing
Under GDPR, we rely on one or more lawful bases to process personal data. These lawful bases may include:
Performance of a Contract
We process personal data when it is required to enter into or perform a contract with a customer. This includes managing accounts, delivering services, handling payments, and providing customer support connected to the service relationship.
Legal Obligation
We may process data when required to comply with applicable laws, tax requirements, accounting obligations, or lawful requests from competent authorities.
Legitimate Interests
We may process data where it is necessary for our legitimate interests, provided those interests are not overridden by the rights and freedoms of the individual. Examples include service improvement, fraud prevention, system security, internal administration, and business reporting.
Consent
In some situations, we rely on consent. Where consent is used, it will be freely given, specific, informed, and unambiguous. Customers may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Interest
These bases are only used in rare cases where necessary to protect vital interests or where processing is required for a task carried out in the public interest under applicable law.
4. Data Sharing and Processors
We may share personal data with trusted third parties that help us operate and deliver services. These third parties act as processors when they process personal data on our behalf and under our instructions. We ensure that appropriate contractual safeguards are in place with each processor.
Processors may include:
- IT and cloud hosting providers.
- Payment processing providers.
- Customer service and communication tools.
- Analytics and performance monitoring providers.
- Professional advisers where necessary.
We may also disclose personal data to independent controllers where required by law, where necessary to protect rights, or where a customer has explicitly requested or authorized such disclosure. In all cases, we aim to limit disclosure to the minimum necessary amount of data.
5. International Transfers
If personal data is transferred outside the European Economic Area or outside the jurisdiction covered by applicable data protection requirements, we will ensure that adequate safeguards are in place. These safeguards may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms permitted under GDPR.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting obligations. Retention periods are determined by the type of data, the purpose of processing, and legal requirements.
As a general rule:
- Service and account records are kept for the duration of the customer relationship and for a reasonable period afterward.
- Transaction and financial records are retained for the period required by tax, accounting, or commercial law.
- Support communications are stored only as long as needed to resolve the issue and maintain records of service interactions.
- Technical logs are kept for security, troubleshooting, and system integrity purposes for limited periods.
When data is no longer required, it is securely deleted, anonymized, or archived in accordance with retention standards. Retention decisions are reviewed periodically to ensure that data is not kept longer than necessary.
7. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption where appropriate, secure storage, staff training, and internal confidentiality procedures.
Although no system can be guaranteed to be completely secure, we are committed to maintaining robust safeguards and continuously improving security practices. If a personal data breach occurs, we will assess the incident and take action in line with applicable law, including notification where required.
8. User Rights Under GDPR
Individuals whose personal data is processed under this policy have the following rights, subject to the conditions and exemptions set out in GDPR:
- Right of access – to obtain confirmation of whether personal data is processed and to receive a copy of that data.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of personal data in certain circumstances.
- Right to restriction – to request limited processing in specified situations.
- Right to data portability – to receive personal data in a structured, commonly used, machine-readable format and transmit it to another controller where applicable.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent, to withdraw that consent at any time.
Customers also have the right not to be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects, unless permitted by law.
Important: exercising these rights does not affect any processing that has already taken place lawfully. We may require information necessary to confirm identity before responding to a rights request.
9. Cookies and Similar Technologies
Where applicable, cookies and similar technologies may be used for functionality, security, performance measurement, and service improvement. Any use of non-essential tracking will be subject to legal requirements and, where required, consent. Customers may manage browser settings or device preferences to limit certain technologies, though this may affect service functionality.
10. Children’s Data
The services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate legal grounds and safeguards. If we become aware that data has been collected in violation of this policy, we will take reasonable steps to delete it as soon as possible.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service features. When updates occur, the revised policy will apply from the date of publication or as otherwise stated. Customers are encouraged to review the policy periodically to remain informed about how personal data is processed.
12. Final Statement
This Privacy Policy is designed to ensure that personal data is handled fairly, transparently, and securely. It applies to all customers in the area and governs how data is collected, used, retained, and shared. By maintaining clear safeguards, lawful processing practices, and respect for individual rights, we aim to protect privacy while delivering reliable services.