Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and other applicable data protection laws.
We are committed to handling personal data lawfully, fairly, and transparently. We only process personal data where we have a valid legal reason to do so, and we take appropriate steps to keep such data secure and accurate.
1. Data We Collect
We may collect and process different categories of personal data depending on how you interact with us and the services you use. The types of data we collect may include:
- Identity data such as your name, title, and similar identifiers.
- Contact data such as address, email address, and telephone number.
- Transaction data such as details about purchases, payments, and records of services provided.
- Technical data such as device information, browser type, internet protocol address, and system settings.
- Usage data such as information about how you access and use our services.
- Communication data such as correspondence, feedback, complaints, and support requests.
- Preference data such as your service and communication preferences.
We generally collect personal data directly from you when you provide it to us. We may also collect data automatically through technical systems or receive it from third parties where permitted by law.
We do not collect more data than is necessary for the purposes described in this Policy.
2. How We Use Personal Data
We process personal data for specific and legitimate purposes, including to:
- provide and manage our services;
- verify identity and maintain security;
- process orders, payments, and refunds;
- communicate with customers about service matters;
- respond to inquiries and handle complaints;
- improve our services, operations, and customer experience;
- maintain records and meet legal, accounting, and regulatory obligations;
- detect, prevent, and investigate fraud or misuse;
- exercise or defend legal claims where necessary.
We use personal data only for purposes that are compatible with the reason it was originally collected, unless we have a lawful basis for a new purpose.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing personal data. Depending on the context, we rely on one or more of the following bases:
Performance of a Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes providing services, administering accounts, processing payments, and delivering customer support.
Compliance with a Legal Obligation
We may process personal data where required to comply with legal and regulatory obligations, including tax, accounting, consumer protection, fraud prevention, and record-keeping requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided that those interests are not overridden by your rights and freedoms. Legitimate interests may include service improvement, network and information security, internal administration, and prevention of misuse.
Consent
In limited circumstances, we may rely on your consent, for example where it is required for certain types of communications or optional processing. Where consent is used, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests
In rare cases, processing may be necessary to protect someone’s vital interests, such as in an emergency situation.
Where personal data is processed on the basis of legitimate interests, we assess the necessity and balance those interests against your rights.
4. Retention of Personal Data
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Retention periods may vary depending on the type of data and the purpose of processing. In general:
- customer account and service records are kept for the duration of the relationship and for a reasonable period afterward;
- transaction and financial records are kept for the period required by law;
- communications and support records are kept as long as needed to manage the matter and for audit or dispute resolution purposes;
- technical and usage data are retained only as long as necessary for security, analytics, and operational purposes.
When personal data is no longer needed, we will delete it, anonymise it, or securely archive it where deletion is not immediately possible.
5. Processors and Third Parties
We may use third-party service providers, also known as processors, to assist us in delivering services and operating our business. These processors may handle personal data only on our documented instructions and must implement appropriate security measures.
Examples of processor services may include:
- IT hosting and infrastructure support;
- payment processing;
- customer relationship and support systems;
- data storage and backup services;
- analytics and performance monitoring tools;
- professional advisers who support legal, accounting, or compliance functions.
Where required, we enter into appropriate contractual arrangements with processors to ensure they process personal data in accordance with GDPR. Processors are not permitted to use your data for their own independent purposes.
We may also disclose personal data to third parties where necessary to comply with law, respond to lawful requests, protect rights and safety, or complete a business transaction such as a reorganisation or transfer of services.
6. International Transfers
Where personal data is transferred outside the European Economic Area or the United Kingdom, we will ensure that appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms permitted by applicable law.
Any international transfer is assessed to ensure that the protection of personal data remains at an adequate level.
7. Data Security
We use technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, monitoring, secure storage, and staff training.
Although we take reasonable steps to safeguard personal data, no system is completely secure. We therefore cannot guarantee absolute security, but we continually review and improve our practices.
8. Your Rights Under GDPR
If you are located in the area covered by GDPR or otherwise entitled to GDPR protections, you have the following rights in relation to your personal data:
- Right of access – to obtain confirmation and a copy of your personal data.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of personal data in certain circumstances.
- Right to restriction – to request limited use of your data in specific situations.
- Right to data portability – to receive your data in a structured, commonly used format and have it transmitted where applicable.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
- Right not to be subject to automated decision-making – including profiling, where such decisions produce legal or similarly significant effects, unless permitted by law.
To exercise these rights, you may make a request in the manner made available to customers. We may need to verify your identity before responding. We will respond within the time limits required by law.
These rights are not absolute and may be subject to legal exceptions or limitations.
9. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without the involvement of a parent, guardian, or other lawful basis where required.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, regulatory guidance, our services, or our data processing practices. Any updated version will apply from the date it is made effective.
We encourage customers to review this Policy periodically so they remain informed about how their personal data is handled.
11. General Principles
We are committed to the core principles of GDPR, including:
- lawfulness, fairness, and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality;
- accountability.
Accordingly, personal data is processed in a manner that is proportionate, necessary, and respectful of individual rights. We only retain and use personal data to the extent required for the stated purposes or as otherwise permitted by law.
This Privacy Policy applies to all customers in the area and governs the processing of personal data connected with our services.
