Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when customers use our services. It applies to all customers in the area where our services are offered, and it is intended to meet the requirements of the General Data Protection Regulation (GDPR) and other applicable privacy laws.
1. Scope and Commitment
We respect the privacy of every customer and are committed to handling personal data in a lawful, fair, and transparent manner. This policy applies to all customers in area, including individuals who interact with our services, make enquiries, receive support, or enter into a business relationship with us.
We collect and process only the personal data necessary for legitimate business purposes and in accordance with data minimisation principles. We also take appropriate technical and organisational measures to protect personal data against unauthorized access, accidental loss, destruction, or damage.
2. Personal Data We Collect
We may collect the following categories of personal data, depending on the nature of the interaction and the services provided:
- Identity data, such as name, title, and similar identifying details.
- Contact data, such as postal address, email address, telephone number, and preferred communication method.
- Transaction data, such as details about services requested, purchased, or delivered.
- Payment-related data, where necessary for processing transactions and preventing fraud.
- Communication data, such as messages, feedback, complaints, and support records.
- Technical data, such as device type, browser type, log information, and usage patterns.
- Profile and preference data, where a customer chooses to provide preferences or settings.
We generally do not intentionally collect special category data, such as information about health, religion, political opinions, or biometric data, unless it is strictly necessary, legally permitted, and supported by an appropriate lawful basis.
3. How We Use Personal Data
We process personal data for the following purposes:
- To provide and manage services requested by customers.
- To respond to enquiries, requests, and complaints.
- To process transactions and maintain accurate records.
- To improve service quality, performance, and customer experience.
- To detect, investigate, and prevent fraud, security incidents, and misuse.
- To comply with legal, regulatory, tax, and accounting obligations.
- To maintain internal administration, auditing, and reporting.
Where required, we will always ensure that the purpose for processing is compatible with the reason the data was originally collected.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. Depending on the context, we rely on one or more of the following bases:
- Contract – processing is necessary to enter into or perform a contract with a customer, or to take steps at the customer’s request before entering into a contract.
- Legal obligation – processing is necessary to comply with a legal or regulatory requirement.
- Legitimate interests – processing is necessary for our legitimate business interests, provided those interests are not overridden by the customer’s rights and freedoms.
- Consent – where customers have given clear and informed consent for a specific purpose, such as certain optional communications or marketing activities.
When we rely on consent, customers may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before the withdrawal.
5. Data Sharing and Processors
We may share personal data with trusted third parties where necessary to operate our services, meet legal obligations, or protect our legitimate interests. These third parties act either as independent controllers or as processors acting on our behalf.
Processors may include service providers that support:
- IT hosting and system administration
- Payment processing
- Customer support and communication tools
- Analytics and performance monitoring
- Document storage and secure archiving
- Professional advisory services, such as legal, accounting, or audit support
All processors are required to handle personal data only under our instructions, to apply appropriate security measures, and to respect confidentiality. Where data is transferred outside the European Economic Area, we ensure that suitable safeguards are in place, such as standard contractual clauses or other approved transfer mechanisms.
We do not sell personal data. We only disclose personal data where necessary and lawful.
6. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including any legal, accounting, reporting, or contractual requirements. The retention period depends on the type of data, the reason for processing, and any mandatory retention obligations.
In determining retention periods, we consider:
- The length of the customer relationship
- Whether there are ongoing service, warranty, or support obligations
- Whether legal claims may be made in future
- Whether tax or regulatory rules require longer retention
When personal data is no longer required, it will be securely deleted, anonymised, or archived in a manner that prevents identification, unless continued retention is required by law.
7. Security of Personal Data
We use appropriate security measures designed to protect personal data from loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, encryption where appropriate, staff training, and monitoring of systems.
Although no system can guarantee complete security, we regularly review our safeguards and update them when necessary. In the event of a personal data breach, we will assess the risk and take action in line with GDPR obligations, including notifying supervisory authorities and affected individuals where required.
8. Your Rights Under GDPR
Customers have important rights in relation to their personal data. Subject to applicable legal conditions and exemptions, these rights include:
- Right of access – to request confirmation of whether personal data is being processed and to obtain a copy of that data.
- Right to rectification – to request correction of inaccurate or incomplete personal data.
- Right to erasure – to request deletion of personal data in certain circumstances.
- Right to restriction – to request that processing be limited in specific situations.
- Right to data portability – to receive certain data in a structured, commonly used format and, where feasible, to have it transferred to another controller.
- Right to object – to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent – where processing is based on consent, to withdraw consent at any time.
- Right not to be subject to automated decision-making – including profiling, where such decisions produce legal or similarly significant effects, except where permitted by law.
We may need to verify identity before responding to a rights request. Requests will be handled without undue delay and within the time limits required by law.
9. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children in a way that would breach applicable law. If we become aware that such data has been collected without proper authorisation, we will take reasonable steps to delete it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or service arrangements. When we do so, the updated version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically to remain informed about how their data is protected.
11. Additional Information
Transparency is central to our approach. We will only process personal data in ways that are compatible with GDPR principles, including lawfulness, fairness, purpose limitation, accuracy, storage limitation, integrity, confidentiality, and accountability.
We also aim to ensure that customer expectations are respected and that personal data is handled with care at every stage of its lifecycle. Where our processing activities change, we will review the legal basis, retention period, and relevant safeguards to ensure ongoing compliance.
By using our services, customers acknowledge that their personal data may be processed as described in this Privacy Policy.
