Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when services are provided to all customers in the area. It applies to individuals whose personal data is processed in connection with our business activities, whether data is collected directly from you, generated during service delivery, or received from third parties where permitted by law. This policy is intended to be consistent with the requirements of the General Data Protection Regulation (GDPR).
1. Scope of This Policy
This policy applies to all customers in the area and describes the standards that govern the processing of personal data. Personal data means any information relating to an identified or identifiable natural person. This may include identifiers, contact details, account information, transaction records, communication history, usage data, and any other information that can be linked to an individual.
We are committed to handling personal data in a lawful, fair, and transparent manner. We also take appropriate technical and organizational measures to reduce risks and protect data against unauthorized access, loss, misuse, or disclosure.
2. Data Collection
We may collect personal data in several ways, depending on how you interact with our services. The categories of data collected may include:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, telephone number, or other communication details.
- Transaction data: records of purchases, payments, and service activity.
- Technical data: device information, browser type, IP address, and log data.
- Usage data: information about how services are used and interacted with.
- Communication data: records of correspondence, inquiries, complaints, or requests.
In some cases, we may also process limited additional information necessary for compliance, fraud prevention, security, or service improvement. Where special category data is involved, it will only be processed where permitted by GDPR and subject to stronger safeguards.
3. Purposes of Processing
We process personal data for specific and legitimate purposes, including:
- to provide and manage services;
- to process transactions and maintain records;
- to communicate with customers about service matters;
- to improve service quality and customer experience;
- to monitor, secure, and maintain systems;
- to comply with legal and regulatory obligations;
- to protect against fraud, abuse, or unauthorized activity;
- to establish, exercise, or defend legal claims.
We do not process personal data in ways that are incompatible with these purposes unless required or permitted by law.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing personal data. Depending on the context, we rely on one or more of the following legal grounds:
4.1 Contractual Necessity
We process personal data where it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract. This may include verifying details, delivering services, managing accounts, and processing payments.
4.2 Legal Obligation
We may process personal data to comply with legal duties, regulatory requirements, tax obligations, record-keeping requirements, or lawful requests from public authorities.
4.3 Legitimate Interests
We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Legitimate interests may include service improvement, operational management, network and information security, fraud prevention, and internal administration. Where we rely on this basis, we assess and balance our interests against the impact on individuals.
4.4 Consent
In limited circumstances, we may rely on your consent. Where consent is used, it will be freely given, specific, informed, and unambiguous. You may withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
4.5 Vital Interests and Public Task
In rare cases, processing may be necessary to protect vital interests or to perform a task carried out in the public interest, where applicable under GDPR.
5. Data Sharing and Processors
We may share personal data with trusted third parties when necessary for the purposes described in this policy and only under appropriate safeguards. These third parties may act as processors or, in some cases, as independent controllers.
Processors are organizations that process personal data on our behalf and under our instructions. They may include providers of hosting services, IT support, payment processing, data storage, analytics, communications, security, and administrative tools.
We require processors to:
- process data only on documented instructions;
- maintain confidentiality;
- implement appropriate security measures;
- assist with data subject rights where required;
- delete or return data when processing ends, unless retention is required by law.
Where personal data is transferred outside the European Economic Area, appropriate legal safeguards will be used, such as adequacy decisions, standard contractual clauses, or equivalent protective measures recognized under GDPR.
6. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting, reporting, and operational requirements. The retention period depends on the nature of the data, the purpose of processing, and applicable law.
When determining retention periods, we consider factors such as:
- the duration of the customer relationship;
- statutory retention obligations;
- limitation periods for legal claims;
- tax and financial record requirements;
- security and fraud-prevention needs.
Once data is no longer needed, it is securely deleted, anonymized, or archived in accordance with applicable legal and operational requirements.
7. Security Measures
We use reasonable technical and organizational measures to protect personal data. These measures may include access controls, encryption, secure storage, logging, staff training, and policies designed to limit access to data on a need-to-know basis.
While no system can be guaranteed to be completely secure, we continuously review and improve our safeguards to protect data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
8. Your Rights Under GDPR
If you are a data subject under GDPR, you may have the following rights, subject to legal limitations and conditions:
- Right of access: to obtain confirmation and a copy of your personal data.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request limited processing in specific situations.
- Right to data portability: to receive data in a structured, commonly used format where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing, where applicable.
- Right not to be subject to automated decision-making: to avoid decisions based solely on automated processing where such rights apply.
You may also have the right to lodge a complaint with the competent supervisory authority if you believe your data protection rights have been infringed.
9. Exercising Your Rights
Requests to exercise data protection rights will be handled in accordance with GDPR. We may need to verify your identity before responding to a request. We aim to respond within the time limits required by law and may extend the timeframe where requests are complex or numerous.
Where we cannot comply with a request, we will explain the reasons, subject to any legal restrictions. Some rights may not apply in full where processing is necessary to comply with legal obligations, protect the rights of others, or establish and defend legal claims.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any revised version will apply from the date of its publication or effective date, as applicable. We encourage customers to review this policy periodically to stay informed about how personal data is processed.
11. General Statement
This Privacy Policy applies to all customers in the area. By using our services, you acknowledge that your personal data may be processed in accordance with the terms set out above, subject always to your rights under applicable data protection law. We are committed to lawful, transparent, and responsible data handling and to protecting personal data throughout the lifecycle of processing.
