About this notice
1.1 This notice explains how GAME CHANGER 360 LTD handles personal data in connection with gamechanger360.co.uk (the "website"). It covers the enquiry form, the newsletter, the Integrity Readiness Check, the analytics we run and the technical data created when you visit a page.
1.2 It is written to meet the transparency requirements of Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where this notice refers to an Article, that is an Article of the UK GDPR.
1.3 It does not cover the personal data that our customers place into 360 Academy, 360 Report, 360 Sentinel or 360 Intelligence. Our role there is different, and section 3 explains why that distinction matters more than anything else in this notice.
1.4 This notice is general information about how we handle personal data. It is not legal advice, and it does not form part of any contract between us.
1.5 In this notice, "we", "us" and "our" mean GAME CHANGER 360 LTD, and "you" means the person whose personal data we are describing. Section and clause references are to the sections and clauses of this notice.
Who we are and how to contact us
2.1 The controller of the personal data described in sections 4 to 7 is GAME CHANGER 360 LTD, a private company limited by shares incorporated in England and Wales with company number 15064064. Our registered office is Tennyson House, Cambridge Business Park, Cambridge, CB4 0WZ, United Kingdom. We trade as GAMECHANGER360.
2.2 Data protection is led internally by our Data Protection Lead. For any question about this notice, or to exercise a right described in section 17, email privacy@gamechanger360.co.uk, which reaches them, or write to the Data Protection Lead at our registered office. We have not appointed a statutory data protection officer under Article 37; if we do, this clause will name them and give their contact details.
When we are a controller and when we are a processor
3.1 We act in two clearly separated capacities, and the capacity determines who you should approach about your data.
3.2 We are the controller for personal data you give us through this website: your enquiry, your newsletter subscription, your Integrity Readiness Check submission, the analytics and technical data described in section 7, and the record our hosting provider makes when a page is served. We decide why and how that data is used, and this notice governs it.
3.3 We are a processor for the personal data that an organisation places into our products. Federations, leagues, clubs, regulators, universities and player associations deploy 360 Academy, 360 Report, 360 Sentinel and 360 Intelligence, and decide what goes into them, why, who may see it and how long it is kept. That organisation is the controller. We process it only on its documented instructions, under a written data processing agreement that meets Article 28.
3.4 So if you are a learner in an academy, a reporter using a whistleblowing channel, a person named in a case file, or a member of staff whose material has been indexed, the controller is the organisation that operates that channel, not us. Its privacy notice applies, and a rights request should go to it. If you approach us instead, we will not act on your data ourselves. We will tell you who the controller is where we are permitted to, and we will pass the request to it.
3.5 We do not use customer data from the products for our own purposes. We do not use it to train publicly available models, and we do not combine it with data from other customers.
Website enquiries and briefing requests
4.1 When you use the enquiry form we process:
- your first and last name
- your work email address
- your organisation and, if you give it, your role
- the stakeholder group you select and the reason for the enquiry
- the content of your message
- whether you asked to receive the newsletter as well
4.2 We use it to read your enquiry, to reply, to arrange a briefing or demonstration if that is what you asked for, and to keep a record of the exchange. Submissions are delivered to our mailbox by email. This website has no customer database behind it, so an enquiry lives in email and in our own business records rather than in a store on the site.
4.3 The lawful bases are Article 6(1)(f), our legitimate interests in responding to a business enquiry and pursuing a commercial relationship, and, where you have asked us to take steps towards a contract, Article 6(1)(b). Section 8 summarises our balancing test. Where a customer relationship follows, Article 6(1)(b) covers the personal data we need to perform that contract, and Article 6(1)(c) covers data we must keep to comply with a legal obligation such as our accounting records.
4.4 The form asks you to confirm that you have read this notice. That confirmation is not the lawful basis for the processing, and withdrawing it would not remove our ability to answer you. Your right to object under Article 21 is set out in section 17.
4.5 Retention: correspondence relating to an enquiry that does not lead to a commercial relationship is deleted three months after our last contact with you about it. Where a commercial relationship follows, the enquiry becomes part of our business records, which we keep for seven years from the end of the relationship in order to meet our legal, accounting and limitation-period obligations. We review what we hold against these periods at least once a year.
