Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the relevant area and is intended to meet the requirements of applicable data protection laws, including the General Data Protection Regulation (GDPR). By using our services, you acknowledge that your personal data may be processed in accordance with this Policy.
1. Scope of this Policy
This Policy applies to all customers in the area where our services are provided, including individuals who browse, register, purchase, communicate with us, or otherwise interact with our services. It covers personal data processed by us as a data controller and explains the purposes and legal grounds for processing, retention periods, transfers, and your rights.
2. Personal Data We Collect
We may collect and process the following categories of personal data, depending on how you interact with us:
- Identity data: name, surname, username, and similar identifiers.
- Contact data: postal address, email address, and telephone number.
- Account data: login details, account preferences, and profile settings.
- Transaction data: purchase history, order details, payment-related records, and service usage information.
- Technical data: IP address, device identifiers, browser type, operating system, language settings, and log data.
- Usage data: interactions with our services, pages viewed, time spent, and feature usage.
- Communication data: records of messages, complaints, feedback, support requests, and correspondence.
- Preference data: marketing preferences, consent choices, and product or service interests.
We generally collect personal data directly from you when you provide it to us. We may also receive data from service providers, payment processors, analytics providers, or publicly available sources where permitted by law.
3. Why We Process Personal Data
We process personal data for specific, legitimate, and lawful purposes, including:
- providing and operating our services;
- creating and managing customer accounts;
- processing payments and fulfilling transactions;
- communicating with you about services, updates, and support;
- improving service quality, usability, and performance;
- maintaining security, preventing fraud, and detecting misuse;
- complying with legal and regulatory obligations;
- managing disputes, claims, and internal record-keeping;
- sending marketing communications where permitted by law and subject to your preferences.
We only process personal data where there is a valid legal basis to do so.
4. Lawful Basis for Processing
Under GDPR, we rely on one or more of the following lawful bases:
4.1 Performance of a Contract
We process personal data when it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes setting up accounts, delivering services, and handling payment or billing activities.
4.2 Legal Obligation
We may process personal data when necessary to comply with legal obligations, such as tax, accounting, consumer protection, anti-fraud, or regulatory requirements.
4.3 Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided that those interests are not overridden by your rights and freedoms. Our legitimate interests include service improvement, fraud prevention, network and information security, and the protection of our business operations.
4.4 Consent
Where required, we rely on your consent, for example for certain marketing activities or non-essential cookies and similar technologies. You may withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
5. Data Sharing and Processors
We may share personal data with trusted third parties acting as processors or, in some cases, independent controllers. These parties process data only when necessary and under appropriate contractual and legal safeguards. The categories of processors may include:
- IT and hosting providers who store and secure systems and infrastructure;
- payment service providers who handle payment processing and fraud checks;
- customer support platforms used to manage enquiries and service requests;
- analytics and performance providers who help us understand service usage;
- marketing service providers who assist with communications where permitted;
- professional advisers such as auditors, legal advisers, and accountants;
- public authorities or regulators where disclosure is required by law.
We require processors to implement appropriate technical and organizational measures to protect personal data and to process it only on our documented instructions, unless they are independently responsible under law.
6. International Transfers
If personal data is transferred outside the European Economic Area or the United Kingdom, we will ensure that appropriate safeguards are in place where required by law. These may include adequacy decisions, standard contractual clauses, or other legally recognized transfer mechanisms.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting obligations. Retention periods vary depending on the type of data and the reason for processing.
- Contract and transaction data may be retained for the duration of the business relationship and for a period afterward to address claims, tax, or accounting obligations.
- Account data is generally retained while the account remains active and for a reasonable period after closure.
- Communication and support records may be retained for quality assurance, dispute handling, and legal protection.
- Marketing data is retained until you withdraw consent or object, subject to legal retention needs.
- Technical and security logs are retained for limited periods necessary for security, troubleshooting, and audit purposes.
When retention is no longer required, we will delete, anonymize, or securely archive personal data in accordance with our internal policies and applicable law.
8. Data Security
We take appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff training, and monitoring of systems. While we strive to safeguard all data, no method of transmission or storage is completely risk-free.
9. Your Rights Under GDPR
You have several rights regarding your personal data, subject to legal limitations and conditions. These rights include:
- Right of access: to obtain confirmation about whether we process your data and receive a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request limited processing in specific situations.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
- Right to complain: to lodge a complaint with a data protection authority if you believe your rights have been infringed.
These rights may be limited in some circumstances, for example where processing is necessary to comply with legal obligations or to establish, exercise, or defend legal claims.
10. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate legal basis and, where required, parental consent. If we become aware that personal data has been collected inappropriately, we will take reasonable steps to delete it.
11. Cookies and Similar Technologies
We may use cookies or similar technologies for essential functionality, analytics, preferences, and security. Where required, we will obtain consent before placing non-essential cookies. You can manage your preferences through available browser settings or consent mechanisms, subject to technical limitations.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or service-related changes. Any updated version will apply from the date it is published or otherwise communicated. We encourage you to review this Policy periodically to stay informed about how we process personal data.
13. Final Provisions
This Privacy Policy should be read together with any other notices we provide about data processing in specific contexts. If any part of this Policy is found to be invalid or unenforceable, the remaining provisions will continue to apply. We process personal data fairly, transparently, and in accordance with GDPR principles of lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
By using our services, you confirm that you have read and understood this Privacy Policy and the ways in which your personal data may be processed.
