Data Protection and Privacy Policy for Premierwin Games and Competitions
[updated 28 September 2025]
- Introduction and Overview
- 1.1 Who we are
Premierwin Competition Ltd (“we”, “us,”, “our”) is a company incorporated in England and Wales (Company Registration Number 16537309). Our registered office is at Riddicks Sports Bar, 22 Fowler Street, South Shields, Tyne and Wear, NE33 1NA, United Kingdon. We operate online skill based competitions and promotional prize draws through our website www.premierwincompetitions.co.uk and associated mobile applications (the “platform”)
- 1.2 Our Commitment to Privacy
We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, store and protect your personal data when you use our Platform and services. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable privacy laws.
- 1.3 Data Controller
For the purposes of data protection law, Premierwin Competitions Ltd is the data controller responsible for your personal information. Our Data Protection Officer can be contacted at info@premierwincompetitions.co.uk
- 1.4 Scope of this policy
This Privacy Policy applies to all personal information we collect about you when you:
- Visit our platform
- Create an account or register for our services
- Participate in our competitions or games either online or live
- Contact our customer support
- Interact with our marketing communications
- Use any of our related services.
- Information we collect
- 2.1 Information provided by you
- a) On account registration
Full name
Date of birth
Email address
Postal address
Phone number
Username and password
Security questions and answers
- b) Identity verification including but not limited to
Government-issued ID (passport, driving licence)
Proof of address documents
Bank statements or utility bills
Selfie photos for identity verification
Biometric data (facial recognition for verification)
- c) Payment and financial information
Payment card details (processed securely by our payment providers)
Bank account information
Transaction history
Wallet balance and transaction records
Tax identification numbers (where required)
Source of funds documentation.
- d) Competition and Gaming Information
Competition entries and preferences
Game play history and statistics
Spending patterns and competition behaviour
Prize claims and winnings
Customer support interactions
- e) Communication Information
Messages sent through our Platform
Customer service correspondence
Feedback and survey responses
Social media interactions
Marketing communication preferences
- 2.2 Information collected automatically
- a) Technical information
IP address and geolocation data
Device type, model and operating system
Browser type and version
Screen resolution and device settings
Internet connection speed
Unique device identifiers
Mobile advertising IDs
- b) Usage Information
Pages visited and time spent on Platform
Click patterns and navigation paths
Game play sessions and duration
Feature usage and preferences
Search queries and filters used
Referral sources and exit pages
- c) Performance and Analytics Data
Platform performance metrics
Error logs and crash reports
Loading times and response rates
A/B testing participation
Feature adoption rates
User journey analytics
- d) Cookies and Tracking Technologies
Session and persistent cookies
Local storage data
Web beacons and pixels
Javascript tracking codes
Cross-device tracking identifiers
Third-party analytics tools
- 2.3 Information from third parties
- a) Payment Processors
Transaction verification data
Fraud risk assessments
Payment method validation
Chargeback and dispute information
- b) Identity Verification Services
Identity document validation
Address verification results
Credit reference checks
Fraud prevention data
Politically Exposed Person (PEP) screening
- c) Social Media Platforms
Profile information from social logins
Friend connections and social graphs
Public posts and interactions
Advertising interaction data
- d) Data brokers and partners
Demographic and lifestyle information
Marketing preferences and interests
Device and household data
Commercial and shopping behaviour
- e) Regulatory and law enforcement
Sanctions and watchlist screening
Criminal background checks
Regulatory compliance data
Investigation and enforcement records
- Legal basis for processing your personal data
- 3.1 Contractual Necessity
- Provide our platform and services
- Process your competition entries
- Manage your account and preferences
- Process payments and prize distributions
- Provide customer support
- 3.2 Legal Obligations
- Anti-money laundering regulations
- Tax reporting requirements
- Gambling commission regulations
- Data protection law obligations
- Court orders and legal processes
- 3.3 Our Legitimate Business Interests
- Fraud prevention and security
- Platform improvement and optimization
- Risk Management and credit control
- Business analytics and research
- Marketing to existing customers
- 3.4 Consent
- Marketing communications
- Optional data collection
- Cookies and tracking (where required)
- Data sharing with partners
- Biometric data processing
- 3.5 Vital interests.
We may process data to protect vital interests in emergency situations or to prevent harm to you or others.
