Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in relation to our services. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and any other applicable data protection laws. By using our services, you acknowledge that your personal data may be processed as described below.
1. Scope and Purpose
We are committed to handling personal data fairly, lawfully, and transparently. This policy describes the categories of personal data we may collect, the purposes for which we use it, the legal grounds that permit processing, the parties with whom we may share it, how long we keep it, and the rights available to individuals under GDPR.
We only process personal data where there is a valid legal basis and only for purposes that are relevant and proportionate to our services.
2. Data We Collect
Depending on your interactions with us, we may collect the following types of personal data:
- Identity data such as name, title, and similar identifiers.
- Contact data such as billing address, service address, email address, and telephone number.
- Transaction data relating to purchases, payments, invoices, returns, and service history.
- Technical data such as device information, IP address, browser type, and system settings.
- Usage data including information about how services are accessed and used.
- Communication data including records of queries, complaints, and correspondence.
- Preference data where relevant to the delivery and personalization of services.
We generally do not seek to collect special category data unless it is strictly necessary and permitted by law. If such data is ever required, it will only be processed with an appropriate legal basis and additional safeguards.
3. How We Collect Personal Data
We may collect personal data directly from you when you:
- make an inquiry or request a service;
- enter into a contract or transaction;
- communicate with us by any available means;
- submit forms, applications, or other documents;
- use our services or interact with our systems;
- provide information through customer support or feedback.
We may also receive personal data from third parties, such as payment providers, delivery partners, professional advisers, or public authorities, where allowed by law.
4. Lawful Basis for Processing
Under GDPR, we must identify a lawful basis for each processing activity. We may process personal data on one or more of the following grounds:
Contract
We process personal data where it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This may include managing orders, delivering services, issuing invoices, and handling related communications.
Legal Obligation
We may process personal data where we are required to comply with a legal or regulatory obligation, such as tax, accounting, fraud prevention, or record-keeping requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. This may include improving our services, maintaining security, preventing misuse, and managing business operations. When relying on this basis, we assess the impact on your privacy and ensure appropriate safeguards.
Consent
Where required, we will rely on your consent. For example, consent may be used for certain optional communications or specific uses of data. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
5. How We Use Personal Data
We use personal data for the following purposes:
- to provide and manage services;
- to process payments and maintain financial records;
- to communicate with customers and respond to requests;
- to monitor service quality and improve operations;
- to detect, investigate, and prevent fraud or security incidents;
- to comply with legal and regulatory obligations;
- to resolve disputes, enforce agreements, and protect rights.
We do not use personal data for purposes that are incompatible with the original purpose of collection unless we have a lawful basis to do so.
6. Sharing Personal Data and Processors
We may share personal data with trusted third parties where necessary for the purposes described in this policy. These third parties may act as independent controllers or as processors acting on our behalf.
Our processors may include providers of hosting, IT support, payment processing, communications services, analytics, document storage, and administrative support. Each processor is selected carefully and is required to process personal data only on our instructions, to keep it secure, and to comply with GDPR obligations through written agreements.
Where personal data is disclosed to independent controllers, such as professional advisers or public bodies, those parties are responsible for their own compliance. We limit disclosures to what is necessary and lawful.
We do not sell personal data. Any sharing is restricted to what is reasonably necessary for service delivery, legal compliance, or legitimate business purposes.
7. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with equivalent protections, we will ensure that appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms. We also consider the security and confidentiality of transferred data and apply additional measures where appropriate.
8. Retention of Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including the purposes of satisfying legal, accounting, tax, and reporting requirements. Retention periods may vary depending on the type of data and the reason it is held.
In general, we determine retention by considering:
- the nature and sensitivity of the data;
- the potential risk of harm from unauthorized use or disclosure;
- the purposes of processing;
- the legal obligations that apply;
- whether the data is needed for claims, dispute resolution, or compliance.
When data is no longer required, we will delete, anonymize, or securely archive it in accordance with applicable law and our retention practices.
9. Data Security
We implement appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and regular review of security practices.
While no system can be guaranteed completely secure, we take reasonable and proportionate steps to protect all personal data processed under this policy.
10. User Rights Under GDPR
Individuals whose personal data we process have the following rights, subject to the conditions and exceptions set out in GDPR:
- Right of access – to request confirmation of whether we process your data and receive a copy of it.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of data in certain circumstances.
- Right to restriction – to request limitation of processing in specific situations.
- Right to data portability – to receive certain data in a structured, commonly used format and to have it transmitted where technically feasible.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent, at any time.
- Right to lodge a complaint – to contact the relevant supervisory authority if you believe your rights have been infringed.
We will respond to rights requests in accordance with GDPR timelines and requirements, and may ask for information necessary to verify identity before acting on a request.
11. Automated Decision-Making
We do not rely on solely automated decision-making that produces legal or similarly significant effects, unless explicitly disclosed and permitted by law. If such processing were to occur, we would provide meaningful information about the logic involved and the significance and consequences of the processing.
12. Children
Our services are not intended for children unless otherwise stated. We do not knowingly collect personal data from children without appropriate authorization, where required by law. If we become aware that personal data has been collected improperly, we will take steps to delete it or obtain the required consent.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updated version will apply from the date it becomes effective. We encourage customers to review this policy periodically to remain informed about how personal data is handled.
14. General Statement
This Privacy Policy applies to all customers in the area and governs personal data processed in connection with our services. By continuing to use our services, you acknowledge that you have read and understood this policy and that your data may be processed in accordance with the terms described above.
We are committed to keeping personal data secure, using it responsibly, and respecting individual privacy rights at all times.