4.6 Giving us this data is voluntary, but we cannot answer an enquiry without a name, an email address and a message.
4.7 Please do not use this form to raise an integrity concern, and please do not attach evidence to it. It is an ordinary business mailbox and it gives you none of the protection that 360 Report is built to provide.
The Integrity Readiness Check
6.1 The Readiness Check is an indicative self-assessment about an organisation's integrity arrangements. It runs in two separate steps, and the first one asks for nothing that identifies you.
6.2 Step one: you describe the organisation (its type, sport, jurisdiction, scale, betting-market exposure and whether it has had integrity cases), the function you work in, your answers to eight questions, and anything you choose to type into three optional free-text boxes. The assessment is then run and the report is returned to your browser. Nothing from step one is stored on our servers or emailed to us, and the response is served with a no-store cache directive. It is transmitted in that step to the AI service that drafts the narrative, and section 9 explains that in full. Your progress is held in your browser's session storage so that a reload does not lose your work; section 3 of our cookie policy describes that.
6.3 Step two, which only happens if you ask for it: you give your name, your work email address, your organisation and, optionally, your job title. We re-run the assessment from your answers on the server, generate a PDF report and email it to you. We also send ourselves a copy, including the organisation profile and anything you typed into the free-text boxes, so that we can follow up on an informed basis.
6.4 The lawful basis for producing and sending the report you asked for is Article 6(1)(b), steps taken at your request before entering into a contract. The lawful basis for the internal copy and for the single follow-up contact described at the point of submission is Article 6(1)(f), our legitimate interests in developing a commercial conversation with an organisation that has asked to be assessed. Section 8 summarises our balancing test. If you tick the newsletter box as well, section 5 applies to that.
6.5 Please keep the free-text boxes at the level of your organisation's arrangements. Do not name individuals, do not describe an open case or an allegation, and do not include health, criminal-offence or other sensitive details. We do not need them, we do not want them in an ordinary mailbox, and section 9 explains that what you type is also sent to an AI model to draft the narrative.
6.6 Retention: the report and the covering emails sit in our mailbox, and are deleted one year after submission. If the conversation that follows becomes a commercial relationship, the correspondence becomes part of our business records and clause 4.5 applies to it instead. We review what we hold against these periods at least once a year. Where we hold anonymous aggregate results for research, they contain no personal data and no organisation name, and are not covered by this notice.
6.7 The result is not an audit, a certification or a statement that any organisation does or does not comply with any law. Clause 4 of our terms of use sets out what it is and what it is not.
Technical, security and analytics data
7.1 When you request a page, our hosting provider processes your IP address, the request headers your browser sends, the page requested and the time of the request, so that it can deliver the page and defend the service against attack and abuse. That is a normal part of serving a website and it happens whether or not you fill in a form.
7.2 Our form endpoints apply a short-lived rate limit keyed to your IP address, held in the memory of the serving instance for sixty seconds, to stop bursts of automated submissions. Each form also carries a hidden field that people never see and automated scripts tend to fill in. Neither creates a profile of you.
7.3 We use two different analytics tools, they work in different ways, and only one of them needs your consent. Vercel Web Analytics and Vercel Speed Insights run for every visitor. Neither sets a cookie, neither reads one, and neither is used to follow you across other websites. They measure aggregate traffic and page performance. Section 4 of our cookie policy describes them in full, and section 6 of it sets out what we do not do.
7.4 We also use Google Analytics 4, and only if you accept it. The measurement ID of our property is G-50TMK90Y6L. No Google script is loaded and no Google Analytics cookie is set unless you click Accept on the banner; refusing, or leaving the question unanswered, means nothing Google-related loads at all. If you accept, two first-party cookies are set in your browser. They hold a randomly generated identifier rather than anything you have told us, and they allow a returning browser to be recognised and several page views to be grouped into one session. Google then records the pages you view, how you arrived, approximate location, device, browser, operating system and interaction events such as scrolls, outbound clicks and file downloads. Google states that it does not log or store IP addresses from visitors in the United Kingdom, the European Union or Switzerland: for that traffic the address is used on servers in those regions to derive approximate location and is then discarded. Sections 3, 4 and 5 of our cookie policy set all of this out in full, including the two cookies, the record of your answer, and how to withdraw it.
