Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when customers use our services. It applies to all customers in the area and is intended to reflect the principles of the General Data Protection Regulation (GDPR). We are committed to processing personal data fairly, transparently, and securely, and to respecting the rights of individuals whose data we process.
1. Who This Policy Applies To
This Policy applies to all individuals in the area who interact with our services as customers, prospective customers, account holders, or users of related features. It also applies where we process personal data on behalf of a customer relationship, including communications, transactions, and service delivery. Where local law provides additional rights or protections, those requirements will also be followed.
2. Data We Collect
We may collect and process different categories of personal data depending on how you use our services. The types of data may include:
- Identity data such as name, title, and similar identifiers.
- Contact data such as address and email-related details used for service administration.
- Transaction data relating to purchases, service requests, payments, or records of interaction.
- Technical data such as device type, browser information, and general usage information.
- Communication data including messages, feedback, complaints, and support requests.
- Preference data that helps us understand service settings or customer choices.
We only collect personal data that is relevant and necessary for the purposes described in this Policy. Where possible, we limit collection to what is adequate, relevant, and not excessive.
3. How We Use Personal Data
We process personal data for purposes that are lawful, specific, and proportionate. These purposes may include:
- providing and maintaining services;
- managing customer accounts and records;
- responding to inquiries and support requests;
- processing transactions and fulfilling obligations;
- improving service quality and user experience;
- ensuring security, preventing fraud, and investigating misuse;
- meeting legal, accounting, or regulatory requirements.
We will not use personal data in ways that are incompatible with the original purpose unless we have a valid legal basis and, where required, informed notice.
4. Lawful Basis for Processing
Under GDPR, personal data must have a lawful basis before it is processed. Depending on the context, we may rely on one or more of the following lawful bases:
Performance of a Contract
We process data where it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
Legal Obligation
We may process personal data to comply with legal and regulatory duties, including recordkeeping, tax, accounting, or disclosure obligations.
Legitimate Interests
We may process data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. This may include service improvement, fraud prevention, network security, or administrative functions.
Consent
Where required, we may rely on your consent. If consent is used as the lawful basis, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Vital Interests and Public Interest
In limited situations, we may process personal data to protect vital interests or where processing is necessary for a task carried out in the public interest or under official authority.
5. Retention of Personal Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, reporting, or dispute-resolution requirements. Retention periods may vary depending on the type of data, the nature of the relationship, and applicable legal obligations.
When determining how long to keep personal data, we consider:
- the purpose of the processing;
- the sensitivity of the data;
- the risk of harm from unauthorised use or disclosure;
- legal limitation periods;
- regulatory retention requirements.
Once data is no longer needed, it is securely deleted, anonymised, or otherwise disposed of in accordance with our retention procedures.
6. Processors and Third Parties
We may engage third-party processors to help us operate, maintain, and improve services. These processors act on our instructions and are required to protect personal data through appropriate technical and organisational measures. Typical processors may provide services such as hosting, analytics, customer support systems, payment processing, document storage, and IT maintenance.
Where a third party acts as an independent controller rather than a processor, they are responsible for their own compliance. We only share personal data when necessary, lawful, and proportionate to the relevant purpose.
Any processor we use is selected with due diligence and is required to implement confidentiality, security, and data protection safeguards. We seek written agreements that reflect GDPR requirements, including limitations on processing, support for data subject rights, and breach notification obligations where appropriate.
7. International Transfers
If personal data is transferred outside the European Economic Area or another jurisdiction with equivalent protections, we take steps to ensure an adequate level of protection. This may include reliance on approved transfer mechanisms, contractual safeguards, or adequacy decisions where applicable. We aim to ensure that the rights of individuals remain protected regardless of where the data is processed.
8. Security Measures
We use reasonable technical and organisational measures to protect personal data against accidental loss, unlawful destruction, unauthorised access, alteration, or disclosure. These measures may include access controls, encryption where appropriate, network security protections, staff confidentiality obligations, and data minimisation practices. While no system can be guaranteed to be completely secure, we continually review our practices to reduce risk and maintain appropriate safeguards.
9. Your Rights Under GDPR
Individuals whose personal data we process have rights under GDPR. Subject to legal limits and verification requirements, these rights may include:
- Right of access – to obtain confirmation and a copy of the personal data we hold about you.
- Right to rectification – to request correction of inaccurate or incomplete data.
- Right to erasure – to request deletion of personal data in certain circumstances.
- Right to restriction – to ask us to limit processing in certain cases.
- Right to data portability – to receive certain data in a structured, commonly used, machine-readable format and to transmit it where applicable.
- Right to object – to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.
- Rights related to automated decision-making – to not be subject to decisions based solely on automated processing where legally applicable.
To protect privacy, we may need to verify your identity before responding to a rights request. We will respond within the time limits required by law and will explain if any request cannot be fully fulfilled due to legal exceptions.
10. Children’s Data
Our services are not intended for children unless explicitly stated otherwise. We do not knowingly collect personal data from children where this would not be lawful. If we become aware that we have collected personal data from a child without proper authorisation, we will take appropriate steps to remove it or obtain the necessary permission, as applicable.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or technical changes. When updates are made, the revised version will apply from the effective date stated in the updated policy. We encourage customers to review this Policy periodically so they remain informed about how personal data is processed.
12. General Principles
We follow the core principles of GDPR, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability. These principles guide how we collect and use data, how long we keep it, and how we manage risks associated with processing.
By using our services, customers acknowledge that personal data may be processed in accordance with this Policy and applicable data protection law. Nothing in this Policy limits rights granted by GDPR or any local law that applies in the area.
