Legal
Privacy Policy
TicTaps – processing of personal data under the GDPR and the UK GDPR
1. Who we are and how to reach us
Tictaps B.V. (“TicTaps”, “we”) is the controller for the personal data we process when you use the Platform. You can address questions or requests to privacy@tictaps.com.
Because TicTaps is established in the Netherlands (EU) and serves users in the UK without an establishment there, we are required to appoint a representative in the UK under Article 27 UK GDPR. This is a company or person established in the UK that acts as the point of contact for the UK supervisory authority (ICO) and data subjects. This appointment is being finalised; once completed, we will publish the representative’s name and UK address here. In the meantime, and for all data protection queries, you can contact us directly at privacy@tictaps.com. An EU representative is not required as we are established in the EU.
2. Scope and applicable law
This policy applies to users in the EEA and the UK. We process personal data in accordance with the General Data Protection Regulation (GDPR) and, for users in the UK, the UK GDPR and the Data Protection Act 2018.
3. Personal data we process
- Account data: name, email address, username, password (encrypted), date of birth, country/region.
- Game data: entries, scores, statistics, rankings and – derived – skill profiles.
- Payment and transaction data: transaction history, (tokenised) payment-method details, withdrawal preferences.
- Verification data (KYC): identity document and, where applicable, a facial capture/scan for comparison; this may constitute biometric / special category personal data (see Article 6).
- Technical and location data: IP address, device and browser information, device identifiers, general location and – with consent – precise location.
- Communication and support data; and data for fraud, AML and sanctions checks.
4. Purposes and legal bases
We process your data for the following purposes and on the legal bases stated:
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Providing the service: account, gameplay, payments and withdrawals | Performance of the contract (Art. 6(1)(b)) |
| Identity, age and location verification (KYC) | Legal obligation and/or legitimate interest (Art. 6(1)(c)/(f)); for biometrics: explicit consent or another Art. 9 condition |
| Fraud, AML and sanctions checks and security | Legal obligation and/or legitimate interest (Art. 6(1)(c)/(f)) |
| Improving the service and analytics (aggregated/pseudonymised where possible) | Legitimate interest (Art. 6(1)(f)) |
| Service and transaction communications | Performance of the contract (Art. 6(1)(b)) |
| Marketing communications | Consent (Art. 6(1)(a)); revocable |
| Complying with legal, tax and retention obligations | Legal obligation (Art. 6(1)(c)) |
5. Special category data (biometrics in KYC)
To the extent that facial/identity verification produces biometric data processed to identify you uniquely, this constitutes special category personal data. We process it only on a valid Article 9 basis (such as your explicit consent, which we request separately and specifically, or an applicable legal basis). If you refuse or withdraw consent, this may prevent verification or withdrawal where no alternative is available or the processing is legally required.
6. Automated decision-making (KYC and fraud)
KYC, fraud or withdrawal decisions may be partly automated. Where a decision is based solely on automated processing and produces legal effects concerning you or similarly significantly affects you, you have the right to human intervention, to express your point of view and to contest the decision, in accordance with Article 22 GDPR/UK GDPR. At a high level, we assess identity, age, location and risk signals against our rules and against information from verification and fraud service providers.
7. Recipients and processors
We share data with service providers who process on our behalf, including payment service providers, identity/KYC verification providers, hosting providers, analytics and anti-fraud services. We conclude data processing agreements with these parties. We may also share data where required by law, to protect rights and safety, or in a merger/acquisition with appropriate safeguards. We do not sell your personal data.
Our categories of recipients are: payment service providers, identity/KYC verification providers, hosting providers, and analytics and anti-fraud services. Hosting, analytics and payment providers typically act as processors; KYC/identity verification providers may, for certain processing, act as independent or joint controllers, with their own privacy notice. A current overview of the providers we use is available on request at privacy@tictaps.com.
8. International transfers
If data is transferred outside the EEA or the UK, we ensure an appropriate safeguard: an adequacy decision, or the European Commission’s standard contractual clauses (SCCs) and/or the UK International Data Transfer Agreement or UK addendum, with supplementary measures where needed. A copy of the safeguard is available on request.
9. Retention periods
| Category | Retention period |
|---|---|
| Account data | Up to 5 years after account closure |
| Transaction and financial records | 7 years (NL tax retention obligation) |
| KYC/AML evidence and records | 5 years after the end of the relationship (AML retention obligation) |
| Game statistics | Until account deletion, then aggregated/anonymised |
| Verification/biometric data | Deleted or anonymised once the verification purpose is achieved, unless a longer period is legally required |
We do not retain data longer than necessary for the stated purposes and the applicable legal retention obligations per market.
10. Security
We apply appropriate technical and organisational measures, including encryption of sensitive data, access controls, monitoring and periodic security reviews. No system is completely secure; use a strong password and protect your login details.
11. Your rights
You have the right of access, rectification, erasure, restriction, objection and data portability, and the right to withdraw consent given. You can address requests to privacy@tictaps.com; we respond within the statutory period (in principle one month). If you disagree with our processing, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or, for the UK, the Information Commissioner’s Office (ICO), or with your local supervisory authority.
12. Cookies and similar technologies
We use essential cookies for the operation of the Platform and – with your consent – analytics and preference cookies. We place non-essential cookies only after consent via our cookie banner. See our Cookie Policy for details and your choices.
13. Minors
The Platform is intended solely for persons aged 18 and over. We do not target persons under 18 and do not knowingly collect their personal data. If we learn that we have processed data of a person under 18, we will delete it. We do not direct advertising at persons under 18. Should TicTaps in future open (free) play to persons under 18, we will apply additional safeguards in accordance with the applicable rules for children, including the UK Age Appropriate Design Code (Children’s Code).
14. Changes
We may amend this policy. We announce material changes in advance by email or a notification in the Platform. The current version is always available on the Platform.
15. Contact
Tictaps B.V.
Chamber of Commerce (KvK) 93585837 · the Netherlands · privacy@tictaps.com