Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when individuals engage with our services. It applies to all customers in the area and is designed to reflect the requirements of the General Data Protection Regulation (GDPR) and related data protection laws. We are committed to handling personal data lawfully, fairly, transparently, and with respect for individual rights.
1. Scope of This Policy
This Policy applies to personal data processed in connection with the provision of our services to customers in the area. It covers data collected directly from individuals, data generated through service use, and data received from third parties where permitted by law. It also explains the purposes for which data is used, the lawful bases relied upon, the retention of data, the use of processors, and the rights available to individuals under applicable law.
2. Data We Collect
We collect only the personal data that is necessary for specified and legitimate purposes. Depending on the nature of the relationship and the services used, this may include:
- Identity data: name, title, date of birth, and similar identifying details.
- Contact data: address, email address, telephone number, and communication preferences.
- Account and service data: login details, account settings, purchase history, service requests, and records of interactions.
- Payment-related data: billing information and transaction records, where necessary for payment processing and financial administration.
- Technical data: device information, browser type, IP address, log files, and usage patterns.
- Communication data: messages, feedback, complaints, and correspondence with us.
We do not intentionally collect special category data unless it is strictly necessary, lawful, and supported by an appropriate condition under GDPR. Where such data may be provided by an individual, it will be processed with heightened safeguards.
3. How We Use Personal Data
Personal data is processed for clear and limited purposes, including:
- providing and administering services;
- managing accounts and customer relationships;
- processing payments and fulfilling transactions;
- responding to enquiries, complaints, and support requests;
- maintaining security, preventing fraud, and detecting misuse;
- meeting legal, regulatory, tax, and accounting obligations;
- improving service quality, performance, and operational efficiency;
- sending necessary service communications and, where permitted, relevant updates.
We will not use personal data for purposes that are incompatible with the original reasons for collection unless permitted by law and appropriately disclosed.
4. Lawful Basis for Processing
Under GDPR, we rely on one or more lawful bases for each processing activity. These may include:
Contract
We process personal data where it is necessary to enter into or perform a contract with a customer, or to take steps at the request of an individual before entering into a contract.
Legal Obligation
We may process data where required to comply with legal obligations, including accounting, tax, consumer protection, record-keeping, and regulatory requirements.
Legitimate Interests
We may process data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the rights and freedoms of the individual. Examples may include service improvement, fraud prevention, network security, and internal administration.
Consent
Where required, we rely on consent. If processing is based on consent, individuals may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Interest
In limited circumstances, we may process data to protect vital interests or where processing is necessary for reasons of public interest, as permitted by applicable law.
5. Sharing and Processors
We may share personal data with trusted third parties who process data on our behalf, known as processors. These processors are selected carefully and are bound by contractual obligations to act only on our instructions, maintain confidentiality, and implement appropriate technical and organisational security measures.
Examples of processor categories may include:
- IT and hosting service providers;
- payment service providers;
- customer support and communication tools;
- security and fraud-prevention providers;
- analytics and system-monitoring providers;
- professional advisers acting under confidentiality obligations.
We may also disclose personal data where required by law, to respond to lawful requests, to enforce legal rights, or to protect the rights, property, or safety of individuals or our organisation. If data is transferred outside the European Economic Area, appropriate safeguards will be used in accordance with GDPR requirements.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. Retention periods depend on the type of data, the purpose of processing, the sensitivity of the data, and relevant statutory obligations.
In general:
- customer account and transaction records are retained for the period needed to administer services and comply with legal duties;
- support and communication records are retained for operational and dispute-handling purposes;
- technical logs may be retained for security, troubleshooting, and fraud prevention;
- where data is no longer required, it will be securely deleted, anonymised, or archived in line with our retention procedures.
Retention may be extended where necessary to establish, exercise, or defend legal claims.
7. Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff training, and monitoring of systems for suspicious activity. While no system can be guaranteed completely secure, we take data protection seriously and regularly review safeguards to keep them effective.
8. Individual Rights
Individuals whose data is processed under this Policy have rights under GDPR, subject to certain conditions and exemptions. These rights include:
- Right of access: to obtain confirmation of whether personal data is being processed and to receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limited processing in specific situations.
- Right to data portability: to receive personal data in a structured, commonly used, machine-readable format where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, that consent may be withdrawn at any time.
Individuals also have the right not to be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects, unless permitted by law.
Requests relating to these rights will be handled in accordance with GDPR and within applicable time limits. Where permitted by law, we may ask for information needed to verify identity before responding to a request.
9. Complaints and Supervisory Authorities
If an individual believes personal data has been processed unlawfully or that their rights have been infringed, they may lodge a complaint with the relevant data protection supervisory authority. Individuals are encouraged to raise concerns so that they can be reviewed and addressed promptly. This does not affect any right to seek a remedy before a court or other competent authority, where available under law.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service arrangements. Any revised version will apply from the date it takes effect. We encourage individuals to review this Policy periodically so they remain informed about how personal data is handled.
11. Summary of Key Principles
In processing personal data, we are guided by the core GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability. We aim to process only what is necessary, keep data secure, and respect the rights of all customers in the area.
This Privacy Policy applies to all customers in the area and governs the processing of personal data in connection with our services.
