Privacy Policy
Last revised: 2026-07-14
1. Introduction and Data Controller
1.1. This Privacy Policy (the "Notice") sets out how [COMPANY], registration number [REG_NUMBER], registered office at Lorem ipsum dolor sit amet, consectetur adipiscing elit (the "Controller", "we"), processes personal data of visitors and customers of servethekey.com (the "Site").
1.2. Processing is carried out in accordance with Regulation (EU) 2016/679 (the "GDPR"), the applicable Cypriot data-protection legislation, and, where relevant, the UK GDPR.
1.3. "Personal data" denotes any information relating to an identified or identifiable natural person, such as name, email address, transaction identifiers, IP address, or device identifiers.
1.4. This Notice applies to all processing connected with browsing the Site, maintaining a customer profile, purchasing digital items, and communicating with our support service.
2. Personal Data We Collect
2.1. Data supplied by you: registration details (name, email, credentials), profile preferences, billing particulars provided at checkout, the content of support enquiries, and any information you volunteer in communications or promotional entries.
2.2. Transaction data: items purchased, purchase history, timestamps, prices and currency, delivery status, together with limited payment-related information (payment status, authorisation outcomes, fraud indicators) received from payment institutions.
2.3. Data generated automatically: IP address, browser and operating-system attributes, device identifiers, language and time-zone settings, session identifiers, pages viewed, click paths, search queries, time spent on pages, performance metrics, error diagnostics, and referral sources.
2.4. Data received from third parties: payment status, authorisation outcomes, and fraud indicators from payment institutions; risk signals from anti-fraud services; delivery confirmations from email providers; and aggregated statistics from analytics vendors.
2.5. We do not deliberately store complete payment-card numbers, and we do not knowingly collect special categories of personal data within the meaning of Article 9 GDPR.
3. Purposes and Legal Grounds for Processing
3.1. Performance of a contract (Art. 6(1)(b) GDPR): operating customer profiles, processing purchases, delivering digital items, and providing support.
3.2. Compliance with legal obligations (Art. 6(1)(c) GDPR): accounting and tax record-keeping, responding to lawful requests of authorities, and retention duties.
3.3. Legitimate interests (Art. 6(1)(f) GDPR): safeguarding the Site against fraud and abuse, securing accounts and transactions, diagnosing and improving performance, and establishing or defending legal claims — in each case following an assessment that such interests are not overridden by your rights and freedoms.
3.4. Consent (Art. 6(1)(a) GDPR): non-essential cookies and similar technologies, and direct-marketing communications where consent is the applicable basis. Consent may be withdrawn at any time with effect for the future.
3.5. Personal data is not used for purposes incompatible with those stated above without prior information and, where required, renewed consent. We observe the principle of data minimisation throughout.
4. Cookies and Automated Collection
4.1. The Site employs cookies and comparable technologies for session integrity, security, preference storage, performance measurement, and — subject to consent — marketing purposes.
4.2. Details of the categories used, their providers, and the available controls are set out in our separate Cookie Notice and in the consent interface displayed on the Site.
4.3. Strictly necessary cookies are deployed without consent, as they are indispensable for the operation of the Site; all other categories are activated only in accordance with your choices.
5. Disclosure of Personal Data
5.1. Personal data is disclosed only where necessary and to the following categories of recipients: payment institutions and payment service providers; hosting, infrastructure, and IT-security providers; support-ticketing and email-delivery vendors; analytics providers; and fulfilment partners, to the limited extent required to validate issuance or route delivery of a digital item.
5.2. All processors act under data-processing agreements imposing confidentiality, security, and purpose-limitation obligations consistent with Article 28 GDPR.
5.3. Data may further be disclosed where required by law, regulation, or enforceable order of a court or authority, or where necessary for the establishment, exercise, or defence of legal claims and the prevention of fraud.
5.4. In the event of a merger, acquisition, restructuring, or transfer of assets affecting the Site, personal data may pass to the successor entity under safeguards ensuring a substantially equivalent level of protection; notice will be given where legally required. Following such a transaction, data subjects retain the rights described in this Notice and may exercise them against the successor controller.
