Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with our services. It applies to all customers in the area where our services are offered and to any individual who interacts with us in that area. We are committed to handling personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
1. Information We Collect
We collect only the personal data that is necessary for the purposes described in this Privacy Policy. Depending on how you interact with us, we may collect the following categories of information:
- Identification data: name, title, and similar identifiers.
- Contact data: address, email address, telephone number, and other communication details.
- Transaction data: records of purchases, services requested, payments, invoices, and related history.
- Technical data: device type, browser type, operating system, and basic usage information.
- Usage data: information about how services are accessed and used.
- Preference data: communication preferences and service choices.
- Any other information you provide: for example, when you submit an inquiry, complaint, or request.
We do not intentionally collect special category data unless it is strictly necessary and we have a valid legal basis to do so. If such data is collected, it will be handled with extra safeguards.
2. How We Use Personal Data
We use personal data for the following purposes:
- To provide and manage our services.
- To process orders, payments, and transactions.
- To communicate with customers about service updates, requests, and administrative matters.
- To maintain records and manage our business operations.
- To improve service quality, functionality, and user experience.
- To prevent fraud, misuse, and security incidents.
- To comply with legal, regulatory, tax, and accounting obligations.
We will always ensure that processing is limited to what is necessary and proportionate to the stated purpose.
3. Lawful Basis for Processing
Under GDPR, we only process personal data when we have a valid lawful basis. Depending on the purpose, we may rely on one or more of the following:
Performance of a Contract
We process personal data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
Legal Obligation
We may process personal data to comply with laws and regulations, including tax, accounting, consumer protection, and record-keeping requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Legitimate interests may include maintaining service security, preventing fraud, improving services, and managing business operations.
Consent
In some cases, we may rely on your consent, for example where the law requires consent for certain types of communications or optional processing. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests
In rare circumstances, we may process personal data to protect someone’s vital interests, such as in an emergency.
4. Data Sharing and Processors
We may share personal data with trusted third parties who act as data processors or, where applicable, independent controllers. These parties are only permitted to process personal data on our instructions or for their own lawful purposes where appropriate.
Examples of processors and service categories may include:
- IT and hosting providers: for secure storage, infrastructure, and system support.
- Payment service providers: for payment handling and transaction processing.
- Accounting and administration providers: for financial administration and record maintenance.
- Customer service tools: for managing requests and communications.
- Security and fraud prevention providers: for protecting services and users.
All processors are required to implement appropriate technical and organizational measures to protect personal data. Where we transfer data outside the European Economic Area, we will do so only where appropriate safeguards are in place, such as Standard Contractual Clauses or other lawful transfer mechanisms.
5. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting obligations. Retention periods depend on the type of data, the nature of the relationship, and applicable legal requirements.
- Contractual and transaction records: retained for the period required to manage the relationship and comply with legal obligations.
- Support and communication records: retained for a reasonable period to handle inquiries, disputes, and service improvements.
- Technical and security records: retained for the time needed to maintain system integrity and investigate incidents.
When personal data is no longer required, it will be securely deleted, anonymized, or archived in accordance with applicable law and internal retention policies.
6. Data Security
We take appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and regular review of internal security practices.
While no system can be guaranteed to be completely secure, we work to maintain a level of protection that is appropriate to the risk associated with the processing of personal data.
7. Your Rights Under GDPR
If you are covered by GDPR, you have the following rights in relation to your personal data, subject to certain conditions and exemptions:
- Right of access: to obtain confirmation of whether we process your data and to receive a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data where legally permitted.
- Right to restriction: to ask us to limit processing in certain situations.
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format and, where feasible, have it transmitted to another controller.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
You also have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been infringed.
8. Automated Decision-Making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals, unless such processing is permitted by law and appropriate safeguards are in place. If this changes, we will provide clear information about the logic involved and your available rights.
9. Children’s Data
Our services are not intended for children unless specifically stated. We do not knowingly collect personal data from children without appropriate authorization where required by law. If we become aware that personal data has been collected from a child in breach of applicable rules, we will take reasonable steps to delete it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our processing practices. When updates are made, the revised policy will apply from the date it takes effect. We encourage customers to review this policy periodically to stay informed about how we protect personal data.
11. Scope and Applicability
This Privacy Policy applies to all customers in the area where our services are provided, as well as to anyone whose personal data we process in connection with those services. By interacting with us, you acknowledge that your personal data may be handled in the manner described in this policy and in accordance with applicable GDPR requirements.
Summary of our approach: we collect only necessary data, process it on a valid lawful basis, retain it for limited periods, use trusted processors under safeguards, and respect your rights as a data subject.
