Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when services are provided to customers in the relevant area. It applies to all customers in that area and should be read together with any service terms or notices presented at the point of data collection. We are committed to processing personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
1. Who This Policy Applies To
This Policy applies to all customers in the area where the services are offered, including individuals who browse, inquire about, purchase, or use the services. It also applies to anyone whose personal data is collected, received, or processed in connection with the delivery of those services.
2. Information We Collect
We collect only the personal data needed to provide and improve our services, to meet legal obligations, and to manage our relationship with customers. Depending on how you interact with us, the types of data we may collect include:
- Identity data, such as name, username, or similar identifiers.
- Contact data, such as address, email address, or telephone number.
- Transaction data, such as details about services requested or provided, payment records, billing history, and related information.
- Technical data, such as device information, browser type, IP address, and usage data.
- Communication data, such as messages, requests, complaints, and feedback.
- Profile data, such as preferences, service history, and customer records.
We may collect data directly from you, automatically through systems used to operate our services, or from third parties where lawful and appropriate. We do not collect more data than is reasonably necessary for the purposes described in this Policy.
3. How We Use Personal Data
Personal data is used for clear and legitimate purposes. These may include:
- providing, managing, and delivering services;
- processing enquiries, transactions, and requests;
- maintaining customer accounts and records;
- communicating service-related updates and notices;
- improving service quality, performance, and customer experience;
- detecting, preventing, and investigating fraud, misuse, or security incidents;
- complying with legal, regulatory, accounting, or tax obligations.
Where required, we will also use data to support legitimate business interests, provided those interests are not overridden by your rights and freedoms.
4. Lawful Basis for Processing
We process personal data only where there is a lawful basis under GDPR. The lawful bases we may rely on are:
- Contract: where processing is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
- Legal obligation: where processing is necessary to comply with a legal requirement.
- Legitimate interests: where processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your rights and interests.
- Consent: where you have given clear consent for a specific purpose. You may withdraw consent at any time where consent is the basis for processing.
When relying on legitimate interests, we assess the impact on individuals and ensure a fair balance between our interests and your privacy rights. We will always identify the relevant lawful basis before processing your data for a specific purpose.
5. Data Sharing and Processors
We may share personal data with trusted third parties who act as processors or, in limited circumstances, as independent controllers. Processors are only permitted to process personal data on our instructions and must protect it with appropriate security measures.
Examples of processors may include:
- IT and hosting service providers;
- payment processing services;
- customer support and communication providers;
- data storage and backup providers;
- analytics or reporting providers used to understand service performance;
- professional advisers acting under confidentiality obligations.
We may also disclose personal data if required to do so by law, court order, or regulatory authority, or to protect rights, safety, and security. Where data is transferred to third parties, we require that appropriate data protection safeguards are in place.
6. International Transfers
If personal data is transferred outside the country or region where it was collected, we will ensure that the transfer is carried out in line with GDPR requirements. This may include using standard contractual clauses, adequacy decisions, or other lawful safeguards designed to protect the confidentiality and integrity of the data.
7. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including meeting legal, accounting, reporting, and dispute-resolution obligations. Retention periods vary depending on the type of data and the reason for processing.
In general, we consider the following factors when determining retention periods:
- the nature and sensitivity of the data;
- the purposes for which the data is processed;
- whether legal or regulatory retention periods apply;
- the risk of harm from unauthorised use or disclosure;
- whether the data is needed to resolve issues or enforce rights.
When data is no longer required, it will be securely deleted, anonymised, or otherwise disposed of in a safe and lawful manner.
8. Data Security
We take appropriate technical and organisational measures to protect personal data against accidental loss, unlawful access, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff training, and regular review of security practices. While no system can guarantee complete security, we work to maintain a level of protection appropriate to the risk.
9. Your Rights Under GDPR
Where GDPR applies, you have a number of important rights in relation to your personal data. These rights may be subject to limitations or exceptions under applicable law.
- Right of access: you can request confirmation of whether your data is being processed and obtain a copy of that data.
- Right to rectification: you can ask for inaccurate or incomplete data to be corrected.
- Right to erasure: in certain cases, you can ask for your data to be deleted.
- Right to restriction: you can request that processing be limited in specific circumstances.
- Right to data portability: you can request that certain data be provided to you or another controller in a structured, commonly used format.
- Right to object: you can object to processing based on legitimate interests or to direct marketing where applicable.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
You also have the right to raise concerns about how your personal data is handled with the relevant supervisory authority. We encourage you to first use the available internal process so concerns can be reviewed promptly and fairly.
10. Automated Decision-Making
We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects, unless this is clearly permitted by law and appropriate safeguards are in place. If this changes, affected individuals will be informed of the logic involved, the significance of the processing, and any rights available to them.
11. Children’s Data
Our services are intended for customers in the relevant area and are not directed to children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate legal basis and safeguards. If we learn that we have collected such data without permission, we will take steps to delete it or obtain the necessary authorisation where applicable.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service arrangements. Any revised version will apply from the date it is made available. You should review this Policy periodically to remain informed about how personal data is handled.
Summary of Core Commitments
- We process personal data lawfully, fairly, and transparently.
- We collect only what is necessary for defined purposes.
- We use processors under appropriate contractual controls.
- We retain data only as long as needed.
- We respect and support your GDPR rights.
This Privacy Policy is intended to provide a clear and accessible explanation of our data protection practices for all customers in the area. If any part of this Policy is found to conflict with applicable law, the law will prevail to the extent of the conflict.