7.5 We use analytics in aggregate, to decide what to write and what to fix. We do not combine it with the enquiry, newsletter or Readiness Check data described in sections 4 to 6, we do not use it to build a profile of you, we do not create advertising audiences from it, and we do not share it with advertisers. Google Signals and advertising personalisation are disabled in the tag itself, on every request it makes, and clause 4.8 of our cookie policy covers that and the matching settings inside the Google property.
7.6 The lawful bases differ, and we keep them apart. For clauses 7.1 to 7.3 the basis is Article 6(1)(f), our legitimate interests in keeping the website available, secure and usable, and in understanding in aggregate which pages are read; section 8 summarises the balancing test. For clause 7.4 the basis is your consent under Article 6(1)(a), because regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 requires consent before those cookies are set and the processing that follows rests on the same consent. You can withdraw it at any time through the Cookie settings control in the footer of every page, and withdrawing is as easy as giving. We do not treat legitimate interests as a fallback for Google Analytics: if you refuse, it does not run.
7.7 Retention: the request and security logs described in clause 7.1 are created and held by our hosting provider as part of running the service, and they are kept only for the period that provider applies to them. Different kinds of log have different periods, and we do not set them. What we can tell you is what we do with them: we do not extend those periods, we do not take a copy of those logs into any system of our own, we do not combine them with the enquiry, newsletter or Readiness Check data described in sections 4 to 6, and we do not use them to build a profile of you. They are read to deliver pages, to investigate an incident and to defend the service, and for nothing else.
7.8 Rate-limit counters are held in memory for sixty seconds and then discarded, as clause 7.2 describes. The Vercel measurements in clause 7.3 are aggregate and are not held against an identifiable person. In Google Analytics, event level data and user level data are both retained for two months, which is the shortest period Google offers. The separate option that would restart the clock on user level data every time the same browser returned is off, so two months runs from the activity itself rather than from a visitor's most recent visit. Clause 4.7 of our cookie policy explains that setting.
7.9 If you want the retention period that applies on the day you ask, email privacy@gamechanger360.co.uk and we will tell you what our providers' published or configured periods are at that point, rather than quote you a figure here that could quietly go out of date.
Our legitimate interests, and how we balance them
8.1 Where we rely on Article 6(1)(f) we are required to balance our interest against your rights. This is a summary of that assessment, which we keep in full and will provide on request.
8.2 The purpose: to respond to business enquiries, to develop commercial relationships with the organisations we sell to, and to keep the website secure and functioning. Those are legitimate business purposes and we cannot operate without them.
8.3 Necessity: the processing is limited to what the purpose needs. We ask for business contact details and nothing about your private life. We do not buy contact data, we do not enrich what you give us from other sources, we do not build behavioural profiles and we do not sell or share anything for advertising.
8.4 The balance: the people who contact us do so themselves, in a professional capacity, and expect a reply. The data is ordinary business contact information given voluntarily for that exact purpose, and its use is described plainly at the point of collection and in this notice. The intrusion is low and there is no realistic prospect of harm or surprise. Where the interest is security and availability, the processing is technical, short-lived and in every visitor's interest.
8.5 Your control: you can object at any time under Article 21, and to direct marketing you can object absolutely. If you object to a follow-up contact we will stop, and we will keep the minimum record needed to remember that you asked us to.
8.6 We conclude that our interests are not overridden by your interests, rights and freedoms in respect of the processing described in sections 4, 6 and 7. The Google Analytics described in clause 7.4 is outside this assessment, because it rests on your consent rather than on a balance we have struck for you. If you disagree with the assessment, tell us and we will look at it again.
AI processing and automated decision-making
9.1 We are direct about this because the Readiness Check involves a model, and because you are entitled to know what it does and does not decide.
9.2 The assessment itself is not done by a model. Your eight answers are scored in our own code against a fixed rule set. The score, the band and the three priorities you see are produced by that code and are the same every time for the same answers.
