Privacy Policy
This Privacy Policy explains how personal data is collected, used, shared, retained, and protected in connection with our services. It applies to all customers in the area where our services are offered and used. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
1. Introduction
We respect your privacy and recognize the importance of protecting personal data. This Policy describes the categories of information we may process, the purposes for which we use that information, the legal bases we rely on, how long we keep it, the types of third parties that may process it on our behalf, and the rights available to individuals under applicable law.
By using our services, you acknowledge that your personal data may be processed as described in this Policy. We only process personal data when we have a valid lawful basis and only for specified, explicit, and legitimate purposes.
2. Data We Collect
We may collect and process the following categories of personal data, depending on how you interact with us:
- Identification data such as name, surname, and account identifiers.
- Contact data such as email address, billing address, or service address.
- Transaction data including purchase history, payment status, and service records.
- Technical data such as device type, browser type, IP address, log files, and system activity.
- Usage data including interactions with our services, preferences, and feature usage.
- Communication data such as messages, requests, complaints, and feedback you send us.
- Compliance data that may be needed for legal, regulatory, accounting, or audit purposes.
We generally collect personal data directly from you, but we may also receive data from authorized third parties, service partners, payment providers, or public sources where permitted by law.
3. How We Use Personal Data
We process personal data for the following purposes:
- To provide, operate, and maintain our services.
- To manage customer accounts, requests, and support matters.
- To process payments, invoices, refunds, and related financial activities.
- To communicate service updates, notices, and administrative information.
- To improve service quality, performance, and user experience.
- To detect, prevent, and investigate fraud, abuse, or security incidents.
- To comply with legal, tax, accounting, and regulatory obligations.
- To defend or establish legal claims and enforce our terms.
We may also use information in an aggregated or de-identified form where it no longer identifies an individual. Such information is not treated as personal data unless it can reasonably be linked back to a person.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process personal data. Depending on the context, we rely on one or more of the following bases:
Performance of a Contract
We process personal data when it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes managing accounts, delivering services, processing payments, and handling customer support related to the service.
Legal Obligation
We process personal data where necessary to comply with legal or regulatory requirements, such as tax laws, financial recordkeeping, consumer protection rules, or lawful requests from public authorities.
Legitimate Interests
We may process personal data based on our legitimate interests, provided those interests are not overridden by your rights and freedoms. Our legitimate interests may include service improvement, fraud prevention, network and information security, internal administration, analytics, and business planning. Where we rely on legitimate interests, we consider the impact on individuals and implement appropriate safeguards.
Consent
In certain cases, we may rely on your consent, particularly where required by law for specific types of communications or processing activities. When consent is used as the lawful basis, you may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
5. Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, reporting, and dispute-resolution requirements. Retention periods depend on the nature of the data, the sensitivity of the information, the purposes of processing, and any applicable legal obligations.
In general:
- Account and service data are kept for the duration of the customer relationship and for a reasonable period afterward.
- Transaction and financial records are retained for periods required by law or standard accounting practice.
- Support communications may be retained for quality, training, and dispute handling purposes.
- Security and log data may be kept for limited periods to monitor systems and investigate incidents.
When personal data is no longer needed, we will delete, anonymize, or securely archive it in accordance with our retention standards and applicable law. We do not keep personal data longer than necessary.
6. Processors and Third Parties
We may use trusted third parties, known as processors, to process personal data on our behalf. These processors are authorized to handle data only according to our instructions and are required to maintain appropriate confidentiality and security measures.
Examples of categories of processors may include:
- Hosting and infrastructure providers that store or transmit service data.
- Payment processors that assist with secure payment transactions.
- Customer support providers that help manage inquiries and service requests.
- Analytics and performance providers that help us understand usage and improve services.
- Security and fraud prevention providers that assist in protecting systems and users.
- Professional advisers such as accountants, auditors, or legal advisers where necessary.
We may also disclose personal data to independent third parties when required by law, when necessary to establish or defend legal claims, to protect rights and safety, or in connection with a corporate transaction such as a reorganization or transfer of assets, subject to appropriate safeguards.
Where data is transferred outside the European Economic Area, we take steps to ensure that an adequate level of protection is in place, such as using approved contractual safeguards or relying on an adequacy decision where available.
7. Security of Personal Data
We implement appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, alteration, disclosure, or destruction. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, monitoring tools, and regular security reviews.
Although no system can be guaranteed to be completely secure, we take data protection seriously and work to reduce risks through ongoing safeguards and operational controls.
8. Your Rights Under GDPR
Depending on your location and the circumstances of processing, you may have the following rights regarding your personal data:
- Right of access to obtain confirmation of whether we process your personal data and a copy of that data.
- Right to rectification to correct inaccurate or incomplete personal data.
- Right to erasure to request deletion of your personal data in certain situations.
- Right to restriction to limit processing in specific circumstances.
- Right to data portability to receive data you provided to us in a structured, commonly used format and, where feasible, have it transmitted to another controller.
- Right to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent where processing is based on consent.
- Right not to be subject to automated decision-making where such decisions have legal or similarly significant effects, subject to legal exceptions.
You may also have the right to lodge a complaint with a supervisory authority if you believe your rights have been infringed. We encourage individuals to raise concerns so that we can address them promptly and fairly.
9. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children where such collection is prohibited by law. If we become aware that personal data has been collected unlawfully from a child, we will take appropriate steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service offerings. The most current version will govern our use of personal data. We encourage you to review this Policy periodically to remain informed about how we protect your information.
11. Scope of This Policy
This Privacy Policy applies to all customers in the area and to personal data processed in connection with our services. By continuing to use our services, you acknowledge that your information may be handled as described above in accordance with applicable law and the principles of transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
We process personal data only where necessary and in a manner that respects your privacy rights.
