Privacy policy

Privacy policy
Last updated: Reading time: 8 min

This privacy policy explains what personal data GamStop Navigator Slots collects when you visit the site, why we collect it, how long we keep it, and what rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We have written it plainly, without legalese where possible, because we think you should be able to read a privacy notice without a dictionary.

Who is the data controller?

The data controller for personal data processed through this site is the publisher of GamStop Navigator Slots. Full contact details are listed on the legal notice page. Until the deployment values are filled in, those entries are placeholders.

If we ever appoint a Data Protection Officer, their contact details will be added to this section. At present the editor handles privacy enquiries and routes them appropriately. You can reach the editorial team through the contact page.

Some short definitions

Personal data
Any information relating to an identified or identifiable living person, such as a name, an email address or an IP address.
Processing
Any operation performed on personal data, including collection, storage, use, disclosure or deletion.
Controller
The organisation that decides why and how personal data is processed.
Processor
A third party that processes personal data on the controller’s behalf, for example a hosting provider.

What personal data do we collect?

We try to collect as little personal data as we can. In practice, three categories of personal data are likely to be processed when you use this site.

The first is server log data. Like almost every web server, ours records the IP address of each request, the user agent string, the page requested, the referring page where applicable, and the timestamp. We use this for operational reasons such as security monitoring, abuse prevention and basic performance diagnostics.

The second is contact-form data. If you write to us through the contact page, we receive the name, email address, subject and message you enter, plus any technical headers attached by the email transport. We use this to read and answer your message.

The third is cookie and analytics data, if and where cookies are set. Details of which cookies are used, what they do and how long they last are on the cookie policy page. Non-essential cookies are only set after you give consent.

What is the lawful basis for processing?

Under Article 6 of the UK GDPR, every act of processing personal data needs a lawful basis. The two we rely on are summarised below.

Legitimate interests under Article 6(1)(f) of the UK GDPR cover server log processing for security, abuse prevention and stability, and the processing of contact-form data so we can answer your message. Where we rely on legitimate interests, we balance our interest against your rights and reasonable expectations and document that balance internally.

Consent under Article 6(1)(a) of the UK GDPR covers non-essential cookies and any future use of analytics or measurement tools that go beyond what is strictly necessary to deliver the site. You can withdraw consent at any time through the cookie controls described on the cookie policy page.

We do not rely on consent for things that are operationally necessary, and we do not rely on legitimate interests as a back-door for marketing or tracking.

How long do we keep personal data?

Server logs are retained for a short period needed for security review and operational diagnostics. Typically this is up to 30 days for live access logs, after which they are deleted or anonymised. Aggregated, non-identifying statistics may be kept longer.

Contact-form correspondence is retained for as long as the conversation is active, plus a reasonable period afterwards for follow-up. Where a correction has been raised and acted on, we may keep the relevant exchange for editorial accountability. Routine messages are deleted within 12 months of the last reply unless you ask us to keep them longer.

Cookie lifetimes are documented on the cookie policy page for each cookie category.

Who do we share personal data with?

We do not sell personal data and we do not share it for marketing purposes. Where personal data is shared, it is shared only with carefully chosen processors who help us operate the site.

Typical categories of recipients include our hosting provider, an email or contact-form delivery service for reading your messages, and, where consent is given, any analytics or measurement provider used to understand how readers find and use the site. Each processor operates under a written contract that includes UK GDPR Article 28 obligations.

We may also disclose personal data where we are legally required to do so, for example in response to a valid request from a regulator, court order or law enforcement authority. Where the law permits, we will tell you about any such request before we comply.

Are personal data transferred outside the United Kingdom?

Some processors we use may store or process personal data outside the United Kingdom, for example in the European Economic Area or another country with an adequacy decision in place. Where a transfer relies on a UK adequacy regulation, we record that as the basis for the transfer.

Where no adequacy decision is in place, we use the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment, as the safeguard for the transfer in line with guidance from the Information Commissioner’s Office.

How do we protect personal data?

We use reasonable and proportionate organisational and technical measures to protect personal data against accidental loss, unlawful destruction, alteration, unauthorised disclosure or access. These include access controls on administrative interfaces, transport encryption with HTTPS, software updates and a limited list of people who can read contact-form messages.

No internet system is perfectly secure. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours where required, and tell you where the breach is likely to result in a high risk to your rights and freedoms.

What are your rights?

Under the UK GDPR you have a set of rights in relation to personal data we hold about you. The main rights are summarised here. Where a right applies, we will action it within one calendar month of a valid request, and we will tell you if we need a short extension on complex cases.

To exercise any of these rights, please write to us through the contact page with enough detail to identify the personal data in question. We may need to verify your identity before we can action a request.

Right to complain to the regulator

If you believe we have not handled your personal data lawfully, you can complain to the Information Commissioner’s Office, the independent UK regulator for data protection. You can contact the ICO at ico.org.uk or on the ICO helpline. We would appreciate the chance to put things right before you complain to the regulator, but it is your right to go directly to the ICO if you prefer.

Children

This site is intended for adult readers aged 18 or over and the content is not directed at children. We do not knowingly collect personal data from anyone we know to be under 18. If we become aware that we have inadvertently collected personal data from a child, we will delete it.

Changes to this policy

We may update this privacy policy from time to time, for example to reflect changes in how the site works, in our processors, or in the law. Material changes will be highlighted by updating the “Last updated” date at the top of this page and, where appropriate, by a notice on the site.