9.3 A large language model is then used to write the narrative around the finished analysis: the executive summary, a note connecting what you typed to what the answers show, a sentence on each priority, and a three-item watch list. The model is reached through Vercel AI Gateway and is currently an Anthropic model. It is given the organisation profile, your eight answers, the score, the band, the priorities our code has already selected, the regulatory items our code has already selected, and whatever you typed into the free-text boxes. It is instructed to use no fact outside that material, and its output must fit a fixed schema. It is not given your name, your email address or your organisation's name. If the model is unavailable, slow or returns something that fails validation, the report is completed from our own written narrative instead.
9.4 The narrative pass is not used to evaluate you, and nothing in the Readiness Check makes a decision about a person. The output is an indicative assessment of an organisation's arrangements. It produces no decision about any individual, and so no decision based solely on automated processing within the meaning of Article 22 is taken about you. Nor does the analytics in section 7 produce one. Where you have accepted Google Analytics, what it yields is aggregate reporting about how the website is used: we do not build or buy audience segments from it, we do not use it to evaluate or predict anything about you, and no decision is taken about any individual visitor on the strength of it.
9.5 The material listed in clause 9.3, including anything you type into the free-text boxes, is sent to Vercel AI Gateway, a service of our hosting provider Vercel Inc., which passes it on to the model provider. It is sent each time the model is asked to draft the narrative: when you complete step one, and again if you ask us to email the report in step two, because the report is rebuilt on the server at that point. We send it for one purpose only, to draft the narrative sections of your report. That is the reason for the warning in clause 6.5, and section 10 lists both recipients.
9.6 It is not retained, and it is not used to train anyone's model. We do not rely on that being the default. Every request we make carries two instructions to the gateway: one that routes it only to a provider holding a verified zero-retention agreement, and one that routes it only to a provider contractually barred from training on what is sent. If no provider meets both, the request fails and your report is completed from our own written narrative instead. Vercel states that the gateway itself permanently deletes prompts and responses once a request completes. Anthropic, the current provider, states that it does not train on commercial API data and deletes inputs and outputs within thirty days, and shorter where a zero-retention agreement applies. We hold neither company to more than it has published, and we will update this clause if either position changes.
9.7 The model used is configurable, so the provider named in clause 9.3 may change. When it does we will update this notice and the record of processors before the change goes live.
9.8 Our products use AI in ways this notice does not cover, because there we act as a processor. Where 360 Intelligence indexes a customer's own material, or 360 Sentinel scores a signal, the customer decides what is processed and its own notice applies. Those arrangements, including any human review a customer requires before action is taken on a case, are set out in the agreement with that customer.
Who we disclose personal data to
10.1 We do not sell personal data, we do not share it with advertisers or data brokers, and we do not disclose it for anyone else's marketing. We use a small number of processors, each engaged under terms that meet Article 28:
- Vercel Inc., United States: hosting, content delivery, request and security logging, the cookie-less analytics described in clause 7.3, and the AI Gateway described in clause 9.3.
- Google Ireland Limited, Ireland: Google Analytics 4, as described in clause 7.4, and only where you have consented to it. Google engages its own affiliates as sub-processors, including Google LLC in the United States. It is engaged under the Google Ads Data Processing Terms, which are the Article 28 terms for Google Analytics and which we have accepted for our property.
- The model provider reached through that gateway, currently Anthropic: generation of the narrative sections of a Readiness Report, as described in section 9.
- Resend, Inc., United States: delivery of transactional email (enquiry confirmations and Readiness Reports) and of The Integrity Brief, including management of the subscriber list.
10.2 We also disclose personal data to our professional advisers, to our accountants and auditors, and to a purchaser or successor if we sell or reorganise the business, in each case under a duty of confidence.
10.3 We disclose personal data where we are required to by law, or where it is necessary to establish, exercise or defend legal claims. Where we receive a request from a public authority we check that it is lawful and properly made, and we disclose no more than the request requires. Section 14 explains the position for material held in the reporting product.
10.4 We will tell you if we add a processor that handles personal data collected through this website, by updating this section before the change takes effect. Our customers receive notice of changes to product sub-processors through their agreement, not through this notice.
