Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area where our services are offered. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with applicable data protection laws, including the GDPR where relevant.
1. Scope of This Policy
This Privacy Policy applies to personal data processed when individuals use our services, make inquiries, enter into agreements with us, or otherwise interact with us. It covers data received directly from customers, data generated through service use, and data obtained from third parties where permitted by law. It applies to all customers in the area and to any other individuals whose personal data we process in connection with those services.
2. Data We Collect
We collect only the personal data that is necessary for legitimate business and legal purposes. Depending on the nature of the interaction, this may include:
- Identity data such as name, title, and similar identifiers;
- Contact data such as address, email address, and telephone number;
- Transaction data such as details of purchases, payments, and service records;
- Account and profile data such as preferences, settings, and service history;
- Technical data such as device type, browser information, log data, and usage information;
- Communication data such as messages, feedback, complaints, and support requests;
- Verification data where necessary to confirm identity or prevent fraud;
- Marketing preferences if you choose to receive communications or set preferences for them.
We do not knowingly collect more data than is needed. Where special category data is processed, we will only do so where a lawful basis applies and additional safeguards are in place.
3. How We Use Personal Data
We use personal data for the following purposes:
- To provide, operate, and manage our services;
- To process transactions and maintain records;
- To communicate with customers about service matters, changes, and support;
- To verify identity and protect against fraud or misuse;
- To comply with legal, regulatory, and contractual obligations;
- To improve service quality, performance, and customer experience;
- To send relevant marketing communications where permitted and not opted out of;
- To establish, exercise, or defend legal claims.
We will not use personal data for incompatible purposes without first ensuring that such use is permitted by law and consistent with the original context of collection.
4. Lawful Basis for Processing
We process personal data only where a lawful basis exists under applicable data protection law. Depending on the activity, the lawful basis may be one or more of the following:
- Contract: processing is necessary to enter into or perform a contract with you;
- Legal obligation: processing is required to meet legal or regulatory duties;
- Legitimate interests: processing is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms;
- Consent: processing is based on your freely given, specific, informed, and unambiguous consent where required;
- Vital interests: processing is necessary to protect someone’s life in exceptional circumstances;
- Public task: where applicable, processing is necessary to perform a task carried out in the public interest.
Where we rely on legitimate interests, we assess whether the processing is necessary and proportionate and whether it has a fair impact on individuals. Where we rely on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
5. Sharing and Processors
We may share personal data with carefully selected third parties that act as processors or, in limited cases, independent controllers. Processors are only permitted to process personal data on our documented instructions and are required to keep it secure and confidential. Examples of processors may include:
- IT and hosting providers;
- Payment service providers;
- Customer support and communications platforms;
- Analytics and system monitoring services;
- Professional advisers such as legal, accounting, or audit providers;
- Cloud storage and backup services;
- Security and fraud prevention vendors.
When we share data with processors, we require appropriate contractual safeguards, including data processing terms that reflect GDPR requirements. We may also disclose personal data where necessary to comply with legal obligations, enforce agreements, protect rights, or respond to lawful requests from public authorities.
If a third party acts as an independent controller, that party is responsible for its own processing activities and privacy practices. In such cases, we encourage individuals to review the relevant privacy information provided by that controller.
6. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including for legal, accounting, tax, regulatory, or reporting requirements. Retention periods are determined by considering:
- The nature and sensitivity of the data;
- The risk of harm from unauthorized use or disclosure;
- The purposes of processing and whether those purposes can be achieved by other means;
- Applicable statutory limitation periods;
- Contractual or regulatory retention obligations.
When personal data is no longer needed, we will delete it securely or anonymize it so that it can no longer identify an individual. Where deletion is not immediately possible due to legal or operational requirements, we will restrict processing until deletion can occur.
7. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and regular security reviews. While no system can be guaranteed to be completely secure, we continually work to maintain a level of security appropriate to the risk.
8. International Transfers
Where personal data is transferred outside the jurisdiction in which it was collected, we will ensure that appropriate safeguards are in place. These safeguards may include adequacy decisions, standard contractual clauses, or other lawful mechanisms recognized under applicable law. We take steps to ensure that transferred data receives a level of protection that is essentially equivalent to that required under GDPR principles.
9. Your Rights
Depending on your location and the legal basis for processing, you may have the following rights in relation to your personal data:
- Right of access to obtain confirmation of whether we process your data and a copy of it;
- Right to rectification to correct inaccurate or incomplete data;
- Right to erasure to request deletion of your data in certain circumstances;
- Right to restriction to limit how we process your data in certain cases;
- Right to data portability to receive certain data in a structured, commonly used, machine-readable format;
- Right to object to processing based on legitimate interests or to direct marketing;
- Right to withdraw consent where processing is based on consent;
- Right not to be subject to solely automated decision-making with legal or similarly significant effects, where applicable.
We may need to verify your identity before responding to a rights request. We will respond within the timeframes required by law and inform you if an extension is necessary. Some rights may not apply in every circumstance, but we will explain the reasons where a request cannot be fulfilled.
10. Cookies and Similar Technologies
Where used, cookies and similar technologies may be applied for basic functionality, security, analytics, and user preference management. Any such technologies will be used in line with applicable law and, where required, on the basis of consent or other lawful grounds. You may manage cookie preferences through the settings available to you on the device or browser you use.
11. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate authorization or legal basis. If we learn that data has been collected from a child in breach of this policy, we will take appropriate steps to delete or protect that data as required by law.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our practices. When changes are made, the revised policy will apply from the date of publication or from any later date specified. We encourage individuals to review this policy periodically so they remain informed about how personal data is handled.
13. Principles We Follow
Our approach to data protection is based on the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability. These principles guide how we collect and use personal data, how long we retain it, and how we choose our processors and security controls.
Summary of Commitments
We collect only necessary personal data, process it on a valid legal basis, retain it for limited periods, share it only with trusted processors under proper safeguards, and respect individual rights. This Privacy Policy applies to all customers in the area and is intended to provide clear, transparent information about our data protection practices.
