1w Privacy Policy for European Users
This document sets out the rules for the collection, use, storage, and sharing of personal data. Personal data is any information that identifies or relates to a specific individual, such as a name, email address, or IP address. This Privacy Policy applies to registered players, visitors, and users of the website and mobile application.
Data processing takes place across multiple countries and jurisdictions. Regional addenda supplement this central document to address specific local legal requirements, including those under the General Data Protection Regulation for European users.
Collection and Protection of Personal Information
The table below covers the main categories of personal data collected by 1w, with example data points and the channels through which each category is collected.
| Data Category | Example Data Points | Collection Channels |
|---|---|---|
| Identifiers | Full name, home address, date of birth | Registration forms, contact centres |
| Contact Details | Email address, phone number, postal code | Online forms, events, contact centres |
| Online Identifiers | IP address, cookie ID, device ID | Cookies, apps, website analytics |
| Behavioural Data | Browsing history, interaction logs, search queries | Cookies, apps, social media |
| Demographic Data | Age, gender, language, country | Registration forms, surveys, social media |
| Financial Information | Payment card details, billing address, transaction records | Checkout forms, payment processors |
| Employment-Related Information | Job title, employer name, professional email | Contact forms, events, registrations |
| Sensitive Data | Health status, biometric data, religious affiliation | Dedicated forms, contact centres |
Each data category receives protection in line with its sensitivity level. Appropriate organisational measures apply across all collection channels listed above.
Purpose of Personal Data Processing
Each processing purpose connects to defined data categories. The table below maps 10 core purposes to the relevant data types and a brief explanation of each.
| Processing Purpose | Data Categories | Explanation |
|---|---|---|
| Service Delivery | Identifiers, financial data | Data enables fulfilment of requested products and transactions |
| Account Management | Identifiers, preferences, login data | Data supports profile creation, access control, and account updates |
| Analytics | Behavioural data, device identifiers | Data measures usage patterns and site performance |
| Product Improvement | Behavioural data, interaction logs | Data informs development decisions and feature adjustments |
| Marketing and Personalisation | Demographics, preferences, cookie data | Data targets relevant offers and personalised content |
| Fraud Prevention | Identifiers, transaction data, IP addresses | Data detects suspicious activity and protects system integrity |
| Compliance and Governance | Financial data, identifiers, contracts | Data supports audits, legal obligations, and internal reporting |
| Customer Support | Identifiers, interaction notes, call records | Data resolves queries, complaints, and support tickets |
| Research and Statistics | Aggregated or pseudonymised behavioural data | Data produces trend analysis and statistical reporting |
Viewing, Updating and Managing Your Personal Data
European users have several clear steps to access, review, and correct personal data held on record. Each step follows a standard process with defined timeframes and identity checks.
- Submit an access request. Send a written request to the dedicated privacy email address or complete the online web form to ask for a full copy of stored personal data;
- Check the data summary. Examine the response document, which lists data categories, processing purposes, and third-party recipients;
- Correct inaccurate records. Contact the privacy team directly and specify which details are wrong, then provide accurate replacement information;
- Use account settings. Log in to the self-service account area and edit profile details, contact information, and communication preferences directly;
- Manage marketing preferences. Navigate to the notification or subscription settings and adjust consent choices for email and other communications;
- Confirm identity. Submit a valid government-issued ID document to verify identity before the team processes any request;
- Expect a response within 30 days. The privacy team responds to all verified requests within 30 calendar days of receipt.
Age Restrictions and Protection of Minors
Several rules apply to the use of services by minors. Each point below sets out a specific obligation or action.
- The minimum age to use the services in Europe is 18 years;
- Any personal data submitted by a person below the required age is deleted or handled according to applicable legal requirements;
- A parent or guardian holds responsibility for supervising a minor’s use of the services;
- Contact the privacy team directly to report any case where a child’s data was submitted without consent.
