Legal · Data protection
Privacy Notice
Version prelaunch-privacy-rc9 · Updated 25 August 2026 · Acceptance record: privacy v6
This notice explains what Rafflux collects, why it is used, when it is created, who may receive it, how long it is kept and the choices and rights available to you. It distinguishes the current website and free pre-launch flow from future paid, competition and winner features that are not yet active.
Required processing is not based on one blanket consent. Rafflux uses the legal basis appropriate to each purpose. Optional marketing and optional winner publicity use separate choices and can be withdrawn without cancelling an otherwise valid membership or prize.
1. Controller and contact
The controller is George Michael / Γιώργος Μιχαήλ, an individual sole trader trading as Rafflux. Business and service address: Daidalou 3a, Larnaca 7020, Republic of Cyprus. Email: geobusiness05@outlook.com. Telephone: +357 95788101. VAT No.: CY60074939F.
Email the monitored business address for data-protection questions, rights requests or service matters. George currently handles Rafflux requests. No other administrator is currently assigned; a future administrator may handle a request only after George specifically assigns that role and the necessary confidentiality, access and response controls. Rafflux has not stated that a Data Protection Officer is appointed. If one is required or appointed, the effective notice will publish the DPO contact separately.
2. Scope and current product status
This notice covers rafflux.net, hosted authentication, free pre-launch enrollment, member status, support and administration. Paid competitions, wallet deposits and prizes are disabled. Website and iOS preview data are fictional or offline illustrations, not a live offer or production competition, until Rafflux decides and publishes a public iOS mode.
The iOS project remains an offline demonstration and is not connected to the production Rafflux backend. If a mobile app later connects, Rafflux must update the app disclosure, provider inventory and this notice before collecting production account or gameplay data through it.
3. Data created before final enrollment
Creating an email-and-password account or completing Google sign-in can create a hosted Supabase Auth identity containing a user identifier, normalized email, email-confirmation time, authentication-provider metadata, session information and security logs. Adding a phone can add a normalized +357 number, one-time confirmation time and provider verification records. These can exist even if you close the page before pressing Complete pre-launch account.
The browser also stores identifier-free OTP protection state, including timestamps, counters, opaque generation values and short request locks. It does not store the email address, phone number or verification code in that security record. A separate remember-device cookie records only whether a browser session may persist for up to 30 days.
Names, Cyprus city or area, age confirmation, policy evidence, marketing choice, membership and the five-attempt grant are intended to be saved only by the final atomic completion action. Unfinished form answers are not restored after a close or reload.
4. Account and membership data
If enrollment completes, Rafflux processes the Supabase user ID, confirmed email, one-time verified unique +357 phone, first name, surname, legal full name, display name, Cyprus city or area, country, 18+ declaration, account and membership status, policy versions and acceptance evidence, optional marketing choice, timestamps and the pre-launch reward entitlement.
Required fields are needed to authenticate the account, enforce Cyprus/18+ eligibility, prevent duplicate rewards and administer membership. If you do not provide them, Rafflux cannot complete pre-launch membership. Your exact delivery address is not required during ordinary enrollment.
5. Authentication and security data
Rafflux processes session cookies, Rafflux password-authentication, Google identity/provider information, email-confirmation and one-time phone-verification events, IP address, device/browser context, failure and rate-limit signals, recovery events, suspicious activity, audit records and access-control decisions to secure accounts and the service.
Passwords are handled by Supabase Auth as the authentication processor and are not available to Rafflux staff in readable form. Email confirmation and one-time phone verification prove control of the account contacts; they are not described as recurring second factors at every login. Rafflux, Supabase, Resend and Twilio may each apply independent code expiry, resend, fraud and rate limits. Never send a password or one-time code to Rafflux support.
6. Future competition and gameplay data
If competitions activate, Rafflux may process competition entries, attempt source and token, exact inputs and replay events, server-calculated score or time, rank, game/ruleset/scorer versions, device/app context, integrity and plausibility signals, disqualification or correction decisions, appeals and settlement records.
Deterministic software calculates scores from the frozen rules. Automated systems may flag risk, but materially adverse anti-cheat, identity, payment and winner decisions must have meaningful human review and a route to contest the result.
7. Future payment and wallet data
Paid competitions and wallet deposits are disabled. Rafflux does not currently take payment, operate a wallet or process payment-provider transaction data.
Before taking payment, Rafflux will publish the applicable provider, legal basis, retention, transfer, consumer disclosures and the specific disclosed refund route. This notice does not promise a universal wallet-credit outcome for refunds.
