Privacy Policy - .
This Privacy Policy explains how we collect, use, retain and share personal data and the rights available to individuals under the General Data Protection Regulation (GDPR). This Policy applies to all customers in the area (including the European Economic Area and other territories where GDPR applies) and governs processing of personal data in connection with our products and services.
1. Controller and Scope
For the purposes of this Policy, "we", "our" and "us" refer to the data controller that determines the purposes and means of processing personal data. This Policy applies to personal data collected from customers, prospective customers, users of our services and related contacts. It does not cover personal data processed by third parties that are independent controllers.
2. Information We Collect
We collect personal data necessary to provide, improve and secure our services. Types of data we process include:
- Identity and account data: name, username, account identifiers, profile information.
- Contact data: email addresses, postal addresses, telephone numbers (where provided to facilitate service delivery).
- Transactional data: records of products and services purchased, billing records, invoices and order history.
- Payment data: payment instrument identifiers and payment confirmation information (collected and processed by our payment processors; we do not store full payment card details).
- Technical and usage data: IP addresses, device identifiers, browser type, operating system, log files, cookies and analytics data about how you use our services.
- Location data: approximate location derived from IP addresses where relevant to the service.
- Customer support and communications: records of correspondence, support requests, and any information you provide when interacting with our support channels.
- Sensitive data: we do not routinely collect special category (sensitive) personal data. If such data is provided, we will process it only where there is a lawful basis and appropriate safeguards.
3. Lawful Bases for Processing
We rely on one or more lawful bases to process personal data, depending on the purpose of processing:
- Performance of a contract: processing necessary to fulfill our contractual obligations to you, such as providing services, billing and customer support.
- Legal obligation: processing necessary to comply with legal obligations, including tax, accounting and regulatory requirements.
- Consent: where you have given clear consent for specific processing activities (for example, certain marketing communications or use of non-essential cookies). You may withdraw consent at any time without affecting prior lawful processing.
- Legitimate interests: where we have a legitimate interest that is not overridden by your rights and freedoms. Examples include fraud prevention, direct marketing (subject to your rights), improving and securing our services, and enforcing our terms.
- Vital interests: in exceptional circumstances to protect life or safety.
4. How We Use Personal Data
We use personal data for the following purposes:
- To provide, maintain and improve our services, including account administration and technical support.
- To process orders, payments and to manage billing and collections.
- To prevent fraud, investigate security incidents and to protect the rights and property of users and third parties.
- To send service-related notifications, updates and information about products and features.
- To provide customer support and respond to inquiries.
- For analytics, research and to personalize content and user experience, including profiling for marketing purposes where lawful.
- To comply with legal and regulatory obligations, including recordkeeping and reporting.
5. Data Retention
Retention periods are determined by the nature of the data and the purpose for which it was collected. We retain personal data only as long as necessary to fulfill the purposes described in this Policy, including satisfying legal, accounting or reporting requirements.
Typical retention criteria include:
- Data processed for contract performance: retained for the duration of the contractual relationship and for a reasonable period thereafter to deal with queries, disputes or legal obligations.
- Financial and transactional data: retained for statutory periods required by tax and accounting laws.
- Support and correspondence records: retained for a period necessary to provide effective support and to maintain records of interactions.
- Marketing data: retained until you withdraw consent or object to processing, subject to lawful retention for compliance or legitimate interests.
When retention is no longer necessary, we will securely delete or anonymize personal data.
6. Processors and Third Parties
We use third-party service providers (processors) to assist with the delivery of our services. Processors are engaged under written contracts that require them to process data only on our documented instructions and to implement appropriate technical and organizational measures.
Categories of processors include:
- Payment processors and gateways.
- Cloud hosting and infrastructure providers.
- Customer support and communication platforms.
- Analytics and performance monitoring providers.
- Marketing and advertising platforms (where applicable).
We may also disclose personal data to competent authorities, courts or other third parties when required by law or to protect legal rights.
7. International Transfers
Personal data may be transferred to and processed in countries outside the European Economic Area. Where transfers occur, we implement appropriate safeguards such as:
- Ensuring transfers are to countries with an adequacy decision;
- Using standard contractual clauses approved by the European Commission;
- Implementing additional technical and organizational measures to protect data.
You may obtain details of the safeguards used by contacting us through the channels available to you in the service.
8. Your Rights
Rights Available to You
Under the GDPR you have certain rights in relation to your personal data. These include the right to:
- Access: request access to the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your personal data where there is no legal basis for further processing.
- Restriction: request restriction of processing in certain circumstances.
- Object: object to processing based on legitimate interests or for direct marketing.
- Data portability: receive personal data you have provided to us in a structured, commonly used and machine-readable format.
- Withdraw consent: withdraw consent to processing where consent was the lawful basis.
- Complain: lodge a complaint with a supervisory authority if you believe your rights have been infringed.
How Requests Are Handled
We will respond to verified requests in accordance with applicable law, generally within one month. This period may be extended by two further months for complex or numerous requests. We may require information to confirm identity and to locate the requested data. Requests that are manifestly unfounded or excessive may be subject to a reasonable fee.
9. Automated Decision-Making and Profiling
We may use automated processing, including profiling, to improve and personalize services, to detect fraud and to target communications. Where such processing produces legal effects or similarly significantly affects you, we will provide meaningful information about the logic involved, the significance and the envisaged consequences and, where required, allow you to request human review.
10. Security Measures
We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction or damage. Measures include access controls, encryption, secure development practices and regular security assessments. While we strive to protect your data, no security measure is guaranteed to be completely secure.
11. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. Material changes will be notified via the service or other provided channels where required. Please review this Policy periodically.
Important: This Privacy Policy applies to all customers in the area and forms the basis on which we process personal data under the GDPR. By using our services you acknowledge that you have read and understood this Policy.
12. Additional Information
If you require further information about how we process personal data, the legal basis relied upon, the retention periods or the safeguards for international transfers, please use the contact methods available to you through our service interfaces. We will provide the requested information in accordance with applicable law.
End of Privacy Policy
