How we collect, use and protect your personal data in compliance with UK GDPR.
Last updated: 27 February 2026
This Privacy Policy explains how Nitrous Competitions Ltd ("we", "us", "our") collects, uses, stores, shares, and protects your personal data when you use our website nitrouscompetitions.com ("the Website") and our services.
Nitrous Competitions Ltd is the Data Controller responsible for your personal data. We are registered in England and Wales under Company Number 11316541, with our registered office at Unit A - 82 James Carter Road, Mildenhall, Bury St. Edmunds, IP28 7DE.
We are committed to protecting your privacy and processing your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using our Website and services, you acknowledge that you have read and understood this Privacy Policy. We encourage you to review this policy regularly, as it may be updated from time to time.
We collect and process the following categories of personal data:
| Data Category | Details | Purpose |
|---|---|---|
| Account Data | Full name, email address, date of birth, telephone number, postal address, password (encrypted) | Account creation, age verification, Prize delivery, communication |
| Transaction Data | Purchase history, ticket numbers, payment method details (processed via third-party provider), order amounts, competition entries | Processing entries, order fulfilment, refund handling, financial records |
| Technical Data | IP address, browser type and version, operating system, device type, screen resolution, time zone, referring URL | Website functionality, security, fraud prevention, analytics |
| Usage Data | Pages visited, time spent on pages, click patterns, competition views, search queries, navigation paths | Website improvement, personalisation, performance analysis |
| Marketing Preferences | Email opt-in/opt-out status, communication preferences, social media interactions | Sending marketing communications, managing consent |
We collect personal data directly from you when you:
We automatically collect certain technical and usage data when you visit the Website through:
We may receive personal data about you from third parties, including:
Under UK GDPR, we must have a valid legal basis for processing your personal data. The legal bases we rely on are:
We process your data where it is necessary for the performance of a contract with you, including:
We process your data where we have a legitimate business interest to do so, provided that our interests are not overridden by your rights and freedoms. This includes:
Where we rely on your consent, we will ask for it explicitly. You may withdraw consent at any time. We rely on consent for:
We process your data where it is necessary to comply with a legal obligation, including:
We use your personal data for the following purposes:
We may send you marketing communications about our competitions, offers, and services. We will only do so where:
Every marketing email we send includes a clear unsubscribe link. You can opt out of marketing communications at any time by:
Opting out of marketing will not affect transactional communications (e.g., order confirmations, draw notifications, and prize claim correspondence), which are necessary for the performance of our contract with you.
We may share your personal data with the following categories of third parties:
We share transaction data with our payment service providers (e.g., Stripe, PayPal) to process your payments securely. These providers act as independent data controllers and process your payment data in accordance with their own privacy policies and PCI DSS (Payment Card Industry Data Security Standard) requirements.
For physical prize delivery, we share your name and delivery address with our logistics and courier partners. These partners process your data solely for the purpose of delivering your prize.
We use third-party analytics services (such as Google Analytics) and marketing platforms (such as Facebook Ads and Google Ads) that may process your data for website analytics and targeted advertising. Where possible, we anonymise or pseudonymise data before sharing.
We may disclose your personal data where required to do so by law, regulation, or legal process, including:
In the event of a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your data.
We will never sell your personal data to third parties for their marketing purposes.
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are as follows:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account Data | Duration of your account plus 6 years after account closure | Contractual obligations, legal claims limitation period |
| Transaction Data | 6 years from the date of the transaction | HMRC requirements, Limitation Act 1980, financial record-keeping |
| Technical & Usage Data | 26 months from the date of collection | Analytics, security, and performance monitoring |
| Marketing Preferences | Until you opt out, plus a record of your opt-out retained indefinitely | Managing your communication preferences and demonstrating compliance |
| Winner Verification Data | 6 years from the date of prize fulfilment | Legal and tax compliance, dispute resolution |
When data is no longer required, we will securely delete or anonymise it in accordance with our data disposal procedures.
Under the UK General Data Protection Regulation, you have the following rights in relation to your personal data:
You have the right to request a copy of the personal data we hold about you (known as a "Subject Access Request"). We will respond to your request within one calendar month of receiving it, free of charge. In exceptional circumstances (e.g., complex or numerous requests), we may extend this period by a further two months, but we will inform you of any extension within the first month.
You have the right to request that we correct any inaccurate personal data we hold about you, or complete any incomplete data. You can update most of your account information directly through your account settings. For other corrections, please contact us.
You have the right to request that we delete your personal data in certain circumstances, including where:
Please note that we may not be able to comply with your request if we are required to retain the data for legal or regulatory purposes, or for the establishment, exercise, or defence of legal claims.
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data, where the processing is unlawful, or where you have objected to processing pending verification of legitimate grounds.
Where we process your data based on consent or for the performance of a contract, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another data controller.
You have the right to object to the processing of your personal data where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.
You have an absolute right to object to the processing of your personal data for direct marketing purposes at any time.
Where we process your personal data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent supervisory authority for data protection:
We would, however, appreciate the opportunity to address your concerns before you approach the ICO, so please contact us first.
To exercise any of the above rights, please contact us at info@nitrouscompetitions.com. We may need to verify your identity before processing your request. We will respond to all legitimate requests within one calendar month.
We primarily store and process your personal data within the United Kingdom and the European Economic Area (EEA).
Where it is necessary to transfer your data outside the UK (for example, where a third-party service provider is based outside the UK), we will ensure that appropriate safeguards are in place to protect your data, including:
You may request further details of the safeguards we have in place for international data transfers by contacting us.
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:
While we take all reasonable precautions, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data to the highest possible standard.
Our Website uses cookies and similar tracking technologies to distinguish you from other users, to remember your preferences, and to enhance your experience on the Website.
For detailed information about the cookies we use, the purposes for which we use them, and how you can manage your cookie preferences, please see our Cookie Policy.
You can control and manage cookies through your browser settings at any time. Please note that disabling certain cookies may affect the functionality of the Website.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data. Your continued use of the Website after any changes constitutes your acceptance of the updated policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:
We aim to respond to all privacy-related enquiries within 48 hours during normal business hours (Monday to Friday, 9:00am to 5:00pm). Formal data subject requests will be responded to within one calendar month in accordance with UK GDPR requirements.