This Privacy Policy explains how Superman collects, uses, stores, and protects personal data of its customers in the relevant service area. It also describes the lawful bases relied upon under the General Data Protection Regulation, how long information is kept, when third-party processors are used, and the rights available to individuals whose data is processed.
This Privacy Policy applies to all Superman customers in the area where Superman offers its products and services. It covers personal data collected through customer interactions, service provision, and related business operations, whether the information is obtained online or offline.
Superman acts as the data controller for personal data processed in connection with the provision of its products and services to customers in the area. As data controller, Superman determines the purposes and means of processing personal data and is responsible for ensuring that such processing complies with applicable data protection laws, including the General Data Protection Regulation.
Superman may collect and process the following categories of personal data about customers and relevant contacts:
Identification and contact data, such as name, title, postal address, billing address, and general contact details.
Account and service data, such as customer account identifiers, service usage information, activation dates, contract numbers, preferences, and communication history with customer support.
Transactional data, such as records of orders, purchases, service subscriptions, payments made, refunds, and related billing information, excluding full payment card details where processed solely by compliant payment providers.
Technical and usage data, such as device identifiers, access logs, basic diagnostic information, and general interaction data with Superman products and services, where applicable.
Communication data, such as correspondence with Superman, feedback, and information provided in the context of support requests or customer surveys.
Superman processes personal data for the following purposes:
To provide and manage products and services, including creating and managing customer accounts, delivering ordered services, and ensuring the proper functioning and security of those services.
To handle customer support and communication, including responding to enquiries, resolving issues, and communicating essential information about services, updates, or changes to terms.
To manage contractual relationships, including administering billing, payments, debt collection where necessary, and maintaining appropriate business records.
To improve and develop services, including analyzing aggregate usage and performance data, enhancing user experience, and developing new offerings where this can be done in compliance with data protection requirements.
To comply with legal obligations, such as maintaining records for tax, accounting, or regulatory purposes and responding to lawful requests from public authorities.
To protect legitimate interests, such as preventing fraud or misuse of services, ensuring network and information security, and defending legal claims.
Superman relies on one or more of the following lawful bases under the General Data Protection Regulation when processing personal data:
Performance of a contract, where processing is necessary to enter into or fulfill a contract with a customer or to take steps at the request of the customer prior to entering into a contract.
Compliance with a legal obligation, where Superman is required to process personal data to meet obligations under applicable law.
Legitimate interests, where processing is necessary for Superman’s legitimate business interests or those of a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the individual. Examples include preventing fraud, securing systems, and improving services.
Consent, where Superman relies on the individual’s freely given, specific, informed, and unambiguous consent for certain activities, such as certain forms of direct marketing or optional analytics where required. When processing is based on consent, individuals may withdraw their consent at any time, without affecting the lawfulness of processing that took place before withdrawal.
Superman retains personal data only for as long as necessary to fulfill the purposes for which it was collected, or to meet legal, regulatory, or operational requirements.
In determining retention periods, Superman considers the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which the data is processed, whether those purposes can be achieved by other means, and applicable legal requirements.
In general, customer account and contractual data is retained for the duration of the customer relationship and for a reasonable period thereafter to handle queries, disputes, or legal claims and to comply with statutory retention obligations. Certain accounting and transactional records may be retained for longer periods as required by law.
Superman may engage carefully selected third-party service providers to process personal data on its behalf in accordance with documented instructions. These providers act as data processors and may provide services such as data hosting, customer support tools, payment processing, analytics support, or security services.
Superman ensures that any data processors are bound by written agreements that require them to implement appropriate technical and organizational measures to protect personal data and to process such data only for the purposes specified by Superman.
Superman may also share personal data with other third parties in limited circumstances, such as with professional advisers, auditors, or insurers, where necessary to manage business operations or comply with legal obligations, or with public authorities where required by law or to protect the vital interests of individuals.
Where Superman or its processors transfer personal data outside the European Economic Area or other regions with data transfer restrictions, Superman will ensure that appropriate safeguards are in place in accordance with applicable data protection laws. These safeguards may include reliance on adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms.
Superman implements appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures take into account the state of the art, implementation costs, the nature of the data, and the risks posed by processing.
Under the General Data Protection Regulation and other applicable data protection laws, individuals whose personal data is processed by Superman may have the following rights, subject to certain conditions and limitations:
Right of access, meaning the right to obtain confirmation as to whether personal data concerning them is being processed and, if so, to receive information about that processing and a copy of the data where appropriate.
Right to rectification, meaning the right to have inaccurate personal data corrected and incomplete data completed.
Right to erasure, meaning the right to request deletion of personal data where there is no longer a lawful basis for Superman to continue processing it, subject to legal or legitimate business constraints.
Right to restriction of processing, meaning the right to request that processing be limited in certain circumstances, for example while the accuracy of the data is being verified.
Right to data portability, meaning the right to receive personal data that the individual has provided to Superman in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another controller.
Right to object, meaning the right to object at any time to processing of personal data based on legitimate interests, including profiling, and to object to processing for direct marketing purposes.
Where Superman relies on consent as a lawful basis, individuals have the right to withdraw consent at any time, without affecting prior lawful processing.
Customers and other individuals in the area whose data is processed by Superman can exercise their rights under this Privacy Policy in accordance with applicable law. They also have the right to lodge a complaint with a data protection supervisory authority if they consider that their personal data has been processed in a way that infringes data protection legislation.
Superman may update this Privacy Policy from time to time to reflect changes in legal requirements, best practices, or the way in which personal data is processed. When this Privacy Policy is updated, the revised version will apply to all Superman customers in the area from the date it is made available.