Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It is intended to meet the requirements of the General Data Protection Regulation (GDPR) and applies to all customers in the area served by our services.
By using our services, you acknowledge that you have read and understood this Privacy Policy. We are committed to handling personal data lawfully, fairly, and transparently, and to respecting the rights of individuals whose data we process.
1. Data Collection
We may collect and process personal data that is necessary to provide our services, manage our operations, and comply with legal obligations. The types of data collected may include:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, telephone number, and other communication details.
- Account and transaction data: records of services requested, purchases, payment status, and related correspondence.
- Technical data: IP address, device information, browser type, operating system, and usage information.
- Communication data: messages, feedback, requests, complaints, and support interactions.
- Preference data: choices regarding services, communications, and settings.
We collect data directly from individuals when they interact with us, and we may also receive data from third parties where lawful and appropriate. Only data relevant to the stated purpose will be collected.
2. Lawful Basis for Processing
We process personal data only when there is a valid lawful basis under the GDPR. Depending on the purpose, the lawful basis may include:
- Performance of a contract: when processing is necessary to provide a requested service or fulfill an agreement.
- Legal obligation: when processing is required to comply with applicable laws, regulations, or official requests.
- Legitimate interests: when processing is necessary for our legitimate business interests, provided these interests do not override the rights and freedoms of individuals.
- Consent: when individuals have given clear, informed, and freely given consent for specific processing activities.
Where consent is used as the lawful basis, individuals may withdraw it at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.
3. Purpose of Processing
Personal data may be processed for the following purposes:
- To provide and maintain services.
- To manage customer relationships and respond to inquiries.
- To process transactions, invoices, and payments.
- To improve service quality, operations, and user experience.
- To monitor security, prevent fraud, and detect misuse.
- To meet legal, regulatory, tax, accounting, and reporting requirements.
- To communicate important updates relating to services, terms, or policy changes.
We process data only for specified, explicit, and legitimate purposes and do not process it in a manner incompatible with those purposes.
4. Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting obligations.
Retention periods may vary depending on the type of data and the applicable legal requirements. In determining retention, we consider:
- the nature and sensitivity of the data;
- the purpose for which it was collected;
- the length of any contractual relationship;
- legal limitation periods and regulatory obligations;
- the potential need to defend or establish legal claims.
When personal data is no longer required, it will be securely deleted, anonymized, or otherwise disposed of in a safe manner. Retention is limited to what is necessary and proportionate.
5. Sharing and Processors
We may share personal data with trusted third parties that act as processors on our behalf. These processors are permitted to process personal data only under our instructions and only for the agreed purposes.
Examples of processors may include providers of:
- IT hosting and cloud infrastructure;
- customer support and communication tools;
- payment processing services;
- data storage and backup solutions;
- analytics and performance monitoring tools;
- administrative and business systems.
Before engaging processors, we take reasonable steps to ensure they provide appropriate guarantees regarding security, confidentiality, and GDPR compliance. Where required, a data processing agreement will be in place.
We may also disclose personal data where necessary to comply with law, enforce our legal rights, protect against fraud or abuse, or respond to lawful requests from public authorities.
6. International Transfers
If personal data is transferred outside the European Economic Area, we will ensure that appropriate safeguards are in place. These safeguards may include adequacy decisions, Standard Contractual Clauses, or other lawful mechanisms recognized under the GDPR.
We will take reasonable steps to ensure that transferred data continues to receive a level of protection consistent with GDPR standards.
7. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, encryption where appropriate, secure storage, and regular review of internal procedures.
No system can be guaranteed to be completely secure, but we maintain reasonable safeguards designed to reduce risk and protect personal information. Security measures are reviewed and updated as needed.
8. User Rights Under GDPR
Individuals whose personal data is processed have several rights under the GDPR. Subject to legal limitations, these rights include:
- Right of access: to obtain confirmation of whether personal data is being processed and to receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limitation of processing in certain situations.
- Right to data portability: to receive personal data in a structured, commonly used, machine-readable format and transmit it to another controller where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time.
- Right not to be subject to automated decision-making: to avoid decisions made solely by automated means where they produce legal or similarly significant effects, unless permitted by law.
To exercise these rights, individuals may make a request in accordance with the procedures applicable to the service relationship. We may need to verify identity before responding to protect privacy and security.
9. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate authorization where required by law. If we become aware that such data has been collected unlawfully, we will take appropriate steps to delete it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal, technical, or operational requirements. Any updated version will apply from the effective date of publication or implementation, as applicable.
We encourage individuals to review this Privacy Policy periodically so they remain informed about how personal data is processed. Continued use of the services after changes take effect indicates acceptance of the updated policy, where permitted by law.
11. Final Statement
This Privacy Policy applies to all customers in the area and governs the processing of personal data in accordance with GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
We are committed to respecting privacy rights and to handling personal data responsibly. Our aim is to ensure that all processing is necessary, proportionate, and carried out with appropriate safeguards.
