Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area where our services are offered, and it is intended to meet the requirements of the General Data Protection Regulation (GDPR). Please read this policy carefully so you understand how your information is handled.
1. Data We Collect
We collect only the personal data that is necessary for legitimate business and operational purposes. Depending on how you interact with us, we may collect the following categories of information:
- Identity data: name, title, and similar identifiers.
- Contact data: billing details, delivery information, and other communication-related information.
- Transaction data: details of purchases, payments, services requested, and related records.
- Technical data: device type, browser type, IP address, operating system, and usage logs.
- Usage data: information about how you use our services, pages viewed, time spent, and interaction patterns.
- Communication data: records of correspondence and support interactions.
We do not intentionally collect special category data unless it is strictly necessary, permitted by law, and supported by an appropriate lawful basis. Where such data is collected, we apply additional safeguards.
2. How We Collect Data
We collect personal data directly from you when you provide it to us, such as when you place an order, submit a request, make an inquiry, or otherwise interact with our services. We may also collect data automatically through technical tools that record usage and device information. In some cases, we may receive personal data from third parties, including service providers, payment processors, delivery partners, or publicly available sources where permitted by law.
3. Purposes of Processing
We use personal data for specific, explicit, and legitimate purposes. These include:
- Providing and managing our services;
- Processing transactions and maintaining business records;
- Responding to inquiries and offering customer support;
- Improving and securing our services, systems, and processes;
- Complying with legal, accounting, tax, and regulatory obligations;
- Preventing fraud, misuse, unauthorized access, and other harmful activity;
- Managing internal administration, reporting, and quality control.
We will not process personal data in a manner that is incompatible with these purposes unless we have a valid legal basis and, where necessary, your consent.
4. Lawful Basis for Processing
Under GDPR, we process personal data only where we have a valid lawful basis. Depending on the specific activity, the lawful basis may include:
- Contract: processing is necessary to enter into or perform a contract with you, or to take steps at your request before entering a contract.
- Legal obligation: processing is necessary to comply with legal requirements.
- Legitimate interests: processing is necessary for our legitimate interests or those of a third party, provided these interests are not overridden by your rights and freedoms.
- Consent: processing is based on your freely given, specific, informed, and unambiguous consent where required.
- Vital interests: processing may be necessary to protect someone’s life in rare circumstances.
When we rely on legitimate interests, we assess the impact on your rights and interests and only continue when the balance is appropriate. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Sharing and Processors
We may share personal data with trusted third parties who act as processors on our behalf. These processors are permitted to handle personal data only under our instructions and are required to protect it using appropriate technical and organizational measures. Typical processor categories may include:
- IT and hosting providers;
- Payment service providers;
- Customer support platforms;
- Analytics and performance service providers;
- Security, fraud prevention, and monitoring services;
- Professional advisers such as accountants, auditors, or legal advisers where necessary.
We may also disclose personal data where required by law, to respond to lawful requests from public authorities, or to protect our rights, users, staff, and property. Where a third party processes data on our behalf, we enter into appropriate contractual arrangements to ensure GDPR-compliant safeguards.
6. International Transfers
If personal data is transferred outside the European Economic Area, we will ensure that suitable safeguards are in place before any transfer occurs. These safeguards may include adequacy decisions, standard contractual clauses, or other legally recognized mechanisms. We take additional steps where necessary to protect transferred data from unauthorized access, disclosure, or misuse.
7. Retention of Personal Data
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, tax, and reporting obligations. Retention periods may vary depending on the type of data and the reason for processing. In general:
- Data needed to provide services is retained for the duration of the relationship and for a reasonable period afterward;
- Financial and transactional records are retained for the period required by applicable law;
- Support and communication records are retained as needed to manage queries, resolve disputes, and maintain records;
- Technical and security logs are retained for a limited period unless longer retention is required for investigation or compliance purposes.
When personal data is no longer required, we will delete, anonymize, or securely archive it in accordance with our retention practices. Where deletion is not immediately possible due to legal or technical reasons, we will restrict processing until deletion can be completed.
8. Data Security
We use appropriate technical and organizational safeguards designed to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, confidentiality obligations, and regular review of security practices. Although no system can be guaranteed completely secure, we continuously work to improve our safeguards and minimize risk.
9. Your Rights Under GDPR
You have important rights in relation to your personal data. Subject to certain conditions and exemptions under GDPR, you may have the right to:
- Access your personal data and receive information about how we process it;
- Rectification of inaccurate or incomplete data;
- Erasure of your data in certain circumstances;
- Restriction of processing in certain circumstances;
- Data portability for data you have provided to us where processing is based on consent or contract and carried out by automated means;
- Object to processing based on legitimate interests or for direct marketing purposes;
- Withdraw consent at any time where processing is based on consent;
- Not be subject to automated decision-making where such decisions produce legal or similarly significant effects, unless permitted by law.
You may also have the right to lodge a complaint with your local data protection authority if you believe your rights have been infringed. We encourage you to review your information and contact us through the appropriate channels if you believe any data is inaccurate or if you wish to exercise any of your rights.
10. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children in circumstances where parental consent is required. If we become aware that personal data has been collected inappropriately, we will take reasonable steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service developments. Any revised version will apply from the date it is made effective. We encourage you to review this policy periodically so you remain informed about how we process personal data.
Summary of Our Commitment
We process personal data fairly, transparently, and only for lawful purposes. We limit collection to what is necessary, retain data only as long as needed, and require processors to protect your information. Your rights matter, and we aim to respect them consistently for all customers in the area.
This policy applies to all customers in the area and governs all personal data processed in connection with our services.
