Aperçu du document
How GRZ Gaming handles personal information
Grz Gaming Limited, trading as GRZ Gaming, is responsible for the personal information described in this Policy. This document explains the information we collect, why and how we use it, how it may be shared, how long it is kept, and the rights available to you.
01Information We Collect From You — Who We Are and the Scope of This Policy
Grz Gaming Limited , trading as GRZ Gaming (“we”, “us” or “our”), is responsible for the personal information described in this Policy. We are registered in England and Wales under company number 13086814 , with our registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom .
We act as the controller where we decide why and how your personal information is used. You can contact us about privacy at support@grzgaming.com , through Live Support on grzgaming.com , or by post to our registered office, marked “Privacy”.
This Policy covers visitors, account holders, customers, intended recipients of purchases, and people contacting or representing a business dealing with GRZ Gaming. It applies to grzgaming.com and other GRZ Gaming portals that expressly display or adopt this Policy. It covers our digital gift cards, prepaid vouchers, wallet cards, gaming subscription cards, redeem codes, in-game currency and direct game top-up services.
“Personal information” or “personal data” means information relating to an identified or identifiable person. Information about a business may also be personal information when it identifies a director, owner, representative or other individual.
This Policy explains our data handling; it is not a request for blanket consent . Visiting the website, registering, making a purchase or accepting our Terms does not automatically authorise optional marketing, advertising tracking, biometric recognition or every other use of your information.
Our Terms and Conditions, Refund Policy & Disclaimer, and KYC, Anti-Money Laundering and Counter-Terrorist Financing Policy explain the relevant service and verification rules. They do not override your data protection rights. Where a particular feature needs additional privacy information, we will provide it before the relevant collection or use.
02Why We Collect Data From You
We collect information for specific purposes and use an appropriate lawful basis for each purpose. The main bases are performance of a contract with you, compliance with a legal obligation, legitimate interests, and consent. We do not rely on all of these interchangeably for every activity.
1. Create and manage your account; process orders; supply codes and top-ups; manage rewards you choose to use
Relevant information: Account and contact details, product selections, recipient identifiers, order and delivery records
Main lawful basis: Performance of our contract with you or steps you request before entering it. For a recipient who is not our contracting customer, legitimate interests in carrying out the requested delivery, subject to their rights.
2. Process payments, refunds and order-related support
Relevant information: Payer and billing details, transaction references, payment status, order records and relevant correspondence
Main lawful basis: Performance of our contract with you; legal obligations for records or remedies where applicable.
3. Assess a business or reseller relationship and communicate with its representatives
Relevant information: Business information, representative details, authority and relevant ownership information
Main lawful basis: Legitimate interests in establishing and managing genuine business relationships; contract where the individual is themselves a contracting party.
4. Verify identity and payment ownership; assess fraud, sanctions and financial-crime concerns; protect accounts and services
Relevant information: Necessary verification evidence, screening results, account, device, payment and transaction information
Main lawful basis: Legal obligation where a specific requirement applies to GRZ Gaming. Otherwise, legitimate interests in preventing misuse, protecting customers and assessing transaction risk, with an assessment of necessity and your rights.
5. Maintain necessary tax and accounting records; respond to lawful official requirements and privacy requests
Relevant information: Relevant transaction, correspondence, identification and compliance records
Main lawful basis: Compliance with applicable legal obligations.
6. Investigate complaints, resolve disputes and establish or defend legal claims
Relevant information: Relevant account, transaction, support and investigation records
Main lawful basis: Legitimate interests in fair dispute resolution and protecting legal rights; legal obligation where a binding requirement applies.
7. Operate, secure and improve the website and support services
Relevant information: Necessary technical logs, service interactions and feedback
Main lawful basis: Legitimate interests in providing a reliable and secure service. Optional analytics and tracking are subject to the consent rules in Section 6.
8. Send optional marketing; use optional analytics, advertising or similar tracking
Relevant information: Contact preferences, consent records, relevant interaction and device information
Main lawful basis: Consent where required. A lawful existing-customer marketing exception may be used only under the conditions explained in Section 7.
9. Administer voluntary surveys, competitions, promotions and initial recruitment enquiries
Relevant information: Information relevant to the activity, entry, response or application
Main lawful basis: Contract where needed to run an activity you enter; otherwise legitimate interests in administering the activity. Optional publicity or additional marketing requires the appropriate permission. Further recruitment information is provided when needed.
