Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with the services provided. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR). We are committed to handling personal data in a lawful, fair, and transparent manner.
1. Data We Collect
We may collect and process the following categories of personal data:
- Identity data, such as name, title, or similar identifiers.
- Contact data, such as address, email address, telephone number, or other communication details.
- Transaction data, including details of purchases, payments, refunds, and related records.
- Technical data, such as device information, browser type, IP address, log data, and system settings.
- Usage data, including information about how services are accessed and used.
- Communication data, including records of messages, complaints, feedback, and support requests.
- Preference data, where relevant, such as marketing or service preferences.
We only collect data that is necessary for the purposes described in this Policy. Where possible, we minimize the amount of data processed and avoid collecting special category data unless it is required and permitted by law.
2. How We Use Personal Data
Personal data may be used for the following purposes:
- to provide and maintain services;
- to process transactions and fulfill requests;
- to manage customer relationships and support;
- to improve service quality, functionality, and user experience;
- to monitor security, prevent fraud, and detect misuse;
- to comply with legal and regulatory obligations;
- to communicate important service-related information;
- where permitted, to send marketing communications in accordance with applicable law.
We process personal data only for specific, explicit, and legitimate purposes. We do not use personal data in a manner that is incompatible with those purposes.
3. Lawful Basis for Processing
We process personal data under one or more of the lawful bases recognized by GDPR:
Contract
We process data when it is necessary to perform a contract with a customer or to take steps at the request of a customer before entering into a contract.
Legitimate Interests
We may process data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the rights and freedoms of the individual. Legitimate interests may include service improvement, fraud prevention, network security, and operational management.
Legal Obligation
We may process personal data where necessary to comply with legal, regulatory, tax, accounting, or reporting obligations.
Consent
In certain circumstances, we rely on consent. Where consent is used, it will be freely given, specific, informed, and unambiguous. Individuals may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, reporting, and operational requirements. Retention periods depend on factors such as the type of data, the purpose of processing, contractual obligations, and statutory limitation periods.
When personal data is no longer required, we will take reasonable steps to securely delete, anonymize, or archive it in accordance with our retention practices. In some cases, data may need to be retained for a longer period if required by law, for the establishment, exercise, or defense of legal claims, or for legitimate business needs.
Retention is reviewed periodically to ensure that personal data is not kept longer than necessary. Where applicable, we apply different retention periods to different categories of data depending on the sensitivity and purpose of the information.
5. Sharing and Processors
We may share personal data with trusted third parties that act as processors on our behalf. These processors are permitted to process data only in accordance with our instructions and are required to implement appropriate technical and organizational security measures.
Examples of processors may include providers of:
- IT and hosting services;
- payment processing services;
- customer support tools;
- analytics and performance monitoring services;
- communication and messaging services;
- data storage, backup, and security solutions.
We may also disclose personal data where necessary to comply with legal obligations, enforce agreements, protect rights, or respond to lawful requests from public authorities. If personal data is transferred outside the European Economic Area, appropriate safeguards will be used to protect the data in line with GDPR requirements.
6. Security of Personal Data
We take the security of personal data seriously and use appropriate measures to protect it against unauthorized access, loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff training, and regular review of internal procedures.
Although no system can be guaranteed as completely secure, we continually assess risks and improve safeguards to protect the confidentiality and integrity of personal data. Security practices are designed to be proportionate to the nature of the data and the risks involved.
7. User Rights Under GDPR
Individuals whose personal data we process have rights under GDPR. Subject to legal conditions and exceptions, these rights include:
- Right of access – to request confirmation of whether personal data is being processed and to receive a copy of that data;
- Right to rectification – to request correction of inaccurate or incomplete personal data;
- Right to erasure – to request deletion of personal data in certain circumstances;
- Right to restriction – to request limited processing in certain situations;
- Right to data portability – to receive personal data in a structured, commonly used, machine-readable format and, where feasible, to have it transmitted to another controller;
- Right to object – to object to processing based on legitimate interests or for direct marketing;
- Right to withdraw consent – where processing is based on consent, to withdraw that consent at any time;
- Right not to be subject to solely automated decisions – including profiling, where such decisions have legal or similarly significant effects.
Requests relating to these rights will be handled in accordance with applicable law. To protect privacy, we may need to verify identity before acting on a request. We may also retain certain information where necessary to comply with legal obligations or to establish, exercise, or defend legal claims.
8. Children’s Data
Our services are not intended to be directed to children unless explicitly stated otherwise. We do not knowingly collect personal data from children in circumstances where such collection would require parental consent or other special safeguards under applicable law. If we become aware that personal data has been collected improperly from a child, we will take appropriate steps to delete or protect that information.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or the way personal data is processed. Any updated version will apply from the date it is made effective. Users are encouraged to review this Policy periodically to remain informed about how personal data is handled.
10. General Principles
We follow the GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. Personal data is processed only where there is a valid basis and only to the extent necessary for the intended purpose.
By using the services, customers in the area acknowledge that personal data may be processed in accordance with this Privacy Policy and applicable law. This statement applies to all customers in the area, regardless of the channel through which services are accessed.
This Privacy Policy is intended to provide clear information about our personal data practices and the rights available to individuals under GDPR.
