Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, retained, and protected in connection with our services. It applies to all customers in the area where our services are offered and to anyone who interacts with us in that region. We are committed to handling personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Who We Are
For the purposes of data protection law, we act as the data controller for the personal data we process in the course of providing our services. This means we determine the purposes and means of processing personal data, subject to applicable legal requirements and safeguards.
2. Personal Data We Collect
We may collect and process the following categories of personal data:
- Identity data such as name, title, and customer identifiers.
- Contact data such as email address, billing address, delivery address, and telephone number.
- Transaction data such as records of purchases, payments, refunds, and service requests.
- Technical data such as IP address, browser type, device information, time zone, and usage logs.
- Profile data such as preferences, feedback, and customer service interactions.
- Communication data such as correspondence, complaint details, and support enquiries.
- Compliance data where needed for legal, regulatory, or fraud-prevention purposes.
We collect personal data directly from you when you provide it to us, and indirectly through lawful and transparent means such as service interactions, technical logs, and third-party providers where appropriate.
3. How We Use Personal Data
We use personal data only for specified, explicit, and legitimate purposes. These may include:
- providing and managing services;
- processing orders, payments, and refunds;
- communicating with customers about their accounts or requests;
- improving our services, systems, and customer experience;
- ensuring security, preventing fraud, and detecting misuse;
- meeting legal, accounting, tax, or regulatory obligations;
- handling complaints, disputes, and support matters.
We only process personal data to the extent that it is relevant and necessary for the stated purpose. We do not use personal data in ways that are incompatible with the original purpose without a valid legal basis.
4. Lawful Basis for Processing
Under GDPR, we rely on one or more of the following lawful bases to process personal data:
Contract
We process data when it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes setting up services, processing payments, and fulfilling service-related requests.
Legal Obligation
We process data where necessary to comply with legal or regulatory obligations, including accounting, tax, auditing, consumer law, and lawful requests from public authorities.
Legitimate Interests
We may process data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Examples include maintaining service security, preventing fraud, improving operations, and managing business administration. When relying on this basis, we assess the impact on your privacy and ensure appropriate safeguards.
Consent
In certain circumstances, we may rely on your consent, particularly for optional communications or specific processing activities. Where consent is used, it will be freely given, informed, specific, and unambiguous. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Data Sharing and Processors
We may share personal data with carefully selected third parties that assist us in delivering services and operating our business. These recipients act either as processors or independent controllers depending on the context.
Processors are service providers that process personal data on our behalf and under our instructions. They may include providers of:
- IT hosting and infrastructure;
- payment processing;
- customer support systems;
- analytics and reporting tools;
- document storage and security services;
- professional advisory services where relevant.
We require all processors to implement appropriate technical and organisational measures to protect personal data and to process it only for the agreed purposes. We do not sell personal data. We may also disclose data where required by law, to protect our rights, or to respond to lawful requests from authorities.
6. International Transfers
If personal data is transferred outside the European Economic Area, we ensure that appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms permitted under GDPR. We take steps to ensure that transferred data receives a level of protection essentially equivalent to that required within the EEA.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including the purposes of satisfying legal, accounting, tax, reporting, and dispute-resolution obligations. Retention periods vary depending on the type of data and the purpose of processing.
When determining retention periods, we consider:
- the nature and sensitivity of the data;
- the risk of harm from unauthorised use or disclosure;
- the processing purpose;
- applicable legal or regulatory requirements;
- whether the data is needed for claims or defence of legal rights.
When personal data is no longer required, we will delete, anonymise, or securely archive it in accordance with our retention procedures.
8. Your Rights Under GDPR
As a data subject, you have a number of rights in relation to your personal data. Subject to legal limitations, these include:
Right of Access
You may request confirmation of whether we process your personal data and obtain a copy of that data, along with related information.
Right to Rectification
You may request correction of inaccurate or incomplete personal data.
Right to Erasure
You may request deletion of your personal data where one of the legal grounds for erasure applies, such as when the data is no longer necessary for the original purpose.
Right to Restriction
You may request that we restrict processing in certain circumstances, for example while a data accuracy issue is being resolved.
Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you may request your personal data in a structured, commonly used, machine-readable format and, where technically feasible, its transmission to another controller.
Right to Object
You may object to processing based on legitimate interests or to processing for direct marketing purposes. Where you object to processing based on legitimate interests, we will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, where such a decision produces legal or similarly significant effects, unless an exception applies under GDPR.
You also have the right to withdraw consent where processing is based on consent. Exercising any of these rights will not affect the lawfulness of processing already carried out before your request.
9. How We Protect Personal Data
We use appropriate technical and organisational measures to safeguard personal data against unauthorised access, loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and regular review of security practices. While no system can be guaranteed completely secure, we take data protection seriously and continuously work to improve our safeguards.
10. Children’s Data
Our services are not directed to children under the age required by applicable law for valid consent. We do not knowingly collect personal data from children except where permitted by law and with the required authorisation. If we become aware that personal data has been collected unlawfully from a child, we will take appropriate steps to delete it.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our practices, or our services. Any updated version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically to stay informed about how we protect personal data.
12. Scope and Applicability
This Privacy Policy applies to all customers in the area served by our organisation, regardless of the channel through which services are accessed. By using our services, you acknowledge that your personal data will be processed in accordance with this Privacy Policy and applicable data protection law.
Summary: We explain what data we collect, why we process it, how long we keep it, who may process it for us, and the GDPR rights available to all customers in the area.
