Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when we provide our services. It applies to all customers in the area and is intended to reflect the principles of the General Data Protection Regulation (GDPR). By using our services, customers acknowledge that personal data may be processed as described in this Policy.
1. Data We Collect
We may collect and process different categories of personal data depending on how a customer interacts with us. This can include information provided directly by the customer, information generated through service use, and limited technical information collected automatically.
Information provided by the customer
- Identity data such as name, surname, and title
- Contact data such as address, email address, and telephone number
- Account and transaction data such as order details, payment status, billing records, and service history
- Communication data such as messages, requests, complaints, and feedback
Information collected automatically
- Technical data such as device type, browser type, operating system, and language preferences
- Usage data such as pages or features accessed, timestamps, and interaction patterns
- Security data such as authentication logs and fraud-prevention records
We do not intentionally collect special category data unless required by law or explicitly provided by the customer for a specific lawful purpose. Where such data is processed, it will be handled with additional safeguards and only where permitted under GDPR.
2. How We Use Personal Data
Personal data is processed for clear, limited, and legitimate purposes. We use data to operate our services, manage customer relationships, comply with legal obligations, and protect our rights and the rights of others.
- To deliver and manage services requested by the customer
- To create and maintain customer records and accounts
- To process payments, invoices, refunds, and related administration
- To respond to inquiries, complaints, and support requests
- To maintain security, prevent fraud, and detect misuse
- To comply with legal, tax, accounting, and regulatory requirements
- To improve service quality, reliability, and operational performance
We will only use personal data for the purposes described above or for compatible purposes permitted under data protection law. We do not use personal data in a way that is incompatible with the expectations of the customer or the requirements of GDPR.
3. Lawful Basis for Processing
We process personal data only where a lawful basis under GDPR applies. The lawful basis used depends on the specific purpose for which data is processed.
Contract
We rely on contractual necessity where processing is required to provide services, manage requests, or fulfill obligations arising from an agreement with the customer.
Legal obligation
We rely on legal obligation where processing is necessary to comply with applicable laws, including accounting, tax, consumer protection, and record-keeping requirements.
Legitimate interests
We may process data on the basis of legitimate interests where it is necessary for security, service improvement, fraud prevention, internal administration, or the protection of our business, provided that such interests do not override the customer’s rights and freedoms.
Consent
Where required by law, we rely on consent. If consent is used as the lawful basis, it will be freely given, specific, informed, and unambiguous. Customers may withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
4. Sharing and Processors
We may share personal data with carefully selected service providers that act as processors on our behalf. These processors may only process data according to our instructions and for the limited purposes we specify.
Types of processors
- IT and hosting providers that support data storage, system availability, and technical operations
- Payment service providers that assist with secure payment processing
- Accounting and administrative providers that help with invoicing and financial record management
- Customer support tools that help manage communications and service requests
- Security and fraud-prevention providers that help protect systems and transactions
Where required, we enter into data processing agreements with processors to ensure appropriate confidentiality, security, and compliance obligations. We may also disclose personal data to public authorities, courts, or regulators when legally required. Any such disclosure will be limited to what is necessary and permitted by law.
5. International Transfers
If personal data is transferred outside the European Economic Area or the United Kingdom, we will ensure an appropriate safeguard is in place, such as an adequacy decision or standard contractual clauses, together with supplementary measures where needed. Transfers will only occur where permitted under GDPR and only to the extent necessary for the relevant processing activity.
6. Data Retention
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, tax, and reporting obligations. Retention periods vary according to the type of data and the reason for processing.
- Customer account and service records are retained for the duration of the customer relationship and for a reasonable period afterward
- Financial and transaction records are retained for the period required by applicable accounting and tax laws
- Support communications are retained for the time needed to resolve the matter and to maintain accurate records
- Security and fraud-related logs are retained for a limited period appropriate to the risk and operational need
When data is no longer needed, it will be securely deleted, anonymized, or archived in a way that prevents further use except where retention is required by law. We apply a retention approach based on necessity and proportionality.
7. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, logging, and regular review of internal processes.
Although we work to protect personal data, no system can be guaranteed to be entirely secure. Where a personal data breach is likely to result in a risk to individuals’ rights and freedoms, we will take the steps required by GDPR, including notifying the relevant supervisory authority and, where applicable, affected individuals.
8. User Rights
Customers have the rights provided under GDPR, subject to applicable legal limitations. We are committed to respecting and facilitating these rights.
Rights available to customers
- Right of access to obtain confirmation and a copy of personal data we hold
- Right to rectification to correct inaccurate or incomplete data
- Right to erasure to request deletion in certain circumstances
- Right to restriction to limit processing in certain circumstances
- Right to data portability to receive data in a structured, commonly used format where applicable
- Right to object to processing based on legitimate interests or direct marketing, where applicable
- Right to withdraw consent at any time where processing is based on consent
- Right not to be subject to automated decision-making where it produces legal or similarly significant effects, unless permitted by law
Customers may also have the right to lodge a complaint with the relevant data protection authority if they believe their rights have been violated. We encourage customers to raise concerns so that they can be reviewed and addressed promptly.
9. Children’s Data
Our services are not intended to be directed to children where such processing would require parental consent or additional legal safeguards. We do not knowingly collect personal data from children in a manner that is unlawful under GDPR. If we become aware that such data has been collected without a valid legal basis, we will take appropriate steps to delete or secure it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service arrangements. When we do so, the revised version will apply from the date it becomes effective. Customers are encouraged to review this Policy periodically to stay informed about how personal data is handled.
Scope: This Privacy Policy applies to all customers in the area and governs the processing of personal data in connection with the services we provide. It is intended to provide clear, lawful, and transparent information in accordance with GDPR.
