Privacy Policy -
This Privacy Policy explains how we collect, use, disclose and protect personal data in compliance with the EU General Data Protection Regulation (GDPR). This policy applies to all customers in the area. It describes the types of personal data we process, the lawful bases for processing, retention periods, the role of processors, and the rights available to data subjects.
1. Scope and Objectives
This Privacy Policy applies to the processing of personal data relating to individuals who interact with our services, including prospective, current and former customers. Our objective is to be transparent about how personal data is handled and to ensure that processing is lawful, fair and transparent.
2. Data We Collect
We collect personal data necessary to perform our services and to meet legal and contractual obligations. Data collected may include:
- Identity Data: names, dates of birth, identification or customer numbers.
- Contact Data: email addresses, postal addresses, phone numbers.
- Transactional Data: payment and billing information, order history, invoices.
- Technical Data: IP addresses, device identifiers, browser type and version, operating system and other diagnostic data.
- Usage Data: information about how you use our services, pages visited, features accessed and session logs.
- Marketing and Communication Data: preferences, consents, and communications history.
- Sensitive Data (special categories): only where strictly necessary and with explicit consent or other lawful basis, such as health information required for service provision.
Sources
- Directly from you when you provide information to register, place orders, subscribe to communications or contact support.
- From third parties such as payment processors, service integrators, public registers and partners when relevant and lawful.
- Automatically through technology when you interact with our services (cookies, analytics and other tracking technologies).
3. Lawful Basis for Processing
We rely on one or more of the following lawful bases to process personal data under the GDPR:
- Contractual necessity: processing is necessary to perform a contract with you or take steps at your request prior to entering into a contract.
- Legal obligation: processing is required to comply with legal or regulatory obligations imposed on us.
- Consent: where you have given explicit consent for specific processing activities (e.g., direct marketing or processing special category data). You may withdraw consent at any time.
- Legitimate interests: for purposes such as fraud prevention, network and information security, direct marketing (where applicable), and improving services, provided such interests are not overridden by your rights and freedoms.
- Vital interests: where processing is necessary to protect someone’s life in emergency situations.
4. Purpose of Processing
We process personal data for the following purposes:
- To deliver and manage products and services, fulfill orders, and provide customer support.
- To process payments, prevent fraud and improve transactional security.
- To comply with legal and regulatory obligations, including tax and accounting requirements.
- To send administrative communications and service-related notices.
- To personalize and improve user experience, perform analytics and measure service performance.
- To conduct marketing and promotional activities, where lawful and consented to.
5. Data Retention
Retention principles: We retain personal data only for as long as needed to fulfill the purposes described in this policy, to satisfy legal or regulatory obligations, resolve disputes, enforce agreements and prevent fraud. Retention periods vary by data type, contractual requirements and applicable law.
- Transactional and accounting records: retained in accordance with statutory requirements but no longer than necessary.
- Account and identity data: retained while the account is active and for a period thereafter to meet legal or legitimate business needs.
- Marketing data: retained until consent is withdrawn or you opt out.
- Technical and analytics data: retention is limited and often anonymized for long-term analytical use.
6. Processors and Third Parties
We use third-party service providers (processors) to perform functions on our behalf. These processors may include payment processors, cloud hosting providers, analytics and email delivery services. We take steps to ensure processors implement appropriate technical and organizational measures and operate under written contracts that require GDPR-compliant handling of personal data.
- Processors act only on our documented instructions and are subject to confidentiality obligations.
- We may share data with third parties when required by law or to protect vital interests.
- Where data is transferred outside the European Economic Area, we ensure transfers are made with appropriate safeguards such as EU Standard Contractual Clauses or other approved mechanisms.
7. Security Measures
We implement technical and organizational measures to protect personal data against unauthorized access, loss, alteration or disclosure. Measures include access controls, encryption, secure development practices, regular security assessments and incident response procedures. However, no system is completely secure; we recommend taking reasonable precautions to protect your personal devices and credentials.
8. Your Rights
Under the GDPR, data subjects have specific rights. To exercise these rights, you may submit a request following the procedures available where you engage with us. The rights include:
- Right of access: obtain confirmation of processing and a copy of the personal data we hold.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure (right to be forgotten): request deletion where there is no overriding legal reason to retain the data.
- Right to restriction: request limitation of processing in certain circumstances.
- Right to data portability: receive personal data in a structured, commonly used and machine-readable format and transmit it to another controller where technically feasible.
- Right to object: object to processing based on legitimate interests or direct marketing; we will stop processing unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent: withdraw consent to processing where consent is the lawful basis, without affecting prior processing.
- Right to lodge a complaint: file a complaint with a supervisory authority if you believe your data protection rights have been violated.
Note: We will respond to valid requests within statutory timeframes and may require verification of identity to protect your data.
9. Automated Decision-Making and Profiling
We may use automated systems for legitimate operational purposes such as fraud detection and service personalization. If automated decision-making produces legal effects or similarly significantly affects you, we will provide additional information and, where required, obtain your explicit consent and offer human review where applicable.
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Major changes will be communicated where required by law. Continued use of our services after changes indicates acceptance of the updated policy.
Final Note
Commitment: We are committed to protecting personal data and to complying with applicable data protection laws. If you have any questions about this policy or wish to exercise your rights, please follow the procedures provided when you interact with our services.
