Privacy Policy
This Privacy Policy explains how we collect, use, store, disclose, and protect personal data in connection with our services. It applies to all customers in the area where our services are offered and accessed. We are committed to processing personal data in a lawful, fair, and transparent manner in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
1. Who This Policy Applies To
This Policy applies to all customers in the area, including individuals who purchase, use, inquire about, or otherwise interact with our services. It also applies to users who browse our services, communicate with us, or engage with our customer support or administrative functions.
2. Personal Data We Collect
We may collect personal data directly from you, automatically through your use of our services, or from third parties where permitted by law. The types of data we may collect include:
- Identity data: name, username, or similar identifiers.
- Contact data: email address, telephone number, billing address, or delivery address.
- Transaction data: details about services purchased, payment status, and order history.
- Technical data: IP address, browser type, device information, operating system, and usage logs.
- Communication data: messages, inquiries, feedback, and records of correspondence.
- Preference data: marketing preferences, language choices, and service settings.
Where necessary, we may also collect limited sensitive information only when required by law or when you provide it voluntarily for a specific purpose. In such cases, we apply enhanced safeguards and process the data only where a valid legal basis exists.
3. How We Use Personal Data
We use personal data for the following purposes:
- To provide, manage, and improve our services.
- To process transactions, billing, and service-related requests.
- To communicate with you about your account, orders, or service updates.
- To respond to inquiries and provide customer support.
- To maintain security, prevent fraud, and detect unauthorized activity.
- To comply with legal and regulatory obligations.
- To analyze usage and improve performance, functionality, and user experience.
- To send marketing communications where permitted and where you have not opted out.
We only use personal data for purposes that are compatible with the original reason for collection, unless we obtain your consent or are otherwise legally permitted to do so.
4. Lawful Basis for Processing
Under GDPR, we process personal data only where we have a valid lawful basis. Depending on the context, the lawful basis may include:
Performance of a Contract
We process personal data when it is necessary to enter into or perform a contract with you, such as providing services, managing transactions, or handling service requests.
Legal Obligation
We may process data to comply with legal requirements, including tax, accounting, consumer protection, and record-keeping obligations.
Legitimate Interests
We may process data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. This may include service improvement, fraud prevention, network security, and internal administration.
Consent
Where required, we rely on your consent, particularly for certain marketing activities or optional data processing. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Interest
In exceptional circumstances, we may process personal data to protect vital interests or where processing is necessary for tasks carried out in the public interest, where applicable.
5. Sharing and Processors
We may share personal data with trusted third parties that act as processors on our behalf. These processors are permitted to process personal data only under our instructions and must implement appropriate technical and organizational safeguards.
Examples of processors may include:
- IT hosting and cloud service providers.
- Payment processing services.
- Customer relationship and support tools.
- Analytics and performance monitoring services.
- Document storage and administrative service providers.
We may also disclose personal data to independent controllers where necessary, such as professional advisers, regulatory authorities, law enforcement, or other parties when required by law or to protect our legal rights. Any transfer or disclosure is carried out in accordance with applicable legal requirements.
We do not sell personal data in the ordinary sense. If a future arrangement requires different handling, we will ensure it is disclosed clearly and supported by a valid legal basis.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. The retention period depends on the type of data, the reason for processing, and any applicable statutory obligations.
In general:
- Account and transaction records are retained for the period needed to manage the service relationship and comply with legal obligations.
- Communication records are retained for a reasonable period to handle queries, resolve disputes, and maintain service quality.
- Technical and analytics data may be retained for shorter periods unless needed for security, troubleshooting, or legal compliance.
When personal data is no longer required, we will delete it, anonymize it, or securely archive it in accordance with our retention practices and applicable law.
7. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, disclosure, or alteration. These measures may include access controls, encryption, monitoring, secure storage, and internal policies governing data handling.
While we strive to protect your information, no system can be guaranteed to be completely secure. You should use reasonable care when sharing information and contact us through secure channels whenever possible.
8. International Transfers
Where personal data is transferred outside the European Economic Area or other jurisdictions with equivalent protections, we ensure appropriate safeguards are in place. These may include standard contractual clauses or other lawful transfer mechanisms recognized under applicable data protection law.
We take steps to ensure that transferred data receives a level of protection that is essentially equivalent to the protection required under GDPR.
9. Your Rights Under GDPR
You have specific rights regarding your personal data, subject to applicable legal conditions and exceptions. These rights may include:
- Right of access: to obtain confirmation and a copy of the personal data we hold about you.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request limited processing in specific situations.
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format, where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: to withdraw consent at any time where processing is based on consent.
You also have the right to lodge a complaint with the relevant supervisory authority if you believe your data protection rights have been violated.
10. Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects, unless such processing is necessary, authorized by law, or based on your explicit consent. If automated decision-making is used in the future, we will provide meaningful information about the logic involved and the significance of the processing.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our processing practices, legal requirements, or operational needs. Updated versions will apply from the date they become effective. We encourage you to review this Policy periodically to stay informed about how we handle personal data.
12. Summary of Key Principles
In summary, we process personal data lawfully, transparently, and only for specified purposes. We collect only the data needed to provide and improve our services, retain it only as long as necessary, and share it only with trusted processors or when required by law. You may exercise your rights at any time, and we will handle requests in accordance with GDPR.
Important: This Privacy Policy applies to all customers in the area where our services are available and is intended to ensure that personal data is handled with care, accountability, and respect for individual privacy.
