Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area and is intended to provide a clear explanation of our data protection practices in accordance with applicable privacy laws, including the General Data Protection Regulation (GDPR).
1. Introduction
We are committed to respecting your privacy and handling personal data in a lawful, fair, and transparent manner. Personal data means any information relating to an identified or identifiable individual. This may include names, contact details, account information, transaction details, communication records, device information, and any other data that can reasonably be linked to a person.
This Privacy Policy applies to all customers in the area who interact with our services, products, systems, or communications. By using our services, you acknowledge that your data may be processed as described in this Policy.
2. Data We Collect
We collect only the data that is necessary for the purposes described in this Policy. Depending on how you interact with us, we may collect the following categories of data:
- Identity data such as your name, title, or similar identifiers.
- Contact data such as billing address, delivery address, email address, and telephone number.
- Account data such as login details, preferences, and profile settings.
- Transaction data such as purchase history, payment status, and service records.
- Technical data such as IP address, browser type, device identifiers, and usage logs.
- Communication data such as inquiries, complaints, feedback, and correspondence.
- Marketing preferences such as your choices regarding promotional messages, where applicable.
We do not intentionally collect more information than is needed for legitimate operational, contractual, or legal purposes. Where sensitive personal data is involved, we will only process it when a valid legal ground exists and additional safeguards are in place.
3. How We Use Personal Data
We process personal data for specific, explicit, and legitimate purposes. These purposes may include:
- providing and managing services;
- processing transactions and related records;
- creating and maintaining customer accounts;
- responding to inquiries and support requests;
- ensuring security, preventing fraud, and detecting misuse;
- meeting legal and regulatory obligations;
- improving service quality, performance, and user experience;
- sending operational notices and, where permitted, marketing communications.
We will not use your data in a way that is incompatible with the original purpose for which it was collected, unless we have a lawful basis to do so.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process personal data. Depending on the activity, our lawful bases may include:
4.1 Performance of a Contract
We process personal data when it is necessary to enter into or perform a contract with you. This includes managing services, processing orders, issuing invoices, and fulfilling customer requests.
4.2 Legal Obligation
We may process personal data where required to comply with legal duties, such as tax, accounting, consumer protection, fraud prevention, or recordkeeping requirements.
4.3 Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Legitimate interests may include maintaining service security, improving operations, managing customer relationships, and preventing abuse.
4.4 Consent
In certain situations, we may rely on your consent, for example where the law requires it or where you choose to receive optional communications. When processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
5. Sharing and Processors
We may share personal data with trusted third parties only when necessary and subject to appropriate safeguards. Such third parties may act as processors or independent controllers depending on the nature of the relationship. Processors handle data on our behalf and only according to our documented instructions.
Examples of processors may include:
- hosting and cloud service providers;
- payment processing services;
- customer support and communication tools;
- IT maintenance, security, and backup providers;
- analytics and performance monitoring services;
- professional advisers such as auditors or legal consultants, where necessary.
Where data is shared, we require processors to implement appropriate technical and organizational measures to protect personal data. They are not permitted to use it for their own purposes unless they are acting as independent controllers under applicable law.
We may also disclose data if required by law, court order, or valid request from a public authority. Any such disclosure will be limited to what is necessary and proportionate.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to meet legal, accounting, or reporting obligations. Retention periods may vary depending on the type of data and the reason for processing.
In general, we consider the following when determining retention periods:
- the duration of our relationship with you;
- any legal obligation to keep records;
- limitation periods for legal claims;
- operational and security requirements;
- whether continued storage is necessary for a legitimate purpose.
When personal data is no longer required, it will be securely deleted, anonymized, or archived in a manner that prevents identification, unless further retention is required by law.
7. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, unlawful destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff training, and monitoring of systems.
Although we take reasonable steps to protect personal data, no method of transmission or storage is completely secure. We therefore cannot guarantee absolute security, but we continuously assess and improve our safeguards.
8. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with comparable protections, we will ensure that adequate safeguards are in place. These safeguards may include standard contractual clauses, approved transfer mechanisms, or other lawful protections required under GDPR.
9. Your Rights
Subject to conditions and exceptions under applicable law, you have the following rights regarding your personal data:
- Right of access – to obtain confirmation and a copy of your personal data.
- Right to rectification – to correct inaccurate or incomplete data.
- Right to erasure – to request deletion of your data where legally permitted.
- Right to restriction – to limit processing in certain circumstances.
- Right to data portability – to receive your data in a structured, commonly used format where applicable.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent.
- Right to lodge a complaint – with the relevant supervisory authority if you believe your rights have been infringed.
We will respond to valid requests within the time limits required by law. In some cases, we may need to verify your identity before acting on a request.
10. Automated Decision-Making
We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects, unless permitted by law and accompanied by appropriate safeguards. If such processing is introduced, we will provide clear information and the available rights.
11. Children’s Data
Our services are not intended to knowingly collect personal data from children without appropriate authorization where required by law. If we become aware that such data has been collected unlawfully, we will take reasonable steps to delete it.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service offerings. Any updated version will apply from the date it is made available. We encourage you to review this Policy periodically to remain informed about how personal data is handled.
13. Summary of Core Principles
We process personal data in a manner that is lawful, fair, and transparent. We collect data for defined purposes, use it only when a lawful basis exists, retain it only as long as necessary, and share it only with appropriate processors or where required by law. We respect the rights of all customers in the area and aim to uphold privacy as a fundamental principle in every stage of processing.
This Policy is intended to be read together with any applicable contractual terms and legal notices governing the use of our services.
