Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the relevant area and is intended to meet the requirements of applicable data protection laws, including the General Data Protection Regulation (GDPR). By using our services, you acknowledge that you have read and understood this Privacy Policy.
1. Scope and Application
This Privacy Policy applies to all customers in the area where our services are offered and to all individuals whose personal data is processed in connection with those services. It covers data collected through service interactions, transactions, communications, and any related operational processes. It does not apply to information that has been anonymized in a way that it can no longer identify a person.
2. Data We Collect
We may collect and process different categories of personal data depending on how you interact with us. The types of data may include:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, telephone number, and other communication details.
- Transaction data: payment-related records, order details, and service history.
- Technical data: IP address, device identifiers, browser type, operating system, and usage information.
- Profile data: preferences, feedback, and records of your interactions with us.
- Communication data: messages, support requests, complaints, and correspondence.
- Location data: general or approximate location, where necessary for service delivery or security.
We collect this information directly from you, automatically through your use of our systems, and from third parties where permitted by law. We only collect data that is necessary, relevant, and limited to the purposes described in this Policy.
3. How We Use Personal Data
Personal data is used for the following purposes:
- to provide, administer, and improve our services;
- to process transactions and manage customer relationships;
- to communicate with you about service updates, changes, and administrative matters;
- to respond to questions, requests, and complaints;
- to maintain security, prevent fraud, and protect against unauthorized access;
- to comply with legal, regulatory, and contractual obligations;
- to analyze performance, improve service quality, and support business operations;
- to establish, exercise, or defend legal claims where necessary.
We do not use personal data for purposes that are incompatible with the reasons for which it was collected unless we have a valid legal basis to do so.
4. Lawful Basis for Processing
Under GDPR, we process personal data only when we have a lawful basis. Depending on the context, our lawful bases may include:
4.1 Contractual Necessity
We process personal data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
4.2 Legal Obligation
We may process personal data to comply with applicable laws, regulations, tax rules, accounting obligations, or lawful requests from public authorities.
4.3 Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided that those interests are not overridden by your rights and freedoms. Examples include service improvement, fraud prevention, network security, and operational management.
4.4 Consent
Where required by law, we rely on your consent. If we process data based on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4.5 Vital Interests and Public Interest
In rare circumstances, we may process data to protect vital interests or where processing is necessary for reasons of public interest, as permitted by law.
5. Data Sharing and Processors
We may share personal data with trusted third parties that assist us in operating our services. These parties act as processors when they process personal data on our behalf and under our instructions. They are bound by contractual obligations to keep data confidential and to use it only for the agreed purposes.
Processors may include:
- IT hosting and infrastructure providers;
- payment and transaction service providers;
- customer support and communication tools;
- analytics and performance monitoring providers;
- security and fraud prevention vendors;
- professional advisers, including legal, audit, and accounting services where necessary.
We may also disclose personal data to independent controllers where required or permitted by law, such as regulators, courts, law enforcement agencies, or business partners involved in a transaction. When data is transferred outside the European Economic Area, appropriate safeguards are implemented in accordance with GDPR requirements.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including the need to satisfy legal, accounting, tax, and reporting obligations. Retention periods vary depending on the type of data, the purpose of processing, and the applicable legal requirements.
In general:
- contractual and transaction records are kept for the duration of the relationship and for a period afterward to meet legal obligations;
- customer communication records are retained as long as needed to resolve the matter and support service administration;
- technical and security logs are retained for limited periods unless a longer retention is needed for investigation or compliance;
- data processed on the basis of consent is kept until consent is withdrawn or the purpose is no longer relevant.
When personal data is no longer required, we will delete, anonymize, or securely archive it in accordance with our retention practices and applicable law.
7. Data Security
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, logging, staff training, and secure storage practices. While no system can be completely secure, we take reasonable steps to reduce risk and safeguard information.
8. Your Rights Under GDPR
Depending on the circumstances and applicable law, you may have the following rights in relation to your personal data:
- Right of access: to obtain confirmation and a copy of your personal data.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain situations.
- Right to restriction: to ask us to limit processing in certain cases.
- Right to data portability: to receive your data in a structured, commonly used format and transfer it where technically feasible.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
- Right to lodge a complaint: to contact the relevant supervisory authority if you believe your rights have been infringed.
You may also have rights related to automated decision-making and profiling where such processing applies. We will respond to valid requests in accordance with GDPR time limits and requirements. We may need to verify your identity before fulfilling a request to protect your privacy and security.
9. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate authorization where required by law. If we become aware that personal data has been collected in error, we will take appropriate steps to delete it or secure the required consent.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, operations, or data processing practices. Any updated version will apply from the time it is made available. We encourage customers to review this Policy periodically so they remain informed about how their data is handled.
11. General Principles
We are committed to the core GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. These principles guide how we design and operate our data handling practices. Wherever possible, we aim to process only the minimum personal data necessary to provide a secure and reliable service.
This Privacy Policy should be read together with any notices provided at the point of data collection and any additional terms that may apply to specific services. If a specific notice conflicts with this Policy, the more specific notice will apply to that particular processing activity, to the extent permitted by law.
