Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, disclosed, and protected. It applies to all customers in the area and to any individual whose personal data is processed in connection with the products or services offered. This policy is intended to meet the requirements of the General Data Protection Regulation (GDPR) and any applicable local data protection laws.
1. Scope of This Policy
This policy applies to personal data processed in the course of providing services, managing customer relationships, maintaining records, and operating the business. It covers data collected directly from individuals, data obtained through service interactions, and data received from third parties where lawful and appropriate.
By using the services, customers acknowledge that their personal data may be processed as described in this policy. Where required by law, additional notices or consents may be provided for specific processing activities.
2. Personal Data We Collect
We may collect the following categories of personal data:
- Identity data, such as name, username, or similar identifiers;
- Contact data, such as email address, billing address, or phone number;
- Account data, including login details and account preferences;
- Transaction data, such as payment status, purchase history, and service records;
- Technical data, including device type, browser information, IP address, and usage logs;
- Communication data, including correspondence and service-related inquiries;
- Preference data, such as marketing choices and service settings;
- Compliance data, where necessary to meet legal, regulatory, or audit obligations.
We collect this information either directly from you, automatically through your interaction with our systems, or from authorized third parties. We only collect data that is relevant, adequate, and limited to what is necessary for the purposes described in this policy.
3. How We Use Personal Data
Personal data is processed for the following purposes:
- To provide and operate services;
- To manage customer accounts and transactions;
- To communicate service updates, notices, and administrative information;
- To improve service quality, functionality, and user experience;
- To maintain security, detect fraud, and prevent misuse;
- To comply with legal obligations and respond to lawful requests;
- To establish, exercise, or defend legal claims;
- To send marketing communications where permitted by law or consent.
We do not use personal data in a way that is incompatible with the purposes for which it was collected.
4. Lawful Basis for Processing
Under GDPR, we process personal data only where a lawful basis exists. Depending on the activity, the lawful basis may be one or more of the following:
- Performance of a contract – when processing is necessary to provide services or fulfill obligations to the customer;
- Legal obligation – when processing is required to comply with applicable laws, tax rules, accounting requirements, or lawful authority requests;
- Legitimate interests – when processing is necessary for our legitimate business interests, provided those interests are not overridden by the rights and freedoms of the individual;
- Consent – when you have given clear, informed, and voluntary permission for a specific purpose, such as certain marketing activities;
- Vital interests – in rare cases where processing is necessary to protect someone’s life;
- Public task or official authority – where applicable under law.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. Data Sharing and Processors
We may share personal data with trusted service providers and other third parties acting as processors or independent controllers where permitted by law. Processors may include:
- Hosting and infrastructure providers;
- Payment service providers;
- Customer support and communication tools;
- Analytics and performance service providers;
- Security, fraud prevention, and compliance providers;
- Professional advisers, including legal, accounting, or audit services;
- Public authorities, regulators, or courts where legally required.
All processors are required to handle personal data securely, only on documented instructions, and in accordance with applicable data protection requirements. Where international transfers are necessary, appropriate safeguards will be used, such as standard contractual clauses or equivalent lawful measures.
We do not sell personal data. Any disclosure is limited to what is reasonably necessary for the purposes set out in this policy.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to meet legal, accounting, tax, reporting, and dispute resolution requirements.
Retention periods vary depending on the type of data and the purpose of processing. In general:
- Account and service data are retained for the duration of the customer relationship and for a reasonable period afterward;
- Transaction and financial records are retained for periods required by law;
- Support and communication records are retained as long as needed to address issues and improve services;
- Marketing data is retained until you opt out or the data is no longer needed;
- Technical and security logs are retained for a limited period unless a longer retention is needed for security or legal reasons.
When personal data is no longer required, it is securely deleted, anonymized, or otherwise disposed of in a lawful and appropriate manner.
7. Data Security
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and monitoring procedures.
Although no system can be guaranteed to be completely secure, we take reasonable steps to reduce risks and respond promptly to potential incidents. Security is reviewed regularly and improved where necessary.
8. Your Rights Under GDPR
Subject to legal limitations, you have the following rights regarding your personal data:
- Right of access – to request confirmation of whether your data is being processed and to obtain a copy;
- Right to rectification – to request correction of inaccurate or incomplete data;
- Right to erasure – to request deletion of your data in certain circumstances;
- Right to restriction – to request limited processing in certain cases;
- Right to object – to object to processing based on legitimate interests or direct marketing;
- Right to data portability – to receive certain data in a structured, commonly used, machine-readable format and, where feasible, transmit it to another controller;
- Right to withdraw consent – where processing is based on consent;
- Right not to be subject to automated decision-making – including profiling, where such decisions produce legal or similarly significant effects and are not otherwise permitted by law.
You may also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated or your personal data has been processed unlawfully.
Requests will be handled in accordance with applicable law and within the time limits required by GDPR.
How Rights Are Managed
To protect privacy, we may need to verify your identity before responding to requests. Certain requests may be declined or limited where necessary to comply with legal obligations, protect the rights of others, or preserve evidence in connection with a claim.
We aim to respond to valid requests promptly and transparently. Exercising your rights will not result in unfair treatment or discrimination.
9. Children's Data
The services are not intended for children unless otherwise stated by applicable law or a specific service notice. We do not knowingly collect personal data from children without appropriate authorization or consent where required. If we become aware that such data has been collected unlawfully, we will take reasonable steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or service operations. Any updated version will apply from the date it becomes effective. We encourage customers to review this policy periodically to stay informed about how personal data is handled.
11. General Statement
This Privacy Policy is designed to provide a clear and lawful framework for data protection, transparency, and accountability. It applies to all customers in the area and governs the processing of personal data in connection with the services provided. By maintaining appropriate safeguards, using data only for lawful purposes, and respecting individual rights, we seek to ensure that personal data is handled in a fair, secure, and GDPR-compliant manner.
