Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected for all customers in the area. It applies to all services, products, and related interactions covered by this policy. We are committed to processing personal data in a lawful, fair, and transparent manner in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
1. Data We Collect
We may collect and process different categories of personal data depending on how you interact with us. The types of information may include:
- Identity data such as your name, title, and similar identifiers.
- Contact data such as billing details, delivery details, and communication preferences.
- Transaction data such as records of purchases, payments, and related interactions.
- Technical data such as device type, browser information, IP address, and system settings.
- Usage data such as pages or features used, session activity, and service interactions.
- Preference data such as marketing choices and service settings.
We generally collect personal data directly from you when you provide it, and we may also obtain it from legitimate third-party sources where appropriate. We collect only the information necessary for the purposes described in this policy and avoid unnecessary or excessive collection.
2. How We Use Personal Data
Personal data may be used for the following purposes:
- To provide and manage products or services.
- To process transactions and maintain records.
- To communicate with you about service-related matters.
- To improve service quality, performance, and user experience.
- To comply with legal, regulatory, and contractual obligations.
- To detect, prevent, and investigate fraud, misuse, or security incidents.
- To send marketing communications where permitted by law and where you have not opted out.
We will not use your personal data for purposes that are incompatible with the original collection purpose unless we have a lawful basis to do so and, where required, we notify you.
3. Lawful Basis for Processing
We process personal data only where a lawful basis under GDPR applies. Depending on the context, our lawful bases may include:
Contract
We process data when it is necessary to enter into or perform a contract with you, such as delivering services, managing requests, or handling payments.
Legal Obligation
We may process data where necessary to comply with legal duties, including tax, accounting, consumer protection, or regulatory requirements.
Legitimate Interests
We may process data for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Such interests may include service improvement, fraud prevention, network security, internal administration, and business development.
Consent
Where required, we rely on your consent, for example for certain marketing communications or optional data uses. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Task
In rare cases, we may process personal data to protect vital interests or to carry out tasks in the public interest where applicable law allows.
4. Retention of Personal Data
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including for any legal, accounting, reporting, or dispute-resolution requirements. Retention periods depend on the nature of the data and the purpose of processing.
- Data used to provide services is retained for the duration of the customer relationship and for a reasonable period thereafter.
- Financial and transaction records may be retained longer where required by law.
- Technical and usage data may be retained for security, analytics, and system integrity purposes for a limited period.
- Where data is no longer needed, it is securely deleted, anonymised, or otherwise irreversibly destroyed.
In some situations, we may retain data for longer if it is necessary to establish, exercise, or defend legal claims. Retention is always limited to what is necessary and proportionate.
5. Sharing and Processors
We may share personal data with trusted third parties that act as processors on our behalf. These processors are only permitted to process personal data according to our documented instructions and must implement appropriate security measures.
Examples of processors may include:
- Payment service providers.
- IT and cloud hosting providers.
- Customer service and communication support providers.
- Analytics and performance monitoring providers.
- Professional advisers assisting with legal, accounting, or compliance matters.
We may also disclose personal data where required by law, court order, or regulatory request, or where disclosure is necessary to protect rights, safety, or security. Any transfer of personal data is handled with appropriate safeguards, including contractual and technical protections where required.
6. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with comparable protections, we will ensure that appropriate safeguards are in place. These may include standard contractual clauses, adequacy decisions, or other legally recognized transfer mechanisms. We take reasonable steps to ensure that your data remains protected to a standard consistent with GDPR requirements.
7. Data Security
We use suitable technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and periodic security reviews.
However, no method of transmission or storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security. If a personal data breach occurs, we will respond in line with applicable legal obligations.
8. Your Rights Under GDPR
Subject to applicable law, you have several rights in relation to your personal data. These rights include:
- Right of access – to request confirmation of whether we process your data and obtain a copy of it.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of data in certain circumstances.
- Right to restriction – to request limited processing in specific situations.
- Right to data portability – to receive your data in a structured, commonly used format, where applicable.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent.
- Right to lodge a complaint – with a relevant supervisory authority if you believe your rights have been infringed.
We may need to verify your identity before responding to a rights request. We aim to respond within the timeframes required by law. If a request is complex or numerous, the response period may be extended in accordance with GDPR.
9. Automated Decision-Making
Where we use automated processes that may significantly affect you, we will do so only when permitted by law and with appropriate safeguards. You may have the right to obtain human intervention, express your point of view, and challenge a decision where applicable.
10. Children’s Data
Our services are intended for adults or for users who are legally able to consent under applicable law. We do not knowingly collect personal data from children where such collection is not permitted. If we become aware that data has been collected inappropriately, we will take reasonable steps to delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or operational needs. Any updated version will apply from the date it becomes effective. We encourage you to review this policy periodically so that you remain informed about how your personal data is handled.
12. Scope and Applicability
This Privacy Policy applies to all customers in the area and to all personal data processed in connection with the services covered by this policy. By continuing to use the relevant services or by providing personal data, you acknowledge that your information will be processed in accordance with this Privacy Policy and applicable data protection law.
We are committed to respecting privacy, limiting data use, and maintaining transparency in every stage of processing.
