Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected when individuals interact with our services. It applies to all customers in the area and is intended to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our services, customers acknowledge that their personal data may be processed as described in this Policy.
1. Data We Collect
We collect only the personal data that is necessary for lawful, specific, and legitimate purposes. Depending on how services are used, we may collect the following categories of information:
- Identity data: name, surname, title, and similar identifiers.
- Contact data: email address, telephone number, billing address, or other communication details.
- Transaction data: records of purchases, payments, invoices, and service history.
- Technical data: device information, IP address, browser type, operating system, and usage logs.
- Profile data: preferences, feedback, service choices, and correspondence.
- Compliance data: records required for fraud prevention, legal compliance, or dispute resolution.
We do not intentionally collect special category data unless it is strictly necessary and we have a valid legal basis to do so. If such data is ever collected, it will be handled with enhanced protection and only for a lawful purpose.
2. How We Use Personal Data
Personal data is processed for clearly defined purposes, including the following:
- To provide and manage services requested by customers.
- To process transactions, payments, and related records.
- To communicate about service updates, account matters, and operational notices.
- To maintain security, prevent fraud, and investigate misuse.
- To comply with legal and regulatory obligations.
- To improve service quality, efficiency, and customer experience.
We will not use personal data in a way that is incompatible with these purposes unless required or permitted by law.
3. Lawful Basis for Processing
Under GDPR, we only process personal data when we have a valid lawful basis. Depending on the activity, the lawful basis may include:
- Performance of a contract: processing is necessary to deliver services, manage accounts, or fulfill agreed obligations.
- Legal obligation: processing is necessary to comply with tax, accounting, consumer protection, or other legal requirements.
- Legitimate interests: processing is necessary for our legitimate business interests, provided those interests are not overridden by the individual’s rights and freedoms. This may include fraud prevention, internal administration, security, and service improvement.
- Consent: where required by law, we will process personal data only after obtaining clear and informed consent. Consent may be withdrawn at any time.
When we rely on legitimate interests, we assess the impact of processing and apply safeguards to ensure fairness and proportionality. We aim to keep all processing transparent and limited to what is necessary.
4. Data Sharing and Processors
We may share personal data with trusted third parties who act as data processors or, in some cases, independent controllers. These parties are engaged only when necessary and are required to protect personal data in accordance with GDPR.
Examples of processors may include:
- IT and hosting providers: for secure storage, infrastructure, and system administration.
- Payment service providers: for processing payments and preventing fraud.
- Customer support systems: for handling inquiries, service requests, and communications.
- Analytics providers: for evaluating usage patterns and improving services.
- Professional advisers: such as legal, accounting, or compliance specialists where necessary.
All processors are subject to contractual obligations requiring them to process personal data only on our instructions, keep it confidential, and implement appropriate technical and organizational security measures. Where data is transferred outside the European Economic Area, such transfers will be protected using approved safeguards such as adequacy decisions or standard contractual clauses.
5. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, reporting, or dispute-resolution requirements. Retention periods vary depending on the type of data and the purpose of processing.
- Contract and transaction records: retained for the period required to manage the relationship and meet statutory obligations.
- Customer support records: retained for as long as needed to resolve issues and maintain service history.
- Technical logs: retained for a limited period for security, diagnostics, and performance monitoring.
- Consent records: retained to demonstrate compliance with applicable legal requirements.
When personal data is no longer required, it is securely deleted, anonymized, or archived in a manner consistent with applicable law. We do not keep data indefinitely without a lawful reason.
6. Security Measures
We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, monitoring, and periodic security reviews. Although no system can be guaranteed to be completely secure, we continuously work to maintain a high standard of protection.
7. Your Rights Under GDPR
Individuals have a range of rights regarding their personal data. Subject to legal conditions and exceptions, these rights include:
- Right of access: to obtain confirmation of whether personal data is being processed and receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction of processing: to ask us to limit processing in specific situations.
- Right to data portability: to receive data in a structured, commonly used, machine-readable format and transmit it elsewhere where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, that consent may be withdrawn at any time.
- Right to lodge a complaint: to contact a supervisory authority if you believe your rights have been infringed.
Requests relating to these rights will be handled without undue delay and in accordance with GDPR timelines. We may request verification information to confirm identity before responding to a request. Exercise of rights will not result in unfair treatment.
8. Children’s Data
Our services are not intended for children unless specifically stated otherwise. If we become aware that personal data has been collected from a child without appropriate authorization, we will take steps to delete it or obtain valid consent where required by law.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or technical changes. Any revised version will apply from the date it is made available. Customers are encouraged to review the Policy periodically to remain informed about how personal data is handled.
10. General Statement
This Privacy Policy applies to all customers in the area and governs the processing of personal data in connection with our services. We are committed to respecting privacy, maintaining transparency, and ensuring that personal data is handled lawfully, fairly, and securely. Protecting personal data is a core part of our responsibility.
