Privacy Policy

Introduction
DiamondWins.co.uk (“we,” “our,” or “us”) is a prize-draw raffle competition website offering participants the chance to win high-value natural diamond jewellery. Tickets for each draw start at £1. By participating in our prize draws or otherwise using our website, you agree to the terms of this Privacy Policy, which explains how we collect, use, disclose, and protect your personal data in compliance with UK data protection laws, including the UK GDPR and Data Protection Act 2018. YouTube

Data Controller
For the purposes of UK data protection law, the data controller responsible for your personal data is:

DiamondZee Ltd
Registered office: Peel House Peel Hall Business Village, Peel Road, Blackpool, Lancashire, England, FY4 5JX
Company number: 13897661
Contact email: contact@diamondwins.co.uk

1. Personal Data We Collect
1.1 Identity Information:

  • Full name

  • Date of birth (to verify eligibility, minimum age 18)

1.2 Contact Information:

  • Email address (for account creation, draw confirmations, marketing opt-ins)

  • Postal address (for prize delivery and eligibility verification)

  • Telephone number (optional – for customer support)

1.3 Payment and Billing Information:

  • Payment method details (e.g., debit/credit card details processed via our third-party payment processors)

  • Billing address (to facilitate secure payment processing)

1.4 Technical and Usage Data:

  • IP address

  • Browser type and version

  • Operating system

  • Device type

  • Date and time of access

  • Pages viewed and actions taken on the Site

1.5 Marketing and Communications Data:

  • Preferences for receiving newsletters, promotional offers, or other communications

  • Records of consents you have provided (e.g., via opt-in checkboxes)

2. How We Collect Your Personal Data
2.1 Directly from You:

  • When you register for an account, enter a prize draw, subscribe to newsletters, or contact us for support.

2.2 Automatically via Our Website:

  • Cookies, web beacons, and similar tracking technologies collect technical and usage data as you navigate the Site (see Section 5).

2.3 From Third Parties:

  • We may obtain identity and contact information from payment processors (e.g., Stripe or PayPal) when you make a purchase of draw tickets.

  • We may receive limited demographic or geographic data from analytics providers (e.g., Google Analytics) to analyse Site performance.

3. Purposes for Processing and Legal Bases
We process your personal data for the following purposes and rely on the corresponding legal bases under UK GDPR:

3.1 To Facilitate Prize Draw Participation and Order Fulfilment

  • Purpose: Register your account; process ticket purchases; verify eligibility (age, postcode); notify winners; arrange prize delivery.

  • Legal Basis: Performance of a contract (you enter into a contract to purchase draw tickets and participate) and compliance with our legal obligations (e.g., proving fair conduct of the draws).

3.2 To Communicate with You

  • Purpose: Send transactional emails (e.g., registration confirmation, payment receipts, draw results), respond to inquiries, provide customer support.

  • Legal Basis: Necessary for performance of our contract with you and our legitimate interest in maintaining customer relations.

3.3 To Send Marketing and Promotional Communications

  • Purpose: Provide you with newsletters, special offers, or promotions if you have opted in.

  • Legal Basis: Your explicit consent (which you can withdraw at any time, see Section 8).

3.4 To Improve Our Site and Services

  • Purpose: Conduct analytics, track user behaviour, and optimise Site performance, layout, and user experience.

  • Legal Basis: Our legitimate interest in understanding how users interact with our Site (so we can continually improve our services) UsercentricsUsercentrics.

3.5 To Comply with Legal Obligations

  • Purpose: Maintain records for tax, accounting, and auditing; cooperate with legal investigations or law enforcement requests.

  • Legal Basis: Compliance with a legal obligation.

4. Sharing Your Personal Data
We may disclose your personal data to the following categories of recipients, strictly for the purposes set out herein:

4.1 Payment Processors:

  • We use reputable third-party payment service providers (e.g., Stripe, PayPal) to process your ticket purchases. These providers require your billing information to complete transactions securely.

4.2 Delivery and Fulfilment Partners:

  • For prize delivery, we share your name and postal address with our chosen courier or fulfilment partner.

4.3 Analytics and Advertising Providers:

  • We use Google Analytics (or similar services) to analyse Site traffic and user behaviour. These providers may use cookies and tracking technologies to collect technical and usage data.

  • We may allow advertising networks (e.g., Facebook Pixel, Google Ads) to collect and process technical data to run targeted campaigns.

4.4 Email Marketing Service Providers:

  • If you opt in to receive marketing communications, we share your email address with our email marketing service (e.g., Mailchimp) to facilitate newsletters and promotional emails.

4.5 Legal and Compliance Advisors:

  • We may share your data with legal counsel, auditors, or regulatory authorities to respond to legal requests, enforce our Terms & Conditions, or otherwise comply with applicable laws.

