1. Data we process
Profile data: full name, email address, phone number, postal address, date of birth, verification documents.
Transaction data: orders, payment intents, wallet top-ups, invoices, refunds, postal entry logs.
Usage data: login activity, device/browser information, language preferences, marketing attribution, support conversations.
2. Why we use your data
To create and manage your account, deliver giveaway participation, verify eligibility, prevent abuse and show localized content.
To process payments, detect fraud, keep financial records, attribute referrals and manage claims/fulfilment.
To send service communications (receipts, draw reminders, claim instructions) and, when consented, marketing updates.
3. Legal bases
Contractual necessity for account creation, ticket purchases, prize claims and support requests.
Legitimate interest for fraud prevention, security monitoring, analytics and platform improvements.
Consent for marketing communications, optional cookies or alternative verification routes.
4. Sharing & processors
EuroGiveaways Web LTD acts as data controller. We only share data with vetted processors such as Stripe (payments), AWS (hosting), email/SMS providers, compliance tools and logistics partners needed for prize delivery.
Where legally required we may share limited information with regulators or law enforcement. We never sell personal data to third parties.
5. Retention
Account data is stored while your profile remains active and up to 5 years afterwards to satisfy AML, tax and audit obligations.
Payment and invoice data is retained for at least 10 years in line with UK accounting regulations.
You can request deletion of certain data categories; we will remove them unless we must keep them for legal reasons.
6. Cookies & tracking
Essential cookies keep you logged in, remember language preferences and secure payment flows.
Optional analytics/marketing cookies are used only when you opt in inside your account or cookie banner.
You can adjust preferences anytime from the account privacy tab or device/browser settings.
7. Security
We apply encryption in transit and at rest, segregate production data, run regular penetration tests and restrict employee access based on role.
Any suspected breach will trigger our incident response plan and we will notify affected users and authorities within statutory deadlines.
Your GDPR rights
- Access – receive a copy of the personal data we hold about you.
- Rectification – correct incomplete or inaccurate information.
- Erasure – request deletion when data is no longer necessary.
- Restriction – limit processing while we verify a concern.
- Portability – obtain data in a machine-readable format.
- Objection – opt out from marketing or processing based on legitimate interests.