Policies

Privacy Policy

Last updated: 31 July 2026

1. Introduction

This Privacy Policy explains how CONDEO LTD collects, uses, stores, shares and protects personal data when you:

  • visit conskins.com;
  • create or use a ConSkins Account;
  • link a Steam Account;
  • top up your ConSkins Balance;
  • purchase or receive a Digital Item;
  • communicate with customer support;
  • participate in identity, payment or security verification;
  • make a complaint or exercise a legal right; or
  • otherwise interact with ConSkins.

This Privacy Policy also explains your rights and how you may contact us about the use of your personal data.

2. Data Controller

The controller responsible for the processing described in this Privacy Policy is:

CONDEO LTD
Company number: 17225871
Registered office: Dept 6790, 196 High Road, Wood Green, London, United Kingdom, N22 8HH
Email: info@conskins.com

In this Privacy Policy, “ConSkins”, “we”, “us” and “our” mean CONDEO LTD.

3. Scope of This Privacy Policy

This Privacy Policy applies to personal data processed by CONDEO LTD in connection with ConSkins.

It does not govern processing carried out independently by:

  • Valve Corporation or Steam;
  • banks and card issuers;
  • payment service providers;
  • identity verification providers;
  • fraud-prevention providers;
  • third-party websites;
  • browser extensions;
  • external applications; or
  • other services that determine their own purposes and methods of processing.

Those organisations may act as separate controllers and provide their own privacy notices.

4. Definitions

For the purposes of this Privacy Policy:

  • “Account” means a registered ConSkins user account;
  • “Balance” or “ConSkins Balance” means the internal account credit available for eligible purchases through ConSkins;
  • “Digital Item” means a virtual in-game item available through ConSkins and capable of being transferred through Steam;
  • “Order” means a confirmed request to purchase a Digital Item using the ConSkins Balance;
  • “Payment Method” means a payment card or another payment method available through the ConSkins payment interface;
  • “Payment Provider” means an independent third party used to process payments, authentication, refunds and related services;
  • “Steam Account” means the Steam account linked to a User’s ConSkins Account;
  • “Steam Trade Offer” or “Trade Offer” means an offer made through Steam to transfer a Digital Item;
  • “Top-Up” means a payment made to add Cash-Funded Balance to an Account;
  • “User”, “you” and “your” mean the individual whose personal data is processed;
  • “UK GDPR” means the United Kingdom General Data Protection Regulation;
  • “personal data” means information relating to an identified or identifiable individual;
  • “processing” includes collecting, recording, organising, storing, using, disclosing, restricting, deleting or otherwise handling personal data.

5. Personal Data We Collect

The personal data we collect depends on how you use ConSkins.

We may collect the categories described below.

6. Account and Registration Data

When you create or manage an Account, we may collect:

  • email address;
  • password in encrypted or cryptographically protected form;
  • internal User identifier;
  • Account creation date;
  • Account status;
  • language and country preferences;
  • age or date of birth where requested;
  • email verification status;
  • marketing preferences;
  • security settings;
  • Account changes;
  • suspension or closure status; and
  • records of acceptance of our Terms and Policies.

We do not store your password in readable plain-text form.

7. Steam Data

When you link a Steam Account or purchase a Digital Item, we may collect or receive:

  • Steam ID or SteamID64;
  • Steam profile URL;
  • Steam display name;
  • avatar;
  • publicly available profile information;
  • Steam Trade URL;
  • Steam inventory information where accessible and necessary;
  • inventory visibility status;
  • Steam Account eligibility information;
  • trade restriction or cooldown information;
  • Steam Trade Offer identifiers;
  • Trade Offer status;
  • item transfer information;
  • delivery and acceptance timestamps;
  • Digital Item information;
  • Steam reversal information;
  • information necessary to investigate delivery or security issues; and
  • other data made available through authorised Steam functionality.

Linking Steam does not give ConSkins access to your Steam password.

ConSkins will never ask you to disclose your Steam password or Steam Guard code.

