Privacy Policy
This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with our services. It applies to all customers in the area and is intended to provide clear information about our practices in line with the General Data Protection Regulation (GDPR) and applicable local privacy laws.
1. Who We Are
For the purposes of data protection law, we act as the data controller for the personal data processed in connection with our services. This means we determine the purposes and means of processing personal data and are responsible for ensuring that it is handled lawfully, fairly, and transparently.
2. Personal Data We Collect
We may collect and process the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: billing details, delivery details, email address, telephone number, and similar contact information.
- Account data: login credentials, account settings, preferences, and service history.
- Transaction data: information about purchases, payments, orders, and related records.
- Technical data: internet protocol (IP) address, browser type and version, device identifiers, operating system, and usage logs.
- Communication data: records of correspondence, feedback, complaints, and service-related messages.
- Marketing and preference data: your choices regarding promotions, communication preferences, and consent records where applicable.
We do not intentionally collect special category data unless it is strictly necessary and permitted by law. If such data is ever provided to us, we will process it only where a lawful basis exists and additional safeguards are in place.
3. How We Collect Personal Data
We collect personal data in several ways:
- Directly from you when you create an account, place an order, make an inquiry, or communicate with us.
- Automatically through technical systems when you interact with our services.
- From third parties such as payment providers, delivery partners, fraud prevention services, and business service providers, where permitted by law.
Where personal data is not obtained directly from you, we take steps to ensure that the source is lawful and that the data is used only for the purposes described in this Policy.
4. Purposes of Processing
We use personal data for the following purposes:
- To provide, manage, and improve our services.
- To process transactions and fulfill orders.
- To manage customer accounts and authenticate access.
- To communicate service updates, notices, and administrative information.
- To detect and prevent fraud, misuse, and security incidents.
- To comply with legal obligations, including accounting and tax requirements.
- To analyze service performance and improve user experience.
- To send marketing communications where permitted by law and where required, with your consent.
We only process personal data for specified, explicit, and legitimate purposes.
5. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. Depending on the context, we rely on one or more of the following bases:
- Performance of a contract: where processing is necessary to provide services, manage accounts, or complete transactions.
- Legal obligation: where processing is required to comply with laws, regulations, or lawful requests from public authorities.
- Legitimate interests: where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include service improvement, fraud prevention, and network security.
- Consent: where you have given clear permission for a specific processing activity, such as certain marketing communications or optional features.
If we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
6. Sharing and Processors
We may share personal data with trusted third parties who act as processors on our behalf. These processors only process personal data according to our instructions and are required to protect it appropriately. Examples of processor categories may include:
- Payment processing providers.
- IT hosting, cloud storage, and system maintenance providers.
- Customer support and communication service providers.
- Analytics and monitoring service providers.
- Fraud prevention and security service providers.
- Professional advisers and business service providers where necessary.
We may also share personal data where required by law, to protect our rights, to respond to lawful requests, or in connection with a business transaction such as a reorganization or transfer of assets. In all cases, we limit disclosures to what is necessary and ensure appropriate safeguards are applied.
7. International Transfers
If personal data is transferred outside the European Economic Area or the United Kingdom, we will ensure that appropriate safeguards are in place, such as an adequacy decision, standard contractual clauses, or equivalent legal protections. These measures are intended to ensure that your personal data receives a level of protection essentially equivalent to that required under GDPR.
8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to meet legal, accounting, reporting, or regulatory requirements. The retention period may vary depending on the type of data and the reason for processing.
- Account and transaction records may be kept for the duration of the business relationship and for a further period required by law.
- Communication records may be retained for a reasonable period to manage inquiries, disputes, and service quality.
- Technical and usage data may be retained for security, diagnostics, and analytical purposes for a limited period.
- Marketing data is retained until you opt out, withdraw consent, or the data is no longer needed.
When personal data is no longer required, we will delete it securely or anonymize it so that it can no longer identify you.
9. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures may include access controls, encryption, secure storage, staff confidentiality obligations, and regular review of our security practices.
While no system can be guaranteed completely secure, we take reasonable steps to reduce risks and to safeguard personal data at all times.
10. Your Rights Under GDPR
Subject to certain conditions and exemptions under applicable law, you have the following rights regarding your personal data:
- Right of access: to obtain confirmation of whether we process your personal data and to receive a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request that processing be limited in certain situations.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and to transmit it to another controller where technically feasible.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time.
- Right to lodge a complaint: to raise concerns with a supervisory authority if you believe your data protection rights have been infringed.
We will respond to requests in accordance with GDPR time limits and requirements.
11. Automated Decision-Making
We do not use personal data for decisions based solely on automated processing that produce legal or similarly significant effects, unless you are informed in advance and such processing is lawful. If automated decision-making is used, we will provide meaningful information about the logic involved and the significance and envisaged consequences of the processing.
12. Children’s Data
Our services are not intended for children unless expressly stated otherwise. We do not knowingly collect personal data from children without appropriate legal basis and, where required, verified consent from a parent or guardian. If we become aware that we have collected data unlawfully from a child, we will take steps to delete it promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing practices, legal obligations, or operational requirements. Any revised version will apply from the date it is made available. We encourage you to review this Policy periodically so that you remain informed about how your personal data is handled.
Summary of Key Commitments
- We collect only the personal data needed to provide and improve our services.
- We process data on the basis of contract, legal obligation, legitimate interests, or consent.
- We share data only with approved processors and where legally required.
- We keep data only as long as necessary and protect it with appropriate safeguards.
- We respect your GDPR rights and apply this Policy to all customers in the area.
This Privacy Policy is intended to be read together with any other terms or notices that may apply to specific services or processing activities.