Transfers outside the United Kingdom
11.1 Some of the processors in section 10 are established in the United States and may process personal data there or in other countries. Google Ireland Limited is established in Ireland, but Google engages affiliates in the United States as sub-processors. Either way, personal data collected through this website can be transferred outside the United Kingdom. One qualification is worth stating: for Google Analytics, Google applies the regional handling described in clause 7.4, so for United Kingdom traffic the IP address itself is discarded before the data reaches Analytics for processing.
11.2 Where the UK Government has made adequacy regulations for the destination, we rely on those. For transfers to a recipient in the United States that is certified under the UK Extension to the EU-US Data Privacy Framework, we rely on that certification for the data the certification covers.
11.3 Otherwise we rely on Article 46 safeguards: either the International Data Transfer Agreement issued by the Information Commissioner, or the European Commission's standard contractual clauses together with the International Data Transfer Addendum to those clauses. Where a processor also transfers data onward, its contract must place the equivalent obligations on the recipient.
11.4 We carry out a transfer risk assessment before relying on an Article 46 safeguard, and we apply supplementary measures where the assessment calls for them, including encryption in transit and minimisation of what is sent.
11.5 You can ask us for a copy of the relevant transfer mechanism, and we will provide it with commercially confidential terms redacted.
11.6 For the products, hosting location and data residency are agreed with each customer in its own agreement and are not determined by this notice.
How long we keep personal data
12.1 We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires. The period for each activity, or the criteria we use to decide it, is stated with that activity above and summarised here:
- Enquiry correspondence that does not lead to a commercial relationship: three months from our last contact about it. Clause 4.5.
- Readiness Check submissions and reports: one year from submission. Clause 6.6.
- Business records, including correspondence that becomes part of a commercial relationship: seven years from the end of the relationship. Clause 4.5.
- Newsletter subscription and suppression records: clause 5.5.
- Request and security logs: clause 7.7.
- Google Analytics, where you have accepted it: two months for both event level and user level data. Clause 7.8. The two cookies expire two years after they are written, or sooner if you withdraw consent, and the record of your answer stays in your browser until you change it or clear your site data.
12.2 Where a claim is reasonably in prospect we keep the material relevant to it until the claim and any appeal are resolved, and then apply the period above.
12.3 Retention in the products is configured by the customer in its agreement with us, and can differ by data type and by case type. We delete or return the data on exit as that agreement requires.
Special category and criminal offence data
13.1 We do not ask for special category data or criminal offence data through this website, and we ask you not to send any. The forms have no field for it. If it reaches us in free text or in a message, we do not use it, and we delete it within thirty days. The only exception is where we must keep it to comply with a legal obligation, or to establish, exercise or defend a legal claim. Where that applies we keep only the part we need, for no longer than the obligation or the claim requires, and we delete it as soon as that ends.
13.2 The position in the products is different. A whistleblowing and case management system receives allegations, and an allegation can contain special category data, meaning data revealing racial or ethnic origin, religious or philosophical beliefs, health, sex life or sexual orientation. It can also contain criminal offence data, meaning data about criminal offences, alleged offences and related proceedings, which Article 10 of the UK GDPR and section 11(2) of the Data Protection Act 2018 govern. Safeguarding material in an academy setting can contain both.
13.3 We are the processor of that material and never the controller of it. The organisation that deploys the product is the controller, and three duties follow for that organisation. First, it must identify a condition in Article 9(2) of the UK GDPR before it processes special category data. Second, where the UK GDPR requires one, it must also identify a condition in Schedule 1 to the Data Protection Act 2018; the ones that usually apply here are paragraph 10, preventing or detecting unlawful acts, paragraph 12, regulatory requirements relating to unlawful acts and dishonesty, and paragraph 18, safeguarding of children and of individuals at risk. Third, most of those Schedule 1 conditions require an appropriate policy document, and it is the controller that must have one in place.
