Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with services provided to customers in the relevant area. It applies to all customers in the area and is intended to comply with the General Data Protection Regulation (GDPR) and applicable local privacy laws. By using the service, you acknowledge that your personal data may be processed as described below.
1. Data We Collect
We collect only the personal data that is necessary for legitimate business and legal purposes. The types of data we may collect include:
- Identity data such as name, title, and account identifiers.
- Contact data such as email address, billing address, delivery address, and telephone number.
- Transaction data such as payment records, order details, service history, and related correspondence.
- Technical data such as IP address, device type, browser type, operating system, and log files.
- Usage data such as pages or features accessed, time spent, and interaction patterns.
- Communication data such as messages, requests, complaints, and feedback.
We do not intentionally collect special category data unless it is strictly necessary and permitted by law. If such data is ever processed, we will do so only with an appropriate lawful basis and additional safeguards.
2. How We Use Personal Data
We process personal data for specific, explicit, and legitimate purposes, including:
- providing and managing services;
- processing orders, payments, and related administration;
- maintaining customer accounts and records;
- communicating service-related notices and updates;
- responding to inquiries and support requests;
- improving service performance, functionality, and security;
- detecting, preventing, and investigating fraud or misuse;
- complying with legal, tax, accounting, and regulatory obligations.
We will not use personal data in a way that is incompatible with these purposes unless we are required or permitted to do so by law or have obtained the necessary consent.
3. Lawful Basis for Processing
Under GDPR, we rely on one or more lawful bases depending on the purpose of processing. These may include:
- Contract: processing is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
- Legal obligation: processing is necessary to comply with applicable legal or regulatory requirements.
- Legitimate interests: processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms.
- Consent: processing is based on your consent where required by law, for example for certain optional communications or activities.
Where we rely on legitimate interests, we consider the nature of the data, the context of processing, and the impact on your rights. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Sharing and Processors
We may share personal data with trusted third parties acting as processors on our behalf. These processors are engaged only to perform specific functions and may process personal data solely under our instructions and contractual safeguards. Examples of processor categories include:
- payment service providers;
- IT hosting and cloud infrastructure providers;
- customer support and communication tools;
- analytics and performance monitoring services;
- document management and secure storage providers;
- professional advisers and compliance service providers.
We may also disclose personal data to independent controllers where required or permitted by law, including public authorities, courts, regulators, accountants, legal advisers, or insurers. In all cases, we aim to share only the minimum data necessary.
5. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with equivalent protections, we will ensure appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms. We apply additional technical and organisational measures where appropriate to protect transferred data.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, reporting, or dispute-resolution requirements. Retention periods vary depending on the category of data and the reason for processing.
In general:
- account and service data is retained for the duration of the relationship and for a reasonable period afterward;
- transaction and financial records may be retained for the period required by tax and commercial law;
- support communications may be retained for quality assurance, audit, and record-keeping purposes;
- technical logs may be retained for security, troubleshooting, and operational monitoring.
When data is no longer needed, it is securely deleted, anonymised, or otherwise irreversibly disposed of. Retention is reviewed periodically to ensure it remains proportionate and lawful.
7. Security Measures
We use appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, system monitoring, and incident response procedures. While no system can be guaranteed to be completely secure, we continuously work to improve our safeguards.
8. Your Rights Under GDPR
Depending on the circumstances and the legal basis for processing, you may have the following rights:
- Right of access to obtain confirmation of whether your data is processed and to receive a copy of it.
- Right to rectification to correct inaccurate or incomplete data.
- Right to erasure in certain cases, also known as the right to be forgotten.
- Right to restriction to limit processing in specific situations.
- Right to data portability to receive certain data in a structured, commonly used format.
- Right to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent where processing is based on consent.
- Right to lodge a complaint with a supervisory authority if you believe your rights have been infringed.
To exercise these rights, you may need to provide sufficient information to verify your identity and locate the relevant records. We may decline requests where permitted by law, for example where processing is necessary to comply with legal obligations or to defend legal claims.
9. Automated Decision-Making
We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects, unless such processing is permitted by law and subject to appropriate safeguards. If this changes, you will be informed of the logic involved, the significance of the processing, and the potential consequences for you.
10. Children’s Data
This service is not intended for children where processing would require special consent or parental authorisation. We do not knowingly collect personal data from children unless permitted by law and with the appropriate safeguards. If we become aware that data has been collected unlawfully, we will take appropriate steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or service operations. Any updated version will apply from the date it takes effect. We encourage customers to review this policy periodically to remain informed about how personal data is handled. Continued use of the service after changes take effect may constitute acceptance of the revised policy where permitted by law.
12. Summary of Core Principles
Our privacy practices are based on the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality. We aim to process personal data only when necessary and always in a manner that respects your rights and expectations. We apply this policy to all customers in the area and seek to maintain a high standard of privacy protection in every stage of processing.
By using the service, you acknowledge that you have read this Privacy Policy and understand how your personal data may be processed.
