Privacy Policy
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when providing our services to customers in the area. It applies to all customers in the area and describes the rights and choices available to individuals under applicable data protection law, including the General Data Protection Regulation (GDPR).
We are committed to handling personal data in a lawful, fair, and transparent manner. We only process personal data for specified purposes and do not use it in ways that are incompatible with those purposes. Where required, we implement appropriate safeguards to protect personal data against unauthorised access, accidental loss, destruction, or misuse.
1. Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data:
- Identity data: name, title, and similar identifiers.
- Contact data: address, email address, telephone number, and other communication details.
- Account data: login details, account preferences, and profile information.
- Transaction data: records of purchases, payments, refunds, and related correspondence.
- Technical data: device type, browser type, IP address, operating system, and usage logs.
- Usage data: pages viewed, actions taken, interaction patterns, and service preferences.
- Communication data: information you provide when making enquiries, complaints, or support requests.
We do not intentionally collect special category data unless it is necessary and permitted by law. If such data is processed, we do so only where a valid lawful basis exists and suitable safeguards are in place.
2. How We Use Personal Data
We use personal data for the following purposes:
- to provide, operate, and maintain our services;
- to manage customer relationships and respond to enquiries;
- to process transactions, invoices, and payments;
- to personalise service delivery and improve customer experience;
- to monitor, secure, and troubleshoot our systems;
- to comply with legal, regulatory, and accounting obligations;
- to detect, investigate, and prevent fraud, misuse, or unlawful activity;
- to send administrative messages relating to the services;
- to analyse service performance and make operational improvements.
Where we rely on legitimate interests, we carry out a balancing assessment to ensure that our interests are not overridden by your rights and freedoms. Where required, we will obtain your consent before using personal data for certain purposes, such as specific marketing or optional processing activities.
3. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. The lawful bases we rely on may include:
Performance of a Contract
We process personal data when it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract. This includes account management, transaction processing, and service delivery.
Legal Obligation
We may process personal data where it is necessary to comply with a legal obligation, such as tax, accounting, record-keeping, consumer protection, or regulatory requirements.
Legitimate Interests
We may process personal data where it is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests. This may include service improvement, security monitoring, fraud prevention, and internal administration.
Consent
In some situations, we rely on your consent. Where we do, you may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Vital Interests
In rare cases, we may process personal data to protect someone’s vital interests, such as in an emergency.
4. Sharing and Processors
We may share personal data with carefully selected third parties that act as processors on our behalf or, where applicable, as independent controllers. These may include:
- IT and hosting providers;
- cloud storage and infrastructure services;
- payment service providers;
- customer support and communications tools;
- analytics and performance monitoring services;
- professional advisers such as accountants, auditors, or legal advisers;
- regulatory, tax, or law enforcement authorities where disclosure is required by law.
Where a third party acts as a processor, it will only process personal data on our documented instructions and must implement appropriate technical and organisational measures to protect the data. We require processors to maintain confidentiality, support security controls, and respect data protection obligations. We do not sell personal data.
5. International Transfers
If personal data is transferred outside the United Kingdom or the European Economic Area, we will ensure that appropriate safeguards are in place. These may include adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms permitted under GDPR. We assess transfer risks where necessary and take steps to ensure an equivalent level of protection.
6. Retention of Personal Data
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting obligations. The retention period depends on the type of data, the nature of the relationship, and any legal requirement that applies.
- Contract and service data: retained for the duration of the relationship and a reasonable period afterwards.
- Financial and tax records: retained for the period required by law.
- Support correspondence: retained for as long as needed to resolve issues and maintain accurate records.
- Technical logs: retained for security, diagnostics, and operational purposes for limited periods.
When personal data is no longer required, we will securely delete, anonymise, or otherwise dispose of it in accordance with our retention practices.
7. Security of Personal Data
We use appropriate technical and organisational measures to protect personal data. These may include access controls, encryption where appropriate, secure storage, role-based permissions, staff confidentiality obligations, and monitoring for suspicious activity. While no system can be guaranteed to be completely secure, we take reasonable steps to reduce risk and respond appropriately to incidents.
8. Your Rights Under GDPR
Subject to applicable law, you have the following rights in relation to your personal data:
- Right of access: you may request confirmation of whether we process your personal data and obtain a copy of it.
- Right to rectification: you may ask us to correct inaccurate or incomplete data.
- Right to erasure: you may request deletion of your personal data in certain circumstances.
- Right to restriction: you may ask us to restrict processing in certain cases.
- Right to data portability: you may request a structured, commonly used, machine-readable copy of certain data.
- Right to object: you may object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
You also have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been infringed. We encourage you to raise any concerns first so we can address them promptly and fairly.
9. Children’s Data
Our services are not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate authorisation and lawful basis. If we become aware that we have collected personal data from a child without appropriate permission, we will take steps to delete it where required.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our processing activities, legal obligations, or operational needs. Any updates will take effect when published or otherwise communicated in accordance with applicable law. We encourage you to review this Privacy Policy periodically to remain informed about how we process personal data.
11. Scope and Application
This Privacy Policy applies to all customers in the area and governs our processing of personal data in connection with the services we provide there. By using our services or interacting with us, you acknowledge that your personal data may be processed as described in this Privacy Policy, subject to the rights and protections granted under applicable data protection law.
In summary: we collect only the data needed to provide and improve our services, process it under a valid lawful basis, retain it only as long as necessary, use trusted processors under contract, and respect your GDPR rights.
