Last updated: November 2025
GDPR
This page summarises how xRaffle applies the EU General Data Protection Regulation (GDPR) and the UK GDPR. It complements our Privacy Policy.
Who is the data controller
xRaffle is the data controller for information you provide directly (your account, raffle configuration, billing details). For public X (Twitter) engagement we retrieve on your behalf, you act as controller for how it is filtered, published, and shared through the audit page, and xRaffle acts as processor.
Legal bases we rely on
- Contract — to deliver the service you signed up for.
- Legitimate interest — securing the service and preventing abuse.
- Legal obligation — tax, accounting, and compliance records.
- Consent — optional cookies and marketing communication.
Your rights
- Access a copy of the personal data we hold about you.
- Ask us to correct inaccurate data.
- Ask us to delete your data ("right to be forgotten").
- Ask us to restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your local supervisory authority.
To use these rights, email support@raffle.dev from the address on your account. We respond within 30 days.
International transfers
Some of our service providers are outside the EU/EEA. Where that is the case, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.
Data breach notification
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay.
Contact
Data protection contact: support@raffle.dev.