Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with the services provided to customers in the area. It applies to all customers in the area and is intended to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using the services, customers acknowledge that their personal data may be processed as described in this Policy.
1. Data We Collect
We collect only the personal data necessary to provide services, manage customer relationships, meet legal obligations, and improve operations. The categories of personal data we may process include:
- Identification data: name, title, and customer reference information.
- Contact data: address, email address, telephone number, and similar communication details.
- Transaction data: records of orders, purchases, service requests, billing, and payment-related information.
- Technical data: device information, IP address, browser type, operating system, and usage logs.
- Communication data: messages, inquiries, complaints, and feedback provided by customers.
- Preference data: service choices, language preferences, and other settings shared by customers.
We may also process limited information from publicly available sources or third parties where permitted by law. We do not intentionally collect more data than is necessary for the stated purposes.
2. How We Use Personal Data
Personal data is processed for the following purposes:
- to provide and manage services requested by customers;
- to handle transactions, billing, and account administration;
- to respond to enquiries, complaints, and support requests;
- to improve service quality, performance, and customer experience;
- to maintain security, prevent fraud, and detect unauthorized activity;
- to comply with legal, regulatory, and contractual obligations;
- to keep records and support internal business operations.
Where required, processing may also occur for legitimate business purposes that do not override the rights and freedoms of customers. Personal data will never be used in a manner that is incompatible with the purposes for which it was collected.
3. Lawful Basis for Processing
Under GDPR, we rely on one or more of the following lawful bases when processing personal data:
Performance of a Contract
We process personal data when it is necessary to enter into or perform a contract with a customer, including delivering services, processing payments, and managing related customer accounts.
Legal Obligation
We may process personal data where required to comply with legal or regulatory obligations, such as tax, accounting, record-keeping, or lawful requests from authorities.
Legitimate Interests
We may process personal data for legitimate interests, including improving services, securing systems, preventing misuse, and maintaining business operations, provided such interests are not overridden by customer rights.
Consent
In certain situations, we may rely on consent. Where consent is the basis for processing, it will be freely given, specific, informed, and unambiguous. Customers may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, or reporting requirements. Retention periods vary depending on the type of data, the purpose of processing, and applicable legal obligations.
When data is no longer needed, it will be securely deleted, anonymized, or archived in a manner that prevents further use except where retention is required by law. Retention decisions are reviewed periodically to ensure that personal data is not kept longer than necessary.
5. Processors and Data Sharing
We may share personal data with third-party processors who act on our behalf and only process data according to our instructions. These processors may include service providers for hosting, IT support, payment processing, communication tools, analytics, document management, and administrative functions.
All processors are required to implement appropriate technical and organizational measures to protect personal data and to process it only for authorized purposes. Where a processor is located outside the European Economic Area, appropriate safeguards will be used where required by law.
We may also disclose personal data where necessary to comply with legal obligations, enforce agreements, protect rights, or prevent fraud and security incidents. We do not sell personal data.
6. Security Measures
We use reasonable and appropriate safeguards to protect personal data against unauthorized access, loss, alteration, or disclosure. These may include access controls, encryption, secure storage, staff training, and internal policies governing data handling. While no system can be guaranteed completely secure, we continuously work to maintain and improve the security of personal data.
7. Customer Rights Under GDPR
Customers in the area have rights regarding their personal data under GDPR. Subject to legal limitations, these rights include:
- Right of access: to obtain confirmation of whether personal data is being processed and to receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction of processing: to request limited processing in specified situations.
- Right to data portability: to receive personal data in a structured, commonly used, machine-readable format and to transmit it where applicable.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time.
- Right not to be subject to automated decision-making: to not be subject to decisions based solely on automated processing where such decisions produce legal or similarly significant effects, unless permitted by law.
Requests relating to these rights will be assessed in accordance with applicable law. If a request cannot be fulfilled, an explanation will be provided where permitted.
8. International Transfers
Where personal data is transferred outside the European Economic Area, we will ensure that appropriate protection is in place, such as an adequacy decision, standard contractual clauses, or other lawful transfer mechanism. These safeguards are intended to preserve the protection required under GDPR.
9. Children’s Data
Our services are not intended for children unless explicitly stated otherwise. We do not knowingly collect personal data from children without appropriate authorization where required. If we become aware that personal data has been collected from a child in violation of applicable law, we will take steps to delete it or obtain the necessary consent.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service developments. Any revised version will apply from the date it takes effect. Customers are encouraged to review this Policy periodically to remain informed about how personal data is handled.
11. General Statement
This Privacy Policy applies to all customers in the area and governs the processing of personal data in connection with the services offered. By continuing to use the services, customers confirm that they have read and understood this Policy. We are committed to processing personal data fairly, lawfully, and transparently, and to respecting the privacy rights of every customer.