5. Cookies and Similar Technologies

5.1 What Are Cookies?
Cookies are small text files placed on your device to collect standard internet log information and visitor behaviour information.

5.2 Types of Cookies We Use:

  • Essential Cookies: Necessary for basic Site functionality (e.g., session cookies that keep you logged in until you log out).

  • Performance and Analytics Cookies: Collect information about how visitors use our Site (e.g., pages visited, errors encountered). We use Google Analytics for this purpose YouTubeUsercentrics.

  • Functional Cookies: Remember your preferences (e.g., language or currency choices).

  • Advertising/Targeting Cookies: Used by third parties (e.g., Facebook, Google Ads) to deliver relevant advertisements both on our Site and elsewhere on the internet if you have consented.

5.3 How to Control Cookies:

  • You can set your browser to refuse all or some cookies or to alert you when cookies are being sent. However, if you block or refuse cookies, some parts of the Site may become inaccessible or not function properly.

6. International Transfers
6.1 Data Hosting and Transfer Locations:

  • We host our servers and data primarily within the UK.

  • Some of our third-party service providers (e.g., email, analytics, payment processors) may store or process data outside the UK or European Economic Area (EEA).

6.2 Safeguards:

  • When transferring data outside the UK/EEA, we rely on approved transfer mechanisms, such as Standard Contractual Clauses, or where applicable, organisations that have certified under the UK-EU Addendum to the EU-US Data Privacy Framework.

7. Data Retention
7.1 Retention Periods:

  • Account and Transaction Data: Retained for as long as your account remains active and for a period of seven years after our last communication to meet legal and financial record-keeping obligations.

  • Marketing Data: Retained until you withdraw consent or unsubscribe.

  • Analytical and Technical Data: Aggregated data is retained indefinitely for statistical purposes; individual session data is retained for up to 26 months.

7.2 Deletion and Anonymisation:

  • When retention periods expire, or if you request erasure (see Section 8), we will delete or anonymise your personal data unless legal reasons require otherwise (e.g., fraud investigations, tax audits).

8. Your Rights Under UK GDPR
You have the following rights regarding your personal data:

8.1 Right to Be Informed:

  • You have the right to transparent information about how and why we process your data (as outlined in this Privacy Policy).

8.2 Right of Access:

  • You can request a copy of the personal data we hold about you. We will provide this within one month of your request, subject to verification.

8.3 Right to Rectification:

  • If you believe any data we hold about you is inaccurate or incomplete, you have the right to request correction.

8.4 Right to Erasure (“Right to be Forgotten”):

  • You can request deletion of your personal data where there is no overriding legal requirement to retain it.

  • We may refuse to erase data if required to keep it for legal or regulatory obligations.

8.5 Right to Restrict Processing:

  • You may request that we suspend processing of your personal data (e.g., while verifying an accuracy dispute).

8.6 Right to Data Portability:

  • Where processing is based on consent or contract and carried out by automated means, you can request transfer of your data to yourself or a third party.

8.7 Right to Object:

  • You can object to our processing of your personal data if that processing is based on our legitimate interests (e.g., direct marketing).

8.8 Right to Withdraw Consent:

  • If you have given us consent to process your data (e.g., for marketing), you may withdraw that consent at any time by emailing privacy@diamondwins.co.uk or clicking “unsubscribe” in any marketing email.

8.9 How to Exercise Your Rights:

  • To exercise any of these rights, please contact us at contact@diamondwins.co.uk with “Data Subject Rights Request” in the subject line. We may need to verify your identity before fulfilling your request.

9. Children’s Privacy
Our Site is intended for users 18 years or older. We do not knowingly collect or solicit personal data from anyone under the age of 18. If we become aware that a user under 18 has provided personal data, we will delete such data immediately.

10. Security of Your Data
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (HTTPS) and, where appropriate, at rest.

  • Access controls limiting data access to authorised personnel only.

  • Regular security assessments and vulnerability scanning.

Although we strive to use commercially acceptable measures, no method of transmission or storage is 100% secure.

11. Third-Party Links and Services
Our Site may contain links to third-party websites, plug-ins, or services not operated by us (e.g., social media platforms, payment gateways). This Privacy Policy does not apply to those third parties. We encourage you to review their privacy policies before providing any personal data.

12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our data practices or legal requirements. We will post the updated policy on diamondwins.co.uk with a revised “Last Updated” date. Material changes will be communicated by email (if you have an account) or via a notice on our Site at least 30 days before they take effect.

13. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, or if you wish to lodge a complaint, please contact our Data Protection Officer (DPO) at:

DPO, DiamondZee Ltd
Email: contact@diamondwins.co.uk
Postal address: Peel House, Peel Hall Business Village, Peel Road, Blackpool, Lancashire, England, FY4 5JX

If you remain dissatisfied after contacting us, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).

Last Updated: 2 June 2025