Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with services provided to customers in the area. It applies to all customers in area and describes the principles and practices used to process personal data in a manner that is lawful, fair, transparent, and compliant with the General Data Protection Regulation (GDPR).
1. Scope and Purpose
This policy applies to all individuals who use, purchase, inquire about, or otherwise interact with our products or services in area. It covers all personal data processed in the ordinary course of business, whether collected directly from the individual or obtained through legitimate third-party sources. The purpose of this policy is to explain what information is collected, why it is collected, the lawful bases relied upon, how long it is retained, who may process it on our behalf, and what rights individuals have under applicable data protection law.
2. Data We Collect
We collect only the personal data necessary for specified, explicit, and legitimate purposes. Depending on the nature of the interaction, the categories of data may include:
- Identity data such as name, title, and account identifiers.
- Contact data such as billing or correspondence details.
- Transaction data such as service history, purchase records, and payment confirmations.
- Technical data such as device information, browser type, IP address, and usage logs.
- Communication data such as messages, feedback, and support requests.
- Preference data such as service choices and communication preferences.
We do not intentionally collect special category data unless it is strictly necessary, expressly permitted by law, or voluntarily provided by the individual for a clear and lawful purpose. When such data is processed, additional safeguards are applied.
3. How We Use Personal Data
Personal data is used for the following purposes:
- to provide and manage services;
- to process transactions and maintain records;
- to communicate about accounts, requests, or service-related updates;
- to improve performance, security, and customer experience;
- to comply with legal and regulatory obligations;
- to detect, prevent, and investigate fraud, abuse, or unauthorized access;
- to defend or establish legal claims;
- to send relevant information where permitted and appropriate.
We follow the principle of data minimisation and only process data that is adequate, relevant, and limited to what is necessary for the intended purpose.
4. Lawful Basis for Processing
Under GDPR, personal data is processed only where a lawful basis exists. The lawful bases we may rely on include:
Consent
Where required, we will process personal data based on freely given, specific, informed, and unambiguous consent. Individuals may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Contract
Processing may be necessary to enter into or perform a contract with an individual, including steps taken at the request of the individual before entering into a contract.
Legal Obligation
We may process data to comply with applicable laws, regulations, tax rules, accounting requirements, and lawful requests from authorities.
Legitimate Interests
We may process data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the individual’s interests, rights, and freedoms. Examples include service improvement, fraud prevention, network security, and internal administration. A balancing assessment is carried out where required.
Vital Interests and Public Task
In limited situations, processing may be necessary to protect vital interests or to perform a task carried out in the public interest, where applicable under law.
5. Data Sharing and Processors
We may share personal data with trusted third parties that process data on our behalf as processors. These processors are engaged only where necessary and are bound by written contracts requiring appropriate confidentiality, security, and GDPR-compliant processing.
Processors may include service providers for:
- IT hosting and infrastructure;
- payment processing;
- customer support systems;
- analytics and performance monitoring;
- document storage and secure archiving;
- professional advisory services;
- fraud prevention and security monitoring.
Where a third party acts as an independent controller, that party will be responsible for its own compliance and privacy obligations. We do not sell personal data. Any disclosure is limited to what is necessary and carried out in accordance with applicable law.
6. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with equivalent protections, we ensure that appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other legally permitted transfer mechanisms. Where necessary, supplementary measures are applied to protect the data against unauthorized access, loss, or misuse.
7. Data Retention
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, regulatory, and contractual requirements. Retention periods vary based on the type of data and the reason for processing.
In general, retention is determined using the following criteria:
- the duration of the customer relationship;
- the time needed to complete the relevant service or transaction;
- legal limitation periods for claims;
- record-keeping requirements;
- security, audit, and fraud-prevention needs.
When personal data is no longer required, it is deleted, anonymised, or securely archived in accordance with retention controls. Where deletion is not immediately possible due to legal holds or technical constraints, the data will be isolated and used only for the permitted purpose.
8. Security Measures
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures may include access controls, encryption, monitoring, least-privilege permissions, staff training, and secure storage procedures. Security controls are reviewed periodically and updated when necessary to reflect risks and technological developments.
9. User Rights
Individuals have rights under GDPR in relation to their personal data. Subject to legal conditions and exceptions, these rights include:
- Right of access – to obtain confirmation of whether data is processed and a copy of it.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of data where lawful grounds apply.
- Right to restriction – to request limited processing in certain circumstances.
- Right to data portability – to receive data in a structured, commonly used, machine-readable format where applicable.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing relies on consent.
- Right not to be subject to automated decision-making – where such decisions have legal or similarly significant effects, except where permitted by law.
Requests will be handled within the time limits required by law. In some cases, we may need to verify identity before responding to a request. Exercising these rights will not result in unfair treatment.
10. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate authorisation where required by law. If we become aware that such data has been collected without lawful basis, we will take reasonable steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, operational practices, or service arrangements. Any updated version will apply from the effective date stated in the revised policy. Customers in area should review this policy periodically to remain informed about how their personal data is handled.
12. Core Principles
Our data protection approach is based on GDPR principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality. These principles guide how personal data is collected and processed across all relevant activities. We aim to ensure that personal data is handled responsibly, only for legitimate purposes, and with respect for individual rights and expectations.
This Privacy Policy applies to all customers in area and is intended to provide a clear and GDPR-compliant description of our personal data practices.