- How we use your information
- 4.1 Platform Services
- Creating and managing your account
- Processing competition entries and transactions
- Determining game outcomes and winners
- Distributing prizes and payments
- Providing customer support
- Maintaining platform security
- 4.2 Identity Verification and Compliance
- Verifying your age and identity
- Confirming your address and residence
- Preventing fraud and money laundering
- Complying with gambling regulations
- Conducting risk assessments
- Reporting to regulatory authorities
- 4.3 Platform Improvement
- Analysing usage patterns and preferences
- Testing new features and functionality
- Optimising platform performance
- Personalising user experience
- Conducting market research
- Improving customer support
- 4.4 Marketing and Communications
- Sending promotional offers and updates
- Personalising marketing content
- Managing email subscriptions
- Social Media engagement
- Affiliate and partnership marketing
- Remarketing to website visitors
- 4.5 Security and Fraud Prevention
- Monitoring for suspicious activity
- Preventing unauthorised access
- Detecting and investigating fraud
- Protecting against cyber attacks
- Maintaining audit trails
- Incident response and investigation
- 4.6 Legal and Regulatory Compliance
- Meeting promotional and competition requirements
- Reporting suspicious activities
- Responding to legal requests
- Tax calculation and reporting
- Record keeping for regulatory purposes
- Cooperating with law enforcement
- Data Sharing and Disclosure
- 5.1 Service Providers and Processors
- a) Payment Processing
Stripe and other payment gateways
Banking partners and card processors
Fraud Prevention services
- b) Identity Verification
Document verification services
- c) Technology and Infrastructure
Cloud hosting providers (AWS, Google Cloud)
Content delivery networks
Analytics and tracking services
Customer support platforms
Email and SMS services
- d) Marketing and Advertising
Social media and advertising platforms
Email marketing services
Affiliate networks
Customer feedback platforms
- 5.2 Regulatory and legal disclosures
Information will be passed to the relevant body when legally requested to do so. This can include but not limited to;
- Trading Standards authorities
- HM Revenue and Customs (HMRC)
- Financial Conduct Authority (FCA)
- National Crime Agency
- Courts and legal authorities
- Other regulatory bodies as required
- 5.3 Business Transfers
In the event of a merger, acquisition, or sale of business assets, your personal data may be transferred to the new owner subject to appropriate safeguards and notifications.
- 5.4 Emergency Situations
Your information may be disclosed to protect the following:
- Your vital interests or those of others
- Our legal rights and property
- Public safety and security
- Prevention of crime or fraud
- 5.5 All data sharing safeguard arrangements include
- Data Processing agreements
- Security and confidentiality requirements
- Data retention limitations
- Purpose limitations
- Regular compliance monitoring
- Data Retention
- 6.1 General Retention Principles
We will retain personal data only as long as necessary for
- The purpose for which it was collected
- Compliance with legal obligations
- Establishment or defence of legal claims
- Legitimate business interests
- 6.2 Specific Retention Periods
- a) Account information
Active accounts: Duration of relationship
Closed accounts: 7 years from closure
Identity Documents: 5 years from account closure
Transaction records: 7 years as required by law
- b) Participation and Competition data
Participation records: 5 years
Prize Claims: 7 years
Responsible participation data: 5 years
Dispute Records: 7 years
c) Marketing and Communications
Email marketing data: Until subscribed + 3 years
Customer Support Records: 7 years
Website Analytics: 26 months
Cookie Data: As specified in Cookie Policy
d) Security and Fraud Data
Fraud Investigations: 7 years
Security Incident Reports: 7 years
Access Logs: 2 years
- 6.3 Deletion Procedures
When deletion periods expire we will
- Securely delete and anonymise data
- Remove data from active systems
- Update backup systems
- Maintain deletion logs
- Notify relevant processors
7. Your Rights under Data Protection Law
- 7.1 Right of access
You have the right to
- Confirm whether we process your personal data
- Obtain a copy of your personal data
- Receive information about our processing activities
- Request details about data sharing
- 7.2 Right to Rectification
You can request correction of
- Incorrect personal data
- Incomplete personal data
- Outdated information
- 7.3 Right to Erasure (“Right to be forgotten”)
You can request deletion of your personal data when
- Retaining your personal data is no longer necessary
- You withdraw consent (where consent is the legal basis)
- Data has been unlawfully processed
- Deletion is required for legal compliance
- 7.4 Right to restrict processing
You can request to restrict processing of your personal data when
- You contest the accuracy of the data
- Processing is unlawful but you prefer restriction rather than deletion
- We no longer need the data, but you need it for legal claims
- You object to processing pending verification
- 7.5 The Right to Data Portability
You can receive your personal data in a structured, commonly used format and transmit it to another controller when processing is based on consent or contract
- 7.6 Right to Object
You have the right to object to processing on
- Legitimate interests (including profiling)
- Direct marketing (absolute right)
- Scientific or historical research
- Statistical purposes
- 7.7 Rights related to automated decision making
You have the right not to be subject to decisions based solely on automated processing, including profiling that produces legal effects or significantly affects you
- 7.8 Right to withdraw consent
Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing based on consent before withdrawal.
