Version: 2026-09-17 | Last updated: 17 September 2026
1. Who we are
Service provider: Oktcom LTD
Contact: contact@combivend.co.uk
Business address: 67 crescent drive north, Brighton, United Kingdom, BN2 6SL
Company number: 14560946
Registered in: England and Wales
Oktcom LTD operates the Combivend platform. For individual campaigns, the client business named on the QR entry page is the promoter and is normally the controller responsible for how campaign entrant data, prize fulfilment records, and marketing choices are used. Combivend stores and processes that campaign data on the client's behalf to provide the QR entry page, dashboard, unlock-code emails, security controls, audit records, exports, and retention tools. Combivend is separately responsible for its own platform administration, account access, security, support, billing, audit, and service communications.
2. Personal data we process
- Customer campaign entry data stored for the client promoter, including email address, entry time, campaign, store, prize result, winner status, and the unlock-code email status.
- Standard campaign fields where enabled by the client, such as first name, mobile number for SMS/text follow-up, newsletter signup, and separate marketing consent choices. For standard newsletter signup prize draws, ticking the email signup box is required before the entry is accepted. Mobile number is optional and is kept hidden from customer-entry tables unless the relevant consent snapshot supports displaying or exporting it.
- Client account data, including company name, legal name, region, group reference, contract reference, contract start date, billing interval, billing notes, OAuth email, limited-company or registration number, company address, contact name, campaign limits, enabled features, account status, and account requests.
- User access data, including invited user name, email address, Google sign-in identity, role, company membership, store assignments, permission flags, session records, and account status.
- Technical, security, and audit data, including session identifiers, protected IP or network identifiers, browser user agent, CSRF data, login attempts, entry attempts, duplicate-entry checks, rate-limit records, system events, and error logs.
- Support and correspondence data, including account updates, requests to cancel or change subscriptions, invitation messages, operational notices, and any information sent to Combivend for support.
3. Why we use data
- To provide client and platform dashboards, Google sign-in, role-based access, store assignments, account administration, and subscription or feature requests.
- To run QR prize-entry pages, validate submissions, enforce campaign entry limits, record win or non-win outcomes, and email unlock codes to winners.
- To support store operations while restricting customer-entry data to authorised roles. Store users should only see winning data needed for fulfilment.
- To send transactional emails, including winner unlock-code emails, account invitations, account updates, request updates, security messages, and service notices.
- To prevent fraud, abuse, duplicate entries, unauthorised access, and misuse of the platform.
- To comply with legal, tax, accounting, regulatory, dispute, audit, or insurance obligations where they apply.
- To record newsletter signup and other marketing choices, then support consented marketing exports for the client promoter. The client is responsible for deciding whether and how exported data is used for marketing.
Where UK or EU data-protection law applies, the client promoter is normally responsible for selecting and documenting the lawful basis for its campaign and marketing use. Combivend's own lawful bases for platform operations may include contract, legitimate interests, legal obligation, and consent where appropriate. Consent is used for newsletter signup draws and optional marketing permissions and can be withdrawn. Legitimate interests include operating a secure prize-box platform, preventing misuse, supporting clients and customers, and keeping reliable audit records.
4. Who data is shared with
- The client promoter responsible for the relevant campaign, so it can administer prizes, support winners, handle privacy requests, and manage its lawful promotion records.
- Postmark or another configured transactional-email provider, to deliver unlock-code emails, account invitations, request updates, and service messages.
- Google, when invited users use Google sign-in.
- Render or another configured hosting/database provider, Cloudflare Turnstile where enabled for entry-page abuse checks, GitHub/deployment tooling for controlled technical operations, and professional advisers where needed to operate, protect, support, or evidence Combivend.
- Authorities, regulators, courts, insurers, accountants, or legal advisers where required by law, regulation, dispute handling, fraud prevention, or to defend legal rights.
5. International transfers
Some providers may process data outside the UK, EU, or US. Where transfer safeguards are required, Combivend relies on appropriate provider terms, adequacy arrangements, standard contractual clauses, or equivalent safeguards required by applicable law.
6. Retention
Combivend keeps personal data only for as long as needed for the purposes described in this notice, then deletes, anonymises, or restricts it where appropriate. Normal retention targets are:
- Non-winning campaign entries without marketing consent: personal contact fields are hidden from customer-entry dashboards by default and normally anonymised 90 days after entry, while limited protected identifiers may be retained to enforce entry limits, security, audit, and abuse-prevention controls.
- Newsletter signup and marketing opt-in entries: contact fields are retained for the client while consent remains valid or until the client instructs deletion, the individual withdraws consent, or the data is no longer needed for the campaign purpose.
- Winner, unlock-code email, audit, and dispute records: normally up to 24 months after the campaign unless the client instructs earlier deletion where lawful, or a longer legal, tax, audit, fraud-prevention, or dispute period is needed.
- Client account, contract, billing, user-access, and account-request records: while the account relationship is active, then normally up to 7 years where needed for contract, tax, accounting, legal, or dispute reasons.
- Security, session, login, rate-limit, and entry-attempt records: normally up to 24 months unless needed to investigate abuse, fraud, security incidents, or legal claims.
- Email delivery records and support correspondence: for as long as needed to confirm delivery, resolve support issues, maintain account records, or deal with disputes.
7. Cookies and security
Combivend uses essential cookies and similar technologies for login sessions, QR entry security, CSRF protection, rate limiting, and fraud or abuse prevention. These are needed for the service to work safely. We do not currently set advertising or marketing tracking cookies. If non-essential cookies are introduced later, we will explain them and ask for consent where required.
We use technical and organisational measures intended to protect personal data, including encryption for sensitive customer entry data, role-based access, store-scoped permissions, secure session cookies in production, CSRF protection, rate limiting, audit logs, and restricted admin/client access. No online service can be guaranteed completely secure, so please contact us promptly if you believe an account or entry record may be at risk.
8. Regional rights and marketing rules
- UK entrants and users may have UK GDPR rights to be informed, access, rectification, erasure, restriction, objection, portability and withdrawal of consent, and can complain to the Information Commissioner's Office. UK electronic marketing must follow PECR and UK GDPR consent or soft opt-in rules.
- EU and EEA entrants and users may have GDPR rights to be informed, access, rectification, erasure, restriction, objection, portability and withdrawal of consent, and can complain to their local supervisory authority. Electronic marketing should follow GDPR and applicable ePrivacy rules.
- US entrants and users may have rights under applicable state privacy laws, including rights to know, access, correct, delete, limit certain sensitive-data uses, and opt out of sale, sharing, targeted advertising or profiling where those laws apply. Commercial email should follow CAN-SPAM, and automated SMS/text marketing may require prior express written consent for the identified seller.
9. Your choices
You can contact us using the details above to ask about access, correction, deletion, restriction, objection, portability, withdrawal of consent, or another privacy request. We may need to verify your identity and may need to keep some records for security, audit, legal, tax, accounting, fraud-prevention, or dispute reasons.
Marketing consent can be withdrawn by using any unsubscribe method provided in a message or by contacting the promoter or Combivend. Withdrawing marketing consent after a valid entry does not remove a confirmed win or prevent necessary transactional emails such as winner unlock-code messages. Future marketing use should stop unless a new valid consent is obtained.
10. Updates
We will update this notice when the platform, providers, lawful bases, retention approach, regional wording, or data use changes. Material changes may be brought to affected users before or when the change takes effect.