8. Balance and Transaction Data

When you top up or use the ConSkins Balance, we may collect:

  • Top-Up amount;
  • Balance amount;
  • transaction currency;
  • transaction date and time;
  • available, reserved or restricted Balance;
  • internal transaction identifier;
  • Payment Provider reference;
  • transaction status;
  • Balance adjustments;
  • promotional credits;
  • refunds;
  • reversals;
  • negative Balance;
  • Account closure refund information;
  • Order history;
  • Digital Item purchase details;
  • pricing information;
  • included fees and taxes; and
  • records required for accounting, reconciliation and dispute resolution.

9. Payment Data

Payments are processed through an independent Payment Provider.

Depending on the payment arrangement, we may receive:

  • Payment Method type;
  • card brand;
  • last digits of the payment card;
  • card expiry information in limited or tokenised form;
  • issuing country;
  • billing country;
  • transaction reference;
  • payment status;
  • payment amount and currency;
  • payment authentication result;
  • 3D Secure result;
  • tokenised payment identifier;
  • fraud or risk indicators;
  • refund status;
  • chargeback information; and
  • limited information needed to identify and reconcile the payment.

ConSkins does not intentionally store complete payment card numbers, card security codes, PINs or online banking passwords on its own servers.

Full payment credentials are handled by the relevant Payment Provider and other participants in the payment process.

10. Identity and Verification Data

Where identity, age, payment ownership, fraud or sanctions verification is required, we or an authorised provider may collect:

  • full legal name;
  • date of birth;
  • residential address;
  • country of residence;
  • nationality;
  • telephone number;
  • identity document type and number;
  • passport, identity card, driving licence or residence permit;
  • proof of address;
  • photograph or selfie;
  • video or liveness verification;
  • document authenticity results;
  • facial comparison results;
  • Payment Method ownership evidence;
  • redacted payment records;
  • source-of-funds information;
  • transaction explanations;
  • sanctions screening results;
  • politically exposed person screening results;
  • fraud-prevention results;
  • verification status;
  • reasons for failed or incomplete verification; and
  • correspondence relating to verification.

Where facial verification generates biometric data used to uniquely identify a person, such data will be processed only where an applicable legal condition permits it.

An external verification provider may process the underlying document, image or biometric information and provide ConSkins with a result rather than the complete source data.

11. Fraud, Security and Compliance Data

To protect Accounts, payments and the Service, we may collect or generate:

  • risk scores;
  • fraud indicators;
  • payment anomalies;
  • sanctions alerts;
  • identity inconsistencies;
  • suspected multiple-Account links;
  • device associations;
  • transaction patterns;
  • disputed payment information;
  • chargeback records;
  • Steam reversal records;
  • suspected phishing information;
  • Account compromise reports;
  • suspicious IP or location information;
  • records of policy violations;
  • investigation notes;
  • restriction or suspension reasons;
  • evidence submitted by a User;
  • information received from fraud-prevention providers; and
  • information received from banks, Payment Providers or competent authorities.

This information may include allegations or indicators that require further investigation and do not necessarily establish wrongdoing.

12. Technical and Device Data

When you access ConSkins, we may automatically collect:

  • IP address;
  • approximate location derived from IP address;
  • browser type and version;
  • device type;
  • operating system;
  • screen and language settings;
  • device identifiers;
  • session identifiers;
  • login dates and times;
  • pages viewed;
  • actions performed;
  • referring website;
  • error reports;
  • server logs;
  • security events;
  • network information;
  • cookie identifiers;
  • consent preferences;
  • performance information; and
  • other technical information reasonably necessary to operate and secure the Service.

We do not use precise GPS location unless a specific feature requires it and an appropriate notice and lawful basis are provided.

13. Communications and Support Data

When you contact us, we may collect:

  • your name;
  • email address;
  • Account identifier;
  • Order and transaction references;
  • Steam information;
  • the content of your message;
  • attachments;
  • screenshots;
  • Trade Offer evidence;
  • complaint details;
  • refund requests;
  • support history;
  • dates and times of communications;
  • our responses; and
  • information necessary to investigate and resolve the matter.

You should not send complete payment card numbers, card security codes, passwords or authentication codes to customer support.

14. Marketing and Preference Data

Where marketing communications are offered, we may collect:

  • email address;
  • marketing consent;
  • date and method of consent;
  • products or topics of interest;
  • email interaction information where permitted;
  • opt-out requests;
  • suppression-list status; and
  • communication preferences.

Service and security communications are not marketing communications and may be sent where necessary to administer your Account or transactions.

