Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, retained, and protected in connection with our services. It applies to all customers in area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and related data protection laws. By using our services, you acknowledge that you have read this Privacy Policy and understand how your personal data is handled.
1. Data We Collect
We collect and process personal data only when it is necessary for legitimate business and service purposes. The types of data we may collect include:
- Identification data, such as name, username, or similar identifiers.
- Contact data, such as email address, telephone number, and address details.
- Account data, such as login credentials, service preferences, and profile settings.
- Transaction data, including service history, purchase records, and billing details.
- Technical data, such as IP address, device identifiers, browser type, operating system, and usage logs.
- Communication data, including inquiries, feedback, and records of support interactions.
We do not intentionally collect special category data unless it is strictly required by law or explicitly provided by you for a lawful purpose. If such data is processed, it will be handled with additional safeguards.
2. How We Use Personal Data
We use personal data to provide and improve our services, manage our business operations, communicate with users, and comply with legal obligations. Specifically, we may use personal data to:
- Deliver and maintain our services.
- Process requests, transactions, and account-related actions.
- Respond to support inquiries and communicate service updates.
- Monitor performance, prevent fraud, and secure our systems.
- Analyze service use to improve functionality and user experience.
- Meet tax, accounting, regulatory, and legal requirements.
We process personal data only for specified, explicit, and legitimate purposes, and we do not use it in a manner that is incompatible with those purposes.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing personal data. Depending on the context, our lawful bases may include the following:
Performance of a Contract
We process data when it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This may include creating accounts, providing services, processing payments, or fulfilling orders.
Legal Obligation
We may process data to comply with legal obligations, including recordkeeping, tax compliance, accounting requirements, or lawful requests from authorities.
Legitimate Interests
We may process data where it is necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms. Examples include improving our services, maintaining security, preventing fraud, and managing internal operations.
Consent
Where required by law, we rely on your consent for certain processing activities. When processing is based on consent, you may withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
4. Sharing and Processors
We may share personal data with trusted third parties that act as processors or service providers on our behalf. These parties are only permitted to process personal data according to our instructions and must implement appropriate technical and organizational security measures.
Processors may include providers that support:
- Payment processing and financial services.
- IT hosting, cloud storage, and infrastructure support.
- Customer support and communication tools.
- Analytics, monitoring, and performance measurement.
- Document management, security, and compliance services.
We may also disclose personal data where required to do so by law, regulation, court order, or other lawful request. In addition, disclosure may occur in connection with a business restructuring, merger, or similar event, provided appropriate safeguards are in place.
We do not sell personal data. If sharing is required for service delivery, it is limited to what is necessary and proportionate to the purpose.
5. International Transfers
Where personal data is transferred outside the jurisdiction in which it was collected, we take steps to ensure an adequate level of protection. This may include the use of standard contractual clauses, adequacy decisions, or other legal safeguards recognized under applicable data protection law.
We are committed to protecting personal data regardless of where it is processed.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, reporting, and operational requirements. The retention period depends on several factors, including:
- The nature of the data and the sensitivity involved.
- The purpose for which the data was collected.
- Whether the data is required to comply with legal obligations.
- Whether the data is needed to resolve disputes or enforce agreements.
When personal data is no longer needed, it is securely deleted, anonymized, or otherwise disposed of in accordance with our retention practices. We do not keep personal data indefinitely.
7. Security Measures
We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, disclosure, or destruction. These measures may include access controls, encryption, monitoring, secure storage, and regular review of internal procedures.
While we strive to protect personal data, no system can be guaranteed to be completely secure. Users should take reasonable steps to protect their own information, including keeping account credentials confidential.
8. Your Rights Under GDPR
Depending on your location and the circumstances of processing, you may have the following rights regarding your personal data:
- Right of access – to obtain confirmation and a copy of the personal data we hold about you.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of personal data in certain situations.
- Right to restriction – to request limited processing in certain circumstances.
- Right to data portability – to receive your data in a structured, commonly used, machine-readable format and request transfer where applicable.
- Right to object – to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
You also have the right to be informed about how your data is processed and, where applicable, to lodge a complaint with the relevant supervisory authority. We encourage you to raise concerns so that we can address them directly and promptly.
9. Automated Decision-Making
We do not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects, unless permitted by law and subject to appropriate safeguards. If such processing is introduced, we will provide clear information about it and your available rights.
10. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children where such collection is not lawful. If we become aware that we have collected personal data unlawfully from a child, we will take steps to delete it as required by law.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. When we make changes, the revised version will apply from the date it becomes effective. We encourage users to review this policy periodically to remain informed about how personal data is protected.
12. Summary of Our Commitment
We are committed to handling personal data lawfully, fairly, and transparently. We collect only what is necessary, use it for legitimate purposes, share it only with trusted processors or where required by law, and retain it only for as long as needed. We respect your rights and aim to maintain a high standard of privacy and security for all customers in area.
Last reviewed: This Privacy Policy is maintained to reflect GDPR principles and applicable privacy obligations.
