Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with our services. It applies to all customers in the relevant area and should be read carefully to understand your rights and our responsibilities under applicable data protection laws, including the General Data Protection Regulation (GDPR).
1. Scope of This Policy
This policy applies to all customers in the area where our services are offered and governs the processing of personal data relating to individuals who use, request, purchase, or otherwise interact with our services. By engaging with our services, you acknowledge that your information may be processed as described in this policy. We are committed to processing personal data in a lawful, fair, and transparent manner.
2. Personal Data We Collect
We may collect different categories of personal data depending on how you interact with us. The types of information collected may include:
- Identity data such as name, title, or other identifiers.
- Contact data such as address, email address, telephone number, or similar contact details.
- Transaction data such as records of purchases, service requests, payments, and related details.
- Technical data such as device information, browser type, operating system, IP address, and usage logs.
- Communication data such as messages, inquiries, complaints, feedback, or other correspondence.
- Preference data relating to your preferences for certain services, settings, or communications.
We generally collect this information directly from you, but we may also receive it from third parties where permitted by law, such as service providers, payment processors, or publicly available sources. We only collect data that is relevant and necessary for the purposes set out in this policy.
3. How We Use Personal Data
We use personal data for the following purposes:
- To provide, operate, and maintain our services.
- To manage customer accounts, requests, and transactions.
- To communicate with you about service-related matters.
- To improve and personalize our services and customer experience.
- To protect against fraud, misuse, unauthorized access, and security incidents.
- To comply with legal and regulatory obligations.
- To establish, exercise, or defend legal claims.
Where appropriate, we may also use data for internal analytics, administrative purposes, service quality monitoring, and record keeping. We will not use personal data in ways that are incompatible with the purposes for which it was collected unless we have a lawful basis to do so.
4. Lawful Basis for Processing
Under GDPR, we only process personal data when we have a valid lawful basis. Depending on the context, our lawful bases may include:
Consent
We may rely on your consent where you have given us clear permission to process your personal data for a specific purpose. You may withdraw consent at any time, where applicable, without affecting the lawfulness of processing carried out before withdrawal.
Contract
We process personal data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
Legal Obligation
We may process data where required to comply with a legal or regulatory obligation, including tax, accounting, consumer protection, or record-keeping requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Examples include improving services, preventing fraud, securing systems, and managing business operations.
Vital Interests and Public Task
In limited cases, we may process data to protect vital interests or to perform a task carried out in the public interest, where applicable law permits.
5. Data Sharing and Processors
We may share personal data with trusted third-party processors who assist us in operating our services and business functions. These processors act on our instructions and are required to process personal data securely and only for specified purposes. Such processors may include:
- IT and hosting service providers.
- Payment and billing processors.
- Customer support and communication providers.
- Analytics and performance monitoring providers.
- Administrative, legal, audit, and compliance service providers.
We may also disclose personal data where required by law, by court order, or to governmental, regulatory, or law enforcement authorities. In the event of a business reorganization, merger, acquisition, or similar transaction, personal data may be transferred subject to appropriate safeguards.
We do not sell personal data. Where data is transferred to processors or third parties, we take reasonable steps to ensure that appropriate contractual, technical, and organizational safeguards are in place.
6. International Transfers
If personal data is transferred outside the European Economic Area or to a jurisdiction that may not provide the same level of data protection, we will ensure that appropriate safeguards are used. These safeguards may include standard contractual clauses or other lawful transfer mechanisms recognized under GDPR. We take steps to protect your information regardless of where it is processed.
7. Data Retention
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, reporting, and compliance obligations. Retention periods vary depending on the type of data and the context in which it is processed. In determining retention, we consider:
- The nature and sensitivity of the personal data.
- The risk of harm from unauthorized use or disclosure.
- The purposes of the processing.
- Applicable legal requirements and limitation periods.
When personal data is no longer needed, we will delete, anonymize, or securely destroy it in accordance with our retention practices and legal obligations.
8. Security Measures
We implement appropriate technical and organizational measures to protect personal data against accidental loss, misuse, alteration, unauthorized access, disclosure, or destruction. These measures may include access controls, encryption, secure storage, monitoring, and staff training. While no system can be guaranteed to be completely secure, we continuously assess and improve our safeguards to reduce risk.
9. Your GDPR Rights
Subject to conditions and exemptions under applicable law, you have the following rights regarding your personal data:
- Right of access — to obtain confirmation of whether we process your data and receive a copy of it.
- Right to rectification — to request correction of inaccurate or incomplete data.
- Right to erasure — to request deletion of your personal data in certain circumstances.
- Right to restriction — to request that processing be limited in certain cases.
- Right to data portability — to receive certain data in a structured, commonly used format and transmit it to another controller.
- Right to object — to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent — where processing is based on consent.
- Right not to be subject to automated decision-making — including profiling, where applicable.
You may also have the right to lodge a complaint with your local data protection authority if you believe your rights have been infringed. We encourage you to raise concerns with us first so that we can address them promptly.
10. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate authorization where required by law. If we become aware that personal data has been collected from a child in violation of applicable requirements, we will take appropriate steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any revised version will apply from the date it is made effective. We encourage you to review this policy periodically to stay informed about how we process personal data.
12. General Statement
This policy is intended to provide a clear overview of how we handle personal data in compliance with GDPR principles such as lawfulness, fairness, transparency, data minimization, storage limitation, and integrity and confidentiality. We strive to ensure that all processing is relevant, proportionate, and respectful of your privacy rights. By using our services, you understand that your information will be processed in line with this policy and applicable legal requirements.
