Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area and is intended to reflect the requirements of the General Data Protection Regulation (GDPR) and related data protection laws. By using our services, customers acknowledge that their personal data may be processed in accordance with this Policy.
1. Personal Data We Collect
We collect only the personal data that is necessary for the purposes described in this Policy. Depending on how you interact with us, we may collect the following categories of data:
- Identity data such as name, title, and similar identifiers.
- Contact data such as billing address, delivery address, email address, and telephone number.
- Account data such as account preferences, login details, and service settings.
- Transaction data such as purchase history, payment status, invoices, and service records.
- Technical data such as device type, browser type, IP address, time zone, and usage logs.
- Communication data such as messages, complaints, service requests, and feedback.
- Marketing preferences such as opt-in or opt-out choices where applicable.
We do not intentionally collect special category data unless required by law or you voluntarily provide it in a specific context and a lawful basis applies.
2. How We Use Personal Data
We use personal data for legitimate business and legal purposes, including to:
- provide and manage our services;
- process transactions and deliver customer support;
- maintain records and fulfil contractual obligations;
- verify identity and prevent fraud;
- improve service performance, quality, and security;
- meet legal, regulatory, and tax obligations;
- communicate service updates, notices, and administrative information;
- where permitted, send marketing communications in line with applicable law.
We only process personal data when we have a valid lawful basis and a clear purpose.
3. Lawful Basis for Processing
Under GDPR, we rely on one or more of the following lawful bases depending on the context of the processing:
3.1 Performance of a Contract
We process personal data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract. This includes processing required to provide services, manage customer accounts, and handle payments.
3.2 Legal Obligation
We may process personal data where required to comply with legal and regulatory obligations, including accounting, tax, fraud prevention, and lawful requests from public authorities.
3.3 Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Legitimate interests may include improving services, maintaining security, preventing misuse, and managing internal administration.
3.4 Consent
Where required, we rely on your consent. This is most commonly relevant for certain marketing or optional processing activities. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Data Sharing and Processors
We may share personal data with trusted third parties that process data on our behalf. These parties act as processors and are only permitted to process personal data according to our instructions and applicable law. We require appropriate contractual safeguards to protect personal data and maintain confidentiality.
Processors and service providers may include:
- payment and transaction processing providers;
- IT hosting, cloud infrastructure, and data storage providers;
- customer support and communications platforms;
- security, monitoring, and fraud-prevention services;
- professional advisers such as legal, accounting, or compliance specialists;
- analytics providers used to measure service performance in a privacy-respecting manner.
We may also share data where required by law, court order, or other lawful request from public authorities. We do not sell personal data in a manner prohibited by applicable law.
5. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with equivalent protections, we ensure appropriate safeguards are in place. These safeguards may include standard contractual clauses, adequacy decisions, or other legally recognised transfer mechanisms.
Wherever data is transferred, we aim to maintain a level of protection consistent with GDPR requirements.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, reporting, and dispute-resolution requirements. Retention periods vary depending on the type of data and the purpose of processing.
- Account and service records may be retained for the duration of the relationship and for a reasonable period afterward.
- Transaction and financial records may be retained for periods required by tax and commercial law.
- Support and correspondence records may be retained for service, quality, and legal purposes.
- Marketing preference records may be retained until you change your preference or withdraw consent.
When personal data is no longer needed, it is securely deleted, anonymised, or otherwise disposed of in a lawful and appropriate manner. Retention is reviewed periodically to ensure data is not kept longer than necessary.
7. Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. Measures may include access controls, encryption, secure storage, staff confidentiality obligations, and monitoring procedures.
Although we work to protect personal data, no system can be guaranteed to be completely secure. We therefore maintain internal procedures to detect, assess, and respond to potential incidents in line with legal obligations.
8. Your Rights Under GDPR
Where GDPR applies, you have several rights in relation to your personal data. These rights may be subject to legal limitations or conditions depending on the circumstances.
- Right of access – you may request confirmation of whether we process your data and obtain a copy.
- Right to rectification – you may request correction of inaccurate or incomplete data.
- Right to erasure – you may request deletion of your data where legal grounds apply.
- Right to restriction – you may request that processing be limited in certain situations.
- Right to data portability – you may request your data in a structured, commonly used format where applicable.
- Right to object – you may object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
- Right not to be subject to automated decision-making – you have rights relating to decisions made solely by automated means where such processing occurs.
To exercise these rights, you may make a request through the relevant service process. We may need to verify your identity before acting on a request. We will respond within the timeframe required by applicable law.
9. Children’s Data
Our services are not intended for children unless explicitly stated otherwise. We do not knowingly collect personal data from children without appropriate authorisation and lawful basis. If we become aware that such data has been collected without proper legal grounds, we will take reasonable steps to delete it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or operational requirements. The revised version will apply from the date it is made available. We encourage customers to review this Policy periodically to stay informed.
11. Complaints
If you believe that your personal data has been handled improperly, you have the right to raise a concern with the relevant supervisory authority. You may also seek to resolve concerns through the applicable internal process or complaint procedure.
This Privacy Policy is intended to provide a clear and transparent explanation of our data practices for all customers in the area. It is designed to support accountability, fairness, and respect for individual privacy rights under GDPR.
Key Principles
We aim to follow the core GDPR principles in all processing activities:
- lawfulness, fairness, and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality;
- accountability.
