Privacy Policy
This Privacy Policy explains how we collect, use, store, share, and protect personal data in connection with our services. It applies to all customers in the area and is intended to provide clear information about how personal information is handled in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR), where relevant.
1. Scope of This Policy
This policy applies to personal data collected from customers, prospective customers, users, and other individuals whose information may be processed in the course of providing our services. It covers data collected directly from you, data collected automatically when you interact with our services, and data received from third parties where permitted by law.
We are committed to processing personal data fairly, lawfully, and transparently. We only collect information that is necessary for defined purposes and retain it for as long as required to fulfill those purposes or comply with legal obligations.
2. Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data:
- Identification data: such as name, title, and account identifiers.
- Contact data: such as address, email address, and telephone number.
- Transaction data: such as service requests, purchase history, billing details, and payment-related information.
- Technical data: such as device type, browser type, IP address, operating system, and usage logs.
- Profile data: such as preferences, feedback, and interactions with our services.
- Communication data: such as enquiries, complaints, and correspondence.
We do not intentionally collect special category data unless it is necessary for a lawful reason and you have been informed appropriately, or another valid legal basis applies.
3. How We Use Personal Data
We use personal data only for specific, explicit, and legitimate purposes. These include:
- providing and managing our services;
- processing transactions and handling payments;
- responding to enquiries and support requests;
- maintaining records and internal administration;
- improving service quality, functionality, and user experience;
- detecting, preventing, and investigating fraud, misuse, or security incidents;
- complying with legal and regulatory obligations;
- communicating updates, notices, or changes relevant to our services.
We will not use personal data in ways that are incompatible with the purposes stated in this policy unless we have a valid legal basis for doing so.
4. Lawful Basis for Processing
Where GDPR applies, we process personal data only when we have a lawful basis. Depending on the context, one or more of the following legal bases may apply:
Contract
We process personal data where it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
Legal Obligation
We may process data where needed to comply with legal, regulatory, tax, accounting, or reporting obligations.
Legitimate Interests
We may process data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Examples include service improvement, fraud prevention, and operational management.
Consent
In limited cases, we may rely on your consent. Where consent is used, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Task
In rare circumstances, we may process personal data to protect someone’s vital interests or where processing is necessary for a task carried out in the public interest, if applicable.
5. Sharing of Personal Data
We may share personal data with trusted third parties where necessary to provide our services, operate our business, or comply with legal obligations. These third parties act as processors or independent controllers depending on the nature of the relationship.
Categories of recipients may include:
- service providers supporting hosting, IT systems, maintenance, and security;
- payment service providers and financial intermediaries;
- professional advisers such as legal, audit, or accounting providers;
- regulatory, law enforcement, or other public authorities where required by law;
- business partners or subcontractors involved in service delivery.
We require processors to handle personal data securely, confidentially, and only on our documented instructions. Where data is transferred outside the applicable jurisdiction, we ensure appropriate safeguards are in place as required by law.
6. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including any legal, accounting, reporting, or dispute-resolution requirements. Retention periods depend on the type of data, the purpose of processing, and applicable legal obligations.
When determining retention periods, we consider:
- the amount, nature, and sensitivity of the data;
- the potential risk of harm from unauthorised use or disclosure;
- the purposes for which we process the data;
- whether those purposes can be achieved by other means;
- mandatory legal retention periods.
Once data is no longer required, it will be securely deleted, anonymised, or otherwise irreversibly removed from active systems where feasible.
7. Data Security
We use appropriate technical and organisational measures to protect personal data against accidental loss, destruction, unauthorised access, disclosure, alteration, or misuse. These measures may include access controls, encryption, secure storage, network protections, and staff confidentiality obligations.
Although we work to safeguard personal data, no system can be guaranteed to be completely secure. If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will take appropriate steps in line with applicable legal requirements.
8. Your Rights
Where GDPR applies, you may have the following rights in relation to your personal data, subject to legal limitations:
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request limited processing in certain situations.
- Right to data portability: to receive certain data in a structured, commonly used format and, where feasible, have it transmitted to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent.
You also have the right to lodge a complaint with the relevant data protection authority if you believe your rights have been infringed. We encourage you to raise concerns so we can address them appropriately.
9. Automated Decision-Making
We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects, unless this is clearly disclosed and permitted by law. If such processing is used, you will be informed of the logic involved and your available rights, where required.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or service arrangements. The updated version will apply from the time it is made available. We encourage you to review this policy periodically to stay informed about how we process personal data.
11. General Statement
This Privacy Policy is intended to be read as a clear and practical statement of how we handle personal data. It applies to all customers in the area and reflects our commitment to respecting privacy, using data responsibly, and processing information only where there is a valid lawful basis. We aim to keep data processing fair, necessary, and proportionate at all times.
