Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR). By using our services, you acknowledge that your personal data may be processed as described in this Policy.
1. Scope of this Policy
This Policy applies to personal data processed in the course of providing our services to customers in the area. It covers data collected directly from customers, data generated through use of our services, and data received from third parties where permitted by law. This Policy does not apply to anonymous information that cannot reasonably be used to identify an individual.
2. Data We Collect
We collect only the data that is necessary, relevant, and limited to what is required for the purposes described below. Depending on how you interact with us, we may collect the following categories of personal data:
- Identity data such as name, title, and customer reference information.
- Contact data such as address, email address, and phone number.
- Transaction data such as records of purchases, service requests, payments, and account activity.
- Technical data such as device type, browser type, IP address, and usage logs.
- Communication data such as messages, feedback, complaints, and support interactions.
- Preference data such as service choices, communication preferences, and consent settings.
We do not intentionally collect special category data unless strictly necessary and lawful to do so. If such data is processed, we will apply additional safeguards in accordance with applicable law.
3. How We Use Personal Data
We use personal data for legitimate business and service purposes, including to:
- provide and manage our services;
- process transactions and maintain records;
- respond to inquiries and support requests;
- maintain security, prevent fraud, and protect against misuse;
- improve our services, operations, and customer experience;
- comply with legal obligations;
- send essential notices and service-related communications;
- exercise or defend legal claims where necessary.
We will not process personal data in a manner that is incompatible with the purposes for which it was collected unless we have a lawful basis to do so.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process personal data. We rely on one or more of the following bases:
- Performance of a contract – where processing is necessary to provide services or take steps at your request before entering into a contract.
- Legal obligation – where processing is required to comply with laws, regulations, tax requirements, or other legal duties.
- Legitimate interests – where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Examples include service improvement, fraud prevention, and internal administration.
- Consent – where you have given clear permission for a specific processing activity, such as certain marketing communications or optional features.
- Vital interests – where processing is necessary to protect someone’s life or physical safety in exceptional cases.
Where we rely on consent, you may withdraw it at any time. Withdrawal will not affect the lawfulness of processing carried out before withdrawal.
5. Sharing and Processors
We may share personal data with trusted third parties who act as data processors on our behalf. These processors only process personal data according to our instructions and are subject to contractual obligations to protect confidentiality and security.
Examples of processors may include:
- IT and hosting providers who support system storage and infrastructure;
- Payment service providers who process payments securely;
- Customer support tools used to manage inquiries and service requests;
- Analytics and monitoring providers who help us understand service performance;
- Professional advisers such as auditors, insurers, legal advisers, and compliance consultants.
We may also disclose data where required by law, court order, regulatory request, or to protect our rights, customers, or the public. We do not sell personal data.
6. International Transfers
If personal data is transferred outside the European Economic Area or the United Kingdom, we will ensure appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms required under GDPR. We only transfer data where adequate protection can be ensured.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, reporting, and dispute resolution requirements. Retention periods depend on the type of data and the context of processing.
In general, we consider the following criteria when determining retention:
- the duration of our relationship with you;
- the need to provide services and support;
- legal and regulatory retention obligations;
- limitation periods for potential claims;
- security, audit, and operational requirements.
When data is no longer needed, it will be deleted, anonymised, or securely archived in accordance with our retention practices.
8. Data Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, monitoring, staff training, and secure data handling procedures. While no system is completely secure, we continually review and improve our safeguards.
9. Your Rights Under GDPR
Subject to legal limitations, you have the following rights regarding your personal data:
- Right of access – to obtain confirmation and a copy of the personal data we hold about you;
- Right to rectification – to request correction of inaccurate or incomplete data;
- Right to erasure – to request deletion of your data in certain circumstances;
- Right to restriction – to request that we limit processing in specific situations;
- Right to data portability – to receive your data in a structured, commonly used, machine-readable format and have it transmitted where feasible;
- Right to object – to object to processing based on legitimate interests or direct marketing;
- Right to withdraw consent – where processing is based on consent;
- Right not to be subject to automated decision-making – including profiling, where legally relevant.
You may also have the right to lodge a complaint with your local data protection authority if you believe your rights have been infringed. We encourage you to raise concerns so that we can address them promptly.
10. Children’s Data
Our services are not directed to children unless expressly stated. We do not knowingly collect personal data from children without the appropriate lawful basis and, where required, verifiable parental or guardian consent. If we become aware that we have collected such data unlawfully, we will take reasonable steps to delete it.
11. Automated Processing and Profiling
We may use limited automated processing to improve service delivery, detect fraud, analyse usage patterns, or manage operational efficiency. Where such processing produces legal or similarly significant effects, we will ensure that it is conducted lawfully and with suitable safeguards. We do not use automated decision-making in a manner that unlawfully impacts your rights.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our operations, or data processing practices. Any revised version will apply from the date it is published. We encourage you to review this Policy periodically so that you remain informed about how your data is handled.
Key Principle
We process personal data fairly, lawfully, transparently, and only for specified purposes, with retention and security controls designed to respect your rights.
Summary of Commitments
We are committed to using personal data responsibly, keeping it no longer than necessary, sharing it only with appropriate processors under contract, and enabling individuals to exercise their GDPR rights. This Policy applies to all customers in the area and forms part of our overall commitment to privacy and compliance.