15. Cookie and Similar Technology Data

We may use cookies, local storage, pixels, scripts and similar technologies to:

  • maintain login sessions;
  • remember settings;
  • secure the Website;
  • prevent fraud;
  • manage consent;
  • measure performance;
  • understand use of the Website;
  • diagnose errors; and
  • provide optional analytics or marketing functionality.

Strictly necessary technologies may be used without optional consent where permitted by law.

Non-essential cookies and similar technologies will be used only where an appropriate legal basis, including consent where required, is available.

Further details are provided in the Cookie Policy.

16. Data We Receive from You

We collect personal data directly from you when you:

  • register an Account;
  • provide or update Account information;
  • link Steam;
  • provide a Steam Trade URL;
  • top up the Balance;
  • place an Order;
  • communicate with support;
  • submit a complaint;
  • request a refund;
  • request Account closure;
  • complete verification;
  • respond to a security review;
  • subscribe to marketing; or
  • otherwise provide information to us.

17. Data We Receive from Steam

We may receive information from Steam when you:

  • link a Steam Account;
  • authenticate or confirm Steam information;
  • provide a Steam ID or Trade URL;
  • place an Order;
  • receive a Trade Offer;
  • accept or reject a Trade Offer;
  • experience a trade restriction;
  • reverse an eligible Steam trade; or
  • request investigation of a delivery issue.

Steam processes personal data under its own terms and privacy policy.

18. Data We Receive from Payment and Verification Providers

We may receive information from:

  • Payment Providers;
  • banks;
  • card issuers;
  • payment networks;
  • identity verification providers;
  • fraud-prevention providers;
  • sanctions screening providers; and
  • authentication services.

This may include transaction status, authentication results, verification results, risk indicators, chargebacks, reversals and limited Payment Method information.

19. Data We Receive from Other Sources

We may receive personal data from:

  • technology and fulfilment providers;
  • hosting and security providers;
  • customer support systems;
  • analytics providers;
  • public sanctions lists;
  • public Steam profiles;
  • publicly available sources;
  • professional advisers;
  • law enforcement authorities;
  • courts;
  • regulators;
  • complainants; and
  • persons reporting suspected fraud or misuse.

We will assess the reliability and relevance of information received from other sources before relying on it for a material decision.

20. Purposes and Lawful Bases

We process personal data only where an appropriate lawful basis applies.

Depending on the activity, we may rely on:

  • performance of a contract;
  • steps taken at your request before entering into a contract;
  • compliance with a legal obligation;
  • our legitimate interests or those of a third party;
  • your consent;
  • establishment, exercise or defence of legal claims;
  • substantial public interest conditions permitted by law; or
  • another lawful basis available under applicable data protection law.

21. Account Administration

We process Account and registration data to:

  • create the Account;
  • verify the email address;
  • authenticate access;
  • maintain Account settings;
  • link Steam;
  • display Account and transaction information;
  • provide customer support;
  • process Account closure; and
  • enforce the Terms and Policies.

The principal lawful basis is performance of our contract with you or taking steps at your request before entering into that contract.

Security-related processing may also be based on our legitimate interests in protecting Users and the Service.

22. Balance, Payments and Orders

We process payment, Balance and transaction data to:

  • process Top-Ups;
  • credit and maintain the Balance;
  • process Orders;
  • arrange Digital Item delivery;
  • issue refunds;
  • reconcile transactions;
  • respond to payment errors;
  • investigate disputed payments;
  • process Account closure refunds; and
  • maintain transaction records.

The principal lawful bases are:

  • performance of our contract with you;
  • compliance with legal obligations;
  • our legitimate interests in accurate accounting, transaction administration and dispute resolution; and
  • establishment, exercise or defence of legal claims.

23. Steam Linking and Digital Item Delivery

We process Steam data to:

  • link the correct Steam Account;
  • verify the Steam destination;
  • validate the Trade URL;
  • arrange a Steam Trade Offer;
  • confirm delivery;
  • investigate failed or incorrect delivery;
  • manage Steam trade reversals; and
  • prevent fraud and trade redirection.

The principal lawful bases are:

  • performance of our contract with you;
  • taking steps at your request;
  • our legitimate interests in secure and accurate delivery; and
  • establishment, exercise or defence of legal claims.