8. Future winner, identity and delivery data
Prizes, winner claims and related identity or delivery processing are disabled. Rafflux will not collect an identity document merely to create an ordinary pre-launch account. Do not email identity documents unless Rafflux has expressly provided the protected private upload route for a genuinely activated future feature.
Only George as Owner or an active Admin specifically assigned by George, with AAL2 multi-factor authentication, may open a submitted card. The document is shown in a short-lived in-page viewer. The access audit records the reviewer, structured purpose, opening time, document side and viewer/session expiry; browser, ordinary support access or an unassigned role does not grant identity-review access.
Submitted identity-card images receive an automated deletion deadline no later than the end of the submission day in Cyprus. The server-mediated decision route deletes the files before finalizing the outcome, while the restricted cleanup worker removes overdue evidence and verifies that the private storage prefix is empty. An exceptional hold is available only to an AAL2-authenticated Owner for a listed law-enforcement, active-security-investigation or litigation-preservation reason and cannot exceed 24 hours at a time. Each further hold must be separately authorized and recorded; expiry or early release returns the case to deletion. The hosted cleanup schedule must be enabled and tested before this inactive workflow is activated.
A rejection uses a structured category and a safe member-facing explanation. The person can correct the evidence and request a human appeal, and the original reviewer is blocked from deciding that appeal. Person-level duplicate prevention may convert a document number only on the server into a secret-keyed HMAC token; the raw number is not stored or logged. The HMAC token is personal data. It, the minimized verification outcome and the purpose/time/access audit may be retained for their stated periods without retaining the identity-document image. A possible token match requires a recorded human resolution and does not automatically reject, suspend or ban the person.
This workflow does not use OCR, facial recognition, biometric templates, liveness analysis, AI identity matching or automated identity rejection. A later introduction of any such processing would require a fresh assessment and notice before use. Identifiable winner photography, video, voice, testimonial or social handle is optional and governed by a separate release.
9. Support, communications and marketing data
Rafflux processes messages, contact details, attachments, complaint or appeal references, status and staff actions needed to answer support, privacy or legal requests. Urgent service communications can use the verified email and, where available, optional SMS and in-app notice for verification, security, policy, membership, competition and claim matters.
The current pre-launch system records the optional launch-news choice, time and source. Before any campaign marketing is sent, Rafflux must operate delivery-status, withdrawal and minimal suppression handling so a withdrawn address is not re-added accidentally. Rafflux will not rely on silence, a pre-ticked box or required policy acceptance as newsletter consent. Each marketing message must offer a free and easy withdrawal method.
10. Future host and supplier data
Invite, streak and bundle promotions are intended for launch, but their final rules are not yet published. Rafflux will publish the exact promotion data categories, purposes, recipients and retention before it activates those promotions.
11. Sources of personal data
Most data comes from you, your browser/device and your use of Rafflux. Authentication and delivery status can come from Supabase, Google, Resend and Twilio. Apple is not an active account route in this release and does not receive an account request; if Apple is genuinely enabled and tested, Rafflux will publish its active role, including any private-relay email processing, before use.
Rafflux may receive lawful reports about fraud, security or rule breaches. It will assess their reliability and will not treat an unverified report as conclusive proof.
12. Purposes and legal bases
Contract and steps requested before contract: create and secure an identity, complete membership, deliver the five-attempt benefit, administer an activated competition or transaction, provide support and handle a valid claim.
Legal obligation: keep records and make disclosures required by tax, accounting, consumer, data-protection, payment, court, regulatory or law-enforcement rules; respond to valid legal requests; and meet breach or rights obligations.
Legitimate interests: prevent duplicate rewards and abuse, secure and diagnose the service, preserve integrity and audit evidence, establish or defend legal claims, measure reliability and maintain essential administration. Rafflux must balance these interests against your rights and allow objection where the law provides it.
Consent: optional email marketing, optional winner publicity and any non-essential browser storage or future processing that specifically requires consent. Consent can be withdrawn prospectively without making earlier lawful processing unlawful.
13. Recipients and processors
Current service categories include Supabase for hosted database and authentication, Vercel for website hosting and delivery, Resend for email delivery, Twilio Verify for SMS verification, and Discord for a private operational-alert channel. George currently handles service, rights, suppression and incident operations. A future administrator receives access only after George specifically assigns the role. Support views are designed to redact contact data unless a higher authorized capability is necessary. Identity-document access is limited to George as Owner or an active Admin specifically assigned by George, using AAL2 authentication, a structured purpose and a short-lived audited session.
Cloudflare Turnstile is active on public account-creation, sign-in, password-recovery and phone-verification request surfaces to distinguish people from automated traffic and protect authentication from abuse. The browser runs Cloudