Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with our services. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR). We are committed to handling personal data fairly, lawfully, and transparently.
1. Scope of this Policy
This Policy applies to personal data collected from customers, prospective customers, and any individual who interacts with our services in the area. It covers data processing carried out in connection with service delivery, administration, support, billing, record-keeping, security, and legal compliance.
By using our services or otherwise providing personal data, you acknowledge that your information may be processed as described in this Policy.
2. Data We Collect
We may collect and process the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, telephone number, and other communication details.
- Account and transaction data: service history, billing records, payment status, and related administrative information.
- Technical data: device type, browser type, IP address, log data, and basic usage information.
- Communication data: messages, enquiries, complaints, feedback, and records of correspondence.
- Preference data: service preferences, consents, and marketing choices where applicable.
We do not intentionally collect more personal data than is necessary for the purposes described in this Policy. Where appropriate, we may also collect limited data from third parties, such as service providers, payment processors, or publicly available sources, if this is lawful and relevant.
3. How We Use Personal Data
We use personal data for the following purposes:
- to provide, manage, and improve our services;
- to process transactions and maintain records;
- to communicate with customers about services, updates, and administrative matters;
- to respond to questions, requests, complaints, and support needs;
- to detect, prevent, and investigate fraud, misuse, or security incidents;
- to comply with legal and regulatory obligations;
- to establish, exercise, or defend legal claims;
- to carry out internal reporting, analysis, and business administration.
We only use personal data for legitimate and specific purposes. If we need to use data for a new purpose that is incompatible with the original purpose, we will take steps to ensure this is permitted by law and appropriately communicated.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. Depending on the circumstances, we rely on one or more of the following bases:
4.1 Contract
We process personal data where it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract. This may include managing your account, delivering services, and handling payment or service-related administration.
4.2 Legal Obligation
We may process personal data where required to comply with applicable laws, regulations, tax obligations, accounting requirements, or lawful requests from public authorities.
4.3 Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Examples include maintaining service security, preventing fraud, improving services, and managing internal operations.
4.4 Consent
Where required by law, we rely on your consent. If consent is the legal basis, you may withdraw it at any time. Withdrawal will not affect processing that took place before the withdrawal.
5. Data Sharing and Processors
We may share personal data with trusted third parties that act as processors on our behalf. These processors are permitted to process personal data only according to our instructions and are required to protect it appropriately.
Examples of processors may include:
- IT hosting and infrastructure providers;
- customer support and communication tools;
- billing, payment, and accounting service providers;
- data storage, backup, and security providers;
- analytics or reporting service providers used for operational purposes.
We may also disclose personal data to independent controllers where necessary, for example to legal, regulatory, or professional advisers, or where disclosure is required by law. In such cases, the recipient will determine its own purposes and means of processing, and will be responsible for its own compliance obligations.
We do not sell personal data.
6. International Transfers
If personal data is transferred outside the European Economic Area or the United Kingdom, we will ensure that appropriate safeguards are in place, such as adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms. Where required, additional technical or organisational measures will be used to protect personal data.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, reporting, and dispute resolution requirements. The retention period may vary depending on the type of data and the purpose of processing.
- Contract and service records are generally kept for the duration of the relationship and for a period afterward as required for administration or legal claims.
- Financial and tax records are kept for the period required by applicable law.
- Communication records may be retained for a reasonable time to support service management, quality control, and complaint handling.
- Technical logs are generally kept for a limited period unless needed longer for security or investigation purposes.
When data is no longer required, it will be securely deleted, anonymised, or otherwise rendered unusable, subject to any mandatory retention duties.
8. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, encryption where appropriate, security monitoring, staff confidentiality duties, and procedures for incident response.
Although no system can be guaranteed to be completely secure, we take reasonable steps to reduce risk and to protect the confidentiality of personal data.
9. Your Rights Under GDPR
Subject to legal conditions and exceptions, individuals have the following rights regarding their personal data:
- Right of access: to obtain confirmation of whether we process your data and receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limited processing in certain situations.
- Right to data portability: to receive data you provided in a structured, commonly used format and, where technically feasible, have it transferred to another controller.
- Right to object: to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time.
- Right to complain: to lodge a complaint with a supervisory authority if you believe your rights have been infringed.
Where we receive a request, we may need to verify identity before responding. We aim to respond without undue delay and within the time limits set by GDPR.
10. Automated Decision-Making
We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects unless such processing is permitted by law and appropriate safeguards are in place. If this changes, we will provide relevant information about the logic involved and the significance and consequences of the processing.
11. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate legal basis and, where required, verifiable parental consent. If we become aware that data has been collected improperly, we will take appropriate steps to delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or technical changes. The updated version will apply from the date it becomes effective. We encourage customers to review the Policy periodically to stay informed about how personal data is protected and processed.
13. Final Statement
This Privacy Policy is intended to provide transparent information about how we handle personal data in compliance with GDPR. It applies to all customers in the area and reflects our commitment to privacy, accountability, and data protection. By continuing to use our services, you acknowledge that your personal data may be processed in accordance with this Policy and applicable law.