24. Fraud Prevention and Security

We process personal data to:

  • authenticate Users;
  • protect Accounts;
  • prevent stolen Payment Method use;
  • identify unauthorised transactions;
  • detect multiple-Account abuse;
  • prevent phishing and Account takeover;
  • detect technical misuse;
  • respond to Chargebacks;
  • investigate Steam reversals;
  • protect Digital Item delivery;
  • enforce transaction limits;
  • secure the Website; and
  • protect our Users, service providers and business.

The principal lawful bases are:

  • our legitimate interests in preventing fraud and protecting the Service;
  • compliance with legal obligations;
  • performance of our contract;
  • establishment, exercise or defence of legal claims; and
  • substantial public interest conditions where special category or criminal offence data is lawfully processed for fraud prevention.

We assess legitimate interests against your rights and reasonable expectations.

25. Identity, Age and Payment Ownership Verification

We may process identity and verification data to:

  • confirm that the User is at least 18;
  • confirm identity;
  • verify Payment Method ownership;
  • investigate inconsistent information;
  • prevent fraud;
  • complete a refund;
  • process Account closure;
  • respond to provider requirements; and
  • comply with law.

The lawful basis may include:

  • performance of our contract;
  • compliance with a legal obligation;
  • our legitimate interests in preventing fraud and ensuring Account integrity;
  • substantial public interest conditions permitted by law; and
  • consent where consent is appropriate and legally valid.

We will not rely on consent where the processing is not genuinely optional.

26. Sanctions and Legal Compliance

We process personal data to:

  • screen against applicable sanctions lists;
  • identify Restricted Jurisdictions;
  • respond to legally binding requests;
  • prevent sanctions evasion;
  • maintain accounting and tax records;
  • comply with court orders;
  • comply with regulatory obligations; and
  • protect legal rights.

The lawful bases may include:

  • compliance with legal obligations;
  • our legitimate interests in avoiding unlawful transactions and managing legal risk;
  • substantial public interest conditions; and
  • establishment, exercise or defence of legal claims.

27. Service Improvement and Analytics

We may process technical and usage data to:

  • understand how the Website is used;
  • diagnose errors;
  • improve navigation and performance;
  • test functionality;
  • measure service reliability;
  • identify popular features;
  • improve customer support;
  • prevent misuse; and
  • plan service development.

Depending on the technology, the lawful basis may be:

  • our legitimate interests in improving and operating the Service; or
  • your consent where consent is required for non-essential cookies or analytics technologies.

28. Communications

We process contact and communication data to:

  • respond to questions;
  • investigate delivery issues;
  • resolve complaints;
  • provide transaction notices;
  • send security alerts;
  • communicate Policy changes;
  • provide Account information; and
  • maintain support records.

The lawful bases may include:

  • performance of our contract;
  • compliance with legal obligations;
  • our legitimate interests in customer support and record keeping; and
  • establishment, exercise or defence of legal claims.

29. Direct Marketing

Where permitted, we may send information about ConSkins products, features or promotions.

We may rely on:

  • your consent; or
  • an applicable existing-customer exception where the legal requirements are met.

You may unsubscribe at any time by:

  • using the unsubscribe link in the communication;
  • changing available Account preferences; or
  • emailing info@conskins.com.

Withdrawing from marketing does not affect essential service, payment, security, legal or Account communications.

We may retain limited suppression-list information to ensure that your opt-out is respected.

30. Legal Claims and Disputes

We may process and retain relevant personal data to:

  • establish facts;
  • investigate a complaint;
  • respond to a Chargeback;
  • recover amounts owed;
  • defend a legal claim;
  • enforce our Terms;
  • obtain legal advice;
  • respond to authorities; and
  • protect our legal rights.

The lawful bases may include:

  • our legitimate interests;
  • compliance with a legal obligation; and
  • establishment, exercise or defence of legal claims.

31. Special Category Data

ConSkins does not ordinarily seek to collect special category personal data.

However, special category data may arise where:

  • identity verification uses biometric data to uniquely identify a User;
  • a User voluntarily includes sensitive information in support communications;
  • sanctions or legal records reveal sensitive attributes; or
  • processing is necessary in connection with a legal claim.