- 7.9 How to exercise your rights
Contact us at support@premierwincompetitions.co.uk or through your account settings. We will respond within one month and may request identity verification.
8. Security measures
We have a number of security measures in place to help keep your personal data safe and secure.
- 8.1 Technical Safeguards
- End-to-end encryption for sensitive data
- Secure Socket Layer (SSL) technology
- Multi-factor authentication
- Regular security patches and updates
- Intrusion detection and prevention systems
- Data-loss prevention tools
- 8.2 Physical Security
- Restricted access to data centres
- Biometric access controls
- 24/7 security monitoring
- Environmental controls
- Secure disposal of hardware
- Visitor access controls
- 8.3 Organisational Measures
- Regular security audits
- Incident response procedures
- Vendor security assessments
- Background checks on employees
- Data protection impact assessments
- Staff training in systems
- 8.4 Data Minimisation
- Collecting only necessary data
- Regular data review and purging
- Purpose limitation enforcement
- Access controls and permissions
- Data anonymisation where possible
- Privacy by design principles
9. Cookies and Tracking Technologies
- 9.1 The types of cookies we use include
- Essential Cookies – necessary for platform functionality
- Performance Cookies – Analytics and optimisation
- Functionality Cookies – User preferences and settings
- Marketing Cookies – Advertising and remarketing
- 9.2 Third Party Tracking
We use third party services including
- Google Analytics for website analytic
- Facebook Pixel for advertising
- Hotjar for user experience analysis
- Stripe for payment processing
- Various affiliate tracking systems
- 9.3 Cookie Management
You can control cookie management through
- Browser settings and preference
- Our cookie preference centre
- Third-party opt-out tools
- Device setting for mobile apps
For detailed information see our separate cookie policy
10. Special Categories of data
- 10.1 Biometric Data
We may process biometric data for identity verification including:
- Facial recognition for account verification
- Voice recognition for security
- Fingerprint data (if supported by device)
- 10.2 Health Data
We may collect health-related information for responsible participant monitoring, including
- Self-exclusion requests
- Spending concern indicators
- Support service referrals
- 10.3 Legal Basis for Special Categories
Processing is based on:
- Explicit consent
- Substantial public interest (fraud prevention)
- Regulatory compliance requirements
12. Children’s Privacy
- 11.1 Age Restrictions
Our platform is strictly for users 18 years and older. We do not knowingly collect personal information from minors.
- 11.2 Age Verification
We implement robust age verification including
- Identity document checks
- Third-party verification services
- Regular re-verification processes
- Suspicious activity monitoring
- 11.3 Underage Account Discovery
If we discover an underage account
- Immediate account suspension
- Data deletion (except as required by law)
- Investigation of verification failures
- System improvements to prevent recurrence
12. Marketing and Communications
- 12.1 Types of Marketing
- Email newsletters and promotions
- SMS marketing messages
- Push notifications (mobile apps)
- Social media advertising
- Personalised website content
- Affiliate marketing
- 12.2 Marketing Consent
- Explicit opt-in required for marketing emails
- Separate consent for SMS marketing
- Clear unsubscribe options provided
- Granular preference controls available
- 12.3 Personalisation
We may personalise marketing based on
- Gaming preference and history
- Demographic information
- Platform usage patterns
- Previous marketing interactions
- 12.4 Opting Out
You can opt out via
- Unsubscribe links in emails
- Account preference settings
- Customer support requests
- Reply “STOP” to SMS messages.
