Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with our services. It applies to all customers in the area where our services are offered, regardless of whether access is obtained directly, through a device, or via any other authorized channel. We are committed to handling personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Scope of this Policy
This Policy applies to personal data relating to identified or identifiable natural persons. It covers information collected from customers, prospective customers, visitors, and other individuals whose data is processed in the course of providing services. It does not apply to anonymized information that can no longer be linked to an individual.
By using our services, you acknowledge that your personal data may be processed as described in this Policy.
2. Data We Collect
We collect only the data necessary for the purposes described below. Depending on how you interact with us, we may process the following categories of personal data:
- Identity data: name, username, and similar identifiers.
- Contact data: postal address, email address, and telephone number.
- Account data: login details, customer ID, and service preferences.
- Transaction data: records of purchases, payments, invoices, and service history.
- Technical data: IP address, device information, browser type, operating system, and usage logs.
- Communication data: records of correspondence, requests, complaints, and feedback.
- Compliance data: information needed to meet legal, regulatory, tax, or audit obligations.
We generally do not seek to collect special category data unless required by law, necessary for a specific service, or explicitly provided by you with an applicable lawful basis.
3. How We Collect Data
Personal data may be collected directly from you when you provide it in forms, communications, service requests, or during account creation. We may also collect data automatically when you interact with our systems, such as through cookies, logs, or similar technologies. In limited cases, we may receive data from third parties, including payment providers, service partners, public authorities, or fraud prevention sources, where permitted by law.
4. Purposes of Processing
We process personal data for the following purposes:
- to provide, administer, and improve our services;
- to manage customer accounts and service relationships;
- to process payments, refunds, and billing matters;
- to communicate with you about service-related matters;
- to maintain security, prevent fraud, and protect against misuse;
- to comply with legal, tax, accounting, and regulatory requirements;
- to resolve disputes, enforce agreements, and exercise legal claims;
- to analyze service performance and improve user experience;
- to send marketing communications where permitted and where appropriate consent or other lawful basis exists.
We do not use personal data for purposes that are incompatible with the original reason for collection unless we have a valid legal basis to do so.
5. Lawful Basis for Processing
We process personal data only where a lawful basis under GDPR applies. Depending on the context, the lawful basis may be one or more of the following:
5.1 Performance of a Contract
We process data where necessary to enter into or perform a contract with you, including providing services, managing your account, and handling payments.
5.2 Legal Obligation
We process data where necessary to comply with legal duties, such as tax, accounting, consumer protection, anti-fraud, or recordkeeping obligations.
5.3 Legitimate Interests
We may process data where necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. This may include service improvement, fraud prevention, network security, internal administration, and limited direct marketing where allowed by law.
5.4 Consent
Where required, we rely on your consent. For example, we may ask for consent for certain marketing activities or optional data uses. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
5.5 Vital Interests or Public Task
In rare circumstances, we may process data where necessary to protect vital interests or to perform a task carried out in the public interest, where applicable.
6. Data Sharing and Processors
We may share personal data with trusted third parties only when necessary for the purposes described in this Policy and in compliance with applicable law. These third parties may act as processors or independent controllers, depending on the context.
Processors may include:
- IT hosting and cloud service providers;
- payment processors and financial service providers;
- customer support and communication tools;
- analytics and security service providers;
- professional advisers, auditors, and compliance support services;
- logistics, delivery, or operational partners where necessary for service delivery.
When we use processors, they are contractually required to process personal data only on our instructions, maintain appropriate confidentiality and security, and implement suitable technical and organizational measures. We do not allow processors to use your data for their own independent purposes unless they are acting as separate controllers under a lawful basis and with proper transparency.
We may also disclose personal data if required by law, court order, regulator request, or to protect rights, property, safety, or security.
7. International Transfers
If personal data is transferred outside the European Economic Area or to a jurisdiction without an adequacy decision, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses or other legally recognized transfer mechanisms. These safeguards are designed to protect your personal data to a standard consistent with GDPR requirements.
8. Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, tax, contractual, and operational requirements. The retention period may vary depending on the type of data and the purpose of processing.
In general, retention is determined by:
- the duration of our relationship with you;
- statutory limitation periods;
- legal and regulatory retention obligations;
- the need to resolve disputes or enforce agreements;
- the need to maintain security, prevent fraud, or preserve evidence.
When personal data is no longer required, we will delete, anonymize, or securely archive it in accordance with applicable laws and internal retention procedures.
9. Data Security
We apply appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Such measures may include access controls, encryption where appropriate, secure storage, network protection, staff confidentiality obligations, and regular review of security practices. No system can be guaranteed to be completely secure, but we take reasonable steps to reduce risk and respond to incidents appropriately.
10. Your Rights Under GDPR
Subject to legal limits and conditions, you have the following rights in relation to your personal data:
- Right of access: to obtain confirmation and a copy of your personal data.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request limited processing in certain situations.
- Right to data portability: to receive data you provided in a structured, commonly used format and, where technically feasible, have it transmitted to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: to withdraw consent at any time where processing relies on consent.
- Right not to be subject to automated decision-making: to avoid decisions based solely on automated processing where such decisions have legal or similarly significant effects, except where permitted by law.
To the extent permitted by applicable law, we may need to verify your identity before acting on a request. Certain requests may be restricted if they would affect the rights of others, conflict with legal obligations, or otherwise fall within a permitted exception.
11. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate authorization or a lawful basis. If we learn that personal data has been collected from a child in violation of applicable law, we will take reasonable steps to delete it or obtain proper authorization as required.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service offerings. Any updated version will apply from the date it becomes effective. We encourage you to review this Policy periodically so that you remain informed about how your personal data is handled.
13. General Statement
This Privacy Policy is intended to provide transparent information about our data processing practices and your rights. If any part of this Policy is found to be invalid or unenforceable, the remaining provisions will remain in effect to the fullest extent permitted by law.
We are committed to protecting personal data and respecting the privacy rights of all customers in the area.
