Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area and is intended to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR). By using our services, you acknowledge that your personal data may be processed as described below.
1. Data Collection
We collect personal data that is necessary to provide and improve our services, manage our relationship with customers, and comply with legal obligations. The types of data we may collect include:
- Identification data such as name, title, and account identifiers;
- Contact data such as email address, telephone number, billing address, and service address;
- Transaction data such as payment records, invoices, purchase history, and service requests;
- Technical data such as IP address, browser type, device information, operating system, and log data;
- Usage data such as preferences, interactions with our services, and feedback provided;
- Communication data such as correspondence, support requests, and complaint details;
- Any other information you choose to provide to us voluntarily.
We collect data directly from you when you complete forms, enter into a contract, communicate with us, or otherwise use our services. We may also receive data from third parties where permitted by law, such as service providers, payment processors, or public sources.
2. How We Use Personal Data
We process personal data only for specified, legitimate purposes. These purposes may include:
- Providing and delivering our services;
- Managing customer accounts and records;
- Processing payments and issuing invoices;
- Responding to inquiries, complaints, and support requests;
- Personalizing and improving service quality;
- Preventing fraud, misuse, and security incidents;
- Meeting legal, regulatory, tax, and accounting obligations;
- Maintaining internal administration and business operations;
- Sending service-related notices and operational communications.
Where required, we will only use personal data in ways that are fair, lawful, and transparent. We do not use personal data for purposes that are incompatible with the reasons for which it was collected unless we have a valid legal basis to do so.
3. Lawful Basis for Processing
Under the GDPR, we must have a lawful basis for each processing activity. Depending on the situation, we may rely on one or more of the following grounds:
3.1 Contract
We process personal data where it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes account setup, service delivery, billing, and customer support.
3.2 Legal Obligation
We may process personal data where necessary to comply with legal obligations, such as tax laws, recordkeeping requirements, anti-fraud measures, or lawful requests from public authorities.
3.3 Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Legitimate interests may include service improvement, business management, fraud prevention, network security, and administrative efficiency. When we rely on this basis, we consider the potential impact on your rights and apply appropriate safeguards.
3.4 Consent
In limited cases, we may rely on your consent to process personal data. Where consent is used, it will be freely given, specific, informed, and unambiguous. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
3.5 Vital Interests and Public Interest
In rare cases, processing may be necessary to protect vital interests or to carry out tasks in the public interest, where applicable law permits this.
4. Retention of Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and reporting requirements. Retention periods depend on the type of data, the purpose of processing, and any legal obligations that apply.
- Customer and contract records are generally kept for the duration of the relationship and for a reasonable period thereafter;
- Financial and tax records are retained for the period required by law;
- Support communications and operational records are kept only as long as necessary to resolve the issue and maintain accurate records;
- Technical logs are retained for security, troubleshooting, and audit purposes for a limited period;
- Where data is no longer required, it will be securely deleted, anonymized, or archived in accordance with applicable rules.
We may retain certain information for longer periods if necessary to establish, exercise, or defend legal claims, or where we are required to do so by law. When retention is no longer justified, we take reasonable steps to dispose of the data securely.
5. Processors and Data Sharing
We may share personal data with carefully selected processors and service providers who act on our behalf and under our instructions. These parties are contractually required to protect personal data and may only process it for the purposes we specify. Examples of processors may include:
- IT and cloud service providers that host systems, store data, or provide infrastructure support;
- Payment service providers that handle transactions securely;
- Customer support and communication tools used to manage inquiries and service requests;
- Accounting, audit, and professional advisers assisting with compliance and business operations;
- Security and fraud prevention providers helping protect systems and users;
- Delivery or operational partners where needed to fulfill service obligations.
We may also disclose personal data if required by law, court order, regulatory request, or to protect our rights, property, safety, or that of others. If data is transferred outside the European Economic Area, we will ensure appropriate safeguards are in place, such as standard contractual clauses or other lawful transfer mechanisms.
6. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. These measures may include access controls, encryption, secure storage, staff training, monitoring, and internal policies designed to limit access to authorized personnel only. While no system can be guaranteed completely secure, we work continuously to maintain a level of protection appropriate to the risk.
7. Your Rights Under GDPR
Subject to applicable legal conditions, you have several rights regarding your personal data:
- Right of access – you may request confirmation of whether we process your data and obtain a copy;
- Right to rectification – you may request correction of inaccurate or incomplete data;
- Right to erasure – you may request deletion of your data in certain circumstances;
- Right to restriction – you may ask us to limit processing in specific cases;
- Right to data portability – you may request data you provided in a structured, commonly used format where applicable;
- Right to object – you may object to processing based on legitimate interests or direct marketing;
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time;
- Right to lodge a complaint – you may complain to the relevant supervisory authority if you believe your rights have been violated.
We may need to verify your identity before responding to a rights request. Some requests may be limited where the law permits or requires us to keep certain information. We will respond within the time periods established by applicable law.
8. Data Minimization and Accuracy
We strive to collect only the personal data that is necessary for the intended purpose. We also take reasonable steps to keep personal data accurate and up to date. If you believe any information we hold about you is incorrect or incomplete, you should update it where possible or request correction in accordance with your rights.
9. Children
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children where such collection is not lawful. If we become aware that personal data has been collected improperly, we will take appropriate steps to delete it or obtain the necessary authorization where permitted by law.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any updates will take effect when made available, unless otherwise required by law. We encourage customers to review this policy periodically to remain informed about how personal data is processed. Continued use of our services after an update indicates acceptance of the revised policy to the extent permitted by law.
Summary of commitments: we process personal data lawfully, transparently, and securely; we use it only for legitimate purposes; we limit retention; we engage processors under contract; and we respect your GDPR rights. This policy applies to all customers in the area.
