Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when services are provided to customers in the relevant area. It applies to all customers in that area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and related data protection laws. By using the services, customers acknowledge that their personal data may be processed as described in this Policy.
1. Data We Collect
We collect and process personal data that is necessary to provide services, manage relationships, maintain records, and comply with legal obligations. The types of data collected may include:
- Identification data, such as name, title, and account or customer reference numbers.
- Contact data, such as address, email address, and telephone number.
- Transaction data, such as payment records, invoices, service history, and purchase details.
- Technical data, such as device type, browser details, IP address, and usage logs where applicable.
- Communication data, such as correspondence, support requests, complaints, and feedback.
- Preference data, such as service preferences, settings, and consent choices where relevant.
We only collect data that is adequate, relevant, and limited to what is necessary for the purposes described in this Policy. Where special category data is processed, it will only be handled when permitted by law and when necessary for a specific lawful purpose.
2. How We Use Personal Data
Personal data is used for legitimate operational and legal purposes, including:
- Providing and delivering services requested by customers.
- Managing customer accounts and maintaining accurate records.
- Processing payments, billing, and financial administration.
- Responding to enquiries, complaints, and support requests.
- Improving service quality, performance, and customer experience.
- Ensuring security, fraud prevention, and misuse detection.
- Complying with tax, accounting, regulatory, and other legal obligations.
We do not use personal data for purposes that are incompatible with the original collection purpose unless required or permitted by law.
3. Lawful Basis for Processing
Under GDPR, personal data is processed only where a lawful basis applies. Depending on the activity, we rely on one or more of the following lawful bases:
Contract
Processing is necessary to enter into or perform a contract with a customer, or to take steps at the customer’s request before entering into a contract.
Legal Obligation
Processing is necessary to comply with legal or regulatory requirements, including accounting, taxation, and record-keeping obligations.
Legitimate Interests
Processing may be necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the customer’s rights and freedoms. Examples include service improvement, business administration, fraud prevention, and network or information security.
Consent
Where required, processing is based on freely given, specific, informed, and unambiguous consent. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests and Public Interest
In limited situations, processing may be necessary to protect vital interests or to perform a task carried out in the public interest, where applicable under law.
4. Sharing and Processors
We may share personal data with trusted service providers and other third parties who act as processors or independent controllers, as appropriate. Processors are engaged only where they provide sufficient guarantees to implement appropriate technical and organisational measures in compliance with GDPR.
Processors may include providers of:
- IT hosting and cloud infrastructure.
- Payment processing and financial administration.
- Customer support and communication tools.
- Data storage, backup, and security services.
- Analytics or reporting tools, where used lawfully and proportionately.
When processors act on our behalf, they may only process personal data according to documented instructions and must not use it for their own purposes. We may also disclose data where required by law, court order, or lawful request from public authorities. Any sharing is restricted to what is necessary and proportionate for the intended purpose.
5. International Transfers
If personal data is transferred outside the European Economic Area or to a jurisdiction that does not provide an adequate level of protection, appropriate safeguards will be used. These may include adequacy decisions, standard contractual clauses, or equivalent lawful transfer mechanisms. Customers may request information about the safeguards used where applicable.
6. Data Retention
Personal data is retained only for as long as necessary for the purposes for which it was collected, including legal, accounting, and reporting requirements. Retention periods are determined by the nature of the data, the reason for processing, contractual obligations, limitation periods, and statutory record-keeping duties.
In general:
- Contract and account data are kept for the duration of the relationship and for a reasonable period thereafter.
- Financial and tax-related records are retained for the period required by applicable law.
- Support and communication records are retained for as long as needed to handle requests and maintain service quality.
- Where data is no longer needed, it is securely deleted, anonymised, or irreversibly destroyed.
Retention is reviewed periodically to ensure data is not kept longer than necessary.
7. Security Measures
Appropriate technical and organisational measures are used to protect personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. These measures may include access controls, encryption where suitable, secure storage, monitoring, staff training, and supplier due diligence. Although no system can be guaranteed to be completely secure, reasonable steps are taken to reduce risk and protect personal information.
8. User Rights
Customers have rights under GDPR in relation to their personal data. Subject to legal limitations, these rights include:
- Right of access: to request confirmation of whether personal data is processed and obtain a copy.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of data in certain circumstances.
- Right to restriction: to request limited processing in certain situations.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and, where feasible, transmit it to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing, where applicable.
- Right not to be subject to automated decision-making: to avoid decisions based solely on automated processing that produce legal or similarly significant effects, except where permitted by law.
Requests relating to these rights will be handled without undue delay and within the time limits required by law. Identity verification may be requested before fulfilling a request to protect personal data from unauthorised disclosure.
9. Consent and Withdrawal
Where processing relies on consent, customers may withdraw consent at any time. Withdrawal will not affect processing carried out before the withdrawal request. If consent is withdrawn, certain services or features may become unavailable where consent is necessary for their operation.
10. Data Accuracy and Customer Responsibilities
Reasonable steps are taken to keep personal data accurate and up to date. Customers are encouraged to inform us of changes to their personal details so records can be maintained correctly. Providing accurate information helps ensure that services are delivered efficiently and securely.
11. Children’s Data
This Policy is intended for customers in the relevant area and is not directed at children unless services are lawfully provided to them. Where children’s data is processed, it will be done only in accordance with applicable law and with the safeguards required by GDPR.
12. Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes in legal, operational, or security requirements. Any revised version will apply from the date it is made effective. Customers are encouraged to review the Policy periodically to remain informed about how personal data is handled. Continued use of the services after a change takes effect indicates acceptance of the updated Policy, to the extent permitted by law.
13. Applicable Scope
This Privacy Policy applies to all customers in the relevant area and covers personal data processed in connection with service delivery, administration, support, compliance, and related business operations. Where local law provides additional protections or rights, those protections will apply alongside this Policy.
Last updated: as applicable