Where we rely on ordinary legitimate interests, we assess whether the processing is necessary and whether your interests, rights or freedoms override those interests, with particular care for children. You may object as explained in Section 11.
A payment provider’s contractual requirement does not, by itself, become a statutory legal obligation on GRZ Gaming. Similarly, adopting an AML policy does not mean that every statutory AML obligation applies to every purchase.
If a purpose involves special-category information or criminal-offence information, an ordinary lawful basis alone is not enough. The additional conditions described in Section 5 must also be satisfied.
03Children’s Privacy
Children’s information requires particular care. Children under 13 should not independently register an account or submit personal information to us. A parent or guardian may make a permitted purchase in their own name and provide only the recipient information needed to fulfil it, subject to our Terms, the product rules and applicable law.
Where we rely on consent for an online service offered directly to a child, we obtain and reasonably verify parental authorisation where the law requires it. The relevant age and requirements can differ by country. A parent’s disclosure of a child’s information does not automatically constitute consent to every use of that information.
We do not knowingly direct marketing to children under 13. Where we know a user is a child, we take their age and interests into account when assessing data collection, privacy settings, marketing and profiling. We do not treat an age statement as a substitute for safeguards required by applicable law.
A parent or guardian who believes a child’s information has been collected improperly should contact us. We will assess the circumstances, stop any processing that lacks a lawful basis and delete information that we have no lawful reason to retain. Any necessary protective, transaction or legal record will be limited to its justified purpose.
04When We Collect Your Personal Information
We collect information when you register or manage an account; place an order; make or query a payment; request a refund; complete a verification check; contact support; submit a complaint, review or other content; choose marketing preferences; or participate in an available survey, competition or loyalty programme.
We also collect relevant information when you browse the website. Optional cookies, pixels and similar technologies are governed by Section 6, not merely by your decision to visit a page.
Where offered, social sign-in provides the information you authorise the relevant service to share, such as your name, email address, profile image and account identifier. We do not obtain your social-account password through that connection.
Information may also come from payment providers and banks; product suppliers and game platforms confirming delivery; verification and fraud-prevention providers; lawful public registers and official sanctions sources; and relevant, reliable public information used for a justified risk assessment. A purchaser may supply a recipient’s game account identifier, and a business may supply information about its representatives, directors or owners.
We may receive information from an authorised representative, a complainant or a competent authority. We do not assume that publicly accessible information is unrestricted or necessarily accurate. Where we obtain your information indirectly, we provide the required privacy information within the applicable legal timeframe unless a specific lawful exception applies.
05What Personal Data We Collect
The information depends on the service, payment method and risk involved. Not every customer is asked for every category below.
Account and contact information: name, username, email address, telephone number, billing or residential address, country, language, account preferences and authentication records. Date of birth or age-related information is requested only where relevant to eligibility, verification or a legal requirement.
Orders, products and recipients: products and denominations selected; order and transaction references; dates, amounts and currencies; delivery and redemption-related records where available; game or platform account identifiers, server, region and character or account name; refunds, paid balances, rewards and relevant order history.
Payment information: payer identity, billing details, payment method and provider, transaction identifiers, status, authentication or risk results, and masked or tokenised payment references made available through the payment flow. Relevant bank or wallet identifiers and redacted proof of a payment may be needed for a payment-ownership check or lawful refund.
Identity and due-diligence information: where required under our KYC/AML Policy, legal name, date of birth, address, country of residence, relevant identity-document details or copies, proof of address, verification results and case correspondence. A proportionate enhanced check may include evidence of the source of funds or wealth, relevant bank statements, income records, business accounts or documents supporting the explanation provided.
Business verification information: entity registration and trading details, representative authority, directors and ultimate owners or controllers, intended purchasing or resale activity and relevant funding evidence. Information about an identifiable person remains protected even when supplied for a business account.
Technical and usage information: IP address, approximate location inferred from it, browser and device characteristics, operating system, language and timezone, page and service interactions, referral information, timestamps, errors and security events. Device or session identifiers may be used for the purposes and subject to the tracking choices described below.
Communications and contributions: messages, complaints, support records, attachments relevant to your request, reviews and other content you choose to submit. If a call or live verification session is to be recorded, we will explain the recording and its purpose beforehand and meet any applicable consent requirement.
