Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when providing services to all customers in the area. It is designed to reflect the requirements of the General Data Protection Regulation (GDPR) and applies to all individuals whose personal data is processed in connection with our services. By using our services, customers acknowledge that their information may be handled as described in this policy.
1. Scope and Purpose
This policy applies to all customers in the area and covers personal data collected through service interactions, account activity, communications, transactions, and any related support or administrative processes. The purpose of processing personal data is to deliver services efficiently, maintain service quality, meet legal obligations, protect legitimate business interests, and support customer requests. We are committed to processing data fairly, transparently, and only for specified and lawful purposes.
2. Data Collection
We may collect and process the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: email address, phone number, postal address, or other communication details.
- Service data: records of purchases, requests, preferences, feedback, and service history.
- Technical data: device type, browser information, IP address, and usage details.
- Financial data: payment-related information and transaction records, where necessary.
- Communication data: messages, complaints, and correspondence related to the services.
Personal data may be collected directly from customers, generated through the use of our services, or provided by authorized third parties acting on behalf of the customer. We limit collection to data that is relevant and necessary for the intended purpose.
3. Lawful Basis for Processing
We process personal data only when there is a valid lawful basis under GDPR. Depending on the nature of the processing, we may rely on one or more of the following:
- Contract: processing is necessary to perform a contract with the customer or to take steps before entering into one.
- Legal obligation: processing is required to comply with applicable laws, regulations, tax rules, or regulatory duties.
- Legitimate interests: processing is necessary for our legitimate business interests, provided those interests do not override customer rights and freedoms.
- Consent: where required, personal data will be processed based on freely given, specific, informed, and unambiguous consent.
- Vital interests: in rare cases, processing may be necessary to protect someone’s vital interests.
When consent is used as the lawful basis, customers may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
4. How We Use Personal Data
Personal data may be used for the following purposes:
- to provide, operate, and maintain services;
- to process transactions and manage customer relationships;
- to respond to questions, complaints, and requests;
- to improve service quality, security, and functionality;
- to comply with legal and regulatory obligations;
- to detect, prevent, and address fraud, misuse, or security incidents;
- to manage internal administration, reporting, and recordkeeping.
We will not use personal data in a manner that is incompatible with the purposes for which it was collected, unless we have a lawful basis to do so and customers are informed where required.
5. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, reporting, or dispute-resolution requirements. Retention periods may vary depending on the type of data and the reason for processing.
In determining retention periods, we consider:
- the amount, nature, and sensitivity of the data;
- the risk of harm from unauthorized use or disclosure;
- the purposes of processing and whether they can be achieved by other means;
- applicable legal requirements and limitation periods.
When personal data is no longer required, we will securely delete, anonymize, or archive it in accordance with our retention procedures.
6. Sharing with Processors and Other Recipients
We may share personal data with trusted processors who act on our behalf and under our instructions. These may include service providers that support hosting, IT systems, payment processing, customer support, analytics, security, and administrative operations. All processors are required to handle personal data securely, use it only for agreed purposes, and comply with GDPR-related contractual obligations.
We may also disclose personal data where necessary to:
- comply with legal obligations or lawful requests from public authorities;
- protect our rights, property, and safety, or those of others;
- support the prevention or investigation of suspected fraud or security incidents;
- complete a business reorganization, merger, or similar corporate event, subject to appropriate safeguards.
We do not sell personal data. Any sharing is limited to what is necessary and proportionate for the intended purpose.
7. International Transfers
Where personal data is transferred outside the European Economic Area or another region with equivalent data protection laws, we will ensure appropriate safeguards are in place. These safeguards may include standard contractual clauses, adequacy decisions, or other legally recognized transfer mechanisms. We take steps to ensure that transferred data remains protected to a standard consistent with GDPR requirements.
8. Security Measures
We apply appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. Such measures may include access controls, encryption where appropriate, secure storage, staff training, and regular review of internal procedures.
While no system can be guaranteed fully secure, we continuously work to reduce risks and maintain a level of protection appropriate to the nature of the data and the processing involved.
9. User Rights
Customers have rights under GDPR regarding their personal data. Subject to legal conditions and exemptions, these rights may include:
- Right of access: to obtain confirmation of whether personal data is being processed and to receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limited processing in specific situations.
- Right to data portability: to receive personal data in a structured, commonly used format and, where feasible, have it transmitted to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time.
Customers also have the right to lodge a complaint with a supervisory authority if they believe their data has been processed unlawfully or their rights have not been respected.
10. Children’s Data
Our services are not intended to knowingly collect personal data from children without appropriate authorization or legal basis. If we become aware that such data has been collected in error, we will take reasonable steps to delete it promptly unless we are legally required to retain it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service offerings. When changes are made, the updated version will apply from the date it takes effect. Customers are encouraged to review the policy periodically to stay informed about how personal data is handled.
Summary of Key Principles
- Transparency: we explain what data is collected and why.
- Lawfulness: we process data only on valid GDPR bases.
- Purpose limitation: data is used only for stated purposes.
- Data minimization: we collect only what is necessary.
- Security and accountability: we protect data and maintain responsibility for its handling.
This Privacy Policy applies to all customers in the area. By continuing to use our services, customers acknowledge that their personal data may be processed in accordance with this policy and applicable data protection laws.
