Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with the services offered by all customers in area. It applies to every individual using or interacting with these services within the relevant area, regardless of whether they access the services directly, through a device, or through another authorized arrangement. This policy is intended to be clear, transparent, and consistent with the General Data Protection Regulation (GDPR).
1. Data We Collect
We collect only the personal data necessary for legitimate business and operational purposes. Depending on how services are used, the categories of data may include:
- Identity data such as name, username, or similar identifiers.
- Contact data such as email address, billing address, or communication preferences.
- Transaction data such as service history, order details, payment status, and records of services provided.
- Technical data such as IP address, device type, browser settings, operating system, and usage logs.
- Profile data such as interests, preferences, service selections, and feedback.
- Usage data such as pages or features accessed, timestamps, session duration, and interaction patterns.
- Communication data such as messages sent, support requests, and records of correspondence.
We do not intentionally collect special categories of personal data unless required by law, necessary for a specific lawful purpose, or provided with explicit consent where permitted. If such data is collected, it will be handled with enhanced safeguards.
2. How We Use Personal Data
Personal data is used only for specific, relevant, and lawful purposes. These purposes may include:
- Providing, operating, and maintaining services;
- Processing requests, transactions, and service-related actions;
- Managing accounts, records, and customer relationships;
- Delivering support, troubleshooting issues, and responding to inquiries;
- Improving service performance, safety, and user experience;
- Detecting, preventing, and addressing fraud, misuse, or security incidents;
- Complying with legal, regulatory, tax, and accounting obligations;
- Sending administrative notices and other essential communications;
- Where permitted, conducting analytics and service improvement activities.
We only use personal data in ways that are fair, lawful, and transparent. Data is not used for incompatible purposes without a valid legal basis.
3. Lawful Basis for Processing
Under GDPR, we process personal data only where a lawful basis applies. Depending on the context, the lawful basis may include:
Consent
In some situations, we rely on consent, especially where the law requires it. When consent is used, it is freely given, specific, informed, and unambiguous. Users may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Contractual Necessity
We process data when it is necessary to enter into or perform a contract, or to take steps at the request of a user before entering into a contract. This may include processing identity, contact, and transaction data.
Legal Obligation
Some processing is required to comply with legal obligations, including recordkeeping, tax compliance, fraud prevention, and responses to valid requests from public authorities.
Legitimate Interests
We may process data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the rights and freedoms of the individual. Examples include maintaining service security, improving operations, preventing misuse, and managing internal administration. Where required, we conduct a balancing test to assess these interests.
4. Data Sharing and Processors
Personal data may be shared with trusted third parties that act as processors on our behalf. These processors are permitted to process data only under our instructions and are required to implement appropriate technical and organizational safeguards.
Categories of processors may include:
- IT and hosting providers that store or support system infrastructure;
- Payment processors that handle payment-related functions;
- Customer support providers that assist with service-related communications;
- Analytics providers that support measurement and performance analysis;
- Security and fraud prevention providers that help detect and prevent abuse;
- Professional advisers such as legal, audit, or accounting service providers.
We may also disclose personal data where necessary to comply with law, enforce legal rights, protect the safety of individuals, or respond to lawful requests from authorities. Where data is transferred outside the European Economic Area, appropriate safeguards will be used, such as standard contractual clauses or other approved transfer mechanisms.
5. Data Retention
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law. Retention periods depend on the type of data and the purpose of processing.
- Service and account data is kept while the relationship remains active and for a reasonable period afterward.
- Transaction and financial records are retained for periods required by tax, accounting, or regulatory rules.
- Support communications are retained as needed to resolve issues and maintain records of service.
- Technical logs may be retained for security, diagnostic, or operational purposes for limited periods.
When data is no longer needed, it is securely deleted, anonymized, or archived in accordance with applicable legal and operational requirements. Retention is reviewed regularly to ensure data is not kept longer than necessary.
6. Security of Personal Data
We use appropriate security measures to protect personal data against unauthorized access, loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, authentication procedures, monitoring, and secure storage practices. Although no system can be guaranteed completely secure, we take reasonable and proportionate steps to safeguard information.
7. User Rights Under GDPR
Individuals whose data is processed under this policy have several rights under GDPR. Subject to legal limitations and verification of identity, users may exercise the following rights:
- Right of access – to obtain confirmation of whether data is processed and to receive a copy of the data.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of data in certain circumstances.
- Right to restriction – to request limited processing in specific situations.
- Right to data portability – to receive data in a structured, commonly used, machine-readable format and, where applicable, have it transmitted elsewhere.
- Right to object – to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to withdraw consent – where processing is based on consent, consent may be withdrawn at any time.
- Right to lodge a complaint – to raise concerns with a competent data protection authority if rights are believed to be infringed.
Requests will be handled in accordance with GDPR timeframes and may require reasonable verification to protect against unauthorized disclosure.
8. Special Rules for All Customers in Area
This Privacy Policy applies to all customers in area and governs the processing of personal data collected in connection with their use of the relevant services. It applies uniformly across the area, unless a specific legal requirement provides otherwise. Any local data protection obligations that apply in the area will be observed alongside GDPR requirements.
Where local law provides additional rights, notices, or restrictions, those rules will be respected. If a conflict arises between this policy and mandatory law, the legal requirement will prevail.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or data processing activities. When updates are made, the revised version will apply from the date it becomes effective. Users are encouraged to review the policy periodically so they remain informed about how personal data is handled.
10. Core Principles We Follow
Our processing practices are guided by the key principles of GDPR, including:
- Lawfulness, fairness, and transparency;
- Purpose limitation;
- Data minimization;
- Accuracy;
- Storage limitation;
- Integrity and confidentiality;
- Accountability.
These principles shape how data is collected, processed, protected, and retained. We aim to process only the minimum amount of personal data necessary and to do so in a responsible and compliant manner.
Effective date: This Privacy Policy applies from the date it is issued and remains in effect until replaced or updated.