Preferences and activity: marketing and cookie choices, consent or withdrawal records, survey responses, competition entries and participation in available reward activities. For an initial job enquiry, this may include your CV, experience and contact details; additional applicant information will be explained separately.
Sensitive information and verification images
An identity photograph or live check is not permission to use your face for other purposes. If a verification method uses biometric recognition to identify you, we will first give you a specific notice explaining the provider, information used, purpose, applicable legal grounds, retention and available alternatives. Where explicit consent is relied upon, it must be obtained separately and there must be a genuine, suitable non-biometric alternative. Biometric recognition must not begin without a valid additional legal condition and the necessary safeguards.
Financial-crime enquiries can sometimes involve allegations, suspected offences or other specially protected information. We process criminal-offence information only with the authority or additional condition required by law. Where relevant and all conditions are satisfied, UK law may permit processing necessary to prevent or detect unlawful acts, prevent fraud, address suspected money laundering or terrorist financing, or deal with legal claims. We establish the condition and any required policy documentation before processing. A screening alert or allegation is not proof of wrongdoing.
Please do not supply unrelated health information, political or religious beliefs, full financial histories or another person’s private information. Follow the verification instructions for permitted redactions. We restrict and minimise inadvertently received sensitive information rather than treating its receipt as unrestricted permission to use it.
06How We Collect Information — Cookies, Payments and Website Features
Direct submission and secure verification
Information is collected through account and order forms, communications and the approved verification route. Identity documents and financial evidence must not be sent through ordinary email, public reviews, social media or general live-chat attachments. Contact support for secure submission instructions.
Payment details
Enter payment credentials only in the authorised checkout or payment-provider flow. Depending on the method, the provider may collect the card number, expiry date, security code or other payment credentials needed to authorise the transaction. GRZ Gaming uses the transaction, payer, billing and masked or tokenised references relevant to administering the payment and assessing risk.
We do not retain card security codes such as CVV/CVC after authorisation, or request them for support or identity verification. Never send support a full card number, card PIN, banking password, one-time authentication code, cryptocurrency private key or recovery phrase. Approved card evidence must conceal every card-number digit except the last four and fully conceal the security code.
A provider’s own privacy notice applies to processing for which it is independently responsible. The involvement of a provider does not remove our responsibility for information that we collect or control.
Cookies and similar technologies
Cookies, local storage, pixels and similar technologies may support sign-in, shopping baskets, security and user preferences, or measure use and advertising performance. Their names, providers, purposes and durations must be explained in the privacy or cookie information presented with the relevant feature.
Technologies genuinely necessary to provide a service you request, or to perform an essential security function within the applicable legal exception, do not require the same optional consent. A technology is not “necessary” simply because it benefits our business, and an essential-security label does not authorise unrelated advertising use.
Our policy is to obtain prior consent for optional analytics and advertising technologies. When these options are offered, you must be able to accept, reject or manage them and later withdraw consent as easily as you gave it. Refusing optional tracking does not, by itself, prevent an ordinary purchase. Some optional embedded features may remain inactive until you choose to enable them.
These rules also apply to relevant tracking pixels in marketing emails and to optional advertising measurement or audience-matching features. Where enabled with the required permission, such features may send identifiers and purchase or interaction events to an advertising platform to measure our campaigns or show relevant GRZ Gaming advertising. Sending data from a server, or hashing an identifier, does not automatically remove privacy obligations or make the information anonymous.
Consent to receive marketing messages is separate from consent to optional website or email tracking. Browser settings may also control storage, but deleting a cookie alone may not withdraw a marketing subscription or every preference held by us. Contact us if you cannot find or use a relevant privacy control.
Logs, devices and location
Necessary server and security logs help us operate the service and investigate misuse. Optional behavioural analytics is handled separately under the consent rule above. An IP-based location estimate is not precise GPS tracking. Any feature requesting precise device location must explain why and obtain the permission required for that feature before accessing it; this Policy is not permission for continuous GPS monitoring.
Public content and third-party tools
Reviews and other contributions intended for publication, together with the display name and information shown with them, may be visible to other visitors. Do not include identity documents, private contact information, passwords or redeemable codes. Content may be moderated under the applicable platform rules; moderation does not remove your privacy rights.
Third-party sign-in, support, analytics or embedded features may involve their providers receiving relevant information. We apply the appropriate notices, permissions and sharing arrangements; a provider’s separate privacy policy is not, by itself, permission to activate optional tracking.
