This Privacy Policy sets out how NOFTR.GAMES LIMITED collects and processes personal data in connection with the FANATIK Platform. It explains what personal data we collect, how we use it, the lawful bases for processing, how long we retain it, and your rights under applicable data protection law (including UK GDPR and, where applicable, EU GDPR)
This Privacy Policy is provided in a layered format so that you can click through to the specific sections set out below.
1. Important information and who we are
This Privacy Policy explains how NOFTR. GAMES LIMITED (“Company”, “we”, “us”, “our”) collects and uses your personal data when you access or use the FANATIK mobile application, related web interfaces, and associated services (together, the “Platform”).
We collect and process personal data when you:
create an account or register on the Platform;
participate in competitions or interactive features;
make User Payments or receive prizes;
select or support a Club;
contact us or submit enquiries;
interact with us via email, social media or in-app messaging; or
otherwise use the Platform.
Where you select a Club within the Platform, we may process certain limited performance-related data in order to provide visibility metrics or engagement summaries to that Club, as described in section 5 (Disclosures of your personal data).
Age Restrictions
The Platform is intended for users aged 18 years and over. We do not knowingly collect or process personal data from individuals under the age of 18. If we become aware that a user under 18 has created an account, we will suspend or delete the account and take appropriate steps to remove associated personal data. We may implement age verification measures where necessary to ensure compliance with applicable laws.
Controller
NOFTR.GAMES LIMITED (company number 17025964), registered in England and Wales with its registered office at 92 York Street, London, England, W1H 1QX, is the data controller responsible for your personal data for the purposes of UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, and where applicable, Regulation (EU) 2016/679 (“EU GDPR).
In this Privacy Policy, references to “NOFTR”, “Company”, “we”, “us” or “our” mean NOFTR.GAMES LIMITED.
NOFTR.GAMES LIMITED acts as controller in respect of personal data processed through the FANATIK Platform, including but not limited to:
competition participation,
Age verification
supporter selection or engagement with a Club,
User Payments made via the Platform,
marketing and communications,
platform security, fraud prevention and compliance monitoring, and
account registration and profile management.
Participating Clubs do not act as joint controllers with NOFTR.GAMES LIMITED in respect of user account data or competition participation data, unless explicitly stated otherwise. Any personal data shared with a Club is limited to aggregated or pseudonymised performance metrics as described below.
Where such providers process personal data on our behalf, they act as data processors under written agreements compliant with Article 28 UK GDPR.
Where a third party processes personal data for its own regulatory or compliance purposes (for example, where an Exchange Partner carries out identity verification, anti-money laundering checks, or financial compliance screening), that third party acts as an independent data controller and will provide its own privacy notice governing that processing.
For the avoidance of doubt, NOFTR.GAMES LIMITED acts as the sole controller in respect of personal data processed through the Platform itself.
Third-party providers, including Exchange Partners and app store providers, act as independent data controllers only in respect of processing carried out within their own services and regulatory obligations.
Blockchain Processing
Certain User Payments and Club Allocations are processed using blockchain infrastructure and smart contract logic. Where blockchain infrastructure is used, certain transaction data (such as wallet addresses and transaction identifiers) may be recorded on decentralised networks.
NOFTR.GAMES LIMITED determines the purposes and means of any personal data it submits to such networks. However, once data is recorded on a blockchain, it may be processed by independent network participants beyond our control.
We design our systems to minimise the use of personal data on-chain and, where possible, store personal data off-chain.
Data Protection Contact
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your legal rights, please contact:
Email: legal@noftr.games
We will respond to all legitimate requests in accordance with applicable data protection law.
2. The types of personal data we collect about you
Personal data means any information about an individual from which that person can be identified, either directly or indirectly.
We may collect, use, store and transfer different kinds of personal data about you through your use of the FANATIK Platform (including the mobile application and any associated web interface). We have grouped this data as follows:
Identity Data
Includes first name, last name, username, display name, date of birth, and any information provided for identity verification purposes where required.
Contact Data
Includes email address and, where provided, postal address and telephone number.
Account Data
Includes login credentials, encrypted passwords, authentication data, account preferences, and selected Club affiliation.
