Privacy Policy
This Privacy Policy explains how we collect, use, store, share, and protect personal data when providing our products and services. It applies to all customers in area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and other applicable data protection laws. We are committed to processing personal data lawfully, fairly, and transparently, and to respecting the rights of individuals whose data we handle.
1. Who This Policy Applies To
This Policy applies to individuals who are customers, prospective customers, users, account holders, and other persons whose personal data we process in connection with our services. It applies to all customers in area, regardless of how they interact with us, including online, in person, or through third parties acting on their behalf.
2. Personal Data We Collect
We may collect and process personal data that identifies you directly or indirectly. The categories of data we collect depend on your relationship with us and the services used.
Information you provide
- Identity data such as name, title, and date of birth where relevant.
- Contact data such as address, email address, and telephone number.
- Account data such as usernames, customer identifiers, and preferences.
- Transaction data such as purchase records, payment status, and service history.
- Communication data such as messages, complaints, feedback, and support requests.
Information we collect automatically
- Technical data such as IP address, browser type, device information, operating system, and log data.
- Usage data such as how you interact with our services, pages viewed, and time spent on features.
- Security data such as authentication records and fraud-prevention signals.
Information from third parties
We may receive personal data from payment providers, delivery providers, service partners, public sources, or other third parties where permitted by law. We only collect data from third parties when there is a lawful basis to do so and when it is relevant to our services.
3. How We Use Personal Data
We use personal data only for specified, explicit, and legitimate purposes. These include:
- providing and managing our services;
- processing orders, payments, and related transactions;
- creating and maintaining customer accounts;
- communicating service updates, notices, and administrative messages;
- handling complaints, inquiries, and support requests;
- preventing fraud, misuse, and security incidents;
- complying with legal obligations;
- improving our services, systems, and customer experience;
- where permitted, sending marketing communications based on your choices and applicable law.
We will not process personal data in a manner that is incompatible with the purposes for which it was collected unless we have a valid legal basis and, where necessary, additional notice or consent.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing personal data. Depending on the activity, we rely on one or more of the following:
Contract
We process personal data where it is necessary to enter into or perform a contract with you, such as providing services, managing accounts, or fulfilling orders.
Legal obligation
We may process data to comply with legal and regulatory obligations, including tax, accounting, consumer protection, fraud prevention, and record-keeping requirements.
Legitimate interests
We may process data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Examples include service improvement, analytics, security, and internal administration.
Consent
Where required, we rely on your consent, for example for certain marketing activities or optional data uses. When consent is used, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Vital interests and public task
In rare cases, we may process personal data to protect vital interests or where processing is necessary for a public task or official authority, if applicable.
5. Sharing Personal Data and Processors
We may share personal data with trusted third parties that help us operate our services. These parties act as either processors or independent controllers, depending on the relationship and the purpose of processing.
Processors
Processors handle personal data on our behalf and under our instructions. They may include providers of:
- IT hosting and infrastructure;
- cloud storage and backup;
- payment processing;
- customer support tools;
- analytics and reporting systems;
- security, monitoring, and fraud detection services;
- document management and communications platforms.
We require processors to implement appropriate technical and organizational security measures and to process personal data only in accordance with our instructions and applicable law.
Other disclosures
We may also disclose personal data where necessary to:
- comply with legal obligations or lawful requests;
- protect our rights, property, or safety;
- respond to disputes or enforce agreements;
- support corporate transactions such as mergers, reorganizations, or asset transfers, subject to legal safeguards.
Where personal data is shared with independent controllers, those parties are responsible for their own processing and privacy practices.
6. International Transfers
If personal data is transferred outside the European Economic Area or the United Kingdom, we will ensure appropriate safeguards are in place. These may include adequacy decisions, Standard Contractual Clauses, or equivalent legal mechanisms. We also assess transfer risks and apply supplementary measures where needed to protect personal data.
7. Data Retention
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, tax, dispute resolution, and enforcement requirements.
Retention periods vary depending on the type of data and the reason for processing. In general:
- account and service data are retained for the period of the customer relationship and for a reasonable time afterward;
- transaction and financial records are retained for statutory periods required by law;
- support communications may be retained for quality, training, and record-keeping purposes;
- security and audit logs are retained for a limited period unless a longer period is required to investigate incidents or comply with legal obligations.
When personal data is no longer needed, we will securely delete, anonymize, or archive it in accordance with our retention practices.
8. Your Rights Under GDPR
Depending on your circumstances and the legal basis for processing, you may have the following rights:
Right of access
You may request confirmation of whether we process your personal data and obtain a copy of that data, along with relevant information about how it is used.
Right to rectification
You may ask us to correct inaccurate or incomplete personal data.
Right to erasure
In certain situations, you may request deletion of your personal data, for example where it is no longer needed or where you withdraw consent and no other lawful basis applies.
Right to restriction
You may request that we restrict processing in specific cases, such as while accuracy is being verified or where you object to processing.
Right to data portability
Where processing is based on consent or contract and carried out by automated means, you may request a copy of your personal data in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller.
Right to object
You may object to processing based on legitimate interests, including profiling based on those interests. You also have an absolute right to object to direct marketing.
Rights related to automated decision-making
You have the right not to be subject to a decision based solely on automated processing, including profiling, if that decision produces legal or similarly significant effects, except where permitted by law.
Where processing is based on consent, you may withdraw consent at any time. Exercising your rights will not generally affect the lawfulness of processing carried out before your request was received.
9. How We Respond to Rights Requests
We will respond to valid requests within the time limits required by GDPR, usually within one month, subject to extensions where permitted. To protect privacy and security, we may need to verify your identity before acting on your request. In some cases, legal exceptions may apply, and we may not be able to fully comply with every request.
10. Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, encryption where appropriate, logging, staff training, and regular review of security practices. However, no system can be guaranteed completely secure, and we encourage customers to take care when sharing information.
11. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate authorization where required by law. If we learn that we have collected such data without lawful basis, we will take appropriate steps to delete it or obtain necessary consent.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services, or our data practices. Any updated version will apply from the date it becomes effective. We encourage you to review this Policy periodically to stay informed about how we protect personal data.
13. General Statement
This Privacy Policy is designed to ensure that personal data is handled in a lawful, fair, and transparent manner. It applies to all customers in area and to all processing activities carried out in connection with our services, subject to the rights and obligations set out in applicable data protection law. By using our services, you acknowledge that your data may be processed as described in this Policy, where lawful and necessary, and always with appropriate safeguards in place.
