Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area where our services are offered, and it is intended to meet the requirements of the General Data Protection Regulation (GDPR) and other applicable data protection laws.
We are committed to handling personal data in a lawful, fair, and transparent manner. We only process personal data where there is a valid legal basis, and we take appropriate technical and organizational measures to protect that data.
1. Data Collection
We may collect personal data directly from you, automatically through your use of our services, and from third parties where permitted by law. The categories of data we may collect include:
- Identity data such as your name, title, or username.
- Contact data such as address, email address, or telephone number.
- Transaction data such as service details, purchase history, payment status, and records of requests or complaints.
- Technical data such as device type, browser type, IP address, language settings, and system identifiers.
- Usage data such as pages viewed, features used, time spent, and interaction patterns.
- Communication data such as messages, feedback, and correspondence related to service inquiries.
We do not intentionally collect special category data unless it is necessary and a lawful basis applies. Where such data is required, we will only process it in line with GDPR conditions and, if appropriate, with your explicit consent or another valid legal ground.
2. Purposes of Processing
We process personal data for the following purposes:
- To provide, operate, and maintain our services.
- To manage customer accounts and service relationships.
- To process transactions and record payments.
- To respond to inquiries, requests, and support issues.
- To improve service quality, functionality, and user experience.
- To detect, prevent, and investigate fraud, misuse, or security incidents.
- To comply with legal obligations, regulatory requirements, and lawful requests from authorities.
- To establish, exercise, or defend legal claims.
We will not use personal data for purposes that are incompatible with the original purpose for which it was collected unless a valid legal basis exists and you are informed where required.
3. Lawful Basis for Processing
Under GDPR, we must identify a lawful basis for each processing activity. Depending on the circumstances, we may rely on one or more of the following:
Contractual Necessity
We process personal data when it is necessary to enter into or perform a contract with you. This includes providing services, managing your account, and handling related requests.
Legal Obligation
We may process personal data to comply with applicable legal or regulatory obligations, such as tax, accounting, anti-fraud, or consumer protection requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided that your interests and fundamental rights do not override those interests. Examples include service improvement, network security, fraud prevention, and internal analytics.
Consent
Where required by law, we will rely on your consent. If we use consent as the basis for processing, you have the right to withdraw it at any time. Withdrawal will not affect the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Interest
In limited situations, we may process personal data where it is necessary to protect someone’s vital interests or to carry out a task in the public interest, where applicable law permits.
We assess and document the lawful basis for each relevant processing activity to ensure compliance with GDPR principles.
4. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to meet legal, accounting, tax, reporting, or dispute-resolution requirements. Retention periods may vary depending on the type of data and the context in which it was collected.
- Data needed to provide services is retained for the duration of the customer relationship.
- Data required to meet legal obligations may be retained for the period mandated by law.
- Data used for security, audit, or dispute management may be retained for a reasonable period based on necessity.
- Where data is no longer needed, it is securely deleted, anonymized, or otherwise rendered unusable.
When determining retention periods, we consider the nature of the data, the potential risk of harm from unauthorized use or disclosure, the purposes of processing, and applicable legal requirements.
5. Processors and Sharing of Data
We may share personal data with trusted processors and other parties only when necessary and in accordance with GDPR. Processors act on our instructions and are contractually required to protect personal data and process it only for specified purposes.
Categories of processors may include:
- IT and hosting service providers.
- Payment processing providers.
- Customer support or ticketing platforms.
- Analytics and performance monitoring providers.
- Professional advisers such as legal, accounting, or audit firms.
- Security and fraud prevention providers.
We may also disclose personal data if required by law, court order, regulatory authority, or to protect rights, safety, and property. If personal data is transferred outside the European Economic Area, we will ensure appropriate safeguards are in place, such as standard contractual clauses or other lawful transfer mechanisms.
We do not sell personal data. Any sharing is limited to what is necessary for the purposes described in this Policy.
6. Data Security
We use appropriate safeguards designed to prevent accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These safeguards may include access controls, encryption, secure storage, staff training, logging, and regular review of security practices. While no system can be completely secure, we continuously work to reduce risks and improve protection.
7. Your Rights Under GDPR
Where GDPR applies, you have the following rights in relation to your personal data, subject to legal limitations:
- Right of access – to obtain confirmation and a copy of your personal data.
- Right to rectification – to correct inaccurate or incomplete data.
- Right to erasure – to request deletion of data in certain circumstances.
- Right to restriction – to limit processing in specific situations.
- Right to data portability – to receive data in a structured, commonly used, machine-readable format and, where feasible, to have it transferred.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent.
- Right not to be subject to automated decision-making – including profiling, where applicable under law.
You may also have the right to lodge a complaint with the relevant supervisory authority if you believe your rights have been infringed. We encourage you to review your rights carefully and to exercise them where appropriate.
8. Exercising Your Rights
Requests to exercise data protection rights will be handled in accordance with applicable law. We may need to verify your identity before responding to a request. We will respond within the time periods required by GDPR, typically within one month, unless an extension is permitted due to complexity or the number of requests.
If a request is manifestly unfounded or excessive, we may refuse to act on it or charge a reasonable fee, as permitted by law.
9. Children’s Data
Our services are not intended for children unless stated otherwise for a specific service. We do not knowingly collect personal data from children in a manner that would require additional parental consent under applicable law. If we become aware that such data has been collected inappropriately, we will take steps to delete it or obtain the necessary authorization.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or service operations. Updated versions will apply from the date they take effect. We encourage customers to review this Policy periodically to stay informed about how personal data is handled.
By using our services, you acknowledge that your personal data will be processed in accordance with this Privacy Policy and applicable data protection law.