Transaction Data
Includes details of User Payments, entry fees, prize allocations, Club Allocations, digital asset transfers, smart contract transaction hashes, and related payment history.
Financial Data and Wallet
Includes blockchain wallet address, transaction identifiers, payment references, Exchange Partner account identifiers, and records of fiat conversion requests. We do not store private wallet keys.
Technical Data
Includes internet protocol (IP) address, device identifier, login data, browser type and version, time zone setting, device operating system, app version, and other technology on the devices used to access the Platform.
Profile Data
Includes username, preferences, competition participation history, selected Club(s), prize history, and feedback responses.
Usage Data
Includes information about how you use the Platform, competitions entered, features accessed, interactions with Clubs, time spent within the Platform, and navigation behaviour.
Compliance and Verification Data
Where required for regulatory or anti-fraud purposes, this may include information provided for identity verification, anti-money laundering (AML) checks, sanctions screening, or financial compliance checks. Such checks may be conducted by regulated Exchange Partners acting as independent data controllers.
Marketing and Communications Data
Includes your preferences in receiving marketing communications from us and your communication preferences.
Blockchain Processing Note
Where User Payments are processed via blockchain infrastructure, certain transaction-related data (such as wallet addresses and transaction hashes) may be recorded on a decentralised ledger. While blockchain data is pseudonymous, it may constitute personal data where it can be linked to an identifiable individual.
We design our systems to minimise personal data stored on-chain wherever possible.
Aggregated Data
We also collect, use, and share aggregated data such as statistical or demographic data for analytical and service improvement purposes. Aggregated data does not directly or indirectly identify you and therefore is not personal data under UK GDPR.
For example, we may aggregate Usage Data to analyse trends in how users interact with competitions or specific Platform features in order to improve functionality and user experience.
3. How is your personal data collected?
We use different methods to collect data from and about you including through:
creating an account on the FANATIK Platform;
Entering your data of birth upon access to the Platform;
selecting or engaging with a Club through the Platform;
entering competitions;
making User Payments;
participating in prize draws;
requesting fiat withdrawals or conversions via an Exchange Partner;
subscribing to updates or marketing communications;
contacting us by email, in-app messaging, social media or otherwise; or
providing feedback or responding to surveys.
Where identity verification is required (for example, for regulatory compliance relating to digital asset transactions), you may provide additional verification data either directly to us or to a regulated Exchange Partner.
Automated technologies and Platform interactions
As you interact with the FANATIK Platform, we automatically collect certain Technical and Usage Data, including:
IP address;
device identifiers;
operating system and app version;
login timestamps;
in-app activity;
competition participation;
wallet interactions;
transaction metadata.
We collect this data using cookies (where applicable), software development kits (SDKs), server logs, device identifiers, analytics tools and similar technologies.
Where blockchain-based payments are made, transaction identifiers and wallet addresses may be recorded on a decentralised ledger.
Please see our Cookie Policy for further details.
Blockchain infrastructure
Where User Payments are processed via smart contracts deployed on blockchain networks, transaction data (including wallet addresses and transaction hashes) is generated and recorded automatically by the relevant blockchain protocol.
We do not control independent blockchain nodes but design our systems to minimise personal data stored on-chain.
Third parties and service providers
We may receive personal data about you from third parties including:
Exchange Partners
Where you use a regulated digital asset exchange provider for wallet services, fiat conversion or compliance verification, that provider may share confirmation data with us (such as verification status or transaction confirmation). Exchange Partners act as independent data controllers for their own regulatory processing.
Analytics providers
We use analytics providers to understand Platform usage and improve functionality.
Cloud hosting and infrastructure providers
We use hosting providers to operate the Platform securely.
App stores
Where you download the FANATIK mobile application via an app store (e.g. Apple App Store or Google Play), we may receive limited technical and transactional information in accordance with that platform’s policies.
Fraud prevention and compliance providers
Where required, we may receive information from providers assisting with fraud monitoring, sanctions screening, anti-money laundering (AML) checks or regulatory compliance.
Public sources
We may receive limited Identity or Contact Data from publicly available sources where required for compliance or verification purposes (for example, Companies House in the UK).
