Privacy Policy
This Privacy Policy explains how personal data is collected, used, stored, disclosed, and protected in connection with services provided to customers in the area. It applies to all customers in area and is intended to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), where relevant. By using the service, customers acknowledge that they have read and understood this policy.
1. Scope of this Policy
This policy applies to all customers in area and describes the processing of personal data relating to individuals who interact with the service, including account holders, representatives, and authorized users. It covers information collected directly from users, information received from third parties, and information generated through use of the service.
Personal data means any information that can identify a natural person directly or indirectly, such as name, contact details, account identifiers, device data, and usage records.
2. Data We Collect
We collect only the data necessary for legitimate business and legal purposes. Depending on how the service is used, the following categories of personal data may be processed:
- Identity data: name, username, or account identifier.
- Contact data: email address, phone number, billing address, or similar details.
- Transaction data: records of purchases, payments, invoices, and related correspondence.
- Technical data: IP address, browser type, device type, operating system, log data, and system event information.
- Usage data: information about how services are accessed and used, including preferences and interaction history.
- Support data: information submitted in inquiries, complaints, or service requests.
- Compliance data: records required to meet legal, tax, accounting, fraud-prevention, or audit obligations.
We do not intentionally collect sensitive personal data unless it is required by law or is voluntarily provided for a specific purpose. If such data is received, it is handled with enhanced care and only where lawful and necessary.
3. How We Use Personal Data
Personal data is used for the following purposes:
- to provide and operate the service;
- to manage accounts, subscriptions, and customer support;
- to process payments and keep financial records;
- to maintain security, prevent fraud, and detect misuse;
- to improve service quality, performance, and functionality;
- to communicate operational notices, updates, and service information;
- to comply with legal, regulatory, and contractual obligations;
- to establish, exercise, or defend legal claims.
We ensure that all uses of personal data are limited to specific, explicit, and legitimate purposes and are not further processed in a manner incompatible with those purposes.
4. Lawful Basis for Processing
Where GDPR applies, personal data is processed only when a lawful basis exists. Depending on the context, the lawful basis may include:
- Contract performance: processing is necessary to provide requested services or take steps at the request of the user before entering into a contract.
- Legal obligation: processing is required to comply with applicable laws, regulations, tax rules, or court orders.
- Legitimate interests: processing is necessary for our legitimate business interests, such as service improvement, fraud prevention, and security, provided these interests are not overridden by user rights and freedoms.
- Consent: processing is based on consent where required, such as for optional communications or certain data uses. Consent may be withdrawn at any time without affecting the lawfulness of processing before withdrawal.
When we rely on legitimate interests, we assess whether the processing is necessary and whether it is proportionate to the expected impact on individuals. When we rely on consent, we make sure it is freely given, specific, informed, and unambiguous.
5. Data Sharing and Processors
We may share personal data with trusted third parties that act as processors or independent controllers, depending on the service relationship and legal requirement. Processors are engaged only under appropriate contractual terms requiring them to process data on our instructions, maintain confidentiality, and implement adequate security measures.
Categories of processors may include:
- Hosting and infrastructure providers that store or transmit data;
- Payment service providers that handle financial transactions;
- Customer support tools used to manage inquiries and communication records;
- Analytics and performance providers that help evaluate service usage;
- Security and fraud-prevention providers that assist in protecting systems and users;
- Professional advisers such as legal, accounting, or audit specialists where necessary;
- Public authorities or regulators where disclosure is required by law.
We do not sell personal data. Any transfer of data to third parties is limited to what is necessary for the stated purpose. Where an international transfer occurs, appropriate safeguards are applied in accordance with applicable law.
6. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including the need to comply with legal, accounting, tax, and reporting obligations.
Retention periods are determined by considering:
- the nature and sensitivity of the data;
- the risk of harm from unauthorized use or disclosure;
- the purpose of processing and whether it can be achieved through other means;
- applicable legal retention requirements;
- whether a dispute, claim, or investigation is ongoing.
When data is no longer needed, it is securely deleted, anonymized, or otherwise disposed of in a manner designed to prevent unauthorized recovery or use. In some cases, limited records may be retained for compliance or archival purposes even after a user relationship has ended.
7. Data Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, encryption where appropriate, logging, network protections, and staff confidentiality obligations.
No system can be guaranteed to be completely secure, but we continuously review safeguards and improve them where reasonable and necessary.
8. User Rights
Where GDPR or similar laws apply, individuals may have the following rights regarding their personal data:
- Right of access: to obtain confirmation and a copy of personal data processed about them.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of personal data in certain circumstances.
- Right to restriction: to request that processing be limited in specific situations.
- Right to data portability: to receive data in a structured, commonly used format where applicable.
- Right to object: to object to processing based on legitimate interests or direct marketing, where applicable.
- Right to withdraw consent: to withdraw consent at any time where processing is based on consent.
- Right not to be subject to automated decision-making: to challenge certain decisions made solely by automated means, where applicable.
Requests relating to these rights should be made through the available support or account management channels. We may need to verify identity before fulfilling a request. Some rights may be limited by law, for example where retention is required for legal compliance or where disclosure would affect the rights of others.
9. Children’s Data
The service is not intended for children unless specifically stated otherwise. We do not knowingly collect personal data from children without appropriate authorization where required by law. If we become aware that such data has been collected improperly, we will take reasonable steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or service features. Updated versions will take effect when published or otherwise communicated as required. Users are encouraged to review this policy periodically to stay informed about how personal data is handled.
By continuing to use the service, customers in area acknowledge this policy and the processing described above.