GDPR COMPLIANCE

General Data Protection Regulation Policy

Last updated: January 15, 2025

1. DATA CONTROLLER INFORMATION

MOXIE SKINS LTD is the data controller for your personal data.

Company number: 16553071

Registered Address: 60 Tottenham Court Road, Office 119 Fitzrovia London W1T 2EW

Data Protection Officer: dpo@poshskins.com

ICO Registration: Pending

2. YOUR RIGHTS UNDER GDPR

As a data subject, you have the following rights:

  • Right to Access: Request copies of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Request limitation of data processing
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time
  • Right to Lodge a Complaint: File a complaint with the ICO

3. DATA WE COLLECT

Account Information:

  • Steam ID and username
  • Email address
  • Profile avatar and display name
  • Steam inventory data
  • Trade URL

Transaction Data:

  • Purchase and sale history
  • Payment information
  • Wallet balance and transaction logs
  • Trading history and patterns

Technical Data:

  • IP address and location data
  • Browser type and version
  • Device information
  • Cookies and similar technologies
  • Usage analytics

Communication Data:

  • Support tickets and correspondence
  • Chat messages (if applicable)
  • Marketing preferences

4. LAWFUL BASIS FOR PROCESSING

We process your data under the following legal bases:

Contract Performance:

  • Account creation and management
  • Processing transactions
  • Providing marketplace services
  • Customer support

Legitimate Interests:

  • Fraud prevention and security
  • Service improvements
  • Business analytics
  • Direct marketing (with opt-out)

Legal Obligations:

  • AML/KYC compliance
  • Tax reporting
  • Law enforcement cooperation
  • Regulatory compliance

Consent:

  • Marketing communications
  • Non-essential cookies
  • Newsletter subscriptions

5. DATA RETENTION PERIODS

We retain data for the following periods:

  • Account Data: Duration of account + 6 years
  • Transaction Records: 7 years (legal requirement)
  • AML/KYC Documents: 5 years after relationship ends
  • Support Tickets: 3 years
  • Marketing Data: Until consent withdrawn
  • Technical Logs: 90 days
  • Cookies: As per Cookie Policy

6. DATA SHARING & TRANSFERS

Third Party Recipients:

  • Steam/Valve (authentication and trading)
  • BitSkins API (market data)
  • Cloudflare (CDN and security)
  • AWS (hosting in EU regions)
  • Vercel (platform hosting)
  • Law enforcement (when legally required)

International Transfers:

  • Data is primarily processed in the EU
  • Steam services may involve US transfers (Privacy Shield)
  • We use Standard Contractual Clauses where required
  • Adequate safeguards are in place for all transfers

7. DATA SECURITY MEASURES

We implement appropriate technical and organizational measures:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Regular security audits and penetration testing
  • Access controls and authentication
  • Employee data protection training
  • Incident response procedures
  • Regular backups and disaster recovery
  • ISO 27001 aligned practices

8. DATA BREACH PROCEDURES

In case of a personal data breach:

  • We will assess the risk to individuals
  • Notify the ICO within 72 hours if required
  • Inform affected users without undue delay
  • Document all breaches internally
  • Implement measures to prevent recurrence
  • Cooperate with regulatory investigations

9. CHILDREN'S DATA

Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.

10. AUTOMATED DECISION MAKING

We use automated systems for:

  • Fraud detection and prevention
  • AML transaction monitoring
  • Market price calculations
  • AI-powered item analysis

You have the right to request human review of automated decisions that significantly affect you.

11. EXERCISING YOUR RIGHTS

To exercise any of your GDPR rights:

  • Email our DPO at dpo@poshskins.com
  • Include proof of identity
  • Specify which right(s) you wish to exercise
  • We will respond within 30 days
  • No fee for most requests
  • Complex requests may take up to 90 days

12. COMPLAINTS

If you're unsatisfied with our data handling:

  • Contact our DPO first at dpo@poshskins.com
  • You may lodge a complaint with the ICO
  • ICO Website: ico.org.uk
  • ICO Helpline: 0303 123 1113

13. UPDATES TO THIS POLICY

We may update this GDPR policy periodically. Material changes will be notified via email or prominent website notice. The "Last updated" date will be revised accordingly.

14. CONTACT INFORMATION

Data Protection Officer:

Email: dpo@poshskins.com

Phone: +44 20 1234 5678

Address: 60 Tottenham Court Road, Office 119 Fitzrovia London W1T 2EW

General Inquiries:

Email: privacy@poshskins.com

Support: support@poshskins.com