Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected by [Controller Name] in connection with its products and services. It applies to all customers in the relevant area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and applicable local data protection laws. By using our services, you acknowledge that your personal data may be processed in accordance with this Policy.
1. Data We Collect
We collect only the personal data that is necessary for the purposes described in this Policy. Depending on your relationship with us and the way you interact with our services, we may collect the following categories of data:
- Identification data: name, title, date of birth, and similar identifiers.
- Contact data: billing address, service address, email address, telephone number, and other communication details.
- Account data: account credentials, preferences, service history, and profile information.
- Transaction data: records of purchases, payments, refunds, invoices, and related financial details.
- Technical data: IP address, device type, browser type, operating system, log data, and usage information.
- Communication data: information you provide when you contact us, submit forms, or respond to surveys.
- Compliance data: data necessary to verify identity, prevent fraud, and meet legal obligations.
We generally do not intentionally collect special category data unless it is necessary for a specific lawful purpose and we are permitted to do so under applicable law. If such data is processed, we will apply additional safeguards and only do so where a valid legal basis exists.
2. How We Collect Data
Personal data may be collected directly from you, automatically through your use of our services, or from third parties where permitted by law. For example, we may receive data from payment providers, delivery partners, customer support tools, fraud prevention services, and public sources.
When data is collected automatically, this may occur through logs, cookies, similar technologies, and system interactions that help us maintain service security, improve performance, and understand how our services are used. Where required, we will seek consent before storing or accessing non-essential cookies or similar technologies.
3. Purposes of Processing
We process personal data for specific and legitimate purposes, including:
- providing and managing our services;
- creating and maintaining customer accounts;
- processing payments and issuing invoices;
- delivering customer support and responding to enquiries;
- maintaining security, preventing fraud, and investigating misuse;
- complying with legal, accounting, and regulatory obligations;
- improving service quality, troubleshooting errors, and conducting analytics;
- sending service-related notices and other necessary communications.
We will not use your personal data in a way that is incompatible with the purposes for which it was collected unless we have a valid legal basis and have informed you where required.
4. Lawful Basis for Processing
Under GDPR, we must rely on one or more lawful bases when processing personal data. Depending on the context, our processing activities are based on the following:
Contractual necessity
We process personal data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract. This includes creating accounts, fulfilling orders, delivering services, and managing payments.
Legal obligation
We process personal data when required to comply with applicable legal obligations, such as tax, accounting, consumer protection, fraud prevention, or regulatory requirements.
Legitimate interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided that these interests are not overridden by your rights and freedoms. Examples include service improvement, network and information security, internal administration, and prevention of abuse. Where we rely on legitimate interests, we will assess the balance between our interests and your privacy rights.
Consent
Where required by law, we rely on your consent, for example for certain marketing communications or non-essential cookies. If processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Vital interests and public interest
In limited circumstances, we may process data to protect someone’s vital interests or where processing is necessary for a task carried out in the public interest or in the exercise of official authority. These bases are used only where applicable.
5. Sharing and Processors
We may share personal data with trusted third parties where necessary to operate our services, fulfill legal obligations, or protect our rights. These third parties may act as processors or independent controllers depending on the service they provide.
Our processors may include:
- IT and cloud service providers that host systems, store data, or provide security tools;
- payment processors that handle transactions;
- customer support providers that manage service requests;
- analytics providers that help us understand service usage;
- professional advisers such as accountants, auditors, and legal advisers;
- delivery or operational partners where needed to provide the service.
All processors are selected carefully and are bound by contracts that require them to process personal data only on our documented instructions, to keep it secure, and to assist us in meeting GDPR obligations. We do not sell personal data.
We may also disclose personal data if required by law, court order, or lawful request from public authorities, or where necessary to establish, exercise, or defend legal claims.
6. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with equivalent data protection standards, we will ensure appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms. We will take reasonable steps to ensure that transferred data receives a level of protection essentially equivalent to that required under GDPR.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying legal, accounting, tax, or reporting requirements. The retention period depends on the type of data, the reason for processing, and any legal obligation to keep the information.
In determining retention periods, we consider:
- the nature and sensitivity of the data;
- the risk of harm from unauthorized use or disclosure;
- the purposes of processing and whether those purposes can be achieved by other means;
- applicable statutory limitation periods;
- contractual and regulatory requirements.
When personal data is no longer needed, we will securely delete, anonymize, or irreversibly aggregate it, unless retention is required by law or for the establishment or defense of legal claims.
8. Security Measures
We implement appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption where appropriate, monitoring, staff training, and policies governing secure handling of data. However, no system can be guaranteed to be completely secure, and you should take care when sharing personal data online.
9. Your Rights Under GDPR
You have several rights in relation to your personal data. Subject to legal limitations, you may exercise the following rights:
- Right of access: to obtain confirmation whether we process your data and receive a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request limitation of processing in certain situations.
- Right to data portability: to receive data you provided in a structured, commonly used format and, where feasible, transmit it to another controller.
- Right to object: to object to processing based on legitimate interests or to direct marketing at any time.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time.
- Right not to be subject to automated decision-making: to request human review where decisions producing legal or similarly significant effects are made solely by automated means, where applicable.
To protect your privacy, we may need to verify your identity before responding to a rights request. We will respond within the time limits required by law, typically within one month, and may extend this period where requests are complex or numerous.
10. Complaints and Supervisory Authorities
If you believe that our processing of your personal data does not comply with GDPR, you have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first so that we may address any concerns promptly and transparently. Exercising your rights will not affect your ability to receive our services, except where the requested action is necessary for service delivery or required by law.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or operational requirements. The revised version will apply to all customers in the relevant area from the date it becomes effective. Where changes are material, we will take reasonable steps to inform you in a clear and appropriate manner.
Summary principle: we process personal data lawfully, fairly, and transparently, and only for specified purposes. We use appropriate safeguards, retain data only as long as necessary, and respect your rights under GDPR. This Policy applies to all customers in the relevant area.
