Privacy Policy
This Privacy Policy explains how personal data is collected, used, shared, stored, and protected in connection with our services. It is intended to meet the requirements of the General Data Protection Regulation (GDPR) and applies to all customers in the relevant area. By using our services, you acknowledge that your personal data may be processed in accordance with this Policy.
1. Scope of This Policy
This Policy applies to personal data relating to identifiable individuals, including customers, prospective customers, and other users whose data we process in the course of providing our services. It applies to all customers in the area where our services are offered and where applicable data protection laws require compliance with the GDPR.
We are committed to processing personal data lawfully, fairly, and transparently. We only collect data that is necessary for specified purposes and take appropriate measures to protect it.
2. Data We Collect
We may collect and process the following categories of personal data:
- Identity data: such as name, title, and similar identifiers.
- Contact data: such as address, email address, telephone number, and other communication details.
- Account data: such as account identifiers, login information, and service preferences.
- Transaction data: such as purchase records, service requests, payment confirmations, and related details.
- Technical data: such as device type, browser type, operating system, IP address, and usage logs.
- Communications data: such as messages, feedback, support enquiries, and correspondence history.
- Usage data: such as interactions with our services, pages viewed, features used, and session activity.
We collect this data directly from you when you provide it to us, and indirectly through normal service use, automated systems, or third parties acting on our behalf. Where relevant, we may also receive limited information from publicly available sources or verification providers.
3. How We Use Personal Data
We process personal data for the following purposes:
- to provide and manage our services;
- to create and administer accounts and customer relationships;
- to process transactions and fulfil requests;
- to communicate service updates, notices, or administrative information;
- to respond to enquiries and support requests;
- to improve performance, functionality, and user experience;
- to detect, investigate, and prevent fraud, abuse, and security incidents;
- to comply with legal obligations and enforce our rights;
- to analyse service use for operational and quality purposes.
We only use personal data in ways that are compatible with the purposes for which it was collected, unless we reasonably determine that another compatible purpose applies or a legal requirement permits otherwise.
4. Lawful Basis for Processing
Under the GDPR, we must have a lawful basis for each processing activity. Depending on the context, we rely on one or more of the following lawful bases:
Performance of a Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes account management, service delivery, billing, fulfilment, and customer support connected to the service relationship.
Legal Obligation
We may process personal data where necessary to comply with legal or regulatory obligations, including recordkeeping, tax, accounting, fraud prevention, and responses to lawful requests from authorities.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Legitimate interests may include improving services, maintaining security, preventing misuse, and carrying out internal administration. When relying on this basis, we assess the potential impact on individuals and use appropriate safeguards.
Consent
In limited circumstances, we may process personal data based on your consent. Where consent is used, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Interest
In rare situations, we may process data to protect vital interests or where processing is necessary for tasks carried out in the public interest. These bases are used only when applicable under law.
5. Data Sharing and Processors
We may share personal data with trusted third parties that support our operations. These parties act as processors when they process personal data on our instructions and under appropriate contractual safeguards.
Examples of processors may include:
- hosting and cloud infrastructure providers;
- payment processing providers;
- customer support and communications tools;
- IT security and monitoring services;
- analytics and reporting services;
- professional advisers who assist with legal, accounting, or compliance functions.
We may also share data with independent controllers where required by law, where necessary to protect rights or property, or where you have expressly requested or authorised such sharing. We do not sell personal data.
Where personal data is transferred outside the applicable jurisdiction, we ensure appropriate safeguards are in place, such as standard contractual clauses or other legally recognised transfer mechanisms.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for any legal, accounting, reporting, or dispute-resolution requirements.
Retention periods may vary depending on the type of data and the context of processing. In general:
- account and contract-related data are retained for the duration of the relationship and for a reasonable period afterward;
- transaction and financial records are retained for the period required by applicable law;
- support and communication records are retained as needed to manage queries and demonstrate service history;
- technical and security logs are retained for limited periods, unless longer retention is needed for investigation or compliance;
- data processed on the basis of consent is retained until consent is withdrawn or the data is no longer needed.
When data is no longer required, it is securely deleted, anonymised, or archived in accordance with applicable retention rules. We apply a retention approach that is proportionate to the purpose of processing.
7. Data Security
We use reasonable technical and organisational measures designed to protect personal data against accidental loss, unauthorised access, misuse, alteration, or disclosure. These measures may include access controls, encryption, secure storage, monitoring, backup systems, and staff confidentiality obligations.
While no system can be guaranteed to be completely secure, we continuously review our safeguards and update them where appropriate to address risks to personal data.
8. Your Rights Under GDPR
Subject to legal conditions and exceptions, individuals whose personal data we process have the following rights:
- Right of access: to obtain confirmation and a copy of the personal data we hold about you.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your personal data in certain circumstances.
- Right to restriction: to request that processing be limited in certain situations.
- Right to data portability: to receive certain data in a structured, commonly used format and to have it transmitted where technically feasible.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time.
- Right not to be subject to solely automated decisions: to not be subject to decisions based solely on automated processing that produce legal or similarly significant effects, where this right applies.
You may also have the right to lodge a complaint with your local data protection authority if you believe your rights have been infringed. We encourage individuals to consider raising concerns directly where possible so they may be reviewed promptly and fairly.
9. Children's Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate authority or consent where required by law. If we become aware that we have collected data from a child in breach of applicable requirements, we will take steps to delete or otherwise handle that data appropriately.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, regulation, operational practices, or service arrangements. Any revised version will apply from the effective date stated in the updated text. We encourage individuals to review this Policy periodically to remain informed about how personal data is handled.
In summary: we process personal data lawfully, limit collection to necessary information, retain data only as long as needed, use processors under safeguards, and respect applicable GDPR rights for all customers in the relevant area.
