Free postal entry on every raffle · how it works
Legal

Privacy policy

Effective date: 10 Oct 2025

Tomboly — Privacy Policy (UK)

This Policy explains what personal data we collect, why and how we use it, who we share it with, your rights and how to contact us.

1) Who we are

Controller: AZENTRA GROUP LTD (Company No. 16745724), 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

Privacy contact: privacy@tomboly.io • Supervisory authority: UK Information Commissioner's Office (ICO).

We do not sell your personal data and we do not allow third parties to market to you without your consent.

2) What is Tomboly

Tomboly is a skill-based competition platform where users purchase Entries to enter competitions and shop for products. Each competition requires a correct skill answer and offers a free postal entry route.

3) Personal data we collect

  • Account & identity: name, date of birth (18+), UK address, email, optional phone.
  • Verification (AYV/KYC): age/address checks before the first entry/top-up and before prize dispatch; we do not create biometric templates.
  • Wallet & transactions: Entry purchases, entries, refunds/credits, shop orders, delivery details.

4) Purposes & lawful bases

  • Create & manage your account — Examples: Sign-up, login, one-person-one-account controls · Lawful basis: Contract; Legitimate interests (platform integrity)
  • Verification (AYV/KYC) — Examples: Age/address checks; prize verification · Lawful basis: Legal obligation; Contract; Legitimate interests
  • Competitions & shop — Examples: Entries (after skill gate), draws, dispatch, returns, Entries re-credits · Lawful basis: Contract; Legitimate interests
  • Payments & fraud controls — Examples: 3-D Secure/SCA, velocity & BIN checks, chargebacks · Lawful basis: Legal obligation; Legitimate interests
  • Customer support & complaints — Examples: Email support, audits, dispute handling · Lawful basis: Contract; Legitimate interests
  • Email marketing — Examples: Newsletters, similar products/services (no SMS) · Lawful basis: Consent or soft opt-in (PECR); opt out anytime
  • Analytics & advertising — Examples: GA4, Meta Pixel (non-essential) · Lawful basis: Consent (PECR/UK GDPR)
  • Compliance & enforcement — Examples: Audit trail, sanctions, court/regulator requests · Lawful basis: Legal obligation; Legitimate interests

5) Automated decisions & profiling

We use automated checks (e.g., fraud scoring, velocity/card-testing detection, basic geolocation/VPN checks) that may affect your ability to enter or pay. Where decisions have legal or similarly significant effects, you have the right to obtain human review, express your view and contest the decision. Contact privacy@tomboly.io.

6) Who we share data with

  • Hosting (e.g., AWS), payment service providers/acquirers (3-D Secure/SCA), email/CRM (e.g., Mailchimp), analytics/ads (GA4, Meta Pixel — only after consent), logistics/couriers (Royal Mail/DPD/DHL).
  • Auditors or independent witnesses for draws, regulators/courts when required, professional advisers (legal, tax, compliance).
  • We do not permit third-party direct marketing without your consent.

7) International transfers

We aim to store/process data in the UK (and, where necessary, in the EEA). If we transfer data outside the UK/EEA, we use approved safeguards (e.g., UK IDTA or the UK Addendum to the EU SCCs).

8) Retention

  • Account & transactional records: 6 years after account closure (tax/contract).
  • KYC/verification records: 5 years from end of relationship/transaction (due diligence).
  • Draw/audit logs: 24 months.
  • Postal Free Entry originals: up to 12 months (securely stored).
  • Marketing consent records: duration of consent + 24 months.
  • Cookies/analytics: per Cookie Policy and consent settings.

9) Security

  • TLS in transit; encryption at rest for core stores; least-privilege access.
  • Rate limiting, CAPTCHA, device fingerprinting; 3-D Secure & BIN checks.
  • Logging/monitoring; periodic testing and patching.

10) Your rights

  • Access, rectification, erasure, restriction, portability and objection (including to direct marketing).
  • Where we rely on consent, you can withdraw it at any time (does not affect prior processing).
  • Rights related to automated decisions with legal or similarly significant effects.
  • To exercise your rights, contact privacy@tomboly.io; we may need to verify your identity.

11) Marketing & refer-a-friend

We send service emails. For marketing emails we rely on consent or the PECR soft opt-in for similar products/services; opt out any time via the unsubscribe link. Refer-a-friend emails are user-initiated; invitees only receive ongoing marketing if they register and consent.

12) Cookies & consent

We use strictly necessary cookies to run the site. Non-essential cookies (analytics, advertising, optionally functional) are used only with your consent via our consent banner/CMP. See our Cookie Policy for details.

13) Changes

We may update this Policy for legal/technical/business reasons. We will highlight material changes on site and, where appropriate, notify by email.

14) Contact & complaints

Questions or requests: privacy@tomboly.io. You can complain to the ICO (www.ico.org.uk). We'd appreciate the chance to resolve concerns first.