Privacy Policy
Effective Date: This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the relevant area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and applicable local privacy laws.
1. Introduction
We are committed to respecting your privacy and protecting your personal data. This policy describes what information we collect, why we collect it, the lawful bases we rely on, how long we keep it, who may process it on our behalf, and the rights available to you under data protection law. By using our services, you acknowledge that your personal data may be processed as described in this policy.
2. Data We Collect
We collect only data that is necessary for legitimate business, operational, contractual, or legal purposes. Depending on how you interact with us, the categories of personal data we may collect include:
- Identification data: name, title, and similar identifiers.
- Contact data: billing address, delivery address, email address, and telephone number.
- Transaction data: records of purchases, payments, refunds, and service history.
- Account data: usernames, authentication details, preferences, and settings.
- Communication data: correspondence sent to us and records of our responses.
- Technical data: device type, operating system, browser details, log files, and usage information.
- Location data: approximate or precise location where necessary for service delivery, subject to lawful requirements.
- Compliance data: information required to meet legal, regulatory, tax, accounting, or audit obligations.
We do not intentionally collect special category personal data unless it is strictly necessary and permitted by law. If such processing is required, it will only occur with an appropriate lawful basis and, where necessary, your explicit consent.
3. How We Use Personal Data
We use personal data for the following purposes:
- to provide, operate, and improve our services;
- to process transactions, orders, payments, and refunds;
- to manage customer accounts and preferences;
- to communicate with you about service-related matters;
- to prevent fraud, misuse, and security incidents;
- to comply with legal and regulatory obligations;
- to maintain accurate records and internal reporting;
- to analyse service performance and customer experience;
- to defend or establish legal claims where necessary.
We process personal data only for specified, explicit, and legitimate purposes and do not use it in ways that are incompatible with those purposes.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. Depending on the context, we may rely on one or more of the following:
Contract
We process personal data where necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract. This includes processing data to deliver services, handle payments, and manage accounts.
Legal Obligation
We may process personal data where necessary to comply with a legal obligation, such as tax, accounting, consumer protection, anti-fraud, or regulatory requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Our legitimate interests may include improving services, ensuring network and information security, detecting fraud, managing business operations, and maintaining records.
Consent
Where required by law, we rely on your consent. If we ask for consent, you may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Vital Interests and Public Interest
In limited circumstances, we may process personal data to protect vital interests or where processing is necessary for a task carried out in the public interest or in the exercise of official authority, if applicable.
5. Retention of Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the satisfaction of legal, accounting, reporting, and dispute-resolution requirements. The exact retention period depends on the type of data, the purpose of processing, and applicable legal obligations.
- Contractual and service data: kept for the duration of the relationship and a reasonable period afterward.
- Financial and tax records: retained for the period required by applicable law.
- Support and communications: stored as long as necessary to resolve issues and maintain records.
- Security and log data: retained for a limited time unless needed for investigation or legal purposes.
When personal data is no longer required, we will delete, anonymise, or securely archive it in accordance with our retention practices and legal obligations. We review retention periods periodically to ensure data is not kept longer than necessary.
6. Sharing and Processors
We may share personal data with carefully selected third parties that act as processors or independent controllers, only where there is a valid legal basis and the sharing is necessary for the purposes described in this policy.
Processors may include:
- IT and hosting providers: for data storage, system maintenance, and service delivery.
- Payment service providers: for handling transactions and related financial processing.
- Customer support tools: for managing communications and service requests.
- Analytics and security providers: for monitoring performance, preventing fraud, and protecting systems.
- Professional advisers: such as auditors, accountants, or legal advisers where necessary.
- Regulators and public authorities: where disclosure is required by law.
All processors are required to process personal data only on our instructions, to maintain confidentiality, and to implement appropriate technical and organisational measures. We ensure that data processing agreements are in place where required by GDPR.
We do not sell your personal data. Any international transfers, if applicable, are safeguarded using appropriate legal mechanisms such as adequacy decisions, standard contractual clauses, or other permitted safeguards.
7. Data Security
We use appropriate security measures designed to protect personal data against unauthorised access, loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, monitoring, secure hosting, staff training, and incident response procedures. Although no system can be guaranteed completely secure, we take reasonable and proportionate steps to protect the information we handle.
8. Your Rights Under GDPR
You have a number of rights in relation to your personal data, subject to applicable legal conditions and limitations. These rights include:
- Right of access: to obtain confirmation and a copy of the personal data we hold about you.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request limitation of processing in specific situations.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and have it transferred where technically feasible.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent.
- Right not to be subject to automated decision-making: including profiling, where applicable and legally relevant.
If you exercise any of these rights, we may need to verify your identity before responding. We will respond within the time limits required by GDPR unless an extension is lawfully permitted due to complexity or the number of requests.
9. Children’s Data
Our services are not intended for children unless clearly stated otherwise. We do not knowingly collect personal data from children without appropriate legal permission where required. If we become aware that personal data has been collected inappropriately, we will take steps to delete it or obtain the necessary authorisation.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, our services, or our data processing practices. Any updated version will apply from the effective date stated in the revised policy. We encourage you to review this policy periodically to remain informed about how we protect personal data.
11. Scope and Applicability
This Privacy Policy applies to all customers in the relevant area, including individuals and entities that receive services from us, interact with us, or otherwise provide personal data in connection with our operations. By using our services or engaging with us, you acknowledge that your data may be processed in accordance with this policy and applicable data protection laws.
In summary: we collect only necessary personal data, use it for lawful and clearly defined purposes, retain it for limited periods, share it only with trusted processors or authorities where required, and respect your rights under GDPR.