13.4 Our duty as processor is narrower and fixed by Article 28: we handle that material only on the controller's documented instructions, and we protect it. In practice that means role-based access, access enforced at the level of the individual record, two-factor authentication for administrators, encryption in transit and at rest, and an audit log of every action taken on a case. Our Security and trust page describes the architecture, and the data processing agreement with each customer records these commitments as binding terms.
Whistleblower and reporter confidentiality
14.1 360 Report is built so that a reporter does not have to identify themselves. There is no account and no sign-up. No name, email address or telephone number is required to submit a report, and the role, sport and organisation fields are optional. Follow-up works through a case reference and a secret access code rather than an identity, so an investigator can put a question back into a case and a reporter can answer it without anyone learning who they are.
14.2 The consequence is deliberate: in a genuinely anonymous case file there is usually no reporter identity for anyone to disclose, including us, including under legal compulsion. That is a stronger protection than a promise of confidentiality, because it does not depend on anyone keeping the promise.
14.3 Where a reporter chooses to identify themselves, or includes details that could identify them, that information sits in the case file under the deploying organisation's control. Any decision about disclosure is that organisation's to make under its own policy and the law of its jurisdiction, not ours. We do not attempt to identify or re-identify reporters, we do not use technical data to work out who filed a report, and we do not disclose case content to anyone outside the deploying organisation unless that organisation instructs us to or the law compels us.
14.4 A UK organisation using the channel will have its own obligations to workers who make protected disclosures under the Employment Rights Act 1996, as amended by the Public Interest Disclosure Act 1998, and organisations operating in the European Union will have obligations under their national implementation of the EU Whistleblower Directive. The product is configured to support those obligations. Meeting them remains the deploying organisation's duty.
14.5 Please do not use this website to raise an integrity concern. The enquiry form is an ordinary business mailbox, it is not anonymous, and it gives you none of the protection described in this section. Use 360 Report, which takes any integrity concern connected to sport: a match-fixing approach, betting-related pressure, a bribery attempt, coercion or intimidation, harassment from bettors, pressure from an agent or intermediary, suspicious behaviour, a safeguarding concern, and corruption or a conflict of interest. You can report anonymously or give your name, and you can attach evidence. One thing it is not: an emergency service. If anyone is in immediate danger, contact your local emergency number first and report afterwards. If your federation, league, club or university runs its own 360 Report deployment, use that one, because your report then reaches the body that can act on it; otherwise use report.gamechanger360.co.uk.
Children
15.1 This website is aimed at professionals working in and around sport. It is not directed at children, and we do not intend to collect personal data about children through it. Please do not include details about a child in an enquiry or in the Readiness Check free-text boxes.
15.2 The products are used in settings where children are present, including academies, youth pathways and university programmes. A child means a person under 18. In those deployments the deploying organisation is the controller. It decides whether children use the service, on what basis, and how their data is handled, and where its service is likely to be accessed by children in the United Kingdom it must apply the Information Commissioner's Age Appropriate Design Code.
15.3 We support that as processor through access control, data minimisation in what the product asks for, configurable retention and the confidentiality measures in section 13. Where a deployment involves children, we expect the customer's data protection impact assessment to address it, and we will contribute to that assessment as Article 28(3)(f) requires.
Security
16.1 We take appropriate technical and organisational measures under Article 32, sized to the risk of what we hold.
16.2 For this website: everything is served over HTTPS, and form submissions travel over TLS. HTTP strict transport security, a strict referrer policy, frame denial and content-type protections are set at the edge. The site has no administrative login and no customer database, so there is no store on it to breach. Access to the mailbox that receives enquiries and Readiness Reports is limited to the people who need it, on managed accounts with multi-factor authentication.
16.3 For the products: the measures are described on the Security and trust page and committed to contractually. They include encryption in transit and at rest, access enforced at the level of the individual record, two-factor authentication for administrators, audit logging across layers and encrypted backups.
16.4 No system is beyond risk. If a personal data breach occurs we will assess it without delay, notify the Information Commissioner within 72 hours where Article 33 requires it, tell affected people where Article 34 requires it, and notify a customer without undue delay where the breach concerns data we process on its behalf.
16.5 If you believe you have found a vulnerability, please tell us before you tell anyone else. The Security and trust page explains how.
