Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with our services. It applies to all customers in the area where our services are offered and used, regardless of whether access is obtained online, in person, or through any other channel. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
1. Personal Data We Collect
We may collect and process personal data that is necessary to provide our services, manage customer relationships, operate our business, and comply with legal obligations. The categories of data we may collect include:
- Identity data such as name, title, and, where applicable, business role.
- Contact data such as billing details, postal address, and delivery information.
- Account and transaction data such as service history, purchase records, invoices, payment status, and related correspondence.
- Technical data such as device identifiers, browser type, IP address, and usage information when systems or digital services are used.
- Communication data such as records of inquiries, feedback, complaints, and other interactions.
- Preference data such as language choice, service preferences, and marketing choices where provided.
We collect data directly from customers when they provide it to us, and in some cases from third parties such as payment providers, service partners, or publicly available sources, where permitted by law. We only collect data that is relevant and limited to what is necessary for the stated purposes.
2. How We Use Personal Data
We use personal data for the following purposes:
- To provide and deliver our products and services.
- To manage accounts, orders, payments, and customer support.
- To communicate important service-related information.
- To maintain records, prevent fraud, and ensure security.
- To improve service quality, operations, and customer experience.
- To comply with legal and regulatory obligations.
- To send marketing communications where we are permitted to do so and where relevant consent or legitimate interest applies.
We do not use personal data in ways that are incompatible with the purposes described above unless we obtain a valid lawful basis to do so.
3. Lawful Basis for Processing
Under the GDPR, every processing activity must rely on a lawful basis. Depending on the context, we may process personal data on one or more of the following grounds:
Contract
We process data when it is necessary to enter into or perform a contract with a customer, including providing services, processing orders, and handling payments.
Legal Obligation
We process data when required to comply with applicable laws, including tax, accounting, consumer protection, and regulatory requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the rights and freedoms of the individual. Such interests may include protecting our systems, preventing fraud, improving services, and maintaining business records.
Consent
Where required by law, we rely on consent for specific processing activities, such as certain marketing communications or optional data collection. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Data Sharing and Processors
We may share personal data with trusted service providers and other third parties that act as processors or independent controllers, depending on the nature of the relationship and the purpose of the disclosure. Processors only act on our documented instructions and are required to protect personal data appropriately.
Examples of processors may include:
- Payment processing providers.
- IT hosting and cloud service providers.
- Customer relationship and support service providers.
- Accounting, auditing, and record management services.
- Security and fraud prevention services.
We may also disclose personal data where required by law, court order, or lawful request from public authorities. If a business transfer, merger, restructuring, or similar event occurs, personal data may be transferred as part of that transaction subject to appropriate safeguards.
We do not sell personal data in exchange for money. Any sharing is limited to what is necessary for the relevant purpose and is subject to appropriate contractual and technical protections.
5. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with comparable protections, we ensure that appropriate safeguards are in place. These may include standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms. We take steps to ensure that any cross-border transfer respects the rights of individuals and the confidentiality of their data.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including the need to meet legal, accounting, tax, and contractual obligations. Retention periods may vary based on the type of data, the nature of the relationship, and legal requirements.
In general:
- Contract and transaction data may be retained for the duration of the customer relationship and for a further period required by law.
- Communication records may be retained for a reasonable period to support service, dispute handling, and quality assurance.
- Marketing preferences are retained until consent is withdrawn or the individual objects to processing.
- Technical and security logs are retained for periods necessary to maintain system integrity, investigate incidents, and prevent misuse.
When personal data is no longer required, it is securely deleted, anonymized, or archived in accordance with our retention practices. Retention is reviewed periodically to ensure data is not kept longer than necessary.
7. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, monitoring, staff training, and vendor oversight. While no system can be guaranteed to be completely secure, we maintain safeguards designed to reduce risk and protect data in line with industry standards.
8. User Rights
Individuals whose personal data we process have rights under the GDPR, subject to conditions and exceptions provided by law. These rights may include:
- Right of access to obtain confirmation of whether personal data is processed and to receive a copy of that data.
- Right to rectification to request correction of inaccurate or incomplete data.
- Right to erasure in certain circumstances, such as when data is no longer needed or consent is withdrawn.
- Right to restriction to limit processing in certain cases.
- Right to data portability to receive data in a structured, commonly used, machine-readable format where applicable.
- Right to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent at any time where processing is based on consent.
- Right not to be subject to automated decision-making where such decisions have legal or similarly significant effects, except where permitted by law.
Requests relating to these rights will be handled in accordance with applicable legal requirements. We may need to verify identity before responding to a request. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act where permitted by law.
9. Children’s Data
Our services are intended for customers who are legally able to enter into the relevant relationship. We do not knowingly collect personal data from children without appropriate authorization or a lawful basis. If we become aware that data has been collected inappropriately, we will take steps to delete or secure it as required.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service offerings. When changes are made, the updated policy will apply from the effective date of the revised version. Customers should review this policy periodically to stay informed about how personal data is handled.
11. General Statement
This Privacy Policy is intended to provide a clear overview of our data processing practices. We aim to act with transparency, accountability, and respect for individual privacy rights. Where local law provides stronger protections, those protections will apply. All customers in the area are covered by this policy when using our services or otherwise interacting with us in connection with the services offered.
Summary of key principles:
- We collect only data that is necessary and relevant.
- We process data on lawful grounds such as contract, legal obligation, legitimate interests, or consent.
- We share data only with appropriate processors and authorized recipients.
- We retain data only as long as needed.
- We respect and facilitate GDPR rights.
This policy reflects a privacy-first approach designed to ensure lawful and responsible handling of personal data.
