Privacy Policy -
Introduction
This Privacy Policy explains how we collect, use, disclose and safeguard personal data relating to our customers. It applies to all customers in the area and governs personal data processed in the provision of our services. By using our services, you acknowledge that your personal data will be handled in accordance with this policy and applicable data protection laws, including the General Data Protection Regulation (GDPR).
Who We Are and Scope
We act as the data controller for the personal data collected and processed in connection with our services. This policy applies to personal data collected directly from customers, through our applications and systems, and from third-party sources where relevant. It covers all processing activities carried out in relation to customers in the area.
Types of Personal Data Collected
- Identity and contact data: name, postal address, email, telephone numbers.
- Account and transaction data: user ID, purchase history, invoices, payment confirmations.
- Payment data: card or bank details processed by payment processors; we do not store full card data on our servers unless explicitly required for business operations and with appropriate safeguards.
- Technical and usage data: IP address, device identifiers, browser type, operating system, log files, error reports.
- Location data: when necessary to provide or improve services and where permitted by law.
- Marketing and preference data: language, communication preferences, marketing consents and responses to promotions.
- Sensitive data: we do not routinely process special categories of personal data (such as health, racial or ethnic origin, political opinions) unless you provide explicit consent or where processing is otherwise permitted by law. Where special categories are processed, we will do so only on a lawful basis and with heightened safeguards.
Lawful Basis for Processing
We rely on the following lawful bases under GDPR for processing personal data:
- Performance of a contract: processing necessary to perform our contractual obligations to you, such as fulfilling orders, delivering services, billing and customer support.
- Legal obligation: processing necessary to comply with legal requirements, including tax, accounting and regulatory obligations.
- Legitimate interests: processing necessary for our legitimate business interests and those of third parties, such as fraud prevention, IT security, network and infrastructure management, and improving services, provided those interests are not overridden by your rights and freedoms.
- Consent: where required (for example, for marketing communications, certain analytics, or processing of special categories of data), we will obtain your freely given, specific, informed and unambiguous consent. You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
How We Use Personal Data
We use personal data to:
- Provide, maintain and improve our products and services.
- Process transactions and manage accounts.
- Communicate with customers about service updates, orders, and support requests.
- Deliver targeted and relevant marketing communications where consent has been obtained or where otherwise permitted.
- Comply with legal and regulatory obligations.
- Protect our rights, property and safety, and those of our customers, partners and employees.
Automated Decision Making
We may use automated processing to support customer service and fraud prevention. Where automated decisions produce legal effects or similarly significantly affect you, we will provide information about the logic involved and the consequences and provide recourse to human review where required by law.
Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected and to satisfy legal, regulatory, tax or accounting requirements. Typical retention periods include:
- Account and transactional records: retained for the duration of the business relationship plus applicable statutory retention periods (for example, financial records may be retained for up to 7 years to meet tax and accounting obligations).
- Marketing preferences and consents: retained until you withdraw consent or opt out.
- Support and communications records: retained for a reasonable period to document interactions and to improve service quality.
- Analytics and log data: retained for limited periods (for example, 12–36 months) unless longer retention is justified by legitimate interests and documented assessments.
Once data is no longer required, we securely delete, anonymize or aggregate it so that it cannot be associated with identifiable individuals.
Processors and Third Parties
We engage third-party processors to perform services on our behalf. These processors are authorized to process personal data only on our instructions and are subject to data processing agreements that impose GDPR-compliant obligations. Typical categories of processors include:
- Payment and billing processors.
- Cloud hosting and infrastructure providers.
- Email and messaging platforms.
- Customer relationship management and support platforms.
- Analytics, advertising and performance measurement services.
Where personal data is transferred outside the European Economic Area (EEA), we implement appropriate safeguards such as adequacy decisions, standard contractual clauses, or binding corporate rules to ensure an adequate level of protection.
Your Rights
You have the following rights regarding your personal data under GDPR, subject to applicable legal limitations:
- Right of access: request copies of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure (right to be forgotten): request deletion of data where there is no lawful reason for continued processing.
- Right to restriction of processing: request restriction of processing where accuracy, legality, or our legitimate interests are contested.
- Right to data portability: receive personal data you provided in a structured, commonly used and machine-readable format where processing is based on consent or contract and carried out by automated means.
- Right to object: object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: withdraw consent at any time for processing based on consent without affecting the lawfulness of processing prior to withdrawal.
- Right to lodge a complaint: if you believe our processing of your personal data infringes applicable law, you have the right to lodge a complaint with a supervisory authority.
To exercise your rights, you may use the privacy or account features available in our services or the channels and mechanisms provided in your account interface. We will respond to requests in accordance with applicable law, typically within one month, which may be extended by two further months for complex requests.
Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction or damage. Measures include access controls, encryption, pseudonymization where appropriate, secure development practices, monitoring, and staff training. Despite these measures, no system can be completely secure and we cannot guarantee absolute security.
Changes to this Policy
We may update this policy to reflect changes in our practices, legal obligations or services. Where changes are material, we will notify customers through the services or other appropriate means. Continued use of our services after notification constitutes acceptance of the updated policy.
Final Remarks
We are committed to protecting your privacy and to handling personal data responsibly. This policy applies to all customers in the area and provides an overview of how we collect, use, retain and protect personal data and the rights available to you. If you need to exercise your rights, please use the mechanisms provided in your account or service interface.
Thank you for trusting us with your personal data.