Your rights, and how to exercise them
17.1 In respect of the personal data for which we are the controller, you have the following rights. Some of them apply only in particular circumstances, and we will explain if one of those limits applies to your request.
- Access (Article 15): to obtain confirmation of whether we are processing personal data about you and, where we are, to receive a copy of that data together with the purposes of the processing, the categories of data concerned, the recipients or categories of recipient it is disclosed to, the retention period or the criteria for setting it, the existence of your other rights, your right to complain to the Information Commissioner, the source of the data where we did not collect it from you, and whether there is any automated decision-making.
- Rectification (Article 16): to have inaccurate personal data about you corrected without undue delay, and to have incomplete data completed, including by providing a supplementary statement.
- Erasure (Article 17): to have personal data deleted without undue delay where it is no longer necessary for the purpose it was collected for, where you withdraw the consent it rested on and there is no other basis, where you object under Article 21 and there is no overriding legitimate ground, where it has been processed unlawfully, or where it must be erased to comply with a legal obligation. The right does not apply so far as the processing is necessary for freedom of expression and information, to comply with a legal obligation, or to establish, exercise or defend legal claims.
- Restriction (Article 18): to have us store personal data without otherwise using it where you contest its accuracy, for a period allowing us to verify it; where the processing is unlawful but you prefer restriction to erasure; where we no longer need it but you need it for a legal claim; or while we verify whether our legitimate grounds override your objection under Article 21.
- Portability (Article 20): to receive the personal data you provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller without hindrance, or to have us transmit it directly where that is technically feasible. This right applies where the processing is based on consent or on a contract and is carried out by automated means.
- Objection (Article 21): to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests, after which we must stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is for legal claims. Where you object to direct marketing there is no balancing exercise and no exception: we stop.
- Automated decisions and profiling (Article 22): not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, except where the decision is necessary for a contract with you, is authorised by law, or is based on your explicit consent, in which cases you may obtain human intervention, express your point of view and contest the decision. As clause 9.4 explains, we take no such decision.
- Withdrawal of consent (Article 7(3)): to withdraw consent at any time where consent is the lawful basis, which applies to the newsletter and to the Google Analytics described in clause 7.4. Withdrawing is as easy as giving it, and it does not affect the lawfulness of processing carried out before you withdrew. For the newsletter, use the unsubscribe link in any issue. For analytics, use the Cookie settings control in the footer of every page.
- Complaint (Article 77): to lodge a complaint with a supervisory authority, which in the United Kingdom is the Information Commissioner. Clause 18.3 gives its contact details. You can complain without contacting us first, though we would rather have the chance to put something right.
17.2 To exercise any of these rights, email privacy@gamechanger360.co.uk or write to us at the registered office in clause 2.1. Tell us which right you are exercising and what you are looking for; a narrower request usually gets a better answer faster. There is no fee.
17.3 We may ask for information to satisfy ourselves of your identity before we act, because disclosing personal data to the wrong person is itself a breach. We will ask only for what we need.
17.4 We respond within one month of receiving your request. Where a request is complex, or where you have made a number of requests, we may extend that by up to two further months under Article 12(3), and if we do we will tell you within the first month and explain why.
17.5 If your request concerns data held in one of our products, section 3 applies: the deploying organisation is the controller, and your request should go to it. Tell us if you are not sure who that is and we will help you identify the right contact.
Complaints to the Information Commissioner's Office
18.1 If you are unhappy with how we have handled your personal data or your request, please tell us first. We would rather fix it, and we can usually do so faster than any other route.
18.2 You also have the right under Article 77 to complain to the Information Commissioner's Office, the United Kingdom's supervisory authority for data protection. You do not need to come to us first.
18.3 Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. Website: ico.org.uk.
18.4 You also have the right to an effective judicial remedy under Article 79.
Changes to this notice
19.1 We review this notice when our processing changes and at least once a year. The date shown with this page is the date of the current version.
19.2 Where a change materially affects how we use personal data for which we are the controller, we will say so on this page and, where the change requires it, contact the people affected before it takes effect.
19.3 We keep previous versions and will provide the version that applied on a given date on request.