Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, disclosed, and protected when individuals use our services. It applies to all customers in the area where our services are offered. We are committed to processing personal data in a lawful, fair, and transparent manner in accordance with the General Data Protection Regulation (GDPR).
1. Scope of This Policy
This policy applies to personal data relating to identified or identifiable natural persons. It covers data provided directly by customers, data collected automatically through service use, and data received from third parties where permitted by law. By using our services, customers acknowledge that their personal data may be processed as described in this policy.
2. Data We Collect
We collect only the data necessary for specific, explicit, and legitimate purposes. Depending on the nature of the relationship, we may collect the following categories of personal data:
- Identity data: name, surname, title, and similar identifiers.
- Contact data: address, email address, telephone number, or other communication details.
- Transaction data: records of purchases, orders, payments, and related service history.
- Technical data: IP address, device identifiers, browser type, operating system, and log information.
- Usage data: information about how services are accessed and used.
- Preference data: choices and settings related to service delivery and communication.
- Communication data: correspondence and records of inquiries, feedback, or complaints.
Where required, we may also process limited sensitive data only when lawful grounds exist and additional safeguards are in place. We do not intentionally collect more data than is needed for the intended purpose.
3. How We Use Personal Data
We use personal data for the following purposes:
- to provide and manage our services;
- to process requests, transactions, and service-related actions;
- to communicate with customers about their accounts or service matters;
- to maintain service quality, security, and operational integrity;
- to prevent fraud, misuse, or unauthorized access;
- to comply with legal, regulatory, accounting, or tax obligations;
- to improve services, including troubleshooting and analytics;
- to send necessary service notices and, where permitted, relevant updates.
We will not use personal data for purposes that are incompatible with the original reasons for collection unless a lawful basis allows such further processing.
4. Lawful Basis for Processing
We process personal data only when a valid legal basis under GDPR exists. The lawful bases we rely on may include the following:
4.1 Performance of a Contract
We process data when it is necessary to enter into or perform a contract with a customer, including fulfilling service requests, handling payments, and providing support.
4.2 Legal Obligation
We may process data to comply with legal obligations, such as recordkeeping, tax compliance, consumer protection requirements, or responses to lawful requests from authorities.
4.3 Legitimate Interests
We may process data for our legitimate interests or those of a third party, provided these interests are not overridden by the rights and freedoms of the individual. Examples include service security, fraud prevention, internal administration, and service improvement.
4.4 Consent
Where required by law, we will rely on consent. When consent is used as the basis for processing, it will be freely given, specific, informed, and unambiguous. Customers may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4.5 Vital Interests and Public Interest
In exceptional circumstances, we may process personal data to protect someone’s vital interests or where processing is necessary for tasks carried out in the public interest or in the exercise of official authority, if applicable.
5. Data Sharing and Processors
We may share personal data with trusted processors and other third parties only when necessary and lawful. Processors act on our instructions and are required to protect personal data through appropriate technical and organizational measures.
Examples of processor categories may include:
- IT and hosting providers: to store, transmit, and secure data systems.
- Payment service providers: to process payments and related financial transactions.
- Customer support tools: to manage service inquiries and communications.
- Analytics and performance providers: to help understand service usage and improve functionality.
- Professional advisers: such as legal, accounting, or compliance advisers.
We ensure that any processor handling personal data is subject to a written agreement requiring confidentiality, security, and compliance with GDPR standards. Where personal data is transferred outside the European Economic Area, appropriate safeguards will be used, such as standard contractual clauses or other lawful transfer mechanisms.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting obligations. Retention periods are determined by the type of data, the purpose of processing, and applicable legal requirements.
In general, data may be retained for the duration of the customer relationship and for a further period where necessary to:
- resolve disputes;
- enforce agreements;
- maintain business records;
- comply with statutory retention obligations.
When data is no longer required, it is securely deleted, anonymized, or otherwise disposed of in a manner that prevents unauthorized access or recovery.
7. Data Security
We implement appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and regular security reviews.
While no system can guarantee absolute security, we take reasonable steps to reduce risks and to respond promptly to suspected data incidents. Where required, relevant incidents will be handled in accordance with GDPR breach notification obligations.
8. User Rights Under GDPR
Individuals whose data is processed under this policy have the following rights, subject to applicable conditions and exemptions:
- Right of access: to obtain confirmation of whether personal data is being processed and receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request that processing be limited in specific situations.
- Right to data portability: to receive data in a structured, commonly used, machine-readable format and, where feasible, have it transmitted to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing, where applicable.
- Right not to be subject to automated decision-making: to avoid decisions made solely by automated means that produce legal or similarly significant effects, except where permitted by law.
When processing is based on consent, individuals also have the right to withdraw consent at any time. Exercising a right will not usually require payment and will be handled without undue delay, in accordance with legal deadlines.
9. How Rights Are Managed
Requests relating to personal data rights will be reviewed carefully to confirm identity and ensure the request is handled lawfully. We may ask for additional information when needed to verify the requester or to locate relevant records. If a request cannot be fulfilled in full, we will explain the reasons where permitted by law.
We aim to respond within the time limits set by GDPR. If a request is complex or numerous, the response period may be extended as allowed by law.
10. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate authorization where required. If we learn that personal data has been collected inappropriately, we will take steps to delete or secure it as appropriate.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data processing practices. Any updated version will apply from the date it is made effective. Customers are encouraged to review this policy periodically to stay informed about how personal data is processed.
12. Final Statement
This Privacy Policy is intended to provide clear information about our data practices and to support accountability under GDPR. It applies to all customers in the area and describes how personal data is collected, used, retained, shared, and protected. We are committed to respecting privacy rights and handling personal data with care, transparency, and lawful purpose.
