Privacy Policy
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when providing our services to customers in the area. It applies to all customers in area and is intended to reflect a GDPR-compliant approach to privacy and data protection. By using our services, you acknowledge that personal data may be processed as described in this Policy and that we are committed to handling such data lawfully, fairly, and transparently.
1. Data We Collect
We collect only the personal data that is necessary for the purposes described in this Policy. Depending on how you interact with us, the categories of data may include:
- Identity data: such as your name, title, or account identifiers.
- Contact data: such as email address, phone number, billing address, or service address.
- Transaction data: such as records of purchases, services requested, payment status, and related details.
- Technical data: such as IP address, device type, browser type, operating system, and usage logs.
- Profile data: such as preferences, service choices, and communication settings.
- Communication data: such as messages, feedback, complaints, and support requests.
- Usage data: such as how you navigate or interact with services, where applicable.
We do not intentionally collect special category data unless it is strictly necessary and permitted under data protection law. If any such data is collected, it will be processed only with an appropriate lawful basis and safeguards.
2. How We Use Personal Data
We use personal data for legitimate business and service purposes, including to:
- provide and deliver services requested by customers in area;
- manage accounts, transactions, and service arrangements;
- communicate with you about service matters, updates, and administrative information;
- respond to enquiries, complaints, and support requests;
- maintain records, improve service quality, and perform internal analysis;
- detect, prevent, and investigate fraud, misuse, and security incidents;
- comply with legal obligations and regulatory requirements;
- establish, exercise, or defend legal claims where necessary.
We will only use personal data in ways that are compatible with the original purpose of collection unless we have a lawful basis for a new purpose and provide appropriate notice where required.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. We rely on one or more of the following grounds:
Performance of a Contract
We process personal data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract. This may include processing identity, contact, and transaction data to provide services and manage your account.
Legal Obligation
We may process personal data where required to comply with applicable laws, tax rules, accounting standards, consumer protection requirements, or lawful requests from public authorities.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Examples include improving services, securing systems, preventing fraud, and maintaining internal records. Where we rely on legitimate interests, we assess whether the processing is necessary and proportionate.
Consent
In limited situations, we may rely on your consent, such as where it is required by law for specific optional processing. Where consent is used, it will be freely given, specific, informed, and unambiguous. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Sharing and Processors
We may share personal data with trusted third parties only when necessary and only for the purposes described in this Policy. These third parties may act as processors or independent controllers, depending on the service they provide.
Examples of processors may include:
- IT and hosting providers that store or secure data;
- payment service providers that handle transactions;
- administrative or customer support systems;
- professional advisers who support legal, financial, or compliance matters;
- service providers that assist with communications, backups, or analytics.
Where we use processors, they are bound by written contracts requiring them to process personal data only on our documented instructions, maintain confidentiality, apply appropriate technical and organisational measures, and assist us in meeting data protection obligations. We do not permit processors to use personal data for their own unrelated purposes.
We may also disclose personal data where necessary to comply with legal requirements, protect our rights, prevent fraud, or respond to lawful requests. If personal data is transferred outside the European Economic Area, we will use appropriate safeguards, such as standard contractual clauses or other lawful transfer mechanisms, to protect the data.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting obligations. Retention periods depend on the type of data, the purpose of processing, and any legal requirement that applies.
In general:
- account and transaction records may be kept for the period required by law;
- customer communications may be retained for a reasonable period to manage service history and resolve disputes;
- technical logs may be kept for security, troubleshooting, and fraud prevention;
- where consent is withdrawn or data is no longer needed, it will be deleted or anonymised unless retention is legally required.
When personal data is no longer needed, we will securely delete, destroy, or anonymise it. Retention is reviewed periodically so that data is not kept longer than necessary.
6. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff training, and monitoring procedures.
Although no system can be guaranteed to be completely secure, we take privacy and security seriously and continuously review our safeguards in light of the nature of the data processed and the risks involved.
7. Your Rights Under GDPR
As a data subject, you have rights in relation to your personal data. Subject to legal conditions and exemptions, you may have the right to:
- Access your personal data and obtain a copy of it;
- Rectification of inaccurate or incomplete data;
- Erasure of your data in certain circumstances;
- Restriction of processing in certain situations;
- Data portability for data you provided to us, where applicable;
- Object to processing based on legitimate interests or direct marketing;
- Withdraw consent where processing is based on consent;
- Not be subject to automated decision-making that produces legal or similarly significant effects, where applicable.
You also have the right to lodge a complaint with a relevant supervisory authority if you believe your rights have been infringed. We encourage you to raise concerns first so that we may address them promptly and fairly.
8. Exercising Your Rights
Requests to exercise privacy rights should be made through the appropriate service channels used for account administration or customer support. We may need to verify your identity before responding to a request, especially where it concerns access, deletion, or disclosure of personal data. We will respond within the time limits required by GDPR, usually within one month, unless the request is complex or multiple requests are made.
We will not charge a fee for a rights request unless it is manifestly unfounded or excessive, in which case a reasonable fee may be applied or the request may be refused in accordance with the law.
9. Data Minimisation and Accuracy
We aim to collect only the personal data necessary for specific, explicit, and legitimate purposes. We also take reasonable steps to keep data accurate and up to date. You are encouraged to notify us if your personal data changes, so that records can be corrected where needed.
Data minimisation is an important principle in our approach, and we regularly review whether the data we hold remains necessary for the relevant purpose.
10. Policy Scope and Changes
This Privacy Policy applies to all customers in area and covers personal data processed in connection with our services. It does not apply to third-party services that are not under our control, although we may work with external processors as described above.
We may update this Policy from time to time to reflect changes in law, our practices, or operational requirements. Any updated version will apply from the date it takes effect. Where changes are material, we will take reasonable steps to ensure you are informed in an appropriate manner.
Summary of our commitment: we process personal data lawfully, transparently, and securely; retain it only as long as necessary; share it only with trusted processors under contract; and respect your rights under GDPR.
