Privacy Policy
This Privacy Policy explains how we collect, use, store, share, and protect personal data when providing our services to customers in the relevant area. It applies to all customers in that area, including individuals acting in a personal capacity and those interacting with our services on behalf of an organization. We are committed to handling personal data in a lawful, fair, transparent, and secure manner in accordance with applicable data protection law, including the General Data Protection Regulation (GDPR).
1. Scope of this Policy
This Policy applies to personal data processed in connection with our services, communications, and related operations. It covers information collected directly from customers, information generated through service use, and information received from third parties where permitted by law. By using our services, you acknowledge that your personal data may be processed as described in this Policy.
For the purposes of this Policy, “personal data” means any information relating to an identified or identifiable natural person. This may include contact details, account information, identifiers, usage data, transaction records, and any other information that can reasonably be linked to an individual.
2. Personal Data We Collect
We collect only the data necessary for specified, explicit, and legitimate purposes. The categories of data we may collect include:
- Identity and contact information: name, email address, postal address, telephone number, and similar details.
- Account and service information: login credentials, preferences, service settings, and records of interactions.
- Transaction and billing information: payment status, purchase history, invoices, and related records.
- Technical data: device type, browser type, IP address, operating system, and log data.
- Usage data: actions taken within our services, time spent, pages viewed, and feature interactions.
- Communication data: correspondence, support requests, feedback, and records of complaints.
We do not intentionally collect special category data unless it is strictly necessary and permitted by law. Where such data is required, we will apply enhanced safeguards and, where appropriate, seek explicit consent or rely on another valid legal basis.
3. How We Use Personal Data
We use personal data for the following purposes:
- to provide, operate, and improve our services;
- to manage customer accounts and preferences;
- to process transactions and maintain financial records;
- to communicate about service updates, changes, and support matters;
- to monitor performance, security, and service reliability;
- to detect, prevent, and investigate fraud, misuse, or unauthorized access;
- to comply with legal obligations and respond to lawful requests;
- to establish, exercise, or defend legal claims.
We will not use personal data for purposes that are incompatible with the reasons for which it was collected unless we have a valid legal basis and have informed you where required.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for every processing activity. Depending on the purpose and context, we rely on one or more of the following bases:
Contract
We process personal data when it is necessary to enter into or perform a contract with a customer, including service delivery, account administration, and billing.
Legal Obligation
We process personal data where we are required to do so by applicable law, regulation, tax rules, accounting rules, or lawful requests from public authorities.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Examples include service improvement, fraud prevention, network security, and internal reporting. Where legitimate interests are relied upon, we assess the impact on individuals and balance our interests against your privacy rights.
Consent
In limited circumstances, we may rely on your consent, for example for optional communications or certain types of data processing where consent is required by law. You may withdraw consent at any time, and withdrawal will not affect the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Interest
Although uncommon in our ordinary operations, we may process personal data where necessary to protect someone’s vital interests or where processing is carried out in the public interest and permitted by law.
5. Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal and regulatory obligations, to resolve disputes, and to enforce agreements. Retention periods vary according to the type of data and the reason for processing.
In determining retention periods, we consider:
- the amount, nature, and sensitivity of the data;
- the potential risk of harm from unauthorized use or disclosure;
- the purposes of processing and whether they can be achieved by other means;
- legal, accounting, and reporting requirements;
- whether a claim or investigation may reasonably arise.
When personal data is no longer required, we will delete it, anonymize it, or securely archive it where permitted by law. Retention does not mean indefinite storage; data is reviewed periodically and kept only as long as necessary.
6. Processors and Data Sharing
We may share personal data with trusted processors and service providers that perform functions on our behalf. These parties act under our instructions and are required to implement appropriate technical and organizational measures to protect personal data.
Typical categories of processors may include:
- IT hosting and infrastructure providers;
- payment and billing service providers;
- customer support and communication platforms;
- analytics and monitoring service providers;
- security and fraud detection providers;
- professional advisers, auditors, and legal service providers.
We may also disclose personal data where necessary to comply with law, protect our rights, prevent harm, or support a legal or regulatory process. If personal data is transferred outside the relevant area or the European Economic Area, we will ensure that appropriate safeguards are in place, such as standard contractual clauses or other approved transfer mechanisms, where required.
7. Security Measures
We use reasonable and appropriate security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures may include access controls, encryption, logging, staff training, data minimization, and regular review of security practices.
While no system can be guaranteed to be completely secure, we take data protection seriously and strive to maintain a level of security appropriate to the risk. In the event of a personal data breach, we will respond in accordance with applicable law and, where required, notify affected individuals and relevant authorities.
8. Your Rights Under GDPR
Depending on the circumstances and applicable law, you may have the following rights regarding your personal data:
- Right of access: obtain confirmation of whether we process your data and receive a copy of it.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of data in certain situations.
- Right to restriction: request limitation of processing in certain circumstances.
- Right to data portability: receive certain data in a structured, commonly used, machine-readable format and, where feasible, request transfer.
- Right to object: object to processing based on legitimate interests or to direct marketing, where applicable.
- Right to withdraw consent: withdraw consent at any time where processing is based on consent.
- Right not to be subject to automated decision-making: request human review where decisions are made solely by automated means and have legal or similarly significant effects, if applicable.
To protect your privacy, we may need to verify your identity before responding to a rights request. We aim to respond within the time limits required by law. If we cannot act on a request, we will explain the legal reason.
9. International and Local Applicability
This Policy applies to all customers in the relevant area and is intended to meet GDPR standards where applicable. If local law provides additional protections, those protections will apply alongside this Policy. Where there is any conflict between this Policy and mandatory legal requirements, the law will prevail.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Where changes are material, we will take reasonable steps to inform customers in a suitable manner. The updated version will apply from the date it becomes effective.
11. Our Commitment to Privacy
We believe personal data should be handled with care, respect, and accountability. Our goal is to process only what is necessary, protect it appropriately, and give individuals meaningful control over their information. If you continue to use our services, we will continue to process personal data in accordance with this Policy and the principles of data protection law.