Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in area and is intended to provide clear information about our processing activities in accordance with applicable data protection laws, including the GDPR where relevant.
1. Scope of This Policy
This Policy applies to all customers in area who use our services, interact with us, or otherwise provide personal data to us. It also applies to individuals acting on behalf of business customers, prospective customers, and other persons whose data we receive in the course of providing our services.
By using our services or providing personal data to us, you acknowledge that your information will be processed as described in this Policy.
2. Data We Collect
We may collect and process different categories of personal data depending on your relationship with us and the services you use. The types of data we may collect include:
- Identity data: name, title, and any identifiers you provide.
- Contact data: address, email address, telephone number, and similar details.
- Account and profile data: login information, preferences, and account settings.
- Transaction data: records of purchases, payments, invoices, and service history.
- Technical data: IP address, browser type, device information, operating system, and usage logs.
- Communication data: correspondence, support requests, feedback, and other messages.
- Marketing data: your preferences for receiving promotional communications.
We generally collect this information directly from you, automatically through your use of our services, or from third parties where lawful and necessary. We strive to collect only the information that is relevant and adequate for the purposes described in this Policy.
3. How We Use Personal Data
We use personal data for the following purposes:
- to provide and manage our services;
- to process orders, payments, and related transactions;
- to communicate with you about your account, requests, or transactions;
- to respond to inquiries and provide customer support;
- to improve service quality, performance, and user experience;
- to protect against fraud, unauthorized access, and security incidents;
- to comply with legal obligations;
- to send marketing communications where permitted by law;
- to establish, exercise, or defend legal claims.
We do not process personal data in ways that are incompatible with the original purposes for which it was collected, unless we have a lawful basis to do so.
4. Lawful Basis for Processing
Where the GDPR applies, we process personal data only when we have a valid lawful basis. Depending on the context, our lawful bases may include:
- Contract: processing is necessary to perform a contract with you or to take steps at your request before entering into a contract.
- Legal obligation: processing is necessary to comply with a legal or regulatory requirement.
- Legitimate interests: processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests.
- Consent: processing is based on your consent where required, such as for certain marketing or optional activities.
- Vital interests: processing may be necessary to protect someone’s life or physical safety in exceptional circumstances.
Where we rely on consent, you may withdraw it at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.
5. Sharing and Processors
We may share personal data with trusted third parties that help us operate our services. These parties act as data processors or, in some cases, independent controllers. Processors may include providers of:
- IT hosting and cloud infrastructure;
- payment processing;
- customer support tools;
- analytics services;
- security and fraud prevention services;
- document storage and administrative support;
- professional advisory services, such as legal, accounting, or auditing support.
We require processors to act only on our documented instructions, to protect personal data appropriately, and to comply with data protection obligations. We do not sell personal data.
We may also disclose personal data if required by law, court order, regulator request, or where disclosure is necessary to protect rights, safety, or property.
6. International Transfers
If personal data is transferred outside the country or region in which it was collected, we will take appropriate safeguards to protect it. These safeguards may include standard contractual clauses, adequacy decisions, or other legal mechanisms recognized under applicable law. We aim to ensure that transferred data remains protected to a standard comparable to that required in the jurisdiction of collection.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, reporting, and operational requirements. Retention periods vary depending on the category of data and the context in which it was collected.
- Data used to provide services is generally kept for the duration of the customer relationship and a reasonable period afterward.
- Financial and transaction records may be retained for longer periods to comply with tax and accounting obligations.
- Support and communication records may be retained for quality assurance, dispute resolution, and recordkeeping purposes.
When data is no longer required, we will delete it, anonymize it, or securely archive it where appropriate. We review retention regularly to avoid keeping personal data longer than necessary.
8. Security Measures
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, encryption, secure storage, monitoring, and staff training. While no system can be guaranteed completely secure, we work to maintain a level of protection appropriate to the risk.
9. Your Rights
Depending on your location and the applicable law, you may have the following rights regarding your personal data:
- Right of access: to obtain confirmation and a copy of the personal data we hold about you.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request that we limit processing in certain situations.
- Right to data portability: to receive certain data in a structured, commonly used format and transmit it elsewhere where feasible.
- Right to object: to object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time.
- Right to lodge a complaint: to raise concerns with a data protection authority if you believe your rights have been violated.
Some rights may be limited where we have a legal obligation or a compelling legitimate reason to continue processing. Requests will be handled in accordance with applicable law.
10. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate authorization where required by law. If we become aware that data has been collected from a child in violation of applicable rules, we will take steps to delete or otherwise handle it lawfully.
11. Automated Decision-Making
We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects, unless such processing is permitted by law and appropriate safeguards are in place. If this changes, we will provide relevant information about the logic involved and your available rights.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updated version will apply from the date it is made available. We encourage you to review this Policy periodically to understand how your personal data is protected.
Summary of Key Commitments
- Data collection: only relevant personal data is collected for defined purposes.
- Lawful basis: processing is based on contract, consent, legal obligation, legitimate interests, or other lawful grounds.
- Retention: data is kept only as long as necessary and then securely deleted or anonymized.
- Processors: third parties are bound by data protection obligations and may act only on our instructions.
- User rights: individuals can access, correct, delete, restrict, port, object, and withdraw consent where applicable.
This Privacy Policy applies to all customers in area and is designed to support transparent and lawful processing of personal data.