13. Automated decision-making and profiling
- 13.1 Automated systems
We use automated decision for
- Fraud detection and prevention
- Risk assessment and scoring
- Competition outcome determination
- Marketing personalisation
- Responsible participation interventions
- 13.2 Profiling Activities
We create profiles based on
- Gaming behaviour and preferences
- Spending patterns and limits
- Risk indicators and flags
- Marketing engagement history
- Device and location patterns
- 13.3 Your Rights
You have the right to
- Request human intervention
- Express your point of view
- Contest automated decisions
- Request explanations of logic involved
14. Data Breaches and Incident Response
- 14.1 Breach Prevention
We take breaches of data very seriously and have the following procedures in place to reduce the likelihood of a breach taking place. These include
- Continuous security monitoring
- Regular vulnerability assessments
- Employee training and awareness
- Vendor security requirements
- Incident simulation exercises
- 14.2 Breach Response
- In the unlikely event of a breach of our security processes we will carry out the following procedures
- Immediate containment and investigation
- Risk assessment and impact analysis
- Notification to authorities within 72 hours
- Individual notifications if high risk without delay
- Remedial action implementation
- 14.3 Notification Process
We will notify you of breaches that
- Pose high risk to your rights and freedoms
- Involve sensitive personal data
- Could result in identity theft or fraud
- Affect your ability to control your data
15. Responsible Competition Participation and Privacy
- 15.1 Data for Participation Protection
We process data to:
- Monitor spending patterns for responsible participation
- Implement voluntary spending and time limits
- Provide self-exclusion tools for those who request them
- Offer support and resources for healthy competition participation
- Comply with consumer protection obligations
- 15.2 Sharing for Protection
We may share data with
- Consumer protection organisations
- Debt counselling services (with consent)
- Regulatory authorities
- Healthcare providers (with consent)
- Financial education services
- 15.3 Sensitive Data Handling
Participation pattern data receives enhanced protection through
- Restricted access controls
- Extended retention periods
- Special category data safeguards
- Confidentiality agreements
16. Regulatory Compliance
- 16.1 Competition and Consumer Protection Compliance
We comply with relevant agencies including
- Competition and consumer protection laws
- Promotional competition regulations
- Consumer rights legislation
- Fair trading standards
- Advertising standards requirements
- 16.2 Financial Regulations
We adhere to
- Payment Services Regulations
- Anti-money laundering (AML) regulations
- Electronic Money Regulations
- Tax reporting obligations
- Counter-terrorism financing (CTF) rules
- 16.3 Data Protection Compliance
We maintain compliance with
- UK GDPR requirements
- Data Protection Act 2018
- Privacy and Electronic Communications Regulations
- Relevant international data protection laws
17. Third-party services
- 17.1 Payment Processors
Stripe Inc
Privacy Policy: https://stripe.com/privacy
Data processed: Payment information, transaction data
Purpose: Payment processing and fraud prevention
- 17.2 Analytics Services
Google Analytics
Privacy Policy: https://policies.google.com/privacy
Data processed: Usage data, demographics
Purpose: Website analytics and optimisation
Hotjar Ltd
Privacy Policy: https://www.hotjar.com/legal/policies/privacy
Data processed: User behaviour, session recordings
Purpose: User experience analysis
17.3 Cloud Services Amazon web services (AWS)
Privacy Policy: https://amazon.com/privacy
Data Processed: All platform data
Purpose: Cloud hosting and infrastructure
Google Cloud Platform
Privacy Policy: https://policies.google.com/privacy
Data Processed: Platform data and analytics
Purpose: Cloud services and data processing
18. Contact Information
- 18.1 Data Protection Officer
Email: info@premierwincompetitions.co.uk
Post: Data Protection Officer, Premierwin Competitions Ltd, 22 Fowler Street, South Shields, Tyne and Wear, NE33 iNA
- 18.2 Complaints
If you have concerns about our data processing you can:
Contact our Data Protection Officer
File a complaint with the Information Commissioner’s Office (ICO)
ICO website: https://ico.org.uk
ICO helpline: 0303 123 1113
19. Policy Changes
- 19.1 Update Process
We may update this Privacy Policy to reflect
- Changes in applicable laws
- New features or services
- Improved data practices
- Regulatory requirements
- Business changes
- 19.2 Notification of Changes
We will notify you of material changes through
- Email notifications
- Platform announcements
- Website banners
- Account login notifications
- 19.3 Effective Date: Changes become effective
- 30 days after notification (for material changes)
- Immediately for major corrections
- As required by law for regulatory changes
- Upon acceptance for consent-based changes
- 19.4 Previous Versions
Previous versions of this Privacy Policy are archived and available upon request
This Privacy Policy is effective from 28 September, 2025 and supersedes all previous versions.