Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, disclosed, and protected in connection with the services offered to customers in the area. This policy applies to all customers in the area and is designed to comply with the General Data Protection Regulation (GDPR) and applicable data protection laws. By using the services, you acknowledge that your personal data may be processed as described in this policy.
1. Who this Policy Applies To
This Privacy Policy applies to all individuals who use or receive services as customers in the area, including prospective customers, active customers, and former customers whose personal data may still be retained for lawful purposes. It also applies to any personal data that is collected through direct interactions, account management, service delivery, payment processing, customer support, and related business operations.
2. Personal Data We Collect
We collect and process personal data only where necessary for legitimate business and legal purposes. The categories of information that may be collected include:
- Identity data: name, title, and similar identifiers.
- Contact data: postal address, email address, and telephone number.
- Transaction data: details relating to purchases, payments, billing, and service history.
- Account data: login details, preferences, and account settings where applicable.
- Technical data: device type, browser type, IP address, and usage information.
- Communication data: correspondence, feedback, requests, and complaint records.
- Compliance data: information needed to verify identity, prevent fraud, or meet legal obligations.
We do not intentionally collect special category data unless it is strictly necessary and permitted under data protection law. If such data is ever required, it will only be processed with an appropriate lawful basis and additional safeguards.
3. How We Use Personal Data
Personal data is used for specific, explicit, and legitimate purposes. These purposes may include:
- providing services and fulfilling customer requests;
- managing accounts, orders, and payments;
- communicating service updates and administrative information;
- responding to inquiries, complaints, and support requests;
- maintaining records, auditing activities, and improving service quality;
- detecting and preventing fraud, misuse, or security incidents;
- complying with legal, regulatory, and tax obligations;
- protecting the rights, property, and safety of customers and the business.
We will not process personal data in a manner that is incompatible with the original purpose for which it was collected, unless a valid legal basis exists.
4. Lawful Basis for Processing
Under GDPR, we rely on one or more lawful bases to process personal data. The applicable lawful basis depends on the specific purpose of the processing:
Contractual Necessity
We process data where it is necessary to enter into or perform a contract with a customer, including delivering services, processing payments, and managing service-related communications.
Legal Obligation
We may process personal data when required to comply with legal or regulatory obligations, including accounting, tax, recordkeeping, anti-fraud, and compliance requirements.
Legitimate Interests
We may process data based on our legitimate interests, provided those interests are not overridden by the rights and freedoms of the individual. Legitimate interests may include service improvement, customer support, operational security, business administration, and internal analytics. Where we rely on this basis, we assess the impact on individuals and apply appropriate safeguards.
Consent
In limited cases, we may rely on consent, particularly where the law requires it. When consent is used, it will be freely given, specific, informed, and unambiguous. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Interest
In exceptional circumstances, we may process data where necessary to protect vital interests or where processing is carried out in the public interest or under official authority, as permitted by law.
5. Data Sharing and Processors
We may share personal data with trusted third parties that assist in operating our services. These third parties act as processors or independent controllers depending on the nature of their role. Processors are only permitted to process personal data on our instructions and must implement appropriate technical and organizational safeguards.
Examples of processor categories may include:
- IT and hosting providers that store or support systems and infrastructure;
- payment service providers that process transactions securely;
- customer support tools used to manage communications and service requests;
- accounting and compliance providers that help with financial and legal obligations;
- security and fraud prevention providers that help protect systems and data.
We may also disclose personal data where required by law, court order, or lawful request by public authorities, or where disclosure is necessary to establish, exercise, or defend legal claims. Any transfer of data outside the applicable jurisdiction will be handled in accordance with GDPR transfer requirements and suitable safeguards.
6. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including any legal, accounting, reporting, or dispute-resolution requirements. Retention periods depend on the type of data, the reason for processing, and our legal obligations.
In general, data may be retained for the duration of the customer relationship and for a further period where needed for compliance or legal defense. When data is no longer required, it will be securely deleted, anonymized, or archived in a way that prevents unnecessary use. We apply retention limits and review data periodically to ensure it is not kept longer than necessary.
7. Data Security
We use appropriate technical and organizational measures to safeguard personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, monitoring, staff confidentiality obligations, and periodic security reviews. While no system can be guaranteed to be completely secure, we take reasonable steps to reduce risk and protect data throughout its lifecycle.
8. Your Rights Under GDPR
Depending on the circumstances, you may have the following rights in relation to your personal data:
- Right of access: to obtain confirmation and a copy of your personal data.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of data in certain situations.
- Right to restriction: to request limited processing in certain cases.
- Right to data portability: to receive data in a structured, commonly used format and transmit it elsewhere where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
You also have the right not to be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects, unless permitted by law.
If you wish to exercise any of these rights, we will respond in accordance with GDPR requirements and may ask for information necessary to verify your identity. Where a request is manifestly unfounded, excessive, or repetitive, we may decline it or charge a reasonable fee as permitted by law.
9. Complaints and Supervisory Authority
If you believe your data protection rights have been violated, you may lodge a complaint with the relevant data protection supervisory authority in your jurisdiction. We encourage you to raise concerns promptly so that we can review and address them in accordance with applicable law.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or service operations. Any updated version will apply from the date it becomes effective. We recommend reviewing this policy periodically to remain informed about how personal data is processed.
11. General Statement
This Privacy Policy applies to all customers in the area. It is intended to provide clear and transparent information about how personal data is handled under GDPR. We are committed to processing personal data fairly, lawfully, and securely, and to respecting the rights of individuals whose data we process.
By continuing to use the services, you acknowledge that you have read and understood this Privacy Policy.
