Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when a customer uses our services. It applies to all customers in the area where our services are offered and is intended to meet the requirements of the General Data Protection Regulation (GDPR). We are committed to handling personal data fairly, transparently, and securely, and to respecting the rights of individuals whose data we process.
1. Scope of this Policy
This policy applies to all customers in the area and to any personal data processed in connection with the provision of our services. It covers data collected directly from customers, data collected automatically through service use, and data received from third parties when necessary for service delivery, legal compliance, or fraud prevention.
Personal data means any information relating to an identified or identifiable natural person. This may include names, contact details, account information, transaction data, device information, and any other information that can directly or indirectly identify an individual.
2. Data Collection
We collect personal data in several ways. The types of data collected depend on how customers interact with our services and the choices they make.
Data provided directly by customers
- Identification details such as name and surname
- Contact details such as email address, telephone number, and postal address
- Account or profile information
- Billing, payment, and transaction information
- Preferences, feedback, complaints, and support requests
Data collected automatically
- Device and browser information
- IP address and approximate location data
- Usage data such as pages viewed, actions taken, and time spent
- Technical logs and diagnostic information
Data obtained from third parties
- Verification or fraud-prevention data from trusted service providers
- Payment confirmation or refund-related information from payment partners
- Publicly available information where lawful and relevant
We aim to collect only the data that is necessary for the purposes described in this policy. Where possible, we limit collection to the minimum required to provide services effectively and lawfully.
3. Purposes of Processing
We process personal data for the following purposes:
- To provide and manage services
- To create and maintain customer accounts
- To process payments and manage invoices or refunds
- To communicate with customers about service-related matters
- To offer support and respond to enquiries or complaints
- To detect, investigate, and prevent fraud, abuse, or security incidents
- To comply with legal and regulatory obligations
- To improve service quality, performance, and user experience
We do not use personal data for purposes that are incompatible with the original reasons for which it was collected, unless we have a lawful basis to do so and, where required, we notify the customer.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing personal data. Depending on the activity, we rely on one or more of the following bases:
- Performance of a contract: when processing is necessary to provide services, manage accounts, or fulfil customer requests.
- Legal obligation: when processing is necessary to meet legal, tax, accounting, or regulatory requirements.
- Legitimate interests: when processing is necessary for our legitimate business interests, provided those interests are not overridden by the customer’s rights and freedoms. This may include service improvement, security, fraud prevention, and internal administration.
- Consent: when the customer has given clear and informed consent for a specific purpose, such as certain marketing or optional data uses. Customers may withdraw consent at any time where consent is the lawful basis.
Where we rely on legitimate interests, we assess the potential impact on individuals and take steps to protect privacy. Where we rely on consent, it is obtained in a manner that is freely given, specific, informed, and unambiguous.
5. Sharing and Processors
We may share personal data with trusted third parties who act as processors or, in limited cases, independent controllers. Processors only process data on our instructions and are required to protect it appropriately.
Categories of processors may include:
- IT hosting and infrastructure providers
- Payment processing providers
- Customer support and communication tools
- Analytics and performance monitoring services
- Security, fraud detection, and identity verification providers
- Professional advisers, including legal, accounting, or compliance services
We require processors to implement appropriate technical and organisational measures, to process personal data only for authorized purposes, and to comply with applicable data protection obligations. We do not sell personal data.
We may also disclose personal data where required by law, to respond to lawful requests from public authorities, to protect our rights or property, or to prevent harm, fraud, or security threats.
6. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with equivalent protections, we ensure that appropriate safeguards are in place. These safeguards may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms. We take reasonable steps to ensure that transferred data remains protected in accordance with GDPR standards.
7. Retention of Personal Data
We keep personal data only for as long as necessary for the purposes for which it was collected, or as required to comply with legal obligations, resolve disputes, and enforce agreements. The retention period may vary depending on the type of data and the context of processing.
Typical retention principles include:
- Account and service records: retained for the duration of the relationship and for a reasonable period afterward
- Transaction and billing records: retained for tax, accounting, and audit obligations
- Support communications: retained as needed to manage issues and service quality
- Security and log data: retained for a limited period for monitoring and investigation
When data is no longer needed, it is securely deleted, anonymized, or otherwise rendered unusable in accordance with our retention procedures.
8. Security Measures
We use appropriate technical and organisational measures to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, monitoring, and staff confidentiality obligations. While no system can guarantee absolute security, we work to maintain a level of protection appropriate to the risk presented by the data processed.
9. User Rights Under GDPR
Customers have several rights regarding their personal data, subject to the conditions and exceptions set out in GDPR. These rights include:
- Right of access: to obtain confirmation and a copy of personal data being processed
- Right to rectification: to correct inaccurate or incomplete data
- Right to erasure: to request deletion of personal data in certain circumstances
- Right to restriction: to limit processing in specific situations
- Right to data portability: to receive data in a structured, commonly used, machine-readable format where applicable
- Right to object: to object to processing based on legitimate interests or direct marketing
- Right to withdraw consent: where processing relies on consent
- Right not to be subject to automated decision-making: including profiling, where it produces legal or similarly significant effects, unless permitted by law
Requests will be handled in accordance with GDPR time limits and requirements. We may need to verify identity before fulfilling a request, especially where the request concerns sensitive data or access to account information.
10. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate authorization or another lawful basis. If we become aware that data has been collected inappropriately, we will take reasonable steps to delete it or obtain the necessary permissions.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or service operations. Any updated version will apply from the date it becomes effective. We encourage customers to review the policy periodically to stay informed about how personal data is processed.
12. Final Statement
This Privacy Policy is designed to ensure transparent, lawful, and fair processing of personal data for all customers in the area. We are committed to respecting privacy rights, using personal data responsibly, and maintaining compliance with GDPR principles including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability.