Where special category data is processed, we will identify both:

  • an Article 6 lawful basis; and
  • an applicable special category condition.

Depending on the circumstances, the condition may include:

  • explicit consent;
  • substantial public interest in preventing fraud;
  • establishment, exercise or defence of legal claims; or
  • another condition permitted by law.

Users should avoid sending unnecessary health, political, religious or other sensitive information to customer support.

32. Criminal Offence Data

Fraud, account theft, payment abuse or law enforcement reports may involve criminal offence data.

We will process such information only where authorised by law and subject to appropriate safeguards.

Where required, we will maintain an appropriate policy document covering the processing.

An allegation or risk indicator will not automatically be treated as proof that an offence occurred.

33. Automated Processing and Profiling

ConSkins and its service providers may use automated systems to:

  • assess payment risk;
  • identify unusual activity;
  • detect possible fraud;
  • link potentially related Accounts;
  • identify location inconsistencies;
  • screen against sanctions lists;
  • prioritise transactions for review;
  • apply transaction limits;
  • request further authentication; and
  • protect Accounts and the Service.

An automated indicator may result in:

  • a manual review;
  • additional verification;
  • delayed processing;
  • a declined Top-Up;
  • a temporary Balance restriction;
  • cancellation of an Order; or
  • Account suspension.

ConSkins does not intend to make a decision producing legal or similarly significant effects based solely on automated processing unless:

  • the decision is necessary for entering into or performing a contract;
  • the decision is authorised by law;
  • you have provided valid explicit consent where permitted; and
  • appropriate safeguards are applied.

Where applicable law gives you the right, you may request:

  • human review;
  • an opportunity to provide additional information;
  • an explanation of the outcome; and
  • reconsideration of the decision.

Independent Payment Providers may make their own automated payment or risk decisions under their own privacy notices.

34. Sharing Personal Data

We may share personal data only where reasonably necessary for the purposes described in this Privacy Policy and where an appropriate legal basis applies.

We may share personal data with the categories described below.

35. Payment Providers, Banks and Card Networks

We may share information with:

  • Payment Providers;
  • acquiring banks;
  • card issuers;
  • card networks;
  • authentication providers;
  • payment fraud-prevention services; and
  • refund and Chargeback administrators.

This sharing may be necessary to:

  • process Top-Ups;
  • authenticate payments;
  • apply 3D Secure;
  • prevent fraud;
  • process refunds;
  • respond to Chargebacks;
  • reconcile transactions; and
  • comply with payment rules.

These organisations may act as processors, independent controllers or both, depending on the activity.

36. Identity, Fraud and Sanctions Providers

We may share personal data with providers that assist with:

  • identity verification;
  • age verification;
  • document authentication;
  • facial or liveness verification;
  • Payment Method verification;
  • sanctions screening;
  • politically exposed person screening;
  • fraud detection;
  • device and transaction risk analysis; and
  • Account security.

We will limit disclosure to information reasonably required for the relevant service.

37. Steam, Technology and Fulfilment Providers

We may share relevant information with:

  • Steam or Valve where necessary;
  • Digital Item inventory providers;
  • technology integration providers;
  • fulfilment providers;
  • providers involved in creating or monitoring Trade Offers; and
  • providers assisting with delivery investigation.

Information shared may include:

  • Steam ID;
  • Steam Trade URL;
  • Order reference;
  • Digital Item information;
  • delivery status;
  • Trade Offer information;
  • security indicators; and
  • information required to investigate a failed or disputed transfer.

The identity and commercial arrangements of individual providers may constitute confidential business information.

This does not limit your rights to receive the privacy information required by applicable law.

38. Hosting, Security and Operational Providers

We may use service providers for:

  • website hosting;
  • cloud infrastructure;
  • databases;
  • content delivery;
  • cybersecurity;
  • email delivery;
  • customer support;
  • error monitoring;
  • analytics;
  • consent management;
  • document storage;
  • accounting;
  • communications; and
  • technical maintenance.

These providers may process personal data only to the extent required to provide their services and subject to appropriate contractual and security measures.

39. Professional Advisers

We may disclose personal data where reasonably necessary to:

  • lawyers;
  • accountants;
  • auditors;
  • tax advisers;
  • insurers;
  • consultants; and
  • other professional advisers

for legal advice, compliance, financial administration, insurance, audits or dispute resolution.

