Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with the services offered by all customers in the area. It applies to every individual and organization that uses or receives services in the relevant area, regardless of whether access is provided online, offline, or through any other channel. We are committed to processing personal data in a lawful, fair, transparent, and secure manner in accordance with applicable data protection law, including the General Data Protection Regulation (GDPR).
1. Scope of This Policy
This Policy applies to all personal data processed in relation to customers in the area. It covers data collected directly from individuals, data generated through the use of services, and data received from third parties where permitted by law. By using the services, customers acknowledge that their information may be processed as described in this Policy.
2. Data We Collect
We may collect and process the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, and phone number.
- Account and transaction data: account details, service history, billing records, payment status, and related records.
- Technical data: device type, browser type, IP address, operating system, and usage logs.
- Communication data: correspondence, requests, complaints, and feedback.
- Preference data: service choices, settings, and consent records where applicable.
We generally do not seek to collect special category data unless it is strictly necessary and a lawful basis exists. If such data is ever processed, it will be handled with enhanced safeguards and only for a clearly defined purpose.
3. How We Use Personal Data
Personal data is used for legitimate operational, contractual, and legal purposes, including:
- providing and managing services;
- verifying identity and preventing fraud;
- processing payments and maintaining records;
- responding to inquiries and support requests;
- improving service quality, security, and reliability;
- complying with legal obligations;
- establishing, exercising, or defending legal claims.
Where required, we may also use data for communications about service changes, operational notices, or similar matters necessary to deliver services effectively.
4. Lawful Basis for Processing
Under GDPR, we only process personal data when we have a valid lawful basis. Depending on the context, our processing may rely on one or more of the following:
- Contract: processing necessary to enter into or perform a contract with a customer in the area.
- Legal obligation: processing required to comply with applicable law, regulation, or lawful request.
- Legitimate interests: processing necessary for our legitimate business interests, provided these are not overridden by the rights and freedoms of the individual. Examples include service improvement, fraud prevention, and security monitoring.
- Consent: where explicit consent is required, processing will only occur after consent has been freely given, informed, and unambiguous. Consent may be withdrawn at any time.
- Vital interests: in rare situations, processing may be needed to protect life or physical safety.
- Public task: where processing is required for a task carried out in the public interest or under official authority, if applicable.
We only collect and use personal data that is relevant and limited to what is necessary for the intended purpose.
5. Data Sharing and Processors
We may share personal data with trusted third parties where necessary for the purposes set out in this Policy. These third parties may act as data processors or independent controllers depending on the circumstances.
Processors
Processors are service providers that handle personal data on our behalf and only in accordance with our instructions. Typical processors may include:
- IT hosting and infrastructure providers;
- payment processing partners;
- customer support and communications tools;
- security and monitoring providers;
- document storage and backup services;
- professional advisers assisting with compliance, auditing, or legal matters.
All processors are required to implement appropriate technical and organizational measures to protect personal data and to process it only for authorized purposes. Where required by law, data processing agreements are in place to ensure GDPR-compliant handling.
We may also disclose personal data if necessary to comply with legal obligations, enforce our terms, protect rights and safety, or respond to lawful requests from public authorities.
6. International Transfers
If personal data is transferred outside the European Economic Area, appropriate safeguards will be used to protect the data. These safeguards may include adequacy decisions, standard contractual clauses, or other mechanisms recognized under GDPR. Such transfers will only occur where necessary and with appropriate protections in place.
7. Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for legal, accounting, reporting, and compliance requirements. Retention periods vary depending on the type of data and the context of processing.
Retention principles include:
- data linked to contracts is kept for the duration of the relationship and for any applicable limitation periods;
- transaction and accounting records are retained for the period required by tax and financial laws;
- technical and security logs are kept for a limited period unless needed longer for investigation or compliance;
- consent records are retained to demonstrate lawful processing where consent is relied upon;
- data that is no longer necessary is securely deleted, anonymized, or archived where appropriate.
When data is no longer required, we take reasonable steps to ensure it is disposed of safely and permanently.
8. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, unlawful use, accidental loss, destruction, or damage. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and regular review of security practices. While no system can be guaranteed completely secure, we work to maintain a level of protection suitable to the risks associated with the data processed.
9. User Rights Under GDPR
Individuals whose personal data is processed under this Policy have rights under GDPR, subject to certain legal limitations. These rights include:
- Right of access: the right to obtain confirmation and a copy of personal data being processed.
- Right to rectification: the right to request correction of inaccurate or incomplete data.
- Right to erasure: the right to request deletion of personal data in certain circumstances.
- Right to restriction: the right to request limited processing in specific situations.
- Right to data portability: the right to receive data in a structured, commonly used format and, where feasible, transmit it to another controller.
- Right to object: the right to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to withdraw consent: where processing is based on consent, the right to withdraw it at any time.
- Right to lodge a complaint: the right to complain to a supervisory authority if data protection rights are believed to have been infringed.
Requests to exercise these rights will be handled within the timeframes required by applicable law. We may request information necessary to verify identity before responding to a request.
10. Children’s Data
Our services are not intended to be directed to children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate legal basis and, where applicable, required parental or guardian consent. If we become aware that personal data has been collected in violation of this Policy, we will take appropriate steps to delete it.
11. Automated Decision-Making
We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects, unless such processing is lawful and accompanied by appropriate safeguards. If automated decision-making is used in any context, customers will be informed where required by law and may exercise available rights.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service arrangements. Any updated version will apply to all customers in the area from the time it takes effect. Customers are encouraged to review the Policy periodically to remain informed about how personal data is processed.
By continuing to use the services, customers acknowledge that they have read and understood this Privacy Policy. This Policy is intended to provide a clear and lawful explanation of how personal data is handled for all customers in the area, with respect for privacy, transparency, and accountability.