5.5. We do not sell personal data.
6. International Data Transfers
6.1. Personal data is processed primarily within the European Economic Area.
6.2. Where a service provider processes data in a third country, the transfer is based on an adequacy decision of the European Commission or on appropriate safeguards within the meaning of Article 46 GDPR, in particular the Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures.
6.3. Information on the safeguards applicable to a specific transfer may be requested via the contact details in Section 13.
7. Retention of Personal Data
7.1. Personal data is retained no longer than necessary for the purposes for which it was collected, subject to statutory retention duties.
7.2. Indicative periods: transactional and invoicing records — for the duration prescribed by Cypriot tax and accounting legislation; profile data — for the lifetime of the profile and a limited period thereafter for dispute handling and fraud prevention; support correspondence — for as long as needed to resolve the matter and maintain an audit trail; technical logs — for limited security and troubleshooting periods, after which they are erased or anonymised.
7.3. Upon expiry of the applicable period, data is deleted or irreversibly anonymised. Retention practices are reviewed periodically for proportionality.
8. Security of Processing
8.1. We implement technical and organisational measures appropriate to the risk, including transport encryption (TLS), access controls and role separation, environment segregation, logging and monitoring, and vulnerability management.
8.2. Access to personal data is confined to personnel and contractors with a demonstrated need, bound by confidentiality undertakings. Equivalent standards are imposed on processors.
8.3. No transmission or storage method offers absolute security. Should a personal-data breach occur that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority and, where the risk is high, the affected individuals, within the statutory time limits, and will take containment and remediation measures.
9. Rights of Data Subjects
9.1. Subject to the conditions of the GDPR, you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on legitimate interests (Art. 21), as well as the right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
9.2. Requests may be submitted via the contact details in Section 13. We may request information reasonably necessary to verify the identity of the requester and will respond within the periods prescribed by law.
9.3. Where a request cannot be met in full — for instance because retention obligations apply or the rights of others would be affected — we will explain the grounds to the extent permitted.
9.4. You further have the right to lodge a complaint with a supervisory authority, in particular the Office of the Commissioner for Personal Data Protection of [JURISDICTION] or the authority of your habitual residence. We would welcome the opportunity to address your concern directly first.
10. Marketing Communications
10.1. Newsletters and promotional messages are sent only on a lawful basis — as a rule, your consent, or the "existing customer" exemption where permitted, always subject to an opt-out.
10.2. Every marketing email contains an unsubscribe mechanism; opting out may also be effected via support. Withdrawal takes effect promptly, subject to short technical processing intervals.
10.3. Service communications indispensable to the contractual relationship (receipts, delivery notifications, security alerts, material policy changes) are not marketing and are sent irrespective of marketing preferences.
10.4. Personal data is not made available to third parties for their own marketing without your explicit consent.
11. Minors
11.1. The Site is not directed at persons under eighteen (18) years of age, and we do not knowingly process their personal data.
11.2. If we become aware that data of a minor has been collected without valid authorisation, such data will be deleted without undue delay. Parents or guardians who believe a minor has provided data through the Site are asked to contact us via Section 13.
12. Third-Party Websites
12.1. The Site contains links to external resources, in particular publisher and redemption platforms on which digital items are activated. Their processing of personal data is governed exclusively by their own privacy documentation.
12.2. Embedded third-party components may register technical data (such as IP address) upon interaction; such processing likewise falls under the third party's responsibility.
12.3. We recommend reviewing the privacy documentation of any external service before providing personal data to it. Browser extensions installed on your device operate outside our control.
13. Amendments and Contact Information
13.1. This Notice may be updated to reflect changes in our processing operations, legal requirements, or the Site's functionality. The date of the current version appears at the top; the authoritative version is the one published on the Site. Material changes may be announced additionally through the Site or by email.
13.2. All privacy-related enquiries and data-subject requests should be addressed to:
[COMPANY]
Registration No.: [REG_NUMBER]
Registered Address: Lorem ipsum dolor sit amet, consectetur adipiscing elit
Email (Data Protection): support@servethekey.com