Privacy Policy -
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data in compliance with the General Data Protection Regulation (GDPR) and applicable data protection laws. This policy applies to all customers located in the European Economic Area (EEA) and describes the rights available to those customers and the lawful bases for processing their personal data.
1. Data We Collect
We collect and process the following categories of personal data to provide and improve our services:
- Identity and contact information: name, billing and shipping address, email address, telephone number;
- Account and transactional data: account identifiers, order history, payment method details (tokenized or partial payment data), invoices and transaction records;
- Technical and device data: IP address, browser type and settings, device identifiers, operating system, log information, and analytics data related to use of our services;
- Communications data: correspondence with our support and sales teams, including recorded call logs and messaging transcripts where applicable;
- Marketing and preference data: consent preferences, subscription status, and preferences for receiving communications;
- Demographic and profiling data: optional information provided by you such as job title, company size, or interests used to tailor our services and communications.
We generally do not collect special categories of personal data (sensitive data) such as health, racial or ethnic origin, political opinions, religious beliefs, or trade union membership.
2. Lawful Bases for Processing
Under the GDPR, we rely on specific lawful bases to process personal data. The applicable lawful basis depends on the purpose of processing:
- Performance of a contract: processing necessary to perform a contract with you, such as creating and managing your account, fulfilling orders, and providing customer support.
- Legal obligation: processing necessary to comply with legal obligations, such as tax, accounting, and regulatory reporting duties.
- Consent: where required, we process personal data based on your explicit consent, for example for certain marketing communications and optional features. You may withdraw consent at any time.
- Legitimate interests: processing necessary for our legitimate interests, including fraud prevention, network and information security, improving our products and services, and exercising or defending legal claims, provided such interests are not overridden by your rights and freedoms.
3. How We Use Personal Data
We use personal data for the following purposes:
- To provide, maintain, and improve our services and customer experience;
- To process orders, manage accounts, and deliver customer support;
- To comply with legal and regulatory obligations;
- To send administrative messages and important service-related notices;
- To conduct analytics, product research, and service improvement activities;
- To send marketing communications where you have given consent or where permitted by law; you may opt out at any time.
4. Disclosure to Processors and Third Parties
We engage trusted third-party service providers (processors) to perform certain functions on our behalf. These processors are contractually bound to process personal data only on our documented instructions and to implement appropriate technical and organizational measures to protect the data.
Categories of processors and recipients include:
- Payment processors and financial institutions for payment and billing;
- Cloud hosting and data infrastructure providers for data storage and application hosting;
- Analytics and performance monitoring providers for usage insights;
- Customer relationship management, email delivery, and marketing platforms;
- Legal, auditing, and professional advisors when required for compliance or defense of legal claims.
When we transfer personal data to processors outside the EEA, we will ensure appropriate safeguards are in place such as European Commission adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms.
5. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy, to comply with our legal obligations, resolve disputes, enforce agreements, and for legitimate business purposes. Specific retention periods include, but are not limited to:
- Account and transactional data: retained for the duration of the business relationship and for a period thereafter as required by applicable tax and accounting laws (typically 6–10 years);
- Communications and support records: retained for up to 3–7 years to allow us to respond to inquiries and defend legal claims;
- Analytics and aggregated usage data: retained in aggregated or anonymized form for ongoing product improvement; where personal identifiers are retained, the retention period will be defined by the purpose and lawful basis.
At the end of the retention period, personal data will be securely deleted, anonymized, or archived as permitted by law.
6. Security Measures
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit and at rest where appropriate, access controls, regular security assessments, and staff training. Despite these measures, no system is completely immune to attack; we continually review and enhance security practices.
7. Your Rights
Subject to applicable law, customers in the EEA have the following rights regarding their personal data:
- Right of access: request confirmation of whether we process your personal data and obtain a copy of such data;
- Right to rectification: correct inaccurate or incomplete personal data;
- Right to erasure: request deletion of personal data where there is no lawful basis to retain it;
- Right to restriction: request limitation of processing in certain circumstances;
- Right to data portability: receive personal data you have provided to us in a structured, commonly used and machine-readable format;
- Right to object: object to processing based on legitimate interests or direct marketing;
- Right to withdraw consent: withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing prior to withdrawal;
- Right to lodge a complaint: file a complaint with a supervisory authority if you believe your rights under applicable data protection laws have been infringed.
To exercise these rights, you may contact us using the channels provided in our account interface or service documentation.
Verification and Response
We may need to verify your identity before fulfilling requests to ensure protection of personal data. We will respond to requests in accordance with applicable legal timelines, typically within one month, subject to extension when necessary.
8. Automated Decision-Making and Profiling
We do not rely on automated decision-making that produces legal effects concerning you or significantly affects you without human intervention, except where explicitly disclosed and permitted by law. Where automated profiling occurs, we will provide information about the logic involved and the significance and envisaged consequences for you.
9. Children
Our services are not intended for children under the age of 16. We do not knowingly collect personal data from children under this age. If we become aware that such data has been collected, we will take steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make material changes, we will provide notice through the service or other appropriate means. Continued use of our services after such changes constitutes acceptance of the revised policy.
11. Additional Information
If you are a customer in the EEA, this policy supplements any other notices we provide and aims to ensure compliance with GDPR obligations. All customers in the EEA are covered by the provisions of this policy, and the protections described herein apply to the processing activities related to the provision of our services.
End of Policy.
