Data Protection Overview
We handle personal data responsibly, securely, and transparently — strictly for the purposes of draw adjudication, certification, and verification.
Our Approach to Data Protection
We are committed to handling personal data responsibly, securely, and transparently — processing only what is necessary for the platform to function.
-
Recording Draw OutcomesDraw results, winner identifiers, and timestamps are recorded to generate verifiable, certified records.
-
Generating CertificatesDraw data is used to produce tamper-evident certificates of completion for each adjudicated draw.
-
Enabling Public VerificationLimited draw outcome data is made accessible via the public verification page so results can be independently confirmed.
-
Supporting Account Access & Platform FunctionalityAccount data is processed to authenticate users and maintain platform security and session management.
Types of Data Processed
Depending on how the platform is used, the following categories of data may be processed.
Lawful Basis for Processing
All processing of personal data on this platform is conducted under one of the following recognised lawful bases.
Public vs Private Data
A clear boundary separates what is publicly accessible from what remains strictly private.
- Draw name
- Organisation name
- Completion timestamp (UTC)
- Winner and reserve winner status
- Certificate ID
- Full entry lists
- Personal contact details
- Uploaded CSV or entry files
- Internal administrative notes
- Account or authentication data
Data Retention
Different categories of data are held for different reasons. Retention periods reflect operational and legal requirements.
Security Safeguards
We implement reasonable and appropriate technical and organisational measures to protect personal data from unauthorised access, alteration, or disclosure.
Organiser Responsibilities
Organisations using this platform act as data controllers for participant data. Specific obligations rest with them, not with CertifiedDraw.
-
Lawful Collection of Entrant DataOrganisations must have a lawful basis for collecting participant data before uploading it to the platform.
-
Providing Privacy Notices to ParticipantsEntrants must be informed of how their data will be used, including that it will be processed by an adjudication service.
-
Local Data Protection ComplianceOrganisations are responsible for ensuring their use of the platform complies with applicable data protection laws in their jurisdiction.
-
Managing Participant Rights RequestsRequests from participants to access, correct, or delete their data should be directed to — and handled by — the organising entity in the first instance.
International Access
The platform may be accessed globally. Cross-border data considerations are the responsibility of the organising entity.
The platform may be accessed by organisations and participants in multiple jurisdictions. We do not restrict access by geography.
Organisations are responsible for ensuring that their use of the platform complies with applicable cross-border data transfer laws — including any requirements that apply when participant data originates in or is transferred across jurisdictions with specific data protection regulations (such as the European Economic Area, the United Kingdom, or other regulated regions).
Individual Rights
Depending on jurisdiction, individuals may have data protection rights. The correct route for exercising them depends on the data involved.
Updates to This Policy
This page may be updated to reflect changes in law, security practices, or platform functionality.
We may update this page periodically to reflect changes in applicable data protection law, our security practices, or how the platform processes data.
Material updates will be reflected with a revised effective date, shown in the sidebar. Continued use of the platform following a material update constitutes acknowledgement of the revised policy.