Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in connection with the services provided to all customers in the area. It applies to all individuals who interact with the relevant products, services, or operations covered by this policy. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
1. Scope of This Policy
This policy applies to personal data processed about customers, prospective customers, users, and other individuals in the area where the services are made available. It covers data collected through direct interaction, automated means, and third parties where permitted by law. By using the services or otherwise engaging with them, individuals acknowledge that their personal data may be processed as described in this policy.
This policy does not apply to anonymous information that cannot identify an individual, although such information may still be used for statistical and operational purposes.
2. Personal Data We Collect
We may collect and process different categories of personal data depending on how a person interacts with the services. The types of data may include:
- Identity information: name, title, username, or similar identifiers.
- Contact information: address, email address, telephone number, and related communication details.
- Account information: account identifiers, preferences, and records of settings or selections.
- Transaction data: details of purchases, orders, payments, billing records, and delivery-related information.
- Technical data: IP address, browser type, device identifiers, operating system, and access logs.
- Usage data: information about how services are accessed and used, including interaction patterns.
- Communication data: correspondence, complaints, feedback, and support requests.
- Marketing preferences: choices regarding communications and promotional materials.
We do not intentionally collect special category data unless this is necessary and lawful. Where such data is processed, additional safeguards will be applied as required by law.
3. How We Collect Personal Data
Personal data may be collected directly from individuals, automatically through technical systems, or from third parties. Collection methods may include:
- information provided when registering for or using services;
- records created when transactions are completed;
- data captured through cookies or similar technologies, where permitted;
- communications sent to support or administrative teams;
- information obtained from service providers, business partners, or public sources where lawful.
Only the data necessary for specific, legitimate purposes is collected.
4. Lawful Basis for Processing
We will only process personal data when we have a lawful basis under GDPR. Depending on the circumstances, the lawful basis may be one or more of the following:
- Performance of a contract: processing is necessary to provide services, manage accounts, or fulfill orders.
- Legal obligation: processing is necessary to comply with laws, regulations, tax requirements, accounting duties, or lawful requests from authorities.
- Legitimate interests: processing is necessary for legitimate business purposes such as improving services, maintaining security, preventing fraud, and managing operations, provided those interests are not overridden by individual rights and freedoms.
- Consent: processing may rely on consent where required, such as for certain marketing activities or optional cookies. Consent can be withdrawn at any time where applicable.
- Vital interests: in rare cases, processing may be necessary to protect someone’s life or physical safety.
- Public task or official authority: where applicable under law, processing may be necessary for tasks carried out in the public interest or under official authority.
The lawful basis used for a particular processing activity depends on the purpose and context of that activity.
5. Purposes of Processing
Personal data may be used for the following purposes:
- providing and maintaining services;
- processing transactions and delivering products or services;
- managing customer accounts and service records;
- communicating about service updates, notices, and administrative matters;
- responding to enquiries, complaints, and support requests;
- monitoring and improving service performance and user experience;
- protecting against fraud, unauthorized access, and misuse;
- meeting legal, tax, regulatory, and compliance obligations;
- carrying out internal reporting, analysis, and planning;
- sending marketing communications where legally permitted and, where required, with consent.
We will not process personal data in a manner that is incompatible with the purposes for which it was collected.
6. Sharing and Processors
Personal data may be shared with trusted third parties who act as processors or, in some cases, independent controllers. Processors only process personal data on documented instructions and are bound by confidentiality, security, and data protection obligations. Examples of processors may include:
- IT and hosting providers;
- payment service providers;
- customer support and communication platforms;
- analytics and system monitoring providers;
- document storage and backup providers;
- professional advisers acting on our behalf.
Where personal data is shared with independent controllers, they are responsible for their own compliance with data protection law. We may also disclose data where required by law, court order, or lawful request from public authorities.
All processors are selected carefully and are expected to implement appropriate technical and organizational measures to protect personal data.
7. International Transfers
If personal data is transferred outside the United Kingdom or the European Economic Area, we will ensure that appropriate safeguards are in place. These may include adequacy regulations, standard contractual clauses, or other legally recognized transfer mechanisms. Additional assessments may be carried out where necessary to ensure a level of protection essentially equivalent to that required by GDPR.
8. Data Retention
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, reporting, or operational requirements. Retention periods vary depending on the type of data and the reason for processing.
- Account and transaction records may be kept for the duration of the customer relationship and for a further period required by law or for dispute handling.
- Support and communication records may be retained for a reasonable period to manage queries and improve services.
- Technical logs may be retained for security, troubleshooting, and system integrity purposes.
- Marketing data will be retained until consent is withdrawn or an objection is made, where relevant.
When data is no longer needed, it will be securely deleted, anonymized, or archived in a form that prevents identification where appropriate.
9. Security of Personal Data
We take appropriate technical and organizational measures to protect personal data against accidental loss, destruction, unauthorized access, disclosure, alteration, or misuse. These measures may include access controls, encryption, monitoring, secure storage, and staff confidentiality obligations. No system is completely secure, but we work to reduce risks and respond promptly to potential incidents.
10. User Rights Under GDPR
Individuals whose personal data is processed under this policy have rights under GDPR, subject to legal limitations and exemptions. These rights include:
- Right of access: to obtain confirmation of whether personal data is processed and to receive a copy of that data.
- Right to rectification: to request correction of inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request that processing be limited in certain situations.
- Right to data portability: to receive personal data in a structured, commonly used, machine-readable format and, where applicable, to have it transferred to another controller.
- Right to object: to object to processing based on legitimate interests or to direct marketing at any time.
- Right to withdraw consent: where processing relies on consent, consent may be withdrawn without affecting the lawfulness of prior processing.
- Right to lodge a complaint: to raise concerns with the relevant data protection authority if an individual believes their rights have been infringed.
Requests to exercise these rights will be handled in accordance with applicable law and within the required time limits.
11. Automated Decision-Making
We do not ordinarily make decisions based solely on automated processing that produce legal or similarly significant effects. If this changes, appropriate information and safeguards will be provided as required by law, including the right to request human review where applicable.
12. Children’s Data
The services are not intended for children unless clearly stated otherwise. We do not knowingly collect personal data from children without appropriate legal basis and, where necessary, verifiable parental or guardian consent.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or service-related changes. Any updated version will apply from the date it takes effect. Individuals are encouraged to review this policy periodically to remain informed about how personal data is handled.
Final Statement
This Privacy Policy applies to all customers in the area and is intended to ensure transparent, lawful, and secure handling of personal data. We are committed to respecting privacy rights and maintaining compliance with GDPR principles, including lawfulness, fairness, transparency, data minimization, accuracy, storage limitation, integrity, and confidentiality.