4. How we use your personal data?
We rely primarily on the performance of a contract and legitimate interests to operate the Platform. More detailed examples of processing activities are set out below.
Legal basis
Under UK data protection law (UK GDPR and the Data Protection Act 2018), we must have a lawful basis for processing your personal data. References in this section to provisions of UK GDPR shall, where applicable, include the equivalent provisions under the EU GDPR.
We rely on the following legal bases:
Performance of a contract (Article 6(1)(b) UK GDPR): We process your personal data where such processing is necessary to provide the FANATIK Platform and related services to you, including registering and maintaining your account, enabling your participation in competitions, processing User Payments, allocating prizes, facilitating Club Allocations, and providing customer support. Without this processing, we would be unable to deliver the core functionality of the Platform or fulfil our contractual obligations to you.
Legitimate interests (Article 6(1)(f) UK GDPR): We may process your personal data where such processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Our legitimate interests include operating, maintaining, and improving the FANATIK Platform; detecting and preventing fraud; preventing abuse or misuse of competitions; maintaining Platform and network security; ensuring the integrity and reliability of smart contract functionality; conducting analytics and performance monitoring; and carrying out general business administration and planning. Where we rely on this legal basis, we conduct a balancing assessment to ensure that our interests do not unfairly impact your fundamental rights and freedoms.
Legal obligation (Article 6(1)(c) UK GDPR): We process your personal data where such processing is necessary to comply with legal and regulatory obligations to which we are subject. This includes obligations relating to anti-money laundering requirements, sanctions screening, financial compliance duties, regulatory reporting, and responding to lawful requests, court orders or enquiries from competent authorities.
Consent (Article 6(1)(a) UK GDPR): We rely on your consent where required by law, including for sending direct marketing communications (where applicable) and for placing non-essential cookies or similar tracking technologies on your device. Where we rely on consent, you have the right to withdraw your consent at any time, and such withdrawal will not affect the lawfulness of processing carried out prior to your withdrawal.
Purposes for which we will use your personal data
Below is a summary of how we use your personal data, the categories of data involved, and our lawful basis.
Purpose/Use | Type of data | Legal basis [and retention period] | Retention period: |
To register you as a user of the FANATIK Platform and create and maintain your account and to verify your age (18+) | (a) Identity (b) Contact (c) Account Data (d) Technical Data | Performance of a contract with you (Article 6(1)(b) UK GDPR). Processing is necessary to create your account, authenticate access, and enable you to use the core features of the Platform, including competition participation and User Payments. | We retain account data for the duration of your account and for 6 years after account closure for contractual record-keeping, fraud prevention and legal compliance purposes. |
To process User Payments and enable competition participation, including: (a) managing entry fees and in-app payments; (b) executing smart contract transactions; (c) allocating Monetary Prizes; (d) facilitating Club Allocations; and (e) collecting and recovering sums owed to us where applicable. | (a) Identity (b) Contact (c) Financial and Wallet Data (d) Transaction Data (e) Technical Data | (a) Performance of a contract with you (Article 6(1)(b) UK GDPR) – necessary to process User Payments, allocate prizes, and execute smart contract logic in connection with your use of the Platform. (b) Legitimate interests (Article 6(1)(f) UK GDPR) – necessary for debt recovery, fraud prevention, platform integrity and business administration. (c) Legal obligation (Article 6(1)(c) UK GDPR) – where processing is required for financial reporting, regulatory compliance or anti-money laundering purposes. | Financial and transaction records are retained for 6 years for accounting and legal compliance purposes. Blockchain transaction data may remain recorded on decentralised networks indefinitely, beyond our direct control. |
To manage our relationship with you, including: (a) notifying you about changes to our Terms, Privacy Policy or Platform features; (b) responding to your enquiries, support requests, complaints or disputes; and (c) communicating important service-related updates relating to competitions, User Payments or account security. | (a) Identity (b) Contact (c) Profile Data (d) Marketing and Communications Data | (a) Performance of a contract with you (Article 6(1)(b) UK GDPR) – where communications are necessary to provide the FANATIK Platform and fulfil our contractual obligations, including account updates and competition-related notices. (b) Legal obligation (Article 6(1)(c) UK GDPR) – where we are required to notify you of changes to our legal terms, regulatory disclosures or compliance-related matters. (c) Legitimate interests (Article 6(1)(f) UK GDPR) – necessary to manage our relationship with you, maintain accurate records, handle complaints, protect the Platform, and ensure effective customer support. | We retain correspondence and relationship management records for up to 6 years following account closure or resolution of the relevant matter, in line with contractual limitation periods and legal compliance requirements. |
