Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when services are provided to customers in the relevant area. It applies to all customers in that area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and any other applicable data protection laws. By using the services, customers acknowledge that their personal data may be processed in accordance with this policy.
1. Data We Collect
We collect only the personal data that is necessary for legitimate business and service-related purposes. Depending on how a customer interacts with us, this may include the following categories:
- Identity data: name, title, username, and similar identifiers.
- Contact data: address, email address, telephone number, and related communication details.
- Account data: account settings, preferences, registration details, and service history.
- Transaction data: records of purchases, payments, billing information, and order details.
- Technical data: IP address, device type, browser type, system settings, and log data.
- Usage data: pages viewed, features used, time spent, and interaction patterns.
- Communication data: messages, inquiries, feedback, complaints, and support records.
Where required, we may also process special category data or other sensitive information only when strictly necessary and where a valid legal basis exists. We do not intentionally collect more data than is needed for the purposes described in this policy.
2. How We Use Personal Data
Personal data is used for the following purposes:
- to provide, operate, and maintain services;
- to process transactions and manage customer accounts;
- to communicate service updates, notices, and support responses;
- to improve service quality, performance, and user experience;
- to detect, prevent, and investigate fraud, abuse, or security incidents;
- to comply with legal, regulatory, and contractual obligations;
- to keep records and manage internal administration;
- to exercise or defend legal claims where necessary.
We will only use personal data for the purposes for which it was collected, unless we reasonably consider that we need to use it for another compatible purpose and that such use is permitted by law.
3. Lawful Basis for Processing
Under GDPR, personal data must be processed only where a lawful basis applies. We rely on one or more of the following legal bases:
Consent
Where required, we process personal data based on the individual’s consent. Consent is always informed, specific, freely given, and withdrawable at any time. If consent is withdrawn, this does not affect processing carried out before withdrawal.
Contract
We process personal data when it is necessary to enter into or perform a contract with the customer, or to take steps at the customer’s request before entering into a contract.
Legal Obligation
We may process personal data to comply with applicable laws, tax requirements, accounting rules, regulatory duties, or lawful requests from public authorities.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided that those interests are not overridden by the individual’s rights and freedoms. Examples include service improvement, business management, network security, and fraud prevention.
Vital Interests and Public Interest
In rare situations, processing may be necessary to protect someone’s vital interests or to perform a task carried out in the public interest, where applicable.
4. Data Sharing and Processors
We may share personal data with trusted third parties that help us operate our services. These third parties act as processors when they process data on our behalf and under our instructions. Such processors are bound by appropriate data processing agreements and are required to implement suitable technical and organisational security measures.
Categories of processors may include:
- IT and hosting providers for infrastructure, storage, and system maintenance;
- payment service providers for transaction processing and fraud checks;
- customer support tools for handling requests and service communication;
- analytics providers for measuring service performance and usage;
- security providers for monitoring and protection against threats;
- professional advisers such as auditors, accountants, and legal counsel where necessary.
We may also disclose personal data where required by law, by court order, or in response to valid requests from competent authorities. If a business transfer, merger, or restructuring occurs, personal data may be transferred as part of that transaction, subject to applicable legal safeguards.
5. International Transfers
Where personal data is transferred outside the European Economic Area, we ensure that appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms. We take steps to ensure that any such transfer protects personal data to a level consistent with GDPR requirements.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, tax, reporting, or contractual obligations. Retention periods vary depending on the type of data and the reason for processing.
In general:
- account and transaction records are kept for as long as required by law and for dispute resolution;
- support communications are retained for a reasonable period to manage service history and complaints;
- technical and usage logs are retained for security, diagnostics, and service improvement;
- data collected on the basis of consent is retained only until consent is withdrawn or the original purpose ends.
When personal data is no longer needed, it is securely deleted, anonymised, or archived in accordance with our retention procedures. We apply retention controls so that data is not kept longer than necessary.
7. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure backups, logging, and staff confidentiality obligations. Although no system can be guaranteed completely secure, we regularly review our safeguards and aim to reduce risks to an acceptable level.
8. User Rights
Individuals whose personal data is processed under this policy have the following rights under GDPR, subject to certain conditions and limitations:
- Right of access – to obtain confirmation and a copy of personal data being processed.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of personal data in certain circumstances.
- Right to restriction – to request limited processing in specific situations.
- Right to data portability – to receive certain data in a structured, commonly used format and transmit it elsewhere where feasible.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – to withdraw consent at any time when processing is based on consent.
- Right not to be subject to automated decision-making – including profiling, where applicable and legally relevant.
To exercise these rights, individuals may make a request through the appropriate service channel. We may need to verify identity before acting on a request. We will respond within the time limits required by law, usually within one month, unless an extension is justified due to complexity or volume of requests.
9. Children’s Data
Our services are not intended for children unless explicitly stated otherwise. We do not knowingly collect personal data from children without appropriate legal grounds and, where required, verifiable parental consent. If we become aware that we have collected data from a child unlawfully, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service offerings. Any updated version will apply from the date it takes effect. Customers are encouraged to review the policy periodically to remain informed about how their data is processed.
11. Scope and Applicability
This Privacy Policy applies to all customers in the relevant area. It governs the processing of personal data collected in connection with services provided in that area, regardless of the device used or the channel through which the services are accessed. By continuing to use the services, customers confirm that they understand this policy and the way in which personal data may be processed in accordance with GDPR.
We are committed to handling personal data lawfully, fairly, and transparently, while respecting the privacy rights of every customer.