Cross-Border Transfer of Personal Data
Personal data gets stored and processed across multiple countries and regions. These locations include the European Union, the European Economic Area, the United Kingdom, the United States, and countries across the Asia-Pacific zone.
Several typical scenarios drive these international data flows. Global teams based in different countries access centralised databases to deliver unified service operations. Cloud infrastructure providers host data across distributed server networks, which means a single user record can sit on servers in more than one country at the same time.
Primary server locations include data centres in the United States and within EU territory. Secondary infrastructure spans Asia-Pacific nodes, which support performance and availability for users in those areas.
These cross-border flows exist to support consistent operations across all regions. A support agent in one country can access the same account records as a technical team in another country. Cloud providers process data on behalf of the organisation across their own global networks.
Users should expect that personal data travels across national borders as part of standard operational activity. This applies to all data categories described elsewhere in this Privacy Policy.
Legal Notice and Limitation of Liability
This Privacy Policy document serves an informational purpose. It explains how personal data is collected, used, stored, and shared, and it does not constitute legal advice. Readers who need specific legal guidance on data protection matters should consult a qualified professional.
This document operates alongside the Terms of Use, and both texts apply to users of the associated services. Reasonable efforts are taken to keep the information accurate and current as of 2026.
Reliance on this document does not create legal liability on the part of the organisation. No responsibility is accepted for decisions made solely on the basis of the content presented here. Users are encouraged to check this document regularly for updates.
Cookie Policy
Cookies and similar technologies collect data across 4 distinct categories. The table below outlines each type, its purpose, the data involved, and high-level retention periods.
| Cookie Type | Purpose | Typical Data | Retention |
|---|---|---|---|
| Strictly Necessary | Enables core site functions and session continuity | Session tokens, authentication identifiers | Session duration |
| Functional | Stores user preferences and personalisation settings | Language preferences, device identifiers | Up to 12 months |
| Analytics | Tracks usage patterns and measures site performance | Usage data, page interaction logs, IP addresses | Up to 24 months |
| Advertising | Delivers targeted ads and measures campaign results | Cookie IDs, behavioural profiles, device identifiers | Up to 13 months |
Your Acceptance of This Privacy Policy
By accessing or using this website and its services, users acknowledge and accept the terms set out in this Privacy Policy. Any continued use of the site after an update to this document takes effect serves as acceptance of the revised terms. Users retain responsibility for checking this page on a regular basis to stay informed of any changes. The most recent version of the document supersedes all prior versions and takes effect upon publication.
When Personal Data May Be Shared with Third Parties
The table below covers the categories of third-party recipients that receive personal data, the reason for each transfer, and the options available to users who want to limit certain disclosures.
| Recipient Category | Reason for Data Transfer | User Limiting Options |
|---|---|---|
| Group Companies | Internal operational support, shared services, and consolidated reporting across affiliated entities | Contact the privacy team to request restricted internal sharing |
| Service Providers and Processors | Hosting, technical support, and data processing carried out on behalf of the data controller | No direct opt-out; governed by binding processor agreements |
| Payment Processors | Transaction authorisation, fraud detection, and billing verification | Select alternative payment methods to reduce transmitted data |
| Analytics and Advertising Partners | Usage analysis, audience segmentation, and targeted content delivery | Adjust cookie preferences or opt out via the consent management tool |
| Professional Advisers | Legal, audit, and compliance consultations requiring access to relevant records | No opt-out; disclosure tied to legal obligation |
| Authorities and Regulators | Mandatory responses to legal orders, regulatory inquiries, or law enforcement requests | No opt-out available under applicable law |
| Potential Acquirers | Due diligence and business transfer processes in corporate transactions | Contact the privacy team before a transaction is finalised |
Links to External Websites
The Privacy Policy covers only the data practices of this organisation. It does not extend to any third-party websites or services that users access through external links.
- Third-party websites operate under their own separate privacy policies;
- Users must review the privacy policy of each external site they visit;
- This organisation holds no responsibility for the content, data practices, or security of external websites;
- No liability applies to any information collected by third-party services.
