Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area where our services are offered, and it is intended to meet applicable privacy and data protection requirements, including the General Data Protection Regulation (GDPR). By using our services, customers acknowledge that their personal data may be processed as described below.
1. Data We Collect
We collect only the personal data that is necessary for the purposes described in this Privacy Policy. Depending on how you interact with us, we may process the following categories of data:
- Identity data: name, title, and similar identifiers.
- Contact data: billing address, delivery address, email address, and telephone number.
- Transaction data: records of purchases, payments, invoices, and related service history.
- Technical data: device information, IP address, browser type, operating system, and usage logs.
- Profile data: preferences, purchase history, and service settings.
- Communication data: records of inquiries, feedback, complaints, and support interactions.
We do not intentionally collect special category data unless it is explicitly required by law or voluntarily provided by you for a lawful purpose. If such data is ever collected, it will be handled with heightened safeguards and only where permitted under the GDPR.
2. How We Use Personal Data
We process personal data for specific, legitimate, and transparent purposes. These may include:
- providing products or services;
- managing customer accounts and orders;
- processing payments and preventing fraud;
- responding to inquiries and customer support requests;
- sending service-related notices and updates;
- improving our operations, systems, and customer experience;
- complying with legal, regulatory, tax, and accounting obligations;
- protecting our rights, property, personnel, and customers.
Where data is used for purposes that are not strictly necessary to perform a contract or comply with legal obligations, we ensure that the processing is carried out only when we have a valid legal basis.
3. Lawful Basis for Processing
Under the GDPR, we rely on one or more of the following lawful bases when processing personal data:
3.1 Contractual Necessity
We process personal data when it is necessary to enter into or perform a contract with you, such as providing services, managing orders, issuing invoices, or handling payments.
3.2 Legal Obligation
We may process personal data to comply with laws and regulations, including tax rules, accounting requirements, consumer protection obligations, and lawful requests from public authorities.
3.3 Legitimate Interests
We may process data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. This may include fraud prevention, network and information security, service improvement, internal administration, and business record-keeping.
3.4 Consent
In limited cases, we may rely on your consent, for example where required for certain communications or optional processing. Where consent is used, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, reporting, and dispute-resolution requirements. Retention periods vary depending on the type of data and the purpose of processing.
Typical retention principles include:
- Contract and transaction records are retained for the duration of the customer relationship and for an appropriate period afterward to meet legal and financial obligations.
- Customer support communications are retained for as long as needed to resolve issues and maintain service records.
- Technical logs are retained for a limited period to ensure security, diagnose issues, and maintain system integrity.
- Marketing or consent-based records are retained until consent is withdrawn or the data is no longer required for the original purpose.
When personal data is no longer required, we will delete, anonymise, or securely archive it in accordance with our retention procedures and applicable law.
5. Processors and Data Sharing
We may share personal data with trusted third parties that act as processors on our behalf. These processors are only permitted to handle personal data according to our instructions and are required to implement appropriate technical and organisational safeguards.
Examples of processor categories may include:
- IT and cloud hosting providers;
- payment service providers;
- customer relationship management systems;
- analytics and performance service providers;
- document storage and backup providers;
- professional advisors assisting with legal, audit, or compliance tasks.
We may also disclose personal data where necessary to comply with law, enforce agreements, protect against fraud or abuse, or respond to lawful requests. Any such disclosure will be limited to what is necessary and proportionate.
Where a processor or recipient is located outside the European Economic Area, we ensure that appropriate safeguards are in place where required by law, such as standard contractual clauses or equivalent protective measures.
6. Your Rights Under GDPR
Subject to conditions and exceptions under applicable law, you have the following rights regarding your personal data:
- Right of access: to obtain confirmation about whether your data is processed and to receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data where there is no valid reason for continued processing.
- Right to restriction: to request limited processing in certain circumstances.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and, where feasible, transmit it to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time.
You also have the right to lodge a complaint with the relevant supervisory authority if you believe your data protection rights have been infringed. We encourage customers to raise concerns promptly so that we may address them internally.
7. Data Security
We use reasonable and appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, unlawful use, alteration, disclosure, or destruction. These measures may include access controls, encryption where appropriate, secure storage, staff confidentiality obligations, and periodic review of security practices.
While no system can be guaranteed to be completely secure, we continuously work to improve our safeguards and limit access to personal data to persons who need it for legitimate business purposes.
8. Data Minimisation and Accuracy
We follow the GDPR principles of data minimisation and accuracy. This means we collect only the data that is relevant and necessary for our stated purposes and take reasonable steps to keep personal data accurate and up to date. Customers are encouraged to notify us of changes to their details so that records remain correct.
9. Children’s Data
Our services are not intended for children unless explicitly stated otherwise. We do not knowingly collect personal data from children without the appropriate legal basis and required authorisation. If we become aware that such data has been collected improperly, we will take steps to delete it where required by law.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, our practices, or our services. Any updated version will apply from the date it becomes effective. Customers should review the policy periodically to stay informed about how their data is handled.
11. General Statement
This Privacy Policy is intended to apply to all customers in the area and governs the processing of personal data in connection with the services provided there. We are committed to processing personal data fairly, lawfully, transparently, and with respect for individual privacy rights. Privacy and accountability remain central to our operations, and we expect all parties acting on our behalf to uphold the same standards.
By continuing to use our services, you acknowledge that you have read and understood this Privacy Policy.
