Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, shared, and protected when customers use our services. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using our services, customers acknowledge that their personal data may be processed in accordance with this policy.
1. Data We Collect
We collect only the personal data that is necessary for the purposes described in this policy. Depending on the nature of the relationship, the information we may collect includes:
- Identity data: name, title, username, and similar identifiers.
- Contact data: billing address, delivery address, email address, and telephone number.
- Transaction data: details about payments, purchases, orders, and services received.
- Technical data: IP address, device information, browser type, operating system, and usage logs.
- Profile data: preferences, interests, feedback, and service history.
- Communication data: records of correspondence and service-related enquiries.
We may also collect information from third parties where permitted by law, such as payment processors, delivery providers, analytics providers, or other service partners. We do not intentionally collect special category data unless it is required for a lawful purpose and appropriate safeguards are in place.
2. How We Use Personal Data
Personal data is processed for specific and legitimate purposes. We use the data to:
- provide, manage, and deliver our services;
- process orders, payments, refunds, and related administration;
- communicate service updates, confirmations, and notices;
- maintain records and improve service quality;
- ensure security, prevent fraud, and detect misuse;
- comply with legal, regulatory, and accounting obligations;
- respond to complaints, disputes, and support requests;
- analyse performance and improve user experience.
We will not process personal data in a way that is incompatible with the purposes for which it was collected unless we have a valid lawful basis to do so and we have informed customers where required.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing personal data. Depending on the situation, we rely on one or more of the following bases:
Performance of a Contract
We process personal data when it is necessary to enter into or perform a contract with a customer, including supplying requested services, managing accounts, and completing transactions.
Legal Obligation
We may process personal data where necessary to comply with legal requirements, including tax, accounting, consumer protection, anti-fraud, and regulatory obligations.
Legitimate Interests
We may process data where it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the customer’s rights and freedoms. This may include service improvement, security monitoring, fraud prevention, and internal administration.
Consent
Where required, we will rely on consent. When processing is based on consent, customers may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn.
Vital Interests and Public Interest
In limited cases, we may process personal data to protect someone’s vital interests or where processing is necessary for a task carried out in the public interest or under official authority.
4. Data Retention
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting requirements. Retention periods depend on the type of data, the purpose of processing, and any legal obligations that apply.
In general:
- customer and transaction records are kept for the period required by applicable law;
- support and communication records are retained only as long as needed to resolve issues and maintain service history;
- technical and usage data are retained for a shorter period, unless needed for security, troubleshooting, or legal reasons;
- data collected based on consent is retained until consent is withdrawn or the data is no longer necessary.
When personal data is no longer required, it will be securely deleted, anonymised, or archived in accordance with our retention practices. We aim to keep retention periods proportionate and limited to what is necessary.
5. Data Sharing and Processors
We may share personal data with trusted third parties who act as processors or, in some cases, independent controllers. Processors only handle data on our instructions and must protect it with appropriate technical and organisational measures. Typical processors may include:
- Payment service providers for payment processing and fraud screening;
- IT and cloud hosting providers for data storage, system maintenance, and security;
- Customer support tools for managing enquiries and service requests;
- Analytics providers for service performance and usage analysis;
- Professional advisers such as accountants, auditors, and legal advisers where required;
- Delivery and logistics partners where services require fulfilment or transport.
We require processors to process personal data only in accordance with our instructions and to keep it secure and confidential. Where personal data is transferred outside the European Economic Area or the UK, we will ensure appropriate safeguards are in place, such as an adequacy decision, standard contractual clauses, or another lawful transfer mechanism permitted by GDPR.
6. Security of Personal Data
We use reasonable and appropriate security measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and regular review of security practices. While no system can be guaranteed to be completely secure, we work to reduce risks and respond promptly to any suspected incident.
7. Data Subject Rights
Customers have rights over their personal data under GDPR. Subject to applicable legal limits, these rights include:
- Right of access: the right to request confirmation of whether we process personal data and to receive a copy of that data.
- Right to rectification: the right to request correction of inaccurate or incomplete data.
- Right to erasure: the right to request deletion of personal data in certain circumstances.
- Right to restriction: the right to request limited processing in certain situations.
- Right to data portability: the right to receive data in a structured, commonly used, machine-readable format, where applicable.
- Right to object: the right to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, the right to withdraw it at any time.
- Right related to automated decision-making: the right not to be subject to decisions based solely on automated processing in certain circumstances.
Customers may also have the right to lodge a complaint with a relevant data protection authority if they believe their rights have been infringed. We encourage individuals to raise concerns so they can be reviewed and addressed appropriately.
8. Children’s Data
Our services are not intended for children unless stated otherwise. We do not knowingly collect personal data from children without the required legal basis or parental authorisation where applicable. If we become aware that we have collected personal data from a child inappropriately, we will take steps to delete it or obtain the necessary permissions.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service arrangements. Any updated version will apply from the date it is made effective. Customers should review this policy periodically to stay informed about how personal data is processed.
10. Scope and Application
This Privacy Policy applies to all customers in the area and to personal data processed in connection with the services we provide. It governs how we handle data throughout the full customer relationship, from initial enquiry through service delivery, support, recordkeeping, and lawful retention. By continuing to use our services, customers confirm that they understand this policy and the ways in which personal data may be processed.
This policy is intended to be clear, fair, and consistent with GDPR principles, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability.