40. Authorities and Legal Recipients

We may disclose personal data to:

  • law enforcement agencies;
  • courts;
  • regulators;
  • tax authorities;
  • sanctions authorities;
  • data protection authorities;
  • consumer protection bodies; and
  • other competent authorities

where:

  • disclosure is required by law;
  • a valid legal request is received;
  • disclosure is necessary to prevent or investigate crime;
  • disclosure is necessary to protect a person;
  • disclosure is necessary to establish or defend legal rights; or
  • another lawful basis applies.

We may be prohibited from notifying you about certain requests or investigations.

41. Corporate Transactions

If CONDEO LTD is involved in:

  • a merger;
  • acquisition;
  • corporate reorganisation;
  • financing;
  • sale of assets;
  • transfer of the ConSkins business; or
  • insolvency process,

personal data may be disclosed to potential or actual purchasers, advisers, financiers or successor operators.

Any recipient will be required to protect the information and use it only for lawful purposes.

42. No Sale of Personal Data

ConSkins does not sell personal data in exchange for money.

We do not disclose personal data to unrelated third parties so that they may independently market their products to you without an appropriate legal basis.

43. International Data Transfers

Some service providers or recipients may be located outside the United Kingdom or may access personal data from another country.

When personal data is transferred from the UK to a country not covered by applicable UK adequacy regulations, we will use an appropriate transfer mechanism where required, such as:

  • the UK International Data Transfer Agreement;
  • the UK Addendum to the European Commission’s Standard Contractual Clauses;
  • another approved contractual safeguard;
  • binding corporate rules;
  • an applicable statutory exception; or
  • another mechanism permitted by UK data protection law.

Where required, we will assess whether supplementary contractual, organisational or technical measures are necessary.

44. EEA and Other International Transfers

Where the EU GDPR or another applicable data protection law applies, transfers may be protected using:

  • an applicable adequacy decision;
  • the European Commission’s Standard Contractual Clauses;
  • binding corporate rules;
  • an applicable legal exception; or
  • another permitted safeguard.

The transfer mechanism used may depend on:

  • the country;
  • the recipient;
  • the purpose of the transfer;
  • the type of data; and
  • the law applicable to the transfer.

You may contact us for further information about safeguards relevant to your personal data.

45. Data Security

We use appropriate technical and organisational measures designed to protect personal data against:

  • unauthorised access;
  • unlawful use;
  • accidental loss;
  • alteration;
  • disclosure;
  • destruction;
  • fraud;
  • account takeover; and
  • other security risks.

Measures may include:

  • access controls;
  • password hashing;
  • encryption in transit;
  • encryption at rest where appropriate;
  • network and application security;
  • monitoring and logging;
  • authentication controls;
  • role-based access;
  • backups;
  • vulnerability management;
  • provider due diligence;
  • incident-response procedures;
  • staff confidentiality obligations; and
  • data minimisation.

No online service can guarantee complete security.

You are responsible for protecting your password, email account, devices and linked Steam Account.

46. Personal Data Breaches

If a personal data breach occurs, we will:

  • investigate the incident;
  • take reasonable steps to contain it;
  • assess the risks to affected individuals;
  • document the incident;
  • notify the Information Commissioner’s Office where legally required; and
  • notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

Where a report to the Information Commissioner’s Office is required, we will make it without undue delay and, where feasible, within the legally applicable 72-hour period after becoming aware of the breach.

47. Retention Principles

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including:

  • providing the Service;
  • administering the Account;
  • completing transactions;
  • processing refunds;
  • maintaining accounting records;
  • preventing fraud;
  • resolving complaints;
  • responding to Chargebacks;
  • complying with law;
  • enforcing agreements; and
  • establishing, exercising or defending legal claims.

Retention may depend on:

  • whether the Account remains open;
  • the type of record;
  • the date of the last transaction;
  • an ongoing dispute;
  • a legal limitation period;
  • a provider requirement;
  • an investigation;
  • a legal preservation obligation; or
  • a request from a competent authority.

48. Indicative Retention Periods

Unless a longer or shorter period is justified, we may apply the following indicative periods:

48.1 Account and Profile Data

Account and profile data may be retained while the Account remains open and for up to six years after closure where necessary for contractual records, disputes, fraud prevention or legal claims.

