Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area and is intended to provide clear information about the handling of personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
1. Scope of This Policy
This Policy applies to personal data processed when individuals use our services, communicate with us, complete transactions, or otherwise interact with us in the relevant area. It covers data collected directly from customers, data generated through service use, and data received from third parties where permitted by law. We are committed to processing personal data in a lawful, fair, and transparent manner.
2. Data We Collect
We may collect different categories of personal data depending on how you interact with us. The types of data may include:
- Identity information: name, username, title, or similar identifiers.
- Contact details: address, email address, and telephone number.
- Transaction data: details about payments, purchases, and service requests.
- Technical data: device type, browser type, operating system, log data, and IP address.
- Usage data: information about how you access and use our services.
- Communication data: records of messages, feedback, complaints, and support requests.
- Preference data: choices related to services, settings, and communication preferences.
We do not intentionally collect special category data unless it is required for a specific lawful purpose, and where such processing occurs, it is handled with heightened care and only when allowed by law.
3. How We Use Personal Data
We use personal data only for specified, explicit, and legitimate purposes. These purposes may include:
- providing, operating, and maintaining our services;
- processing transactions and fulfilling requests;
- communicating updates, notices, and service-related information;
- managing customer support and resolving inquiries;
- improving service quality, functionality, and user experience;
- ensuring security, preventing fraud, and detecting misuse;
- complying with legal and regulatory obligations;
- managing records, reporting, and internal administration.
Where required, we will not use personal data for new purposes that are incompatible with the original purpose unless we have a valid legal basis and, where necessary, your consent.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing your personal data. Depending on the context, we rely on one or more of the following bases:
Contract
We process personal data where it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This may include processing identity and contact details, payment information, or service preferences.
Legal Obligation
We may process personal data to comply with legal, tax, accounting, consumer protection, or regulatory obligations. This includes keeping records, responding to lawful requests, and maintaining necessary documentation.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided that those interests are not overridden by your rights and freedoms. Legitimate interests may include service improvement, fraud prevention, network and information security, and internal administration.
Consent
In certain cases, we rely on your consent to process personal data, particularly where the law requires it. When consent is used, it will be specific, informed, and freely given. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, reporting, and operational requirements. Retention periods vary depending on the type of data and the reason for processing.
When determining how long to keep data, we consider factors such as:
- the nature and sensitivity of the data;
- the risk of harm from unauthorised use or disclosure;
- the purposes of processing and whether those purposes can still be achieved;
- legal or regulatory retention requirements;
- whether a dispute, claim, or investigation is ongoing.
When personal data is no longer needed, it is securely deleted, anonymised, or otherwise disposed of in accordance with applicable law and internal retention procedures.
6. Sharing and Processors
We may share personal data with trusted third parties that act as processors on our behalf. These processors only process personal data according to our instructions and are required to protect it appropriately. Typical categories of processors may include:
- IT and hosting providers;
- payment and billing service providers;
- customer support and communication tools;
- analytics and performance monitoring providers;
- security and fraud prevention providers;
- professional advisers and compliance service providers.
We may also disclose personal data where necessary to comply with law, enforce our rights, protect vital interests, or respond to valid requests from public authorities. Where personal data is transferred outside the relevant jurisdiction, appropriate safeguards will be used in line with GDPR requirements, such as standard contractual clauses or equivalent lawful transfer mechanisms.
7. Security of Personal Data
We take reasonable technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures may include access controls, encryption, role-based permissions, secure storage, and staff confidentiality obligations.
No method of transmission or storage is completely secure, but we continuously review and improve our safeguards to reduce risk. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will act in accordance with applicable legal obligations.
8. Your Rights Under GDPR
If you are a customer in the area, you may have the following rights in relation to your personal data, subject to legal limitations and conditions:
- Right of access: to obtain confirmation of whether your data is being processed and to receive a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request that processing be limited in specific situations.
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format and, where feasible, have it transferred to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time.
- Right to lodge a complaint: to raise concerns with the competent data protection authority.
We may need to verify your identity before responding to a request. Where permitted by law, requests may be refused or limited if they are manifestly unfounded, excessive, or would adversely affect the rights of others.
9. Children’s Data
Our services are not intended for children unless explicitly stated otherwise. We do not knowingly collect personal data from children without an appropriate lawful basis and any necessary authorisation. If we become aware that personal data has been collected inappropriately, we will take steps to delete it or obtain the proper permissions where required.
10. Automated Decision-Making
We do not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects unless this is permitted by law and appropriate safeguards are in place. If such processing is ever used, you will be informed about the logic involved and your available rights.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, our practices, or the services we provide. When updates are made, the revised version will apply from the date it becomes effective. We encourage customers to review this Policy periodically to remain informed about how personal data is handled.
12. Final Statement
This Privacy Policy is designed to provide transparent information about our data processing practices for all customers in the area. We are committed to respecting your privacy and ensuring that personal data is handled responsibly, securely, and in accordance with GDPR principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity, and accountability. Your trust matters, and we aim to process personal data only when it is necessary and justified.