Data Retention and Storage Periods
Each type of personal data has a distinct retention period. The list below outlines the standard durations or criteria applied to different data categories across this service.
- Account data – retained for the full duration of an active account, plus a standard period of up to 7 years after closure to meet legal obligations;
- Transaction records – kept for a minimum of 7 years to satisfy financial and tax requirements;
- Marketing data – stored until a user withdraws consent or submits a valid objection;
- Analytics logs – retained for up to 26 months, then deleted or anonymised;
- Backups and archives – held until the next scheduled deletion cycle, subject to a maximum of 3 years.
No data is kept beyond the period necessary for its stated purpose or beyond what applicable law requires.
Deletion, Restriction and Objection to Processing
Users have several rights over their personal data. The steps below outline how to act on those rights and what to expect at each stage.
- Submit a deletion request. Contact the privacy team via the dedicated web form or email address listed in the contact section.
- Request a temporary restriction. Ask for processing to pause on specific data categories through the same submission channels.
- Object to direct marketing. Use the unsubscribe link in any marketing email or submit a written objection through the online form.
- Check applicable exceptions. Note that data tied to active legal obligations, contractual duties, or regulatory requirements cannot be erased immediately.
- Understand archive retention. Recognise that records held in backup systems remain until the next scheduled deletion cycle runs.
- Await confirmation. Expect a written response within 30 days of submitting any deletion, restriction, or objection request.
- Escalate unresolved requests. Direct unresolved matters to the relevant supervisory authority listed in the complaints section.
Data Portability and Automated Decisions
Data portability and automated decision-making are two distinct areas within a Privacy Policy. Both relate to how personal data flows and how systems use it to produce outcomes for users.
- What data portability means in practice. A user has the right to receive certain personal data in a structured, machine-readable format, such as JSON or CSV, for transfer to another service provider;
- Data categories covered by portability. Portability rights apply to data a user provided directly, including profile details, contact information, and account preferences;
- How automated decision-making operates. Automated systems process behavioural data, demographics, and stated preferences to produce recommendations and personalised content without manual review;
- Profiling in practice. Profiling groups users by interaction patterns to adjust content, offers, and service features presented to each individual account;
- Right to request human review. A user has the right to request that a human examines any important decision produced solely by automated processing;
- Opting out of profiling. A user can withdraw consent for profiling used in non-essential activities, such as targeted content delivery.
How to Contact Us About Privacy and Make Complaints
There are 4 contact channels available for privacy enquiries and rights requests. Each channel fits a different type of request, and response times vary by method.
| Contact Channel | Best Used For | Indicative Response Time |
|---|---|---|
| Dedicated email | Access, correction, deletion, and portability requests | Up to 30 days |
| Online web form – available in the footer | General enquiries, preference updates, consent withdrawal | Up to 14 days |
| Postal address – registered legal office | Formal written requests, signed declarations, legal notices | Up to 45 days |
Users who receive no response within the stated timeframe, or who dispute the outcome of a request, can escalate the matter directly to the relevant national or regional supervisory authority. Contact details for applicable regulators appear on the official government or data protection authority websites in each territory.
Global Scope and Regional Variations of This Policy
This Privacy Policy is structured for use across all territories, with particular attention to European data protection requirements. The core document sets out the foundational principles that apply to all users – covering data categories, processing purposes, individual rights, and contact details for privacy-related requests.
Over 140 national and regional frameworks regulate personal data processing across United Nations member states. To address this, regional notices or addenda supplement the main document where local rules require distinct disclosures or additional protections.
The core principles remain consistent across all versions of the document. Data categories, the purposes attached to each category, the rights available to individuals, and the contact channels for submitting requests all follow a unified structure. Local variations adjust specific wording, retention periods, or legal bases to reflect the requirements of each applicable regime.
This approach keeps the document readable and consistent for all users, regardless of their location. Regional addenda are published alongside the main text and carry the same authority for users in those specific territories.