To enable you to participate in competitions, prize draws or surveys on the FANATIK Platform, including managing entries, validating eligibility, executing smart contract logic, allocating prizes (including Monetary Prizes), and administering competition outcomes. | (a) Identity (b) Contact (c) Profile Data (d) Usage Data (e) Financial and Wallet Data (where relevant to prize distribution) (f) Marketing and Communications Data | (a) Performance of a contract with you (Article 6(1)(b) UK GDPR) – necessary to administer competitions, process entry fees (where applicable), execute smart contract functionality, allocate prizes and facilitate Club Allocations. (b) Legitimate interests (Article 6(1)(f) UK GDPR) – necessary to monitor competition integrity, prevent fraud or abuse, analyse participation trends, improve competition formats, and grow our business. (c) Legal obligation (Article 6(1)(c) UK GDPR) – where required for regulatory compliance, financial reporting or fraud monitoring. | Competition participation records are retained for up to 6 years following completion of the relevant competition for contractual and compliance purposes. Blockchain transaction data may remain recorded on decentralised networks indefinitely beyond our direct control. |
To administer, operate and protect the FANATIK Platform and our business, including troubleshooting, system maintenance, smart contract deployment and monitoring, blockchain integration, fraud detection and prevention, cybersecurity monitoring, data analysis, testing, reporting, hosting of data, and business continuity planning. | (a) Identity (b) Contact (c) Technical Data (d) Usage Data (e) Transaction Data (where relevant to fraud monitoring or security analysis) | (a) Legitimate interests (Article 6(1)(f) UK GDPR) – necessary for running and securing our business, maintaining Platform functionality, ensuring network and smart contract integrity, preventing fraud or misuse of competitions, monitoring cybersecurity threats, and managing business operations including potential restructuring or corporate transactions. (b) Legal obligation (Article 6(1)(c) UK GDPR) – where processing is required to comply with regulatory, financial, cybersecurity or reporting obligations.
| Technical logs and security-related data are typically retained for up to 12 months, unless required for fraud investigations, legal claims or regulatory compliance, in which case they may be retained for up to 6 years. |
To deliver relevant content within the FANATIK Platform and associated digital interfaces, to provide in-app promotions and marketing communications (where permitted), and to measure, analyse and understand the effectiveness of advertising, promotions and engagement features. | (a) Identity (b) Contact (c) Profile Data (d) Usage Data (e) Marketing and Communications Data (f) Technical Data | (a) Legitimate interests (Article 6(1)(f) UK GDPR) – where processing is necessary to analyse user engagement, improve Platform functionality, measure campaign effectiveness, develop our services, and inform our marketing strategy, provided such interests are not overridden by your rights and freedoms. (b) Consent (Article 6(1)(a) UK GDPR and PECR, where applicable) – where required for placing non-essential cookies, tracking technologies, behavioural advertising or similar technologies.
| We retain marketing preference data for as long as you maintain an account with us and for up to 24 months after your last interaction with the Platform, unless you withdraw consent earlier. Technical and analytics data are typically retained for up to 12 months unless required for security or legal purposes. |
To use data analytics to improve the FANATIK Platform, enhance user experience, optimise competition mechanics and prize structures, improve customer support and relationships, measure engagement and performance, and assess the effectiveness of communications and marketing activity. | (a) Technical Data (b) Usage Data (c) Profile Data (where relevant to engagement analysis) | Legitimate interests (Article 6(1)(f) UK GDPR) – processing is necessary for the operation, improvement and optimisation of the FANATIK Platform, including analysing usage trends, monitoring engagement, preventing misuse, refining competition formats, improving user experience, and informing business and marketing strategy. We have carried out a balancing assessment to ensure that such processing does not override your rights and freedoms. Where analytics involve the use of non-essential cookies or similar tracking technologies, we rely on consent under PECR and Article 6(1)(a) UK GDPR.
