Privacy Policy
This Privacy Policy explains how personal data is collected, used, shared, stored, and protected when services are provided to all customers in the area. It applies to individuals who interact with us in any capacity, including customers, prospective customers, and other service users. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Scope and Purpose
This policy describes the categories of personal data we process, the lawful bases we rely on, how long we keep data, the third parties that may process data on our behalf, and the rights available to individuals. We process personal data only for specified, explicit, and legitimate purposes, and we do not use data in ways that are incompatible with those purposes.
The policy applies to all customers in the area where our services are offered, regardless of whether the interaction takes place in person, by phone, by email, or through other communication methods. It also applies where personal data is collected through administrative, operational, or service-related activities.
2. Data We Collect
We may collect and process the following categories of personal data:
- Identification data, such as name, title, and account identifiers.
- Contact data, such as address, email address, and telephone number.
- Transaction data, such as records of purchases, service requests, invoices, and payment status.
- Communication data, such as correspondence, feedback, complaints, and support messages.
- Technical data, such as device information, browser type, log data, and usage patterns where relevant.
- Preference data, such as service preferences, communication choices, and consent records.
- Verification data, where needed to confirm identity and prevent fraud.
We generally collect personal data directly from the individual concerned. In some cases, data may be provided by an authorised representative, a payment provider, a delivery partner, a public authority, or other third parties where permitted by law.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. Depending on the context, we may rely on one or more of the following bases:
- Contract: processing is necessary to enter into or perform a contract with a customer.
- Legal obligation: processing is required to comply with applicable laws, regulations, tax rules, accounting requirements, or lawful requests by authorities.
- Legitimate interests: processing is necessary for our legitimate business interests, provided these interests are not overridden by the individual’s rights and freedoms. Examples may include fraud prevention, service improvement, security, and internal administration.
- Consent: where required by law, we rely on freely given, specific, informed, and unambiguous consent. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
Where we process special category data, if ever necessary, we do so only where a GDPR condition applies and additional safeguards are in place.
4. How We Use Personal Data
We may use personal data to:
- provide and manage services;
- process transactions and maintain records;
- communicate about service updates, requests, or issues;
- respond to enquiries, complaints, and support matters;
- maintain security, prevent fraud, and protect our systems;
- meet legal, regulatory, and tax obligations;
- analyse service performance and improve operations;
- manage internal administration and business planning.
We will not process personal data in a manner that is incompatible with the purposes for which it was collected, unless we have a valid lawful basis to do so.
5. Data Sharing and Processors
We may share personal data with trusted third parties that act as processors on our behalf. These processors are only allowed to process personal data under our instructions and are required to protect it using appropriate technical and organisational measures.
Processors may include:
- IT and cloud hosting providers;
- payment processing providers;
- customer support and communications service providers;
- accounting, audit, and compliance service providers;
- security, fraud prevention, and data backup providers;
- professional advisers acting under confidentiality obligations.
We may also disclose personal data where necessary to comply with legal obligations, defend legal claims, or protect the rights, property, or safety of individuals or our organisation. If data is transferred outside the European Economic Area, we will ensure appropriate safeguards are in place, such as standard contractual clauses or another lawful transfer mechanism permitted under GDPR.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, reporting, or regulatory retention requirements. The length of retention depends on factors such as the nature of the data, the sensitivity of the information, the potential risk of harm from unauthorised use or disclosure, and the legal obligations that apply.
In general:
- contractual and transaction records are kept for the duration of the relationship and for a reasonable period afterward;
- tax, financial, and accounting records are retained for the periods required by law;
- communications and support records are kept long enough to resolve enquiries and improve service quality;
- data processed on the basis of consent is retained until consent is withdrawn or the purpose no longer applies.
When personal data is no longer required, it is securely deleted, anonymised, or otherwise rendered inaccessible in accordance with our retention procedures.
7. Security Measures
We implement appropriate technical and organisational measures to protect personal data against accidental loss, destruction, unauthorised access, alteration, or disclosure. These measures may include access controls, encryption where appropriate, secure storage, staff confidentiality obligations, backup procedures, and regular review of data handling practices. While no system can be guaranteed to be completely secure, we take reasonable steps to reduce risks and maintain the integrity and confidentiality of personal data.
8. User Rights Under GDPR
Individuals whose personal data we process have certain rights under GDPR. Subject to legal limitations, these rights include:
- Right of access: to obtain confirmation of whether personal data is being processed and to receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request that processing be limited in certain cases.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and to request transmission to another controller where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to withdraw consent: to withdraw consent at any time where processing is based on consent.
- Right not to be subject to automated decision-making: to not be subject to decisions based solely on automated processing that produce legal or similarly significant effects, except where permitted by law.
Requests relating to these rights will be handled in accordance with applicable law. We may need to verify identity before responding to a request in order to protect personal data from unauthorised disclosure.
9. Children’s Data
Our services are not directed at children unless expressly stated otherwise. Where we become aware that personal data of a child has been collected without appropriate authority or lawful basis, we will take steps to address the situation in line with applicable legal requirements.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or the types of personal data we process. Any revised version will apply from the date it takes effect. We encourage individuals to review this policy periodically so they remain informed about how personal data is handled.
11. Final Statement
This Privacy Policy applies to all customers in the area and is intended to ensure that personal data is processed lawfully, transparently, and securely. By using our services, individuals acknowledge that their personal data may be processed as described in this policy, subject always to applicable legal rights and protections.
We respect privacy and are committed to maintaining compliance with GDPR principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability.
Nothing in this policy limits any rights provided by applicable data protection law.
