Privacy Policy
This Privacy Policy explains how personal data is collected, used, shared, stored, and protected in connection with our services. It applies to all customers in the area and is intended to meet the requirements of the General Data Protection Regulation (GDPR). We are committed to processing personal data lawfully, fairly, and transparently, and to respecting the rights of individuals whose data we handle.
1. Scope of this Policy
This Policy applies to personal data collected from customers, prospective customers, service users, and others who interact with us in the area covered by this Policy. It covers data collected through direct interactions, service use, account creation, communications, and any other relevant business activities. By using our services or providing personal data, individuals acknowledge that their information may be processed in accordance with this Policy and applicable data protection law.
2. Personal Data We Collect
We may collect and process different categories of personal data depending on the nature of the relationship and services provided. This may include:
- Identity data such as name, title, date of birth, or similar identifiers.
- Contact data such as postal address, email address, and telephone number.
- Transaction data such as records of purchases, payments, invoices, and service history.
- Technical data such as IP address, device information, browser type, and system logs.
- Usage data such as information about how services are accessed and used.
- Communication data such as records of enquiries, complaints, and support requests.
- Preference data such as marketing choices and service preferences.
We do not intentionally collect special category data unless it is necessary and a valid legal condition applies. Where such data is processed, we take additional safeguards and only do so when lawful and appropriate.
3. How We Collect Personal Data
Personal data may be collected directly from individuals when they register, place an order, request information, submit forms, or communicate with us. We may also collect data automatically through technical systems when services are used. In some cases, we may receive data from third parties such as payment providers, delivery partners, fraud prevention services, or publicly available sources where permitted by law.
4. Purposes of Processing
We process personal data only for specified, explicit, and legitimate purposes. These may include:
- Providing and managing our services.
- Processing transactions and fulfilling requests.
- Maintaining customer accounts and records.
- Responding to enquiries and providing support.
- Improving service quality, performance, and security.
- Detecting, investigating, and preventing fraud or misuse.
- Complying with legal, regulatory, and accounting obligations.
- Sending direct marketing where permitted and where consent or another lawful basis applies.
We will not process personal data in ways that are incompatible with these purposes unless we have a valid legal basis to do so.
5. Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process personal data. Depending on the context, we rely on one or more of the following bases:
- Contract: Processing is necessary to enter into or perform a contract with the individual, or to take steps at the individual’s request before entering into a contract.
- Legal obligation: Processing is necessary to comply with a legal or regulatory requirement.
- Legitimate interests: Processing is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by the individual’s rights and freedoms. This may include fraud prevention, service improvement, and internal administration.
- Consent: Processing is based on the individual’s clear and informed consent, such as for certain marketing activities or optional data uses. Consent may be withdrawn at any time.
- Vital interests: In rare cases, processing may be necessary to protect someone’s life.
- Public task: Where applicable, processing may be necessary for a task carried out in the public interest.
When we rely on legitimate interests, we assess the impact on individuals and ensure that appropriate safeguards are in place. Where consent is used, it will be obtained in a way that is specific, informed, and freely given.
6. Data Sharing and Processors
We may share personal data with trusted third parties where necessary for the purposes described in this Policy. These parties may act as data processors or, in some cases, as independent controllers. Processors are only permitted to process personal data on our documented instructions and must implement appropriate technical and organisational security measures.
Examples of processors may include:
- IT hosting and infrastructure providers.
- Payment processing services.
- Customer support and communication tools.
- Analytics and performance monitoring services.
- Archiving, backup, and document management providers.
We may also disclose personal data where required by law, to respond to lawful requests by authorities, or to protect rights, property, safety, or security. Where personal data is transferred outside the European Economic Area, we ensure that an appropriate transfer mechanism is in place, such as an adequacy decision, standard contractual clauses, or another lawful safeguard.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, tax, and reporting obligations. Retention periods vary depending on the type of data and the context of processing. For example, transactional and financial records may need to be retained for a longer period than general enquiry data.
When personal data is no longer required, it is securely deleted, anonymised, or archived in accordance with our retention practices. If deletion is not immediately possible for technical or legal reasons, we will restrict the data so that it is only processed for those limited purposes.
8. Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, unlawful processing, alteration, and disclosure. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and regular review of security practices. While no system is completely secure, we take reasonable steps to reduce risk and to protect personal data throughout its lifecycle.
9. Your Rights Under GDPR
Individuals whose personal data we process have a number of rights under GDPR, subject to certain conditions and exemptions. These rights include:
- Right of access: To obtain confirmation of whether we process personal data and to receive a copy of that data.
- Right to rectification: To request correction of inaccurate or incomplete personal data.
- Right to erasure: To request deletion of personal data in certain circumstances.
- Right to restriction: To request that processing be restricted in certain circumstances.
- Right to data portability: To receive personal data in a structured, commonly used, machine-readable format and to transmit it to another controller where applicable.
- Right to object: To object to processing based on legitimate interests or to direct marketing at any time.
- Right not to be subject to automated decision-making: To not be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects, unless permitted by law.
- Right to withdraw consent: Where processing is based on consent, to withdraw that consent at any time without affecting prior processing.
Requests relating to these rights will be handled in accordance with GDPR timeframes and legal requirements. We may need to verify identity before fulfilling a request. Some rights may not apply in all situations, and we may be entitled or required by law to retain or continue processing certain information.
10. Marketing Preferences
Where we send marketing communications, individuals may object at any time or withdraw consent where consent is the lawful basis. When a marketing preference is changed, we will update our records accordingly. We will not use personal data for marketing in a way that disregards an individual’s legal rights or stated preferences.
11. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate authorisation or lawful basis. If we become aware that personal data has been collected from a child inappropriately, we will take steps to delete or protect that data in line with applicable law.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Any revised version will apply from the date it is published or otherwise communicated. Individuals are encouraged to review this Policy periodically to remain informed about how personal data is handled.
Summary of Key Principles
- Transparency: We explain what data we collect and why.
- Lawfulness: We process data only where a valid lawful basis applies.
- Minimisation: We collect only what is necessary.
- Retention control: We keep data only as long as needed.
- Rights: We respect and facilitate individual GDPR rights.
This Privacy Policy applies to all customers in the area and governs our handling of personal data in accordance with GDPR and related data protection laws.