| Technical and analytics data are typically retained for up to 12 months unless required for security, fraud prevention or legal compliance purposes. |
To send you relevant marketing communications and, where appropriate, make personalised suggestions and recommendations about features, competitions or services available on the FANATIK Platform, based on your Profile, Usage and engagement data. | (a) Identity Data (b) Contact Data (c) Technical Data (d) Usage Data (e) Profile Data (f) Marketing and Communications Data | Consent (Article 6(1)(a) UK GDPR and PECR) – where required, we rely on your prior opt-in consent to send electronic direct marketing communications (including email, SMS or push notifications). You may withdraw your consent at any time. Legitimate interests (Article 6(1)(f) UK GDPR) – in limited circumstances, where permitted by applicable law (for example, where the “soft opt-in” applies in respect of existing customers), we may send marketing communications relating to similar services, provided you have not opted out. Our legitimate interests include promoting and developing the FANATIK Platform and informing users about relevant competitions and features. We conduct a balancing assessment to ensure your rights are not overridden. Where we use profiling to tailor marketing communications, such profiling is limited to engagement and preference analysis and does not produce legal or similarly significant effects. | Marketing preference data is retained until you withdraw consent or opt out, after which we retain suppression data to ensure we do not contact you again. |
To carry out market research through your voluntary participation in surveys, feedback requests, beta testing, user experience studies or feature evaluation exercises relating to the FANATIK Platform. | (a) Identity Data (b) Contact Data (c) Profile Data (d) Usage Data (e) Marketing and Communications Data | Legitimate interests (Article 6(1)(f) UK GDPR) – We process this data where necessary to understand how users interact with the FANATIK Platform, improve competitions and digital features, enhance user experience, develop new functionality and support business planning. We conduct a balancing assessment to ensure that our interests in improving and developing the Platform do not override your rights and freedoms. Where participation is clearly optional and separate from the provision of core Platform services, and where specific survey processing requires it, we may rely on consent (Article 6(1)(a) UK GDPR), which you may withdraw at any time.
| Survey responses are retained only for as long as necessary to analyse results and implement improvements, after which responses are anonymised or securely deleted. Personal data linked to survey participation is typically retained for no longer than 24 months unless a longer period is required for audit, regulatory or dispute resolution purposes. |
To enable you to participate in competitions… facilitating Club Allocations. | (a) Identity (b) Contact (c) Profile Data (d) Usage Data (e) Financial and Wallet Data (where relevant to prize distribution)
| (a) Performance of a contract (Article 6(1)(b) UK GDPR) where sharing is necessary to provide the Club selection feature you have chosen; and/or (b) Legitimate interests (Article 6(1)(f) UK GDPR) in providing engagement analytics to participating Clubs, provided such interests are not overridden by your rights and freedoms.
| Account data: retained for the duration of the account plus 6 years after account closure (contractual limitation period). Competition records and fraud monitoring data: up to 6 years for legal defence and regulatory compliance. Wallet address records: retained for audit and compliance purposes for up to 6 years. |
Direct marketing
During the registration process on the FANATIK Platform, you will be given the opportunity to choose whether you would like to receive marketing communications from NOFTR.GAMES LIMITED by email, in-app notification, SMS or other electronic means (where available). We will only send you electronic marketing communications where we have obtained your consent, or where permitted under the “soft opt-in” rules under the Privacy and Electronic Communications Regulations (PECR), for example where you have previously engaged with our services and have not opted out.
Marketing communications may include updates about new competitions, features, prize opportunities, platform developments, promotional campaigns and related products or services.
We may analyse your Identity Data, Contact Data, Technical Data, Usage Data and Profile Data to better understand your interests and engagement with the Platform in order to tailor marketing communications to you. This profiling is limited to marketing personalisation and does not produce legal or similarly significant effects.
You can withdraw your consent to marketing at any time.
Third-party marketing
We do not sell your personal data. We will obtain your express opt-in consent before sharing your personal data with any third party for their own direct marketing purposes.