07How We Use Your Information
We use the information relevant to the purposes in Section 2 to fulfil purchases, administer accounts and rewards, provide support, verify payments, protect against misuse, comply with applicable requirements and resolve disputes. Information is not available for unrestricted reuse simply because it was supplied to GRZ Gaming.
Verification, profiling and human review
Where used, payment and fraud tools may compare account details, transaction patterns, device or location indicators, verification results and connected activity. This can produce a risk indicator or recommendation and may trigger additional authentication, a request for evidence, an order hold or a decline. For example, a mismatch between payer information and account details may lead to a payment-ownership check rather than immediate fulfilment.
You may provide correcting information and request human review of a GRZ Gaming verification or account-restriction decision through support. An authorised reviewer must consider the relevant evidence and be able to change our decision where appropriate, rather than simply repeat a tool’s output. A review request does not require release of an order while necessary checks remain unresolved. An independent payment provider’s decision may also require review through that provider.
Where a decision is made solely by automated means and has legal or similarly significant effects, the applicable legal conditions and safeguards must be met. We will provide meaningful information about the relevant process, its main factors and likely consequences, and the opportunity to express your view, contest the decision and obtain human intervention. Additional restrictions apply to specially protected information and where required by the law applicable to you. Confidential fraud thresholds are not a blanket reason to withhold information you are entitled to receive.
Marketing, research and service messages
We distinguish necessary service messages, such as order confirmations, security notices and refund updates, from optional promotions. You cannot stop essential communications for an active order merely by unsubscribing from advertising, but we do not use that distinction to disguise promotions as service messages.
Marketing by email, text or similar electronic message is sent with the required consent, or under a lawful existing-customer exception where every condition is satisfied. For the UK products-and-services exception, this means contact details obtained during a sale or genuine sales negotiation, marketing of our own similar products or services, and a clear opportunity to opt out both when details were collected and in each message. More restrictive rules apply where required by another applicable law.
You can object to direct marketing at any time using the unsubscribe method or by contacting us. We will stop using your information for that marketing, including related profiling, and may keep only the limited suppression information needed to respect your choice. A purchase or account registration does not automatically enrol you in every marketing channel.
We may use relevant feedback and service information to improve the experience, and invite you to voluntary surveys or activities with appropriate notices. Optional personalised advertising and analytics remain subject to Section 6. Identity documents, verification selfies, source-of-funds evidence and confidential compliance case information are not used for advertising audiences or unrelated marketing.
08How Long We Store Your Data
We retain personal information only for as long as needed for its stated purpose, applicable legal obligations or a justified, documented preservation requirement. Different records have different retention needs.
Account records: retained while needed to operate your account and address related requests. Closure or a period of inactivity triggers a review of what remains necessary; it does not justify preserving an entire inactive profile indefinitely.
Transactions and accounting: the necessary order, payment, refund, invoice and accounting records are normally kept for six years from the end of the last company financial year to which they relate to meet UK tax record requirements, or longer where a particular legal requirement or documented preservation need applies. This does not make every identity document, browsing record or support attachment an accounting record.
Verification and compliance: necessary verification outcomes and supporting evidence are retained for the applicable statutory period where statutory AML record-keeping duties actually apply. Otherwise, retention is determined by the need to complete the check, manage a continuing assessed risk and resolve relevant disputes or claims. We review raw identity and financial documents separately from the verification outcome and remove unnecessary copies when that evidence is no longer needed. We do not apply an automatic lifetime KYC retention rule to all customers.
Support and complaints: retained while the matter is being handled and for the justified period needed to evidence its resolution, handle a related dispute or meet a legal requirement. Irrelevant attachments should not be retained merely because they arrived in a support conversation.
Technical records: necessary operational and security logs are retained for their troubleshooting and protection purposes. Specific records may be preserved for a documented incident or claim. Optional tracking lifetimes are explained in the relevant cookie or feature information.
Marketing and consent: preferences and consent evidence are retained while relied upon and as necessary to demonstrate lawful handling. Limited opt-out records may be kept to prevent renewed unwanted contact; that does not justify retaining an entire marketing profile.
Public contributions and voluntary activities: retained for the period relevant to their publication or administration, subject to a valid removal request, moderation and any necessary claim or legal record. Recruitment-specific retention is explained with any further applicant notice.
