Privacy Policy
This Privacy Policy explains how personal data is collected, used, shared, retained, and protected in connection with our services. It applies to all customers in area and is intended to be consistent with the General Data Protection Regulation (GDPR) and other applicable data protection laws. Please read this Policy carefully to understand how we handle personal data and what rights data subjects have in relation to that data.
1. Scope of This Policy
This Policy applies to personal data processed when individuals use our services, communicate with us, or otherwise interact with us as customers, prospects, or users. It covers data processed in electronic and, where relevant, paper form. It also applies to data processed on behalf of customers where we act as a controller or, in certain cases, as a processor depending on the nature of the relationship and the service provided.
Important: this Policy applies to all customers in area and describes the general data protection principles followed across our operations.
2. Data Collection
We collect personal data only when necessary and in a manner that is fair, lawful, and transparent. Depending on how you interact with us, we may collect the following categories of data:
- Identity data: name, title, and any identifiers used to verify identity.
- Contact data: email address, phone number, postal address, and similar details.
- Account and service data: account preferences, service settings, transaction history, and communications.
- Technical data: IP address, device identifiers, browser type, operating system, and usage logs.
- Payment and billing data: invoice details, payment status, and billing records where applicable.
- Communication data: messages, inquiries, feedback, complaints, and support interactions.
- Marketing preferences: consent choices and communication preferences.
We may collect data directly from you, automatically through your use of our services, or from third parties where permitted by law. We do not intentionally collect special category data unless there is a clear legal basis and appropriate safeguards in place. If such data is provided unexpectedly, it will be handled in accordance with GDPR requirements.
3. Purposes of Processing
We process personal data for specific and legitimate purposes, including:
- providing and administering our services;
- creating and managing accounts;
- processing transactions and billing;
- responding to enquiries, complaints, and support requests;
- ensuring security, fraud prevention, and service integrity;
- maintaining records and internal administration;
- meeting legal, regulatory, and compliance obligations;
- improving our services and user experience;
- sending relevant communications where permitted and appropriate.
We ensure that personal data is not further processed in a way that is incompatible with these purposes.
4. Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each processing activity. Depending on the context, we rely on one or more of the following:
a) Contractual necessity
We process data where it is necessary to perform a contract with you or to take steps at your request before entering into a contract. This includes account creation, service delivery, billing, and support.
b) Legal obligation
We may process data where required to comply with legal or regulatory obligations, such as accounting, tax, recordkeeping, anti-fraud, or responding to lawful requests from public authorities.
c) Legitimate interests
We may process data where it is necessary for our legitimate interests, provided these interests are not overridden by your rights and freedoms. Examples may include service improvement, network and information security, business administration, and preventing misuse.
d) Consent
Where required by law, we rely on your consent, for example for certain marketing communications or non-essential cookies and similar technologies. You may withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
e) Vital interests and public task
In rare situations, we may process data to protect vital interests or where processing is necessary for a task carried out in the public interest. These bases are used only where applicable and justified.
5. Data Sharing and Processors
We may share personal data with trusted third parties where necessary for the purposes described in this Policy. These third parties may act as processors or, in some cases, independent controllers. Where they act as processors, they process personal data only on our documented instructions and must implement appropriate technical and organizational measures.
Typical categories of processors may include:
- hosting and infrastructure providers;
- payment service providers;
- customer support and communication tools;
- analytics and performance monitoring services;
- document storage and backup providers;
- professional advisers and compliance service providers.
We require processors to protect personal data, act only within the scope of our instructions, and assist with GDPR compliance where appropriate. Where data is transferred outside the European Economic Area, we ensure suitable safeguards are in place, such as adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms.
6. Retention of Personal Data
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law. Retention periods vary depending on the category of data and the legal basis for processing.
- Contractual and account data: retained for the duration of the relationship and for a reasonable period thereafter.
- Financial and tax records: retained for periods required by accounting and tax laws.
- Support and communication records: retained as needed for service management, dispute resolution, and quality assurance.
- Marketing data: retained until you withdraw consent or object, where applicable.
- Technical logs: retained for security, operational, and diagnostic purposes for limited periods.
When personal data is no longer required, it is securely deleted, anonymized, or irreversibly aggregated where appropriate.
7. Security Measures
We take appropriate technical and organizational measures to safeguard personal data against unauthorized access, disclosure, alteration, loss, or destruction. These measures may include access controls, encryption, secure storage, training, logging, and regular review of internal practices. While no system can be guaranteed completely secure, we continuously work to improve our controls and reduce risk.
8. User Rights Under GDPR
Subject to applicable law, individuals have the following rights regarding their personal data:
- Right of access: to obtain confirmation of whether we process your data and receive a copy of that data.
- Right to rectification: to correct inaccurate or incomplete personal data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request limited processing in certain situations.
- Right to data portability: to receive data you provided in a structured, commonly used format and, where feasible, transmit it to another controller.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent: where processing is based on consent, to withdraw it at any time.
- Rights related to automated decision-making: to challenge decisions based solely on automated processing where applicable.
We may need to verify your identity before responding to a rights request. We will respond within the time limits required by law and may refuse or limit requests where permitted under GDPR, for example if the request is manifestly unfounded, excessive, or adversely affects the rights of others.
9. Complaints and Supervisory Authority
If you believe your personal data has been processed unlawfully or that your rights have been infringed, you have the right to lodge a complaint with the relevant data protection authority in your country or region. You may also raise concerns with us so that we can review and address the matter in accordance with applicable law.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. When updates are made, the revised Policy will apply from the date it becomes effective. We encourage individuals to review this Policy periodically to remain informed about how personal data is handled.
Summary of our commitment: we process personal data lawfully, transparently, and securely; retain it only as long as needed; use vetted processors; and respect the rights of all customers in area in accordance with GDPR.
