Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with services offered to customers in the area. It applies to all customers in the area and should be read carefully to understand how personal information is handled under applicable data protection law, including the General Data Protection Regulation (GDPR).
1. Scope and purpose
This policy applies to personal data processed when a customer uses services, communicates with support, makes an inquiry, submits a form, completes a transaction, or otherwise interacts with the services provided. The purpose of this policy is to explain what data is collected, why it is processed, the lawful basis for processing, how long it is retained, who may process it on our behalf, and what rights individuals have.
We are committed to processing personal data in a lawful, fair, and transparent manner. We only collect data that is necessary for specified purposes and take appropriate measures to safeguard it.
2. Data collection
We may collect and process the following categories of personal data:
- Identity data: such as name, username, or similar identifier.
- Contact data: such as email address, telephone number, billing or service address, and other contact details.
- Transaction data: such as records of services requested, purchased, or delivered, payment status, and related correspondence.
- Technical data: such as device type, browser information, internet protocol address, login data, and usage logs.
- Communication data: such as messages, feedback, complaints, and customer support interactions.
- Preference data: such as service choices, language settings, or communication preferences.
We may collect data directly from the customer, through automated means, or from third parties where lawful and necessary. In some situations, providing personal data may be required to enter into or perform a contract, to satisfy legal obligations, or to receive certain services. Where data is not mandatory, we will make that clear.
3. Lawful basis for processing
Under GDPR, we rely on one or more lawful bases for each processing activity. These may include:
- Performance of a contract: where processing is necessary to provide requested services, manage accounts, or complete transactions.
- Legal obligation: where processing is required to comply with tax, accounting, regulatory, or other legal duties.
- Legitimate interests: where processing is necessary for our legitimate business interests, provided those interests are not overridden by the individual’s rights and freedoms. Examples include service improvement, fraud prevention, internal administration, and security monitoring.
- Consent: where we rely on consent for specific activities, such as optional communications or certain types of marketing, and where consent can be withdrawn at any time.
Where special categories of personal data are processed, we will only do so when a valid GDPR condition applies and appropriate safeguards are in place. We will always aim to minimize the amount of personal data processed and limit use to the stated purpose.
4. How personal data is used
Personal data may be used for the following purposes:
- to provide and administer services;
- to process requests, bookings, and transactions;
- to communicate with customers regarding service updates, queries, or issues;
- to maintain records and perform internal business operations;
- to improve service quality, safety, and user experience;
- to detect, prevent, and investigate fraud, misuse, or security incidents;
- to comply with legal and regulatory obligations;
- to establish, exercise, or defend legal claims.
We will not use personal data in a way that is incompatible with the original purpose unless we have a lawful basis to do so. Where we rely on legitimate interests, we assess the impact on individuals and take care to avoid unnecessary intrusion.
5. Data retention
Personal data is retained only for as long as necessary to fulfill the purpose for which it was collected, including legal, accounting, or reporting requirements. Retention periods vary depending on the nature of the data and the purpose of processing.
- Account and transaction records may be retained for the duration of the relationship and for a further period required by law.
- Support correspondence may be retained for a reasonable period needed to resolve issues and maintain service records.
- Technical logs may be kept for security, troubleshooting, and operational analysis for a limited period.
- Where consent is withdrawn and there is no other lawful basis for processing, the relevant personal data will be deleted or anonymized.
When retention is no longer necessary, data will be securely deleted, anonymized, or otherwise rendered unusable in line with our retention procedures. Retention is never indefinite unless legally required.
6. Processors and disclosures
We may share personal data with trusted third parties acting as data processors or independent controllers, as permitted by law. Processors only process personal data on documented instructions and are required to apply appropriate security and confidentiality measures.
Processors may include providers of:
- IT hosting and cloud infrastructure;
- payment processing and financial administration;
- customer support tools and communication systems;
- analytics, security, and fraud detection services;
- document storage, archiving, and business administration tools.
We may also disclose personal data to professional advisers, auditors, insurers, regulators, law enforcement authorities, or courts where necessary and lawful. If a transfer of personal data occurs outside the European Economic Area, appropriate safeguards will be implemented in accordance with GDPR requirements, such as standard contractual clauses or equivalent protections.
All processors are selected with care and are subject to contractual obligations concerning confidentiality, security, and data protection. No processor may use personal data for its own independent purposes unless it acts as a separate controller under law.
7. Security measures
We use administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, disclosure, alteration, or destruction. These measures may include access controls, encryption where appropriate, secure storage, role-based permissions, staff training, and monitoring for security incidents.
Although no system can be guaranteed completely secure, we continually review our controls and update them to reflect risk and best practices. In the event of a personal data breach that is likely to result in a risk to individuals, we will take action in accordance with applicable law, which may include notifying supervisory authorities and affected individuals where required.
8. User rights
Individuals whose personal data is processed under this policy have rights under GDPR. Subject to legal limitations and verification of identity, these rights may include:
- Right of access: to request confirmation of whether personal data is processed and obtain a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limited processing in specific cases.
- Right to data portability: to receive data in a structured, commonly used, machine-readable format and, where technically feasible, have it transferred to another controller.
- Right to object: to object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of prior processing.
- Right to complain: to raise concerns with a competent supervisory authority if an individual believes their rights have been infringed.
Requests relating to these rights will be assessed and handled within the time limits required by law. In some cases, we may need additional information to verify identity or determine whether a request can be fulfilled. If a request is refused or limited, we will explain the reason where permitted.
9. Children
The services are intended for customers in the area and are not directed to children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate authorization where required by law. If we become aware that personal data has been collected inappropriately, we will take reasonable steps to delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, service operations, or data processing practices. The revised version will apply from the date it is made effective. We encourage customers to review this policy periodically to remain informed about how personal data is handled.
Summary of commitments
- Transparency: we explain what data is collected and why.
- Lawfulness: we process data only where a valid GDPR basis applies.
- Minimization: we collect only data that is necessary.
- Retention control: we keep data only as long as required.
- Processor oversight: we use contractual and security safeguards.
- Rights protection: we respect and enable individual GDPR rights.
This policy applies to all customers in the area. By using the services, individuals acknowledge that their personal data may be processed in accordance with this Privacy Policy and applicable data protection laws.