Opting out of marketing
You can opt out of marketing communications at any time by:
using the unsubscribe link included in any marketing email;
adjusting your marketing preferences within your account settings; or
contacting us at legal@notfr.games
Opting out of marketing communications will not affect service-related communications that are necessary for the performance of your contract with us or for compliance purposes. This includes communications relating to your account, competitions you have entered, prize notifications, security updates, regulatory notices, or changes to our Terms or Privacy Policy.
Cookies
The FANATIK Platform and our website use limited technical storage mechanisms to ensure the Platform functions securely and effectively.
We use strictly necessary cookies or similar technologies (such as local storage or session tokens) where required to:
enable secure log-in and account authentication;
maintain session integrity;
ensure the proper functioning of competitions and smart contract interactions;
prevent fraud, abuse, and unauthorised access; and
support essential Platform security and operational functionality.
These technologies are necessary for the operation of the Platform and do not require your consent under UK law. We do not use analytics, tracking, advertising, or behavioural marketing cookies.
You may configure your browser to block cookies; however, doing so may affect your ability to use certain core features of the Platform.
If our use of cookies or similar technologies changes in the future, we will update this Privacy Policy and, where required, implement an appropriate consent mechanism.
5. Disclosures of your personal data
We may share your personal data where necessary and in accordance with applicable data protection law for the purposes set out in the section “How we use your personal data”. However, we do not sell personal data to third parties.
We may share your personal data with the following categories of recipients:
Service providers (data processors)
Third-party providers who process personal data on our behalf in connection with operating and supporting the FANATIK Platform, including:
cloud hosting and infrastructure providers;
IT support and cybersecurity providers;
analytics and performance monitoring providers;
customer support providers;
payment service providers and digital asset infrastructure providers;
Exchange Partners facilitating the conversion of digital assets into fiat currency;
identity verification, fraud prevention, anti-money laundering (AML) and sanctions screening providers.
These third parties act as our data processors and are contractually required to process personal data only on our documented instructions and in accordance with applicable data protection law.
Participating Clubs
Where you select a Club within the Platform, we may share limited aggregated or pseudonymised performance data with that Club for the purposes of providing engagement visibility, participation metrics and support analytics.
participation frequency;
competition engagement metrics;
leaderboard positioning (in aggregated or anonymised format);
overall activity trends relating to supporters of that Club.
We do not share:
private keys or wallet credentials;
full transaction histories;
government identification documents;
financial compliance documentation;
Clubs act as independent data controllers in respect of any personal data they receive and are responsible for their own compliance with applicable data protection laws.
Professional advisers
Lawyers, accountants, auditors, insurers and other professional advisers who provide professional services to us.
Regulators and authorities
HM Revenue & Customs (HMRC), the Information Commissioner’s Office (ICO), law enforcement bodies, courts, regulators or other authorities where disclosure is required by law or necessary to establish, exercise or defend legal claims.
Corporate transaction parties
Third parties to whom we may choose to sell, transfer, assign or merge parts of our business or our assets.
6. International transfers
Some of our third-party service providers, infrastructure providers and digital asset service partners may be located outside the United Kingdom. In addition, where blockchain infrastructure is used, transaction data may be recorded on decentralised networks that operate globally. Where participating Clubs are located outside the United Kingdom, personal data shared with such Clubs will be transferred in accordance with the international transfer safeguards described in this section.
This means your personal data may be transferred to, stored in, or accessed from countries outside the UK. Where transfers occur in connection with blockchain infrastructure, such transfers are inherent to the operation of decentralised networks and may not be restricted to specific jurisdictions.
Where we transfer personal data outside the UK to countries that do not benefit from UK adequacy regulations, we ensure that a similar degree of protection is afforded to it by implementing appropriate safeguards in accordance with UK data protection law.
These safeguards may include:
transferring personal data to countries that have been deemed by the UK Government to provide an adequate level of protection;
entering into the UK International Data Transfer Agreement (IDTA);
entering into the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses;
implementing additional technical and organisational safeguards where necessary.
Where we transfer personal data from the EEA to a country outside the EEA that is not subject to an adequacy decision of the European Commission, we implement appropriate safeguards including:
Standard Contractual Clauses (SCCs);
the UK International Data Transfer Agreement (IDTA), where applicable; or
the UK Addendum to the SCCs.
