Privacy Policy -
Scope and applicability
This Privacy Policy explains how personal data is collected, used, disclosed, retained and protected by us. This policy applies to all customers in the area where we operate and to any individual whose personal data is processed in relation to products, services, purchases, support or other business interactions. The policy is intended to meet the requirements of the General Data Protection Regulation (GDPR) and related national data protection laws.
1. Data we collect
We collect personal data necessary to provide and improve our services. Categories of personal data we process include:
- Identity and contact data: name, postal address, email address, telephone number.
- Account and transaction data: user IDs, order history, payment records, invoices.
- Technical data: IP address, device identifiers, browser type, operating system, log files.
- Communications data: correspondence, support tickets, feedback and queries.
- Usage data: interaction with services and products, analytics and behavioral information.
- Sensitive data (only if voluntarily provided): limited special categories of data where you explicitly supply it for a specific purpose, processed only with your explicit consent or where strictly necessary and lawful.
2. Lawful basis for processing
Under the GDPR, we rely on one or more lawful bases depending on the processing activity. The principal lawful bases we use are:
- Contract: processing necessary to perform a contract with you, to deliver products, provide services, process payments and manage accounts.
- Consent: where you have given clear consent to the processing of your personal data for specific purposes, such as marketing communications or optional features.
- Legal obligation: processing necessary to comply with applicable laws, tax or regulatory requirements.
- Legitimate interests: processing necessary for our legitimate business interests, such as fraud prevention, network and information security, business administration, and direct marketing, where such interests are not overridden by your rights and freedoms.
How we determine the lawful basis
For each processing activity we document the lawful basis and ensure that it is appropriate, balancing our interests against your rights. When relying on consent you have the right to withdraw consent at any time without affecting prior processing.
3. Purposes of processing and use of data
We use personal data for the following purposes:
- To deliver products and services, manage accounts and handle transactions.
- To communicate with customers about orders, support requests, updates and important notices.
- To verify identity, prevent fraud and assure safety and security of systems.
- To analyze usage patterns, improve products and develop new features.
- To send marketing communications where you have consented or where permitted under legitimate interests; you may opt out at any time.
- To comply with legal obligations and respond to lawful requests by public authorities.
4. Data retention
Retention principles: We retain personal data only as long as necessary for the purposes described in this policy and to meet legal, regulatory and operational requirements. Retention periods are based on the nature of the data, the purpose of processing and applicable retention obligations.
- Account and transactional data: retained for the duration of the customer relationship and, thereafter, for up to seven years where necessary for tax, accounting, legal claims and compliance.
- Support and communications records: retained for up to three years after the last interaction, unless a longer period is required to resolve disputes or comply with law.
- Marketing data: retained until consent is withdrawn or until you opt out; anonymized data may be kept for analytics.
- Analytics and aggregated data: retained in aggregated or anonymized form indefinitely for reporting and improvement purposes.
5. Processors and third-party recipients
We share personal data with carefully selected service providers and partners (processors) to deliver services. Categories of processors include:
- Payment and billing processors;
- Cloud hosting and infrastructure providers;
- Email, customer support and communication platforms;
- Analytics and research providers;
- Legal, audit and professional advisors where required.
Data Processing Agreements: We enter into written contracts with all processors that require appropriate technical and organizational measures to protect data and to process data only on our documented instructions. We do not authorize processors to use personal data for their own purposes.
International transfers
Where personal data is transferred outside the European Economic Area, we implement appropriate safeguards such as Standard Contractual Clauses, binding corporate rules or rely on an adequacy decision by the European Commission. Transfers are limited to the minimum necessary and documented.
6. Security measures
We implement technical and organizational measures to protect personal data against unauthorized access, loss, alteration or disclosure. Measures include encryption, access controls, pseudonymization where feasible, regular security assessments and staff training.
7. Your rights
Under the GDPR, you have the following rights, subject to applicable conditions and limitations:
- Right of access: obtain confirmation whether we process your personal data and request a copy of that data.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data where processing is no longer necessary or lawful.
- Right to restriction of processing: request limitation of processing while a dispute is resolved.
- Right to data portability: receive personal data you provided in a structured, machine-readable format and transmit it to another controller.
- Right to object: object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: withdraw consent at any time for consent-based processing without affecting the lawfulness of prior processing.
- Right to lodge a complaint: with a supervisory authority if you believe your rights have been infringed.
Exercising your rights
To exercise any of the rights above, please use the communication channels we provide in transactional communications or in your account interfaces. We will verify your identity before responding and will respond without undue delay and in accordance with applicable law. Where requests are manifestly unfounded or excessive, we may charge a reasonable fee or refuse to act.
8. Changes to this policy
We may update this policy from time to time to reflect changes in processing practices or legal requirements. Material changes will be highlighted in our communications. Continued use of our services after changes are posted constitutes acceptance of the updated policy.
9. Additional information
Data minimization and accuracy: We limit the collection of personal data to what is necessary and take reasonable steps to ensure data accuracy. Children: Our services are not directed to minors; we do not knowingly collect personal data from children under applicable age limits.
Accountability: We maintain records of processing activities and undertake periodic reviews of our privacy program to ensure ongoing compliance with GDPR principles. We will cooperate with supervisory authorities and affected individuals to address privacy concerns in a timely manner.
This Privacy Policy applies to all customers in the area and to any individuals whose personal data we process in connection with our goods and services.
Effective date: the date on which this policy is published or otherwise communicated to you.
