Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when customers interact with our services in the area. It applies to all customers in the area, including individuals who browse, inquire about, purchase, or otherwise use our services. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with applicable data protection laws, including the GDPR where it applies.
1. Scope of this Policy
This policy applies to personal data relating to identifiable individuals. It covers information processed in connection with service delivery, account administration, customer support, billing, security, and legal compliance. It does not apply to anonymized data that cannot reasonably identify a person.
Important: By using our services, you acknowledge that your personal data may be processed as described in this policy, subject to your rights under data protection law.
2. Data We Collect
We collect only the data necessary for legitimate business and legal purposes. Depending on how you interact with us, we may collect the following categories of personal data:
- Identity Data: name, title, and similar identifiers.
- Contact Data: email address, telephone number, postal address, and other communication details.
- Transaction Data: details of services requested or delivered, payment records, billing information, and related correspondence.
- Technical Data: device identifiers, browser type, IP address, log data, and usage information.
- Profile Data: preferences, service history, and feedback.
- Communications Data: records of inquiries, complaints, and support requests.
- Compliance Data: records needed to meet legal, regulatory, tax, accounting, or audit obligations.
We may collect data directly from you, automatically through systems and devices, or from third parties where lawful and appropriate.
3. How We Use Personal Data
We use personal data for specific and limited purposes, including:
- providing and managing our services;
- processing transactions and maintaining financial records;
- responding to questions, requests, and complaints;
- verifying identity and preventing fraud;
- maintaining security, system integrity, and service performance;
- meeting legal, tax, and regulatory obligations;
- improving our services and customer experience;
- establishing, exercising, or defending legal claims.
We will not use personal data in ways that are incompatible with the original purpose unless we have a lawful basis to do so.
4. Lawful Basis for Processing
Where the GDPR applies, we process personal data only when we have a valid legal basis. Depending on the activity, our lawful bases may include:
- Contract: processing is necessary to perform a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: processing is necessary to comply with a legal duty, such as recordkeeping, tax, fraud prevention, or regulatory reporting.
- Legitimate Interests: processing is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Examples include improving services, securing systems, and managing business operations.
- Consent: where required by law, we may rely on your consent, which you may withdraw at any time.
- Vital Interests: in rare cases, processing may be necessary to protect someone’s life or physical safety.
When we rely on legitimate interests, we consider the nature of the data, the context of processing, and the impact on individuals. We aim to process data in a way that is proportionate, secure, and respectful of privacy.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, reporting, or dispute-resolution requirements. Retention periods vary depending on the type of data and the reason for processing.
- Customer and transaction records are generally retained for the period required by contract, law, and financial recordkeeping obligations.
- Support and communications records may be kept for a reasonable period to manage ongoing service issues and quality assurance.
- Technical logs are typically retained for a shorter period unless needed for security investigations, fraud prevention, or legal claims.
Once data is no longer needed, we will delete it securely or anonymize it so that it can no longer identify you. Retention is reviewed periodically to ensure data is not kept longer than necessary.
6. Sharing and Processors
We may share personal data with trusted third parties who act as processors or independent controllers, only where necessary and lawful. Processors process data on our behalf and under our instructions. We require them to implement appropriate technical and organizational safeguards.
Examples of processors and service providers may include:
- IT and hosting providers;
- payment and billing service providers;
- customer support and communication tools;
- analytics and security service providers;
- professional advisers, such as legal, accounting, or audit services.
We may also disclose personal data where required by law, court order, or other lawful request, or where necessary to protect rights, safety, or property. Where data is transferred outside the EEA or UK, appropriate safeguards will be used to protect your information.
7. Data Security
We use reasonable and appropriate security measures to protect personal data from unauthorized access, alteration, disclosure, loss, or destruction. These measures may include access controls, encryption, secure storage, staff training, and monitoring.
However, no system can be guaranteed completely secure. If a personal data breach occurs that poses a risk to individuals, we will take appropriate steps in line with applicable law, which may include notifying affected individuals and relevant authorities where required.
8. Your Rights
Depending on your location and the applicable law, you may have the following rights regarding your personal data:
- Access: to request confirmation of whether we process your data and obtain a copy of it.
- Rectification: to request correction of inaccurate or incomplete data.
- Erasure: to request deletion of data in certain circumstances.
- Restriction: to request limited processing in certain cases.
- Portability: to receive data you have provided in a structured, commonly used format, where applicable.
- Objection: to object to processing based on legitimate interests or direct marketing, where applicable.
- Withdrawal of Consent: to withdraw consent at any time where processing is based on consent.
You may also have the right to lodge a complaint with a data protection authority if you believe your rights have been violated. We encourage you to raise concerns so we can address them promptly and fairly.
9. Automated Decision-Making
We do not intend to make decisions based solely on automated processing that produce legal or similarly significant effects, unless this is permitted by law and appropriate safeguards are in place. If such processing is ever used, we will provide relevant information about the logic involved and your available rights.
10. Children’s Data
Our services are not directed at children, and we do not knowingly collect personal data from children unless this is necessary and lawful. If we become aware that data has been collected from a child without proper authorization, we will take steps to delete it or seek the required permission, as applicable.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service offerings. Any updates will take effect when published unless otherwise stated. We encourage customers to review this policy periodically to remain informed about how personal data is handled.
Summary of Key Commitments
We collect only necessary data, process it on a valid lawful basis, retain it for no longer than needed, use trusted processors, and respect your rights. This policy applies to all customers in the area and is designed to support transparent, secure, and lawful data processing.