You may request further information about the specific safeguards used for international transfers by contacting us at legal@notfr.games
Blockchain-specific note
Where User Payments are processed via blockchain infrastructure, transaction-related data (such as wallet addresses and transaction identifiers) may be recorded on decentralised networks that are not limited to a single geographic jurisdiction. Such networks may involve nodes located globally. We do not control the geographic location of independent blockchain nodes, and once recorded, blockchain data may be publicly accessible and immutable.
We design our systems to minimise personal data stored on-chain wherever possible.
7. Data Security
We have implemented appropriate technical and organisational measures designed to protect your personal data in accordance with Article 32 UK GDPR. These measures are intended to prevent your personal data from being accidentally lost, destroyed, altered, disclosed, or accessed without authorisation.
Our security measures include, where appropriate:
encryption of data in transit and at rest;
secure authentication and access controls;
role-based access restrictions;
secure cloud infrastructure;
monitoring and logging of system activity;
cybersecurity controls and vulnerability management processes;
regular review of smart contract deployment and infrastructure integrity; and
contractual security obligations imposed on third-party service providers.
Access to personal data is restricted to employees, contractors, service providers and advisers who have a legitimate business need to access it. All such individuals are subject to confidentiality obligations and are required to process personal data only in accordance with our instructions and applicable law. While we implement appropriate security measures, no system is completely secure and we cannot guarantee absolute security of personal data.
Where blockchain infrastructure is used, certain transaction-related data may be recorded on decentralised networks. While blockchain networks are designed to provide integrity and immutability, we design our systems to minimise personal data stored on-chain and to avoid storing sensitive personal information within smart contract logic.
We have procedures in place to detect, investigate and respond to suspected personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) and affected individuals where required by law.
8. Data retention
How long will you use my personal data for?
We will retain your personal data only for as long as reasonably necessary to fulfil the purposes for which we collected it, including to provide the FANATIK Platform and related services, to comply with our legal and regulatory obligations, and to resolve disputes.
In general:
Account information (including Identity, Contact and Profile Data) is retained for as long as your account remains active.
If you close your account, we will delete or anonymise your personal data within a reasonable period unless we are required to retain it for legal or regulatory purposes.
Transaction, Financial and Payment Data may be retained for up to six (6) years after the end of our relationship with you in order to comply with tax, accounting, anti-money laundering and financial reporting obligations.
Technical and Usage Data may be retained for a shorter period unless required for security, fraud prevention, regulatory or evidential purposes.
Marketing data is retained until you withdraw consent or opt out.
We may retain personal data for longer where necessary:
to establish, exercise or defend legal claims;
in response to regulatory requests; or
where we reasonably believe there is a prospect of litigation.
Where blockchain infrastructure is used, certain transaction-related records may be recorded on decentralised networks. Due to the immutable nature of blockchain technology, such records cannot be altered or deleted. However, we design our systems to minimise personal data stored on-chain and, where possible, personal data is stored off-chain and can be deleted or anonymised.
In some circumstances, you may request erasure of your personal data (see section 9 – Your legal rights).
In certain cases, we may anonymise personal data so that it can no longer be associated with you. Anonymised data may be retained and used indefinitely for research, analytics, security monitoring and business improvement purposes.
To determine the appropriate retention period, we consider the nature, sensitivity and volume of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes of processing, and applicable legal, regulatory, tax and accounting requirements. Retention periods may vary where required for legal, regulatory or dispute resolution purposes.
9. Your legal rights
Under applicable data protection law (including UK GDPR and, where applicable, EU GDPR), you have a number of rights in relation to your personal data. These rights are not absolute and may be subject to certain conditions or exemptions.
You have the right to:
Access: Request access to your personal data (commonly known as a “subject access request”). This enables you to receive a copy of the personal data we hold about you and to understand how and why we are processing it.
Rectification: Request correction of inaccurate or incomplete personal data that we hold about you. We may need to verify the accuracy of the new information you provide.
Erasure: Request erasure of your personal data in certain circumstances. This enables you to ask us to delete or remove personal data where there is no lawful reason for us continuing to process it.
