Privacy Policy for Byewu Effective Date: Nov 2024 Introduction Byewu (“we,” “us,” or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. Byewu provides an online platform for event planning services, including vendor and customer accounts. This document outlines how we handle the personal information of our customers, vendors, and users of our platform. 1. Information We Collect We collect the following types of personal data from our users (both vendors and customers): - Customer Data: - Full name - Contact details (email address, phone number) - Payment details (credit/debit card information, billing address) - Event details (event type, event date, location) - Communication history (emails, messages, etc.) - Any additional information provided for event planning purposes - Vendor Data: - Full name of contact person(s) - Business name and address - Contact details (email address, phone number) - Payment details (bank account or payment service details) - Service offerings (type of services provided, pricing) - Compliance and insurance details (if applicable) - Communication history with Byewu and customers - Reviews and feedback provided by customers 2. How We Collect Your Data We collect personal data from you in the following ways: - When you create an account on our platform (as a customer or vendor). - When you submit information to request a service, communicate with us, or interact with the platform. - Through automatic technologies such as cookies and tracking technologies when you visit our website. 3. How We Use Your Data We use the personal data we collect for the following purposes: - For customers: - To provide event planning services and manage your event details. - To communicate with you regarding your event, bookings, and customer service. - To process payments and manage billing. - To improve our platform and customer service based on feedback and usage data. - To send you relevant marketing communications, where you have opted in to receive such communications. - For vendors: - To facilitate the listing of your services and connect you with customers. - To manage payments, billing, and commissions. - To verify your credentials, insurance, and compliance (if applicable). - To communicate with you regarding customer inquiries, bookings, and platform updates. - To send you relevant communications regarding new features, offers, or policies related to your account. 4. Legal Basis for Processing Data Under the GDPR, we rely on the following legal bases for processing your personal data: - Contractual Necessity: We process your personal data to fulfill our contractual obligations, including providing event planning services and managing vendor-client relationships. - Legitimate Interests: We may process your data based on our legitimate interests in providing our services, improving our platform, and communicating with you. - Consent: Where required, we will ask for your explicit consent to process certain types of data (e.g., marketing communications). - Legal Obligation: We may process your data when required by law, such as for accounting or legal compliance purposes. 5. Sharing Your Data We may share your personal data with the following parties: - Vendors: When you, as a customer, select a vendor for your event, we may share your event details with the selected vendor to facilitate the service. - Payment Providers: To process payments securely, we may share payment details with third-party payment processors. - Service Providers: We may share your data with trusted third-party providers who assist with our platform’s operation, such as hosting services, email service providers, or customer support platforms. - Legal and Regulatory Authorities: We may share your data to comply with applicable laws or respond to lawful requests, including subpoenas or court orders. We will not share your data with third parties for marketing purposes without your consent. 6. Data Retention We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including compliance with legal, accounting, or reporting requirements. Typically, we retain data for: - Customer accounts: For as long as you are an active user of our platform. - Vendor accounts: For as long as your business is listed and providing services through Byewu. - Transaction data: We may retain transaction data for a period of up to 7 years, in line with legal and accounting obligations. 7. Your Rights Under GDPR As a data subject, you have the following rights under GDPR: - Right to Access: You can request a copy of the personal data we hold about you. - Right to Rectification: You can request correction of inaccurate or incomplete personal data. - Right to Erasure (“Right to be Forgotten”): You can request the deletion of your personal data, subject to certain conditions. - Right to Restrict Processing: You can request that we restrict the processing of your personal data under specific circumstances. - Right to Data Portability: You can request a copy of your data in a structured, commonly used, and machine-readable format. - Right to Object: You can object to the processing of your personal data in certain situations, particularly for direct marketing purposes. - Right to Withdraw Consent: If we process your data based on your consent, you can withdraw your consent at any time. To exercise any of these rights, please contact us at the contact details below. 8. Security of Your Data We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it from unauthorized access, alteration, disclosure, or destruction. These measures include encryption, secure servers, and access controls. 9. Cookies and Tracking Technologies We use cookies and similar tracking technologies to improve the functionality and user experience of our platform. These technologies help us analyse usage patterns, remember user preferences, and optimize our website and services. You can control cookies through your browser settings. For more information on how we use cookies, please refer to our Cookie Policy. 10. International Transfers of Data We may transfer your personal data outside the European Economic Area (EEA) to third-party service providers who assist us in operating our platform. We ensure that appropriate safeguards are in place to protect your data in accordance with GDPR requirements. 11. Changes to This Privacy Policy We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. Any updates will be posted on this page with the revised effective date. Please review this Privacy Policy periodically to stay informed. 12. Contact Us If you have any questions or concerns about this Privacy Policy, or if you wish to exercise your data protection rights, please contact us at: Byewu Email: byewultd@gmail.com