Privacy Policy
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you use our services. It applies to all customers in the area where our services are offered. We are committed to handling personal data in a fair, transparent, and lawful manner in accordance with applicable data protection laws, including the GDPR.
1. Who This Policy Applies To
This policy applies to individuals who purchase, access, or use our products or services, as well as anyone who interacts with us in connection with those services. It also applies to prospective customers, account holders, and users who communicate with us through support or service-related channels.
By using our services, you acknowledge that your personal data may be processed as described in this policy.
2. Data We Collect
We collect personal data that is necessary to provide and improve our services, manage our relationship with you, and comply with legal obligations. The types of data we may collect include:
- Identity data such as name, username, or similar identifiers.
- Contact data such as email address, billing details, or communication preferences.
- Transaction data such as records of purchases, payments, refunds, and service history.
- Technical data such as device type, browser type, IP address, operating system, and usage logs.
- Profile data such as preferences, feedback, and service interactions.
- Support data such as messages, complaints, and information provided when requesting assistance.
- Marketing preferences such as consent choices and communication settings, where applicable.
We generally collect personal data directly from you when you create an account, place an order, make an inquiry, submit a form, or otherwise interact with us. We may also collect data automatically through technical systems and security tools, or from third parties when permitted by law.
3. How We Use Personal Data
We use personal data only for specified, explicit, and legitimate purposes. These purposes may include:
- providing and delivering our services;
- processing orders, payments, and related administrative tasks;
- managing accounts and customer relationships;
- responding to inquiries, requests, and complaints;
- maintaining security, preventing fraud, and detecting misuse;
- improving service performance, functionality, and user experience;
- meeting legal, regulatory, tax, and accounting obligations;
- sending service-related notices and, where permitted, marketing communications;
- analyzing usage trends and operational performance;
- protecting our rights, property, and legitimate business interests.
We do not process personal data in a way that is incompatible with these purposes.
4. Lawful Basis for Processing
Under GDPR, we process personal data only where we have a valid lawful basis. Depending on the context, our lawful bases may include:
Performance of a contract
We process personal data when it is necessary to enter into or perform a contract with you. This includes handling orders, accounts, deliveries, payments, and customer support connected to our services.
Legal obligation
We may process personal data to comply with legal and regulatory requirements, including tax, accounting, consumer protection, anti-fraud, and recordkeeping obligations.
Legitimate interests
We may process personal data where it is necessary for our legitimate interests, provided that those interests are not overridden by your rights and freedoms. These interests may include improving our services, ensuring network and information security, preventing fraud, and managing business operations.
Consent
In certain cases, we rely on your consent, for example where required for specific types of marketing or optional data collection. Where consent is used, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Sharing and Processors
We may share personal data with trusted third parties who act as data processors or independent controllers, depending on the context. We ensure that any sharing is limited to what is necessary and that appropriate safeguards are in place.
Processors may include service providers that assist with:
- payment processing and financial administration;
- hosting, cloud storage, and data infrastructure;
- customer relationship management;
- email delivery and communications;
- IT support, maintenance, and cybersecurity;
- analytics and service performance monitoring;
- document management and secure archiving;
- professional services such as legal, accounting, or compliance support.
We require processors to process personal data only on our instructions, keep it confidential, apply appropriate technical and organizational measures, and assist us in meeting GDPR requirements where applicable.
We may also disclose personal data if required by law, to respond to lawful requests, to protect our rights, or in connection with a business transaction such as a merger, restructuring, or asset transfer, subject to applicable legal requirements.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, reporting, and dispute-resolution requirements. Retention periods vary depending on the type of data and the reason for processing.
In general, we consider the following when determining retention:
- whether the data is needed to provide services or support;
- whether the data is required to comply with legal obligations;
- whether the data is necessary to establish, exercise, or defend legal claims;
- the nature, sensitivity, and volume of the data;
- the potential risk of harm from unauthorized use or disclosure;
- applicable industry or regulatory retention requirements.
When personal data is no longer required, we will securely delete, anonymize, or otherwise irreversibly dispose of it in accordance with our retention practices.
7. Data Security
We use reasonable technical and organizational measures designed to protect personal data against accidental loss, unauthorized access, disclosure, alteration, or destruction. These measures may include access controls, encryption where appropriate, secure storage, staff training, and monitoring of systems for suspicious activity.
No system is completely secure. Although we take steps to protect personal data, we cannot guarantee absolute security. We encourage users to take appropriate steps to protect their own information, including using strong passwords and safeguarding account credentials.
8. International Transfers
Where personal data is transferred outside the country or area in which it was collected, we take steps to ensure an adequate level of protection. These measures may include relying on adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms recognized under GDPR.
9. Your Rights Under GDPR
Depending on your location and the applicable legal basis for processing, you may have the following rights regarding your personal data:
- Right of access – to request confirmation of whether we process your data and to obtain a copy of it.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of your data in certain circumstances.
- Right to restriction – to request limited processing in certain cases.
- Right to data portability – to request a copy of certain data in a structured, commonly used format.
- Right to object – to object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
- Right not to be subject to automated decision-making – where applicable, to challenge decisions made solely by automated means that have legal or similarly significant effects.
To exercise your rights, you may submit a request through the channels made available by us. We may need to verify your identity before responding to your request. If a request is excessive, unfounded, or affects the rights of others, we may lawfully refuse it or limit our response.
10. Complaints and Supervisory Authority
If you believe that your personal data has been handled improperly, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. We encourage you to raise concerns with us first so that we can attempt to resolve the matter promptly and fairly.
11. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate authorization or as otherwise permitted by law. If we learn that personal data has been collected from a child without lawful basis, we will take appropriate steps to delete it.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. The most current version will apply to your use of our services. We encourage you to review this policy periodically so that you remain informed about how we process personal data.
Summary: This Privacy Policy explains how we collect, use, share, retain, and protect personal data for all customers in the area, and outlines lawful bases and user rights under GDPR.