Complain (UK Users only): You have the right to complain to us if you are unhappy with how we process your personal data. We will acknowledge your complaint and respond in accordance with applicable data protection law.
However, please note:
We may need to retain certain information to comply with legal, regulatory, tax, accounting, or anti-money laundering obligations.
Where personal data has been recorded on blockchain infrastructure, certain transaction records may be technically immutable. In such cases, we will take reasonable steps to minimise the association of that data with you and delete or anonymise any off-chain personal data under our control.
Restriction of Processing: Request restriction of processing of your personal data in certain circumstances, for example:
○if you contest the accuracy of the data;
○where the processing is unlawful but you do not want us to erase it;
○where we no longer require the data but you need it for legal claims; or
○while we verify overriding legitimate grounds following an objection.
Object: Object to the processing of your personal data where we rely on legitimate interests as the legal basis, including certain types of profiling. We will stop processing unless we can demonstrate compelling legitimate grounds which override your rights, or where processing is required for legal claims. You have an absolute right to object at any time to the processing of your personal data for direct marketing purposes.
Data portability: Request the transfer of your personal data to you or to a third party in a structured, commonly used, machine-readable format. This right applies only to information you have provided to us and where processing is based on consent or performance of a contract and carried out by automated means.
Withdraw consent: Where we rely on consent as the legal basis for processing (for example, for marketing communications or non-essential cookies), you may withdraw your consent at any time. Withdrawal will not affect the lawfulness of processing carried out before consent was withdrawn. Please note that withdrawing consent may affect your ability to use certain Platform features.
No fee is usually required
You will not usually have to pay a fee to exercise your rights. However, we may charge a reasonable fee or refuse to act if a request is manifestly unfounded, repetitive or excessive.
Identity verification
We may request specific information from you to confirm your identity before responding to your request. This is a security measure to ensure that personal data is not disclosed to unauthorised individuals. We may also contact you to clarify the scope of your request.
Time limit to respond
We aim to respond to all valid requests within one month. If your request is complex or involves multiple requests, we may extend this period by up to two further months, in which case we will inform you and explain the reasons for the delay.
10. Contact details
If you have any questions about this privacy policy, about how we use your personal data, or if you wish to exercise any of your data protection rights, please contact us using the details below:
Data Protection / Privacy Enquiries
Email: legal@notfr.games
Postal address:
NOFTR.GAMES LIMITED
92 York Street
London
England
W1H 1QX
United Kingdom
We do not currently provide dedicated telephone support for data protection enquiries. Please contact us by email in the first instance.
11. Complaints
If you have concerns about how we handle your personal data, we encourage you to contact us first at legal@notfr.games so that we can investigate and try to resolve your concerns promptly and fairly.
You also have the right to lodge a complaint at any time with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection matters.
You can contact the ICO at:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Website: https://www.ico.org.uk
If you are located in the European Union, you also have the right to lodge a complaint with the supervisory authority in your Member State of habitual residence, place of work, or place of the alleged infringement.
12. Changes to the privacy policy and your duty to inform us of changes
We keep this Privacy Policy under regular review to ensure it remains accurate and reflects how we process personal data.
This version was last updated on 2 July 2026.
We may update this Privacy Policy from time to time to reflect changes in law, regulatory guidance, our business practices, or the functionality of the FANATIK Platform. Where changes are material, we will take reasonable steps to notify you, for example by posting a notice on the Platform or contacting you directly where appropriate.
The personal data we hold about you must be accurate and up to date. Please inform us promptly if your personal data changes during your relationship with us, for example if you change your email address, wallet details, or other contact information.
13. Third-party links
The FANATIK Platform and our website may contain links to third-party websites, applications, plug-ins, blockchain explorers, exchange providers, social media platforms, or other external services.
Clicking on those links or enabling those connections may allow third parties to collect or share personal data about you. We do not control these third-party websites or services and are not responsible for their content, security, or privacy practices.
Where you interact with third-party providers (for example, an Exchange Partner, payment processor, app store, wallet provider, analytics provider, or social media platform), your personal data will be processed in accordance with their own privacy policies and terms.
We encourage you to read the privacy notice of every third-party website or service you access before submitting any personal data.