When information is no longer needed, we securely delete it or make it genuinely anonymous. Restricted backup copies are removed through the applicable backup lifecycle and are not used to continue a discontinued purpose. Where a backup must be restored, relevant deletion and suppression instructions must be reapplied.
Account deletion, consent withdrawal or an objection does not automatically require erasure of every record, and neither does it permit us to retain information merely because we might find it useful. You can ask about the retention criteria relevant to your information.
09What We Request From You
Provide accurate information relevant to your account, purchase or verification, and tell us of important changes. If you supply information about a recipient, representative or other person, ensure that you are entitled to do so, give them this Policy where appropriate and provide only what is necessary. Your submission does not replace any separate permission that person must give.
Some information is necessary to enter or perform an order, verify payment ownership or meet an applicable legal requirement. If it is missing, we may be unable to create an account, fulfil the affected order or complete a required check. We will explain the relevant requirement where lawful. Refusal to complete a check does not automatically forfeit money legally due to you.
Optional marketing, unrelated profiling and unnecessary personal details are not conditions of an ordinary purchase. Do not send extra documents “just in case”. Where a particular verification method is inaccessible to you, contact support about suitable alternatives.
10Privacy and Security
We apply technical and organisational safeguards appropriate to the sensitivity and risks of the information, including access restrictions, secure transmission and appropriate protection of stored records. Verification information is restricted to authorised people who need it for the relevant task. Providers handling information for us must be subject to appropriate confidentiality, security and data-protection requirements.
No online service can promise absolute security. We investigate suspected breaches and make notifications to affected individuals or competent authorities where the law requires them. This does not limit our responsibility to maintain appropriate safeguards.
Protect your password and authentication methods, use secure devices and tell us promptly if you suspect account misuse or an improper request for documents. These precautions do not transfer all security responsibility to you or excuse failures by GRZ Gaming.
Links to an independent website do not mean that we control its practices. Check its privacy information before supplying data. Where we integrate a provider into our own service, we remain responsible for our own collection and disclosure decisions.
11Your Rights
Depending on the applicable law and the circumstances, you may have the right to:
- Access your personal information and receive information about its use.
- Correct inaccurate information and complete information that is incomplete.
- Erase information where there is no continuing lawful basis to retain it, or restrict its processing in qualifying circumstances.
- Receive and transmit data you provided in a structured, commonly used, machine-readable format where the portability conditions apply.
- Object to processing based on legitimate interests, and object at any time to direct marketing and related profiling.
- Withdraw consent without affecting the lawfulness of earlier consent-based processing, and obtain applicable safeguards for significant solely automated decisions.
- Complain to us, to the relevant data protection authority, or seek a judicial remedy where available.
Your right to object to direct marketing is not conditional on explaining why. For other legitimate-interest processing, we assess your objection and stop unless there are overriding legitimate grounds or another basis for continuing that is permitted by law, such as necessary legal-claims processing.
Rights are subject to applicable conditions and specific exemptions. For example, an accounting requirement may prevent deletion of a necessary transaction record. Any restriction must be justified for the particular information and request; “KYC”, “AML” or “fraud prevention” is not an automatic exemption from all rights.
We do not require you to surrender a refund, withdraw a legitimate payment dispute or close your account merely to exercise a privacy right.
12Disclosure of Your Information and International Processing
Who may receive information
We share only information appropriate to the relevant purpose and with a lawful basis. Recipients may include:
Payment providers, banks and payment networks , to process or authenticate payments, confirm ownership, manage refunds, prevent fraud and resolve disputes.
Product suppliers, distributors, issuers and game platforms , to deliver or investigate a purchase. A direct top-up may require your player identifier, server, region and ordered amount; this does not make your full identity-verification file necessary for routine delivery.
Verification, screening and fraud-prevention providers , to perform relevant identity, payment-ownership, sanctions or risk checks and investigate misuse.
Hosting, infrastructure, security, communications and customer-support providers , to operate the website, protect information and manage messages or support. Optional analytics and advertising providers receive information only under the rules in Sections 6 and 7.
Authorised personnel and professional advisers , where access is needed for operations, accounting, audit, legal advice or a relevant claim, subject to confidentiality and appropriate restrictions.
Competent authorities, regulators and courts , where disclosure is required or otherwise lawfully justified. Reports and requests are assessed against the applicable legal requirements, rather than an unrestricted discretion to disclose anything.
