Privacy Policy
This Privacy Policy explains how we collect, use, store, disclose, and protect personal data in connection with our services. It applies to all customers in the area where our services are offered, regardless of how they interact with us. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with applicable data protection law, including the General Data Protection Regulation (GDPR).
1. Scope of This Policy
This Privacy Policy applies to personal data processed when you use our services, communicate with us, make enquiries, or otherwise interact with us as a customer. It covers both information provided directly by you and information collected automatically during the course of providing our services.
Personal data means any information relating to an identified or identifiable individual. This may include name, contact details, account information, transaction records, device identifiers, and any other data that can reasonably be linked to a person.
2. Data We Collect
We collect only the data necessary for the purposes described in this Policy. Depending on the nature of your interaction with us, we may collect the following categories of personal data:
- Identity data: name, title, date of birth, and similar identifiers.
- Contact data: address, email address, telephone number, and preferred communication details.
- Account and service data: account identifiers, service preferences, records of requests, and service history.
- Transaction data: purchase or service records, payment status, invoicing details, and related administrative information.
- Technical data: IP address, browser type, device type, operating system, and log data.
- Usage data: information about how you interact with our services, including pages or features used and frequency of use.
- Communication data: messages, complaints, feedback, and correspondence with us.
We do not intentionally collect special category data unless required by law or where you have expressly provided it for a specific and lawful purpose. If such data is processed, it will be handled with appropriate safeguards.
3. How We Use Personal Data
We use personal data for the following purposes:
- to provide and manage our services;
- to process transactions and maintain records;
- to communicate with you about your account, requests, or service matters;
- to improve service quality, functionality, and customer experience;
- to comply with legal and regulatory obligations;
- to detect, prevent, and investigate fraud, abuse, or security incidents;
- to handle complaints, disputes, and enforcement matters;
- to protect our rights, property, and legitimate business interests.
We will not use your personal data for purposes that are incompatible with the original purpose for which it was collected, unless we have a lawful basis to do so and, where required, have provided appropriate notice.
4. Lawful Basis for Processing
We process personal data only when we have a lawful basis under GDPR. The lawful bases we rely on may include:
4.1 Contract
We process personal data where it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes using your data to deliver services, administer your account, and complete transactions.
4.2 Legal Obligation
We may process personal data where required to comply with legal obligations, such as tax, accounting, consumer protection, or data protection requirements.
4.3 Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Legitimate interests may include service improvement, security, fraud prevention, and business administration.
4.4 Consent
Where required, we will rely on your consent. If we process data on the basis of consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Retention of Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, reporting, or dispute-resolution requirements. Retention periods may vary depending on the type of data and the reason for processing.
When determining how long to keep data, we consider:
- the nature and sensitivity of the data;
- the purpose of the processing;
- whether we are legally required to retain the data;
- whether the data is needed to establish, exercise, or defend legal claims;
- our operational and security needs.
When personal data is no longer required, we will securely delete, anonymise, or otherwise irreversibly destroy it in accordance with our retention procedures.
6. Processors and Data Sharing
We may use trusted third-party service providers, known as processors, to help us operate and deliver our services. These processors act only on our instructions and are contractually required to protect personal data and process it in compliance with applicable law.
Processors may provide services such as:
- IT hosting and infrastructure;
- payment processing;
- customer support systems;
- data storage and backup;
- analytics and reporting tools;
- security and fraud-prevention services;
- administrative and document management tools.
We may also disclose personal data to professional advisers, regulators, law enforcement authorities, or other parties where required by law or necessary to protect our rights, comply with legal obligations, or respond to lawful requests.
Where personal data is transferred outside the European Economic Area, we will ensure appropriate safeguards are in place, such as standard contractual clauses or other legally recognised transfer mechanisms.
7. Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include access controls, encryption, secure storage, staff training, and monitoring procedures.
While no system can be guaranteed to be completely secure, we regularly review our safeguards and update them as needed to reduce risk and maintain an appropriate level of protection.
8. Your Rights Under GDPR
Subject to legal conditions and exceptions, you have the following rights in relation to your personal data:
- Right of access: to obtain confirmation about whether we process your data and to receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request that we limit processing in certain situations.
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format and, where feasible, have it transmitted to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time.
- Right to lodge a complaint: to complain to a data protection supervisory authority if you believe your rights have been infringed.
We will respond to valid requests in accordance with applicable law and may need to verify your identity before acting on your request. In some cases, we may be unable to comply fully where retention or processing is required by law or necessary for legitimate grounds.
9. Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you, unless such processing is lawful and you have been informed accordingly. If such processing is ever used, you will be provided with meaningful information about the logic involved and the significance of the processing.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any revised version will apply from the date it is made effective. We encourage you to review this Policy periodically so that you remain informed about how your personal data is handled.
11. General Statement
This Privacy Policy is intended to ensure that personal data is processed in a lawful, transparent, and secure way. It applies to all customers in the area and governs the handling of personal data throughout the lifecycle of the customer relationship. We are committed to respecting privacy rights and maintaining responsible data practices at every stage of processing.
Summary of commitments: We collect only necessary data, process it on a lawful basis, retain it for limited periods, use vetted processors, and uphold your GDPR rights.
