Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected when customers use our services. It is designed to reflect the requirements of the General Data Protection Regulation (GDPR) and applies to all customers in the relevant area. By using our services, you acknowledge that your personal data may be processed in the ways described below.
1. Scope of this Policy
This Privacy Policy applies to all customers in area where our services are offered and where GDPR or equivalent data protection rules apply. It covers personal data collected through direct interactions, service use, account activity, communications, and any related administrative or operational processes. The policy is intended to provide clear information about what data we collect, why we collect it, how long we keep it, who processes it, and what rights you have.
2. Personal Data We Collect
We may collect and process different categories of personal data depending on the nature of our relationship with you and the services provided. The personal data collected may include:
- Identity data: name, title, username, or similar identifiers.
- Contact data: address details, email address, telephone number, or other communication details.
- Account data: login credentials, account preferences, and service settings.
- Transaction data: details of purchases, payments, service history, and related records.
- Technical data: IP address, device type, browser type, operating system, and usage logs.
- Usage data: information about how you interact with services, pages viewed, and actions taken.
- Communication data: records of correspondence, requests, and feedback.
- Compliance data: information required for legal, regulatory, fraud-prevention, or audit purposes.
We aim to collect only the personal data that is necessary, relevant, and proportionate to the purpose for which it is processed.
3. How We Use Personal Data
We use personal data for the following purposes:
- To provide, operate, and maintain services.
- To manage customer accounts and service access.
- To process transactions and deliver requested services.
- To communicate with customers regarding service updates, notices, or administration.
- To improve service performance, customer experience, and functionality.
- To monitor security, prevent fraud, and protect against unauthorized access.
- To comply with legal obligations and regulatory requirements.
- To establish, exercise, or defend legal claims.
We do not use personal data in a way that is incompatible with the purposes described in this policy unless required or permitted by law.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing personal data. Depending on the situation, we rely on one or more of the following bases:
4.1 Contract
We process personal data when it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This may include account management, service delivery, or transaction processing.
4.2 Legal Obligation
We process data when necessary to comply with a legal or regulatory duty, including tax, accounting, fraud prevention, consumer protection, and recordkeeping obligations.
4.3 Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Examples include service improvement, network security, operational management, and limited internal analytics.
4.4 Consent
In some cases, we rely on your consent, particularly for optional communications or specific categories of processing where consent is required. Where processing is based on consent, you have the right to withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
4.5 Vital Interests and Public Interest
In rare cases, we may process personal data where necessary to protect vital interests or where processing is carried out in the public interest or under official authority, as permitted by law.
5. Data Sharing and Processors
We may share personal data with trusted third parties who act as processors on our behalf. Processors are bound by contractual obligations to process data only according to our instructions and to implement appropriate security measures. Examples of processors may include:
- IT hosting and infrastructure providers.
- Payment processing services.
- Customer support and communication platforms.
- Analytics and service monitoring providers.
- Document storage, backup, and archive services.
- Professional advisers acting under confidentiality obligations.
We may also disclose personal data where required by law, court order, regulator request, or to protect our rights, customers, staff, or the public. Any disclosure is limited to what is necessary and proportionate.
6. International Transfers
If personal data is transferred outside the country or region where it was collected, we take steps to ensure an adequate level of protection. Such steps may include approved contractual safeguards, adequacy decisions, or other measures permitted under GDPR. We ensure that cross-border transfers do not reduce the protection of your personal data.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, tax, security, and dispute-resolution requirements. Retention periods vary depending on the type of data and the context of processing.
- Data related to active accounts is kept for the duration of the customer relationship.
- Transaction and financial records are retained for the period required by law.
- Customer support records are kept for a reasonable period to address ongoing issues or disputes.
- Security logs and technical records are retained for a limited period necessary for monitoring and protection.
When personal data is no longer required, it is securely deleted, anonymized, or otherwise disposed of in a lawful and safe manner.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff training, and regular review of security practices. No system can be guaranteed to be completely secure, but we work to maintain a level of protection appropriate to the risks involved.
9. Your Rights Under GDPR
Depending on the circumstances and applicable law, you may have the following rights regarding your personal data:
- Right of access: to request confirmation and obtain a copy of your personal data.
- Right to rectification: to correct inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain situations.
- Right to restriction: to limit how data is processed in certain cases.
- Right to data portability: to receive data in a structured, commonly used format and transmit it where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent.
- Right not to be subject to solely automated decisions: where such decisions produce legal or similarly significant effects, subject to legal exceptions.
These rights are not absolute and may be subject to legal limits or exceptions. We will assess each request in accordance with applicable law.
10. Exercising Your Rights
You may exercise your rights by making a request through the appropriate internal process. We may need to verify your identity before responding to protect your privacy and prevent unauthorized access. We will respond within the time limits required by GDPR, ordinarily within one month, unless an extension is permitted due to complexity or volume of requests.
11. Children’s Data
Our services are not intended for children unless specifically stated. If we become aware that personal data has been collected from a child without a valid lawful basis or appropriate authorization, we will take steps to delete or protect that data as required by law.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service arrangements. Any updated version will take effect when published or otherwise communicated as required. We encourage customers to review this policy periodically to stay informed about how personal data is handled.
13. General Statement
This policy is intended to ensure transparency, accountability, and lawful processing of personal data. It applies to all customers in area and should be read together with any other relevant data protection notices or terms that may apply to specific services. By continuing to use our services, you acknowledge that you have read and understood this Privacy Policy.
