Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when we provide our services. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our services, you acknowledge that your personal data may be processed as described in this Policy.
1. Data We Collect
We collect only the personal data that is necessary for specific, legitimate, and clearly defined purposes. Depending on how you interact with us, we may collect the following categories of data:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, phone number, and other communication details.
- Transaction data: details of services requested, purchased, or delivered, including payment-related records where relevant.
- Account data: usernames, account preferences, settings, and communication history.
- Technical data: IP address, browser type, device identifiers, system information, and usage logs.
- Service data: information provided in forms, requests, feedback, and support interactions.
- Marketing data: preferences regarding communications and promotions, where applicable.
We do not knowingly collect special category data unless it is strictly necessary and a valid lawful basis applies. Where such data is processed, we apply additional safeguards as required by law.
2. How We Use Personal Data
We use personal data for clear and lawful purposes only. These include:
- providing and managing our services;
- verifying identity and maintaining records;
- processing transactions and related administrative tasks;
- responding to inquiries and customer requests;
- improving service quality, performance, and user experience;
- detecting, preventing, and investigating fraud, misuse, or security incidents;
- meeting legal, regulatory, accounting, and tax obligations;
- sending service-related communications;
- carrying out limited marketing where permitted by law and subject to your choices.
We will only process personal data in ways that are compatible with the purposes for which it was collected, unless we have obtained consent or have another lawful basis to do so.
3. Lawful Basis for Processing
Under GDPR, we must have a valid lawful basis before processing personal data. Depending on the context, we rely on one or more of the following bases:
- Contract: processing is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
- Legal obligation: processing is necessary to comply with legal or regulatory duties.
- Legitimate interests: processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests. This may include service improvement, security, and fraud prevention.
- Consent: where required, we will ask for your consent before processing certain personal data, especially for optional marketing or specific uses of data.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal will not affect the lawfulness of processing carried out before the withdrawal.
4. Data Retention
We retain personal data only for as long as necessary to fulfill the purpose for which it was collected, including to satisfy legal, accounting, reporting, and dispute-resolution obligations. Retention periods depend on factors such as the nature of the data, the purpose of processing, legal requirements, and whether the data is needed to establish, exercise, or defend legal claims.
When personal data is no longer required, we will delete, anonymize, or securely archive it in accordance with applicable laws and our internal retention procedures. If deletion is not immediately possible due to legal or technical reasons, we will ensure the data is securely stored and no longer actively used for the original purpose.
5. Data Sharing and Processors
We may share personal data with trusted third parties when necessary for the purposes described in this Policy. These third parties may act as data processors or, in some cases, independent controllers. We only disclose data where there is a valid legal basis and appropriate safeguards are in place.
Typical processors may include providers that support:
- IT hosting and infrastructure;
- data storage and backup;
- payment handling;
- customer support tools;
- analytics and performance monitoring;
- security and fraud prevention;
- document management and administrative services.
All processors are required to handle personal data only on our instructions, to keep it confidential, and to apply appropriate technical and organizational measures to protect it. Where data is transferred outside the European Economic Area, we ensure lawful transfer mechanisms and adequate safeguards are in place.
6. Data Security
We use reasonable and appropriate measures to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. These measures may include access controls, encryption, secure storage, staff training, and internal policies designed to minimize risk. While no system can be guaranteed completely secure, we continuously review and improve our safeguards.
7. Your Rights Under GDPR
Subject to legal conditions and exceptions, you have the following rights in relation to your personal data:
- Right of access: to obtain confirmation of whether we process your data and receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your personal data in certain circumstances.
- Right to restriction: to request limited processing in specific situations.
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format and, where feasible, to have it transferred to another controller.
- Right to object: to object to processing based on legitimate interests or to direct marketing at any time.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
- Right not to be subject to automated decision-making: to avoid decisions based solely on automated processing where such decisions produce legal or similarly significant effects, unless permitted by law.
If you wish to exercise any of these rights, we will assess your request in line with GDPR and applicable legal requirements. You may also have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been infringed.
8. Cookies and Similar Technologies
Where applicable, we may use cookies or similar technologies to support essential functionality, improve performance, analyze usage, and remember preferences. Where consent is required, we will obtain it before placing non-essential cookies. You can manage browser settings to limit or block cookies, although some features may not function properly as a result.
9. Children's Data
Our services are not directed to children unless explicitly stated. We do not knowingly collect personal data from children without appropriate authorization or consent where required by law. If we become aware that data has been collected unlawfully, we will take reasonable steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service offerings. The revised version will apply from the date it is made available. We encourage you to review this Policy periodically to stay informed about how we protect personal data.
11. Additional Information
Principles we follow: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
Our commitment is to process personal data only when necessary and to respect the privacy rights of all individuals whose data we handle. We apply these standards consistently to all customers in the area, regardless of the service channel used.
Summary of our approach: collect only what is needed, use it for defined purposes, keep it secure, share it only with trusted processors under contract, retain it only as long as required, and honor user rights under GDPR.