Data that is not required after Account closure may be deleted or anonymised sooner.

48.2 Balance, Payment and Order Data

Top-Up, Balance, payment, Order, refund and delivery records may be retained for up to six years after the relevant transaction or end of the business relationship, or longer where required by law, an unresolved dispute or a legal preservation obligation.

48.3 Verification Data

Identity and verification data may be retained for the duration of the Account and for a reasonable period after the relationship ends where necessary for fraud prevention, provider requirements, legal claims or compliance obligations.

Underlying identity documents may be deleted earlier where only the verification result is required.

48.4 Security and Technical Logs

Routine security, login and technical logs may generally be retained for up to 24 months.

Relevant records may be retained longer where connected to:

  • fraud;
  • an Account compromise;
  • a Chargeback;
  • a complaint;
  • a security incident;
  • a legal claim; or
  • an authority request.

48.5 Support and Complaint Records

Support, complaint and dispute records may be retained for up to six years after the matter is resolved where necessary to demonstrate how it was handled or to protect legal rights.

48.6 Marketing Data

Marketing preferences may be retained while you remain subscribed.

Limited suppression-list data may be retained after an opt-out to ensure that further marketing is not sent against your wishes.

48.7 Cookie Data

Cookie and similar technology retention periods are described in the Cookie Policy and consent interface.

49. Anonymisation and Deletion

When personal data is no longer required, we may:

  • securely delete it;
  • anonymise it;
  • aggregate it;
  • remove direct identifiers; or
  • retain only the limited information necessary for a legal or security purpose.

Properly anonymised information that can no longer identify an individual is not personal data and may be retained for statistical, security or service-improvement purposes.

50. Account Closure

You may request permanent Account closure by emailing:

info@conskins.com

The request should be sent from the email address registered to the Account.

Before closure, we may need to:

  • verify Account ownership;
  • complete or cancel active Orders;
  • process eligible Balance refunds;
  • resolve pending Steam Trade Offers;
  • investigate fraud or Account compromise;
  • resolve Chargebacks;
  • comply with sanctions restrictions; or
  • retain information required by law.

Closing an Account does not require immediate deletion of every record.

We may retain limited information where necessary for:

  • accounting;
  • fraud prevention;
  • legal obligations;
  • unresolved complaints;
  • payment disputes;
  • sanctions compliance;
  • enforcement of agreements; or
  • legal claims.

51. Children

ConSkins is intended only for individuals aged 18 or over.

We do not knowingly permit children or minors to create or use an Account.

If we reasonably believe that a User is under 18, we may:

  • request age verification;
  • restrict the Account;
  • cancel pending Orders;
  • close the Account; and
  • delete or retain relevant information in accordance with law.

A parent or guardian who believes that a minor has provided personal data to ConSkins may contact info@conskins.com.

52. Your Data Protection Rights

Depending on the law applicable to you, you may have the rights described below.

These rights are not absolute and may be subject to legal conditions, exemptions and the rights of other persons.

53. Right to Be Informed

You have the right to receive clear information about how your personal data is collected and used.

This Privacy Policy is intended to provide that information.

Additional notices may be provided at the point where specific information is collected.

54. Right of Access

You may request:

  • confirmation that we process your personal data;
  • access to that personal data; and
  • supplementary information about the processing.

We may need to verify your identity before disclosing personal data.

We will not disclose information that would unlawfully reveal another person’s data, compromise security or breach a legal restriction.

55. Right to Rectification

You may ask us to correct inaccurate personal data or complete incomplete information.

Some Account information may be updated through Account settings.

We may require supporting evidence before changing identity, transaction or payment-related information.

56. Right to Erasure

You may ask us to delete personal data in certain circumstances.

The right to erasure does not apply where processing remains necessary for:

  • compliance with law;
  • accounting or transaction records;
  • fraud prevention;
  • sanctions compliance;
  • freedom of expression;
  • public interest purposes;
  • establishment, exercise or defence of legal claims; or
  • another lawful exception.

Account closure and data erasure are related but separate processes.

57. Right to Restriction

You may ask us to restrict processing in certain circumstances, including while:

  • the accuracy of data is being verified;
  • an objection is being considered;
  • processing is disputed as unlawful; or
  • information is required for a legal claim.