Parties involved in a genuine business transaction , such as advisers and a prospective buyer in a merger, restructuring or sale, where disclosure is necessary and appropriately protected. A business transfer does not remove your rights or make information available for unrestricted use.
We do not sell or rent customer contact lists to other organisations for their independent marketing. Optional advertising disclosures described in this Policy remain subject to applicable notice, consent and objection requirements; this statement is not a claim that advertising-related data is never shared.
Some providers act as processors on our instructions; others, including certain payment or fraud-prevention providers, may be independent controllers or joint controllers for particular purposes. The relevant service or collection information must identify the provider and any additional arrangements where required. We do not describe an independent controller as bound only by our instructions when that is not its role.
Processing outside your country
Providers, product fulfilment partners and authorised personnel may process information outside your country, including outside the United Kingdom or European Economic Area. Storage and remote access both need consideration; a UK-registered company does not imply UK-only processing.
Where an international transfer is restricted by applicable law, we use a permitted mechanism. This may be a relevant adequacy arrangement or appropriate contractual safeguards, such as the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or the EU standard contractual clauses where EU rules apply. The required assessment and any necessary additional protections must be completed before relying on those safeguards. We do not rely on your use of the website as blanket consent to international transfers.
You may contact us for information about the destinations relevant to your data and copies or details of applicable safeguards, with necessary redactions to protect confidential information and other people. Any further collection notice must provide additional transfer information where required. We do not transfer information where the required protection or another lawful route cannot be established.
13Withdrawing Consent, Accessing and Correcting Information
You can withdraw optional consent through the relevant privacy controls or unsubscribe method, or contact support@grzgaming.com . Withdrawal stops the processing that depended on that consent; it does not automatically end an unrelated service or invalidate another properly established lawful basis.
To request access, correction, erasure, restriction, portability or review of a decision, contact us by email, Live Support or post. You do not have to use a specific form, subject line or legal phrase. An authorised representative may act for you where their authority is established. Available account controls may help you manage information, but they are not the only way to exercise a right.
We may ask for proportionate information to confirm identity or authority before disclosing or changing personal information. We do not routinely require full KYC documentation for every privacy request, and we will not ask you to send sensitive evidence through an insecure channel.
Under the UK GDPR, rights requests are normally answered without undue delay and within one calendar month, subject to the applicable rules on verifying identity and any lawful clarification. Where a permitted extension is necessary because of complexity or the number of requests, we may take up to a further two months and explain this within the initial applicable period. We will not use clarification to force you to narrow a valid request or create avoidable delay.
Requests are normally free. A fee or refusal is used only where the law permits it, such as a manifestly unfounded or excessive request. If we cannot comply fully, we will explain the reason and available complaint or remedy routes unless the law restricts that explanation.
14Changes to This Privacy Policy
We may update this Policy to reflect changes in our services, providers, data handling or legal requirements. The published version will show its version date. Material changes will be brought to your attention in an appropriate way, including directly where required.
A revised policy does not retroactively authorise unrelated use of information already collected. Before a new purpose begins, we assess its lawfulness, provide the required information and obtain new consent where necessary. Continued use of the website does not, by itself, amount to that consent or waive your rights.
15Contacting GRZ Gaming and Making a Privacy Complaint
Privacy contact: support@grzgaming.com Live Support: through grzgaming.com Post: Privacy, Grz Gaming Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Company number: 13086814
You have the right to complain to GRZ Gaming about how we handle your personal information. Describe the issue and how we can reply; an order or account reference can help but is not compulsory. Ask for referral to the person responsible for data protection. Do not attach identity documents or financial evidence until an appropriate secure route has been arranged.
We accept privacy complaints through our available contact channels and do not require a particular form or account login. We will acknowledge a privacy complaint within 30 days of receipt, investigate without undue delay, keep you informed of material progress and communicate the outcome without undue delay. This acknowledgement period is separate from the usual one-month response period for a data-rights request; making a complaint does not restart an existing request deadline.
You may also complain to the Information Commissioner’s Office (ICO) , the UK data protection regulator, through its website at ico.org.uk , or to another competent data protection authority where applicable, including an authority in the country where you live, work or believe an infringement occurred. Contacting us can help resolve the issue, but we do not make it a contractual waiver of your right to approach a regulator or court.