Privacy Policy (Including UK-GDPR)
We protect your data. This Privacy Policy sets out how Prize Drop (“we”, “us”, or “our”), registered at *Address*, collects, processes, stores, and discloses your personal information.
We are committed to handling your information in compliance with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and other relevant data protection laws. Before using our website, please read this policy to understand how and why we process your data.
Last Updated: October 2025
This Document Explains
- What personal data we may collect about you
- How we collect, store, and protect your data
- The purposes for which your data is processed
- Your legal rights under data protection laws
If you have any questions or concerns about this policy, please contact us at info@prizedrop.uk
The Personal Data We Process
We collect personal data when you interact with our website, enter competitions, subscribe to updates, or contact us. This may include your full name, address, country, contact details, competition entries, and technical information obtained via cookies.
The Purposes for Which We Process Your Data
- Confirming entries and sending competition updates
- Processing entry payments and notifying winners
- Personalising your experience and providing support
- Sending promotional materials (if you have opted in)
- Administering events and services you subscribe to
Lawful Basis for Processing
We process your personal data under the following lawful bases:
- Consent – when you opt in to receive marketing or create an account.
- Contract – when processing is necessary to fulfil a competition entry or deliver a prize.
- Legal obligation – when required by law or regulation.
- Legitimate interests – to operate and improve our services, prevent fraud, and ensure fair participation.
If You Refuse to Provide Personal Data
Where we must collect personal data by law or under the terms of an agreement with you, and you fail to provide that data when requested, we may be unable to perform our obligations (for example, to deliver your prize). In such cases, we may have to cancel the prize and select another winner, though we will notify you first.
Sharing Information with Affiliates and Third Parties
We do not share your personal data with third parties except as described in this policy, or where you have otherwise agreed. We may share data with our trusted partners (“Affiliates”) to provide services and perform legitimate business operations. This includes providers for email delivery, payment processing, analytics, hosting, marketing, logistics, and technical integration.
All third parties processing your data follow strict data protection procedures in compliance with applicable law. Unless otherwise stated, we remain the data controller for your information even where third parties act as processors.
Your Rights as a Data Subject
- The right to request a copy of your data held by us (free of charge).
- The right to correct any inaccurate or incomplete personal data held by us.
- The right to request that we erase the personal data we hold about you.
- The right to request that we restrict the processing of your data.
- The right to object to certain types of processing of your data by us.
- The right to lodge a complaint with the Information Commissioner’s Office (ICO).
Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. While no online system is completely secure, we maintain strong safeguards to ensure the confidentiality and integrity of your data.
Storage and Retention of Your Data
We store your data for as long as necessary to provide our services and up to twelve months after the promotional period of the relevant competition or contest. If you request account deletion, we will erase your data once it is no longer required to fulfil obligations or comply with legal requirements.
Links to Third-Parties
Our website may contain links to third-party websites beyond our control. Please review their respective privacy policies before providing any personal data. We cannot be held responsible for the practices of third-party websites.
Cookies
Our website uses cookies to distinguish you from other users, improving your experience and allowing us to enhance website performance. You can manage or block cookies via your browser settings, though blocking essential cookies may affect site functionality.
Prize Drop (GDPR) Statement
Prize Drop is registered as a Data Controller with the Information Commissioner’s Office (ICO), registration reference: 245603. We have implemented internal policies and controls to ensure full compliance with GDPR and UK data protection regulations.
GDPR Activity Overview
Prize Drop activities fall within three key areas:
- A data controller of its own employee data.
- A data controller or processor of third-party data such as activity relating to direct marketing.
- A data processor or controller of customer personal data.
We have designed our company policies and procedures to ensure full GDPR compliance, including reviews of all data handling and security protocols.
What We Need and Why
We collect personal data such as name, age, address, phone number, and email address to verify eligibility, process competition entries, and deliver prizes to winners. We will not collect any data that we do not need to provide our services.
What We Do With It
All data is processed within the UK, and all servers we use are based in the UK. We may share data with trusted third-party service providers such as email delivery, website analytics, logistics, and social media platforms, all of which maintain GDPR-compliant policies and procedures.
Frequently Asked Questions
What personal data do you process?
We process any data relating to an identifiable person, such as name, age, address, phone number, and email.
For what purpose do you process this data?
Data is collected for legitimate purposes, including running skill, judgment, or knowledge-based competitions and verifying eligibility.
What are the risks to data subjects’ rights?
We believe risks are minimal due to secure storage and limited data sharing. Potential risks include loss, alteration, or unauthorised access, which we mitigate through strict internal security controls.
What provisions do you have for deletion?
When requested, we delete or return data after verifying the request. Otherwise, we retain data for 12 months from last contact for legitimate business purposes.
Do you understand GDPR requirements?
Yes. Prize Drop fully understands and complies with GDPR requirements and their impact on our customers and business operations.
Access to Your Information
You have the right to access the personal data we hold about you. Requests can be made free of charge by emailing info@prizedrop.uk If any information we hold about you is incorrect, please contact us so we can promptly update or correct it.
