Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with our services. It applies to all customers in the area and is intended to provide clear information about how we handle personal data in line with applicable data protection laws, including the General Data Protection Regulation (GDPR), where applicable.
1. Scope of this Policy
This policy applies to all customers in the area who use our services, interact with us, or otherwise provide personal data to us. It also applies to personal data collected through customer support interactions, account registration, service delivery, payment processing, communications, and related activities. We aim to process personal data lawfully, fairly, and transparently.
2. Personal Data We Collect
We may collect and process different categories of personal data depending on how you interact with us. This may include:
- Identity data such as name, title, and other identifying details.
- Contact data such as mailing address, email address, and telephone number.
- Account data such as login details, account preferences, and profile information.
- Transaction data such as payment status, billing records, and service history.
- Technical data such as device type, IP address, browser type, language settings, and system logs.
- Usage data such as how you use our services, pages visited, features accessed, and timing of interactions.
- Communication data such as messages, inquiries, complaints, and feedback.
- Preference data such as service choices and marketing preferences.
We generally collect personal data directly from you when you provide it to us. In some cases, we may also receive information from third parties, service providers, payment processors, or publicly available sources, where permitted by law.
3. How We Use Personal Data
We use personal data for the following purposes:
- To provide and deliver our services.
- To manage customer accounts and records.
- To process payments, invoices, and refunds.
- To communicate with you about service-related matters.
- To respond to inquiries, requests, and complaints.
- To improve our services, systems, and customer experience.
- To maintain security, prevent fraud, and detect misuse.
- To comply with legal and regulatory obligations.
- To manage our business operations and internal administration.
We only use personal data for specified purposes and do not process it in a manner that is incompatible with those purposes unless otherwise required or permitted by law.
4. Lawful Basis for Processing
Where the GDPR applies, we process personal data only when we have a valid lawful basis. Depending on the context, these lawful bases may include:
- Contract: processing is necessary to enter into or perform a contract with you, such as delivering services, managing your account, or processing payments.
- Legal obligation: processing is necessary to comply with legal requirements, including accounting, tax, and record-keeping obligations.
- Legitimate interests: processing is necessary for our legitimate business interests, provided these do not override your rights and freedoms. This may include service improvement, security monitoring, fraud prevention, and internal reporting.
- Consent: where required, we rely on your consent, for example for certain marketing communications or optional data uses. You may withdraw consent at any time.
- Vital interests: in rare cases, processing may be necessary to protect someone’s life or physical safety.
- Public task: where relevant, processing may be carried out in the public interest or under official authority.
We will only process special category data if a lawful basis and an additional condition under applicable law are met.
5. Data Sharing and Processors
We may share personal data with trusted third parties that act as data processors or, where applicable, independent controllers. These parties may process personal data on our behalf and only according to our instructions or in accordance with their own legal responsibilities.
Typical categories of processors may include:
- IT and cloud hosting providers.
- Payment service providers.
- Customer support and communication tools.
- Analytics and reporting service providers.
- Document storage and backup providers.
- Professional advisers such as auditors, legal advisers, and accountants.
We take reasonable steps to ensure that processors are bound by appropriate data protection obligations and maintain adequate technical and organisational safeguards. Where personal data is transferred outside the EEA or UK, as relevant, we will ensure appropriate safeguards are in place, such as standard contractual clauses or other lawful transfer mechanisms.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, reporting, and operational requirements. Retention periods may vary depending on the type of data and the nature of the relationship with you.
When determining retention periods, we consider:
- the amount, nature, and sensitivity of the data;
- the potential risk of harm from unauthorised use or disclosure;
- the purposes of processing;
- whether those purposes can be achieved by other means; and
- legal and regulatory retention obligations.
Once personal data is no longer needed, we will securely delete it, anonymise it, or otherwise render it inaccessible, unless retention is required by law or for the establishment, exercise, or defence of legal claims.
7. Data Security
We implement appropriate technical and organisational measures designed to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff training, and regular review of our security practices.
While no system can be guaranteed as completely secure, we take reasonable and proportionate steps to reduce risk and protect personal data.
8. Your Rights
Where GDPR or similar laws apply, you may have the following rights in relation to your personal data:
- Right of access: to obtain confirmation of whether we process your personal data and request a copy.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your personal data in certain circumstances.
- Right to restriction: to request that we limit processing in certain cases.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and to transmit it to another controller where technically feasible.
- Right to object: to object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: where we rely on consent, you may withdraw it at any time.
- Right not to be subject to solely automated decisions: to request human review where legally applicable.
We may need to verify your identity before responding to a request. In some cases, rights may be limited by law, for example where fulfilling the request would adversely affect the rights of others or where we must keep data for legal reasons.
9. Marketing Communications
Where permitted by law, we may send you marketing communications about relevant products or services. If consent is required, we will only send such communications with your permission. You may opt out of marketing at any time by following the unsubscribe instructions included in the message or by updating your preferences where available.
Even if you opt out of marketing, we may still send you service-related messages that are necessary for the performance of our services or for legal purposes.
10. Cookies and Similar Technologies
We may use cookies or similar technologies to support essential functionality, improve performance, and understand how services are used. These technologies may collect technical and usage data. Where required, we will ask for your consent before placing non-essential cookies on your device. You can manage cookie preferences through your browser settings or other available controls.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or service features. Any updated version will apply from the date it is made effective. We encourage you to review this policy periodically so that you remain informed about how your personal data is handled.
12. Additional Information
This Privacy Policy should be read together with any other notices we provide at the time personal data is collected. If any part of this policy is inconsistent with mandatory applicable law, that law will prevail to the extent of the inconsistency.
By using our services, you acknowledge that you have read and understood this Privacy Policy.
