GDPR COMPLIANCE
General Data Protection Regulation Policy
Last updated: January 15, 2025
1. DATA CONTROLLER INFORMATION
MOXIE SKINS LTD is the data controller for your personal data.
Company number: 16553071
Registered Address: 60 Tottenham Court Road, Office 119 Fitzrovia London W1T 2EW
Data Protection Officer: dpo@poshskins.com
ICO Registration: Pending
2. YOUR RIGHTS UNDER GDPR
As a data subject, you have the following rights:
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Lodge a Complaint: File a complaint with the ICO
3. DATA WE COLLECT
Account Information:
- Steam ID and username
- Email address
- Profile avatar and display name
- Steam inventory data
- Trade URL
Transaction Data:
- Purchase and sale history
- Payment information
- Wallet balance and transaction logs
- Trading history and patterns
Technical Data:
- IP address and location data
- Browser type and version
- Device information
- Cookies and similar technologies
- Usage analytics
Communication Data:
- Support tickets and correspondence
- Chat messages (if applicable)
- Marketing preferences
4. LAWFUL BASIS FOR PROCESSING
We process your data under the following legal bases:
Contract Performance:
- Account creation and management
- Processing transactions
- Providing marketplace services
- Customer support
Legitimate Interests:
- Fraud prevention and security
- Service improvements
- Business analytics
- Direct marketing (with opt-out)
Legal Obligations:
- AML/KYC compliance
- Tax reporting
- Law enforcement cooperation
- Regulatory compliance
Consent:
- Marketing communications
- Non-essential cookies
- Newsletter subscriptions
5. DATA RETENTION PERIODS
We retain data for the following periods:
- Account Data: Duration of account + 6 years
- Transaction Records: 7 years (legal requirement)
- AML/KYC Documents: 5 years after relationship ends
- Support Tickets: 3 years
- Marketing Data: Until consent withdrawn
- Technical Logs: 90 days
- Cookies: As per Cookie Policy
6. DATA SHARING & TRANSFERS
Third Party Recipients:
- Steam/Valve (authentication and trading)
- BitSkins API (market data)
- Cloudflare (CDN and security)
- AWS (hosting in EU regions)
- Vercel (platform hosting)
- Law enforcement (when legally required)
International Transfers:
- Data is primarily processed in the EU
- Steam services may involve US transfers (Privacy Shield)
- We use Standard Contractual Clauses where required
- Adequate safeguards are in place for all transfers
7. DATA SECURITY MEASURES
We implement appropriate technical and organizational measures:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Regular security audits and penetration testing
- Access controls and authentication
- Employee data protection training
- Incident response procedures
- Regular backups and disaster recovery
- ISO 27001 aligned practices
8. DATA BREACH PROCEDURES
In case of a personal data breach:
- We will assess the risk to individuals
- Notify the ICO within 72 hours if required
- Inform affected users without undue delay
- Document all breaches internally
- Implement measures to prevent recurrence
- Cooperate with regulatory investigations
9. CHILDREN'S DATA
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information.
10. AUTOMATED DECISION MAKING
We use automated systems for:
- Fraud detection and prevention
- AML transaction monitoring
- Market price calculations
- AI-powered item analysis
You have the right to request human review of automated decisions that significantly affect you.
11. EXERCISING YOUR RIGHTS
To exercise any of your GDPR rights:
- Email our DPO at dpo@poshskins.com
- Include proof of identity
- Specify which right(s) you wish to exercise
- We will respond within 30 days
- No fee for most requests
- Complex requests may take up to 90 days
12. COMPLAINTS
If you're unsatisfied with our data handling:
- Contact our DPO first at dpo@poshskins.com
- You may lodge a complaint with the ICO
- ICO Website: ico.org.uk
- ICO Helpline: 0303 123 1113
13. UPDATES TO THIS POLICY
We may update this GDPR policy periodically. Material changes will be notified via email or prominent website notice. The "Last updated" date will be revised accordingly.
14. CONTACT INFORMATION
Data Protection Officer:
Email: dpo@poshskins.com
Phone: +44 20 1234 5678
Address: 60 Tottenham Court Road, Office 119 Fitzrovia London W1T 2EW
General Inquiries:
Email: privacy@poshskins.com
Support: support@poshskins.com