Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area where our services are offered, and it is intended to meet the requirements of the General Data Protection Regulation (GDPR) and applicable local data protection laws.
1. Scope of This Policy
This Privacy Policy applies whenever we process personal data relating to individuals who use, purchase, request, or otherwise interact with our services. It covers both online and offline interactions and applies equally to existing and prospective customers in the relevant area. By “personal data,” we mean any information that identifies, relates to, describes, or can reasonably be linked to an identifiable person.
2. Data We Collect
We may collect the following categories of personal data depending on how you interact with us:
- Identity data: such as name, title, and similar identifiers.
- Contact data: such as address, email address, and telephone number.
- Transaction data: such as details about purchases, orders, invoices, payments, and service history.
- Communication data: such as records of correspondence, complaints, feedback, and support requests.
- Technical data: such as device information, browser type, IP address, log data, and usage information.
- Preference data: such as language preferences, service choices, and marketing preferences.
We generally collect data directly from you when you provide it to us. We may also receive data from third parties where permitted by law, such as service providers, payment processors, or publicly available sources.
3. How We Use Personal Data
We use personal data only where permitted by law and for specific, legitimate purposes. These purposes may include:
- providing and managing our services;
- processing transactions and fulfilling requests;
- communicating with you about service updates, inquiries, or support matters;
- maintaining records and internal administration;
- improving service quality, safety, and performance;
- detecting, preventing, and investigating fraud, misuse, or security incidents;
- complying with legal and regulatory obligations;
- where appropriate, sending marketing communications in accordance with applicable law.
We will not process personal data in a way that is incompatible with the purposes described above unless we have a lawful basis to do so.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. Depending on the context, we rely on one or more of the following lawful bases:
Contractual necessity
We process personal data where it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract. This may include managing orders, providing services, and handling payments.
Legal obligation
We may process personal data to comply with legal obligations, such as tax, accounting, consumer protection, record-keeping, and regulatory requirements.
Legitimate interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Examples include business administration, fraud prevention, service improvement, network security, and limited direct marketing where permitted.
Consent
Where required by law, we rely on your consent, for example for certain marketing activities or optional cookies and similar technologies. You may withdraw consent at any time, and such withdrawal will not affect the lawfulness of processing carried out before it was withdrawn.
5. Data Sharing and Processors
We may share personal data with trusted third parties that act as processors on our behalf. These processors are only permitted to process personal data under our instructions and must implement appropriate technical and organizational measures to protect it.
Examples of processors may include:
- information technology and hosting providers;
- payment service providers;
- customer support and communication tools;
- analytics and security service providers;
- professional advisers and administrative service providers.
We may also disclose personal data where necessary to comply with legal requirements, to protect our rights, to prevent fraud or abuse, or in connection with a business restructuring or transfer, provided such disclosure is lawful and appropriately safeguarded.
Where personal data is transferred outside the European Economic Area or to another jurisdiction with different data protection laws, we will ensure appropriate safeguards are in place, such as standard contractual clauses or another valid transfer mechanism recognized under GDPR.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, reporting, and audit requirements. Retention periods are determined based on the type of data, the nature of the relationship, legal obligations, and the need to resolve disputes or enforce agreements.
In general, we will:
- retain contract and transaction records for the period required by applicable law;
- retain communication records for as long as needed to respond to queries and maintain service continuity;
- retain marketing-related data until you opt out, withdraw consent, or the data is no longer necessary;
- delete or anonymize personal data when it is no longer needed, unless retention is required by law.
When personal data is no longer required, we will securely delete, destroy, or anonymize it in a manner consistent with our retention procedures.
7. Data Security
We use appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption where appropriate, secure storage, staff confidentiality obligations, and regular review of security practices.
Although we take reasonable steps to safeguard your data, no method of transmission or storage is completely secure. We therefore cannot guarantee absolute security, but we continuously work to improve our safeguards and minimize risk.
8. Your Rights Under GDPR
Subject to conditions and exceptions under applicable law, you have the following rights regarding your personal data:
- Right of access: to obtain confirmation of whether we process your personal data and receive a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request that we limit the processing of your data in certain situations.
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format and have it transferred where technically feasible.
- Right to object: to object to processing based on legitimate interests or to direct marketing.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time.
- Right to lodge a complaint: to raise concerns with the relevant data protection authority if you believe your rights have been infringed.
We may need to verify your identity before responding to a request. We will respond within the timeframe required by GDPR and applicable law.
9. Automated Decision-Making
We do not intend to use personal data for decisions based solely on automated processing that produce legal or similarly significant effects, unless this is permitted by law and appropriate safeguards are in place. If such processing is used, you will be informed where required and provided with the relevant rights and explanations.
10. Children’s Data
Our services are not directed to children unless expressly stated otherwise. We do not knowingly collect personal data from children in circumstances where parental consent or other special protections are required, unless permitted by law and appropriate safeguards are in place.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updated version will apply from the date it is made available. We encourage you to review this policy periodically to stay informed about how we handle personal data.
12. Final Statement
This Privacy Policy applies to all customers in the area where our services are provided. We are committed to processing personal data lawfully, fairly, and transparently, while respecting your rights and protecting your information. If any part of this policy is found to be inconsistent with applicable law, the remaining provisions will continue to apply to the fullest extent permitted.
