Privacy Policy -
Introduction
This Privacy Policy describes how we collect, use, disclose, retain, and protect personal data. This policy applies to all customers in the area where our services are provided. By using our services or interacting with us, you accept the practices described in this policy.
Scope and Applicability
This policy applies to all customers in the area and governs the processing of personal data that we collect directly from customers, through our service interactions, via our digital platforms, and from third-party sources as permitted by law. It applies to all personal data processed by us, whether processed in electronic or physical form.
Data We Collect
We collect the following categories of personal data, depending on the nature of your relationship with us:
- Identity and Contact Data: name, postal address, email address, telephone number, and similar identifiers.
- Account and Transaction Data: account credentials, purchase history, billing and payment information (excluding full card data where we do not store it), order details, and service usage records.
- Technical Data: IP address, device identifiers, browser type, operating system, and log data collected automatically through use of our services.
- Communications Data: correspondence with our support teams, feedback, and other customer service interactions.
- Marketing and Preference Data: communication preferences, marketing consents, and profile information used to tailor communications.
- Legal and Compliance Data: data required to comply with legal obligations, such as identity verification, tax or regulatory information, and records required for dispute resolution.
Sources of Personal Data
We obtain personal data directly from you when you provide it (for example, when you create an account, make a purchase, or contact customer support). We also receive data from third parties, such as payment processors, credit reference agencies, and partners who provide services on our behalf, in accordance with applicable law.
Lawful Bases for Processing
Under the General Data Protection Regulation (GDPR), we rely on the following lawful bases for processing personal data:
- Contractual Necessity: processing necessary to perform a contract with you or to take steps at your request prior to entering into a contract (for example, to deliver products or services, process payments, or provide customer support).
- Legal Obligation: processing necessary to comply with legal or regulatory obligations (for example, recordkeeping for tax purposes or responding to lawful requests from public authorities).
- Consent: where you have given clear consent for us to process your personal data for a specific purpose (for example, marketing communications). You may withdraw consent at any time where processing is based on consent.
- Legitimate Interests: where processing is necessary for our legitimate interests and does not override your rights and freedoms (for example, to detect and prevent fraud, improve our services, and manage our relationship with you).
- Vital Interests: in rare cases, processing may be necessary to protect someone’s life.
How We Use Personal Data
We use personal data for the following purposes, consistent with the lawful bases above:
- To provide, operate, and maintain our services and to fulfill contractual obligations.
- To process orders, payments, refunds, and returns.
- To communicate with you about products, services, updates, and transaction-related messages.
- To provide customer support and respond to inquiries.
- To carry out marketing and promotional activities where permitted by law or with consent.
- To detect, prevent, and investigate fraud, security breaches, or other unlawful activities.
- To comply with legal obligations and respond to lawful requests from public authorities.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with applicable legal, tax, or accounting requirements, or to resolve disputes. Typical retention periods include:
- Transactional and Billing Records: retained for a period required by applicable tax and accounting laws (commonly up to 7 years).
- Account and Service Records: retained for the duration of the customer relationship and for a reasonable period afterward to address disputes or provide ongoing services (commonly 2–7 years depending on the record type).
- Support and Communication Records: retained for a limited period to ensure service quality and for dispute resolution (commonly 1–3 years).
- Marketing Data: retained until you withdraw consent or opt out.
- Legal and Compliance Records: retained for periods required by law, which may exceed other retention terms.
Retention periods are determined based on the nature of the data, the purpose of processing, and legal obligations. We periodically review what personal data we hold and securely dispose of or anonymize data that is no longer required.
Processors and Third Parties
We use third-party processors to support our operations. These processors act on our behalf and are contractually obligated to implement appropriate technical and organizational measures to protect your personal data. Typical categories of processors include:
- Payment service providers and financial institutions.
- Cloud hosting and infrastructure providers.
- Customer support, analytics, and marketing service providers.
- Legal, tax, and compliance advisors.
We may transfer personal data to processors located outside the European Economic Area. Where such transfers occur, we put in place suitable safeguards, such as Standard Contractual Clauses or other legal mechanisms permitted under applicable data protection laws.
User Rights
Under the GDPR, you have the following rights in relation to your personal data:
- Right of Access: you may request confirmation as to whether we process your personal data and obtain a copy of that data.
- Right to Rectification: you may request correction of inaccurate or incomplete data.
- Right to Erasure (Right to be Forgotten): you may request deletion of personal data where there is no legitimate ground for continued processing.
- Right to Restriction of Processing: you may request that processing be restricted in certain circumstances.
- Right to Data Portability: you may request transfer of your data to another controller in a structured, commonly used, and machine-readable format where technically feasible.
- Right to Object: you may object to processing based on legitimate interests or direct marketing at any time.
- Right to Withdraw Consent: where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
We will respond to requests to exercise these rights within relevant statutory timeframes (typically one month). In complex cases, we may extend this period by up to two further months and will inform you of any extension and the reasons for delay. We may also request information to verify your identity before fulfilling a request.
Security Measures
We implement appropriate organizational and technical measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures include encryption, access controls, secure data storage, and regular security assessments. While we strive to protect personal data, no internet transmission or storage system can be guaranteed completely secure.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. When material changes are made, we will provide notice through appropriate channels. Continued use of our services following changes constitutes acceptance of the updated policy.
Supervisory Authority and Complaints
If you believe your rights under applicable data protection laws have been infringed, you have the right to lodge a complaint with a supervisory authority. You may also seek a judicial remedy where appropriate. We will cooperate with supervisory authorities and strive to resolve complaints directly where possible.
Final Remarks
We take your privacy seriously and are committed to handling personal data responsibly and transparently. This Privacy Policy is intended to explain our data handling practices in clear terms for all customers in the area. If you exercise any rights under this policy, we will process your requests in accordance with applicable law and the procedures described above.
End of Privacy Policy
