Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with the services offered to customers in the area. It applies to all customers in the area and is intended to reflect privacy practices in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Scope of This Policy
This Policy applies to all customers in the area, including individuals who purchase, subscribe to, inquire about, or otherwise interact with the services. It also applies to personal data processed when customers use support channels, submit forms, communicate with us, or engage with service-related content. By using the services, you acknowledge that your personal data may be processed as described below.
2. Data We Collect
We collect only the personal data that is necessary for the purposes described in this Policy. Depending on how you interact with the services, we may collect the following categories of data:
- Identity data such as name, title, or similar identifiers.
- Contact data such as postal address, email address, telephone number, or other communication details.
- Customer and transaction data including purchase history, service records, billing information, and payment status.
- Technical data such as device type, browser type, IP address, time zone setting, operating system, and log information.
- Usage data including how you interact with our services, pages visited, preferences, and service performance data.
- Communication data including records of correspondence, support requests, feedback, and complaints.
We do not intentionally collect special category data unless it is required by law or you choose to provide it in a specific context. When such data is processed, it will be handled with additional safeguards and only where permitted under GDPR.
3. How We Collect Data
Personal data may be collected directly from you when you provide it, such as when you register, place an order, request support, or otherwise communicate with us. We may also collect data automatically through technical means, including logs and similar tools that help us maintain security, diagnose problems, and improve service quality. In some cases, we may receive data from third parties, such as payment providers, delivery partners, or service processors acting on our behalf.
4. Purposes of Processing
We process personal data for the following purposes:
- To provide, operate, and maintain the services.
- To manage customer relationships and respond to requests.
- To process payments, invoices, and transactions.
- To deliver customer support and handle complaints.
- To improve performance, usability, and service reliability.
- To ensure security, prevent fraud, and protect against misuse.
- To comply with legal, regulatory, and contractual obligations.
- To send service-related notices and administrative communications.
We will not use personal data for purposes that are incompatible with the original reasons for collection unless we have a lawful basis to do so.
5. Lawful Basis for Processing
Under GDPR, we rely on one or more lawful bases to process personal data. These include:
Contractual Necessity
We process personal data where it is necessary to enter into or perform a contract with you, such as providing services, handling orders, or managing accounts.
Legal Obligation
We may process personal data to comply with legal obligations, including tax, accounting, consumer protection, fraud prevention, or regulatory requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Examples include service improvement, security monitoring, internal administration, and defending legal claims.
Consent
Where required, we will process personal data based on your consent. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Interest
In limited cases, we may process personal data where necessary to protect vital interests or where processing is carried out in the public interest in accordance with applicable law.
6. Sharing and Processors
We may share personal data with carefully selected third parties that help us operate and improve our services. These third parties may act as processors under GDPR and are only allowed to process data according to our instructions and applicable law.
Examples of processors may include:
- IT and hosting providers.
- Payment processing services.
- Customer support systems.
- Analytics and performance tools.
- Accounting, auditing, and compliance providers.
- Delivery and logistics partners where applicable.
We require processors to implement appropriate technical and organizational safeguards, maintain confidentiality, and process data only for specified purposes. We may also share personal data with independent controllers, such as regulators, professional advisers, or public authorities, when required by law or when necessary to protect legal rights.
7. International Transfers
If personal data is transferred outside the European Economic Area, we will take appropriate steps to ensure a lawful and secure transfer. These steps may include using approved safeguards such as Standard Contractual Clauses or other legally recognized mechanisms. Where required, we will assess the destination country and the receiving party’s ability to protect your data.
8. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, reporting, and operational requirements. Retention periods are determined by factors such as the nature of the data, the reason for processing, legal obligations, the need to resolve disputes, and the security of our systems.
When personal data is no longer required, it will be securely deleted, anonymized, or otherwise disposed of in a safe and lawful manner. In some cases, we may retain limited information for longer periods where required by law or where necessary to establish, exercise, or defend legal claims.
9. Data Security
We apply appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption where appropriate, secure storage, staff training, and regular review of security practices. However, no system can be guaranteed to be completely secure, and you should also take steps to protect your own information.
10. Your Rights Under GDPR
If you are a customer in the area and GDPR applies to your personal data, you have the following rights, subject to legal limitations:
- Right of access to obtain confirmation and a copy of your personal data.
- Right to rectification to correct inaccurate or incomplete data.
- Right to erasure to request deletion of personal data in certain circumstances.
- Right to restriction to limit processing in specific situations.
- Right to data portability to receive data in a structured, commonly used format and transmit it to another controller where applicable.
- Right to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent where processing is based on consent.
- Right not to be subject to automated decision-making in cases where such decision-making has legal or similarly significant effects, subject to applicable exceptions.
You may also have the right to lodge a complaint with your local data protection authority if you believe your personal data has been handled unlawfully.
11. Exercising Your Rights
Requests to exercise rights will be reviewed in accordance with applicable data protection laws. We may need to verify your identity before responding to a request. In some cases, we may be unable to comply fully if retaining the data is necessary to meet legal obligations, protect the rights of others, or support legitimate and lawful business interests. Any response will be provided within the timeframe required by GDPR or other applicable law.
12. Children’s Data
The services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate legal basis and, where required, parental consent or other lawful authorization. If we become aware that data has been collected in violation of this Policy, we will take reasonable steps to delete or secure it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or technical changes. When we do, we will revise the policy text accordingly. The updated version will apply from the date it takes effect, unless otherwise required by law. We encourage you to review this Policy periodically to stay informed about how your data is processed.
14. Final Statement
This Privacy Policy is intended to ensure transparency and accountability in the processing of personal data for all customers in the area. We are committed to handling personal information lawfully, fairly, and securely, with respect for your rights and freedoms. Privacy, trust, and compliance remain central to how we operate.