Restricted data may continue to be stored and processed where legally permitted.

58. Right to Object

You may object to processing based on legitimate interests.

We will stop the processing unless:

  • we demonstrate compelling legitimate grounds that override your interests, rights and freedoms;
  • the processing is necessary for legal claims; or
  • another lawful reason permits continued processing.

You may object to direct marketing at any time.

59. Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you may have the right to receive certain personal data in a structured, commonly used and machine-readable format.

Where technically feasible and legally required, you may request transmission to another controller.

60. Right to Withdraw Consent

Where processing is based on consent, you may withdraw consent at any time.

Withdrawal does not affect processing carried out lawfully before consent was withdrawn.

Withdrawal may affect optional features that depend on the relevant consent.

61. Rights Relating to Automated Decisions

Where applicable law provides the right, you may object to a decision based solely on automated processing that produces legal or similarly significant effects.

You may also request:

  • human intervention;
  • an opportunity to express your position;
  • reconsideration; and
  • information about the decision.

62. How to Exercise Your Rights

Requests should be sent to:

info@conskins.com

Please include:

  • your registered email address;
  • the right you wish to exercise;
  • sufficient information to identify the relevant data; and
  • any information reasonably necessary to verify your identity.

You do not need to use specific legal terminology.

We will respond without undue delay and ordinarily within one month after receiving the request or any necessary identity verification.

Where permitted, the period may be extended by up to two additional months if the request is complex or multiple requests are received. We will inform you of an extension and the reason for it.

63. Identity Verification for Rights Requests

Before responding to a request, we may ask for information reasonably necessary to confirm:

  • your identity;
  • ownership of the Account;
  • authority to act for another person; or
  • the scope of the request.

We will not request more information than is reasonably necessary.

The response period may begin after necessary identity information has been received, as permitted by applicable law.

64. Fees and Refusal

Data protection requests are generally handled without charge.

Where permitted by law, we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, including because it is repetitive.

If we refuse or charge a fee, we will explain the reason and inform you of available complaint rights.

65. Data Protection Complaints

You may submit a complaint about our use of personal data by emailing:

info@conskins.com

Please include:

  • your registered email address;
  • a description of the concern;
  • relevant dates;
  • relevant Account, Order or transaction references;
  • supporting information; and
  • the resolution requested.

We will:

  • provide a clear method for raising the complaint;
  • acknowledge receipt within 30 days;
  • take appropriate steps to investigate;
  • keep you informed where appropriate; and
  • communicate the outcome without undue delay.

66. Complaints to the Information Commissioner

You also have the right to complain to the United Kingdom Information Commissioner’s Office.

We encourage you to contact ConSkins first so that we have an opportunity to investigate, but you are not required to do so before contacting the supervisory authority.

If you live outside the United Kingdom, you may also have the right to complain to the data protection authority responsible for your country or region.

67. Third-Party Links

The Website may contain links to external websites or services.

ConSkins is not responsible for the privacy practices of an independent third party.

You should review the relevant privacy notice before providing personal data to an external service.

68. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to the Service;
  • new payment or verification providers;
  • changes to Steam integration;
  • new functionality;
  • changes in law;
  • security improvements;
  • operational changes; or
  • corrections and clarifications.

The updated Policy will be published on the Website with a revised “Last updated” date.

Where a change materially affects your rights or how we use personal data, we will provide an appropriate notice through:

  • the Website;
  • your Account;
  • email; or
  • another suitable method.

69. Relationship with Other Policies

This Privacy Policy should be read together with:

  • the Terms and Conditions;
  • the Digital Item Delivery & Steam Trade Policy;
  • the ConSkins Balance, Payments & Pricing Policy;
  • the Refund, Cancellation & Failed Delivery Policy;
  • the Acceptable Use, Fraud Prevention & Account Security Policy;
  • the KYC & Sanctions Policy;
  • the Cookie Policy; and
  • the Complaints & Dispute Resolution Policy.

70. Contact Details

Questions, rights requests, Account closure requests and data protection complaints should be sent to:

CONDEO LTD
Company number: 17225871
Registered office: Dept 6790, 196 High Road, Wood Green, London, United Kingdom, N22 8HH
Email: info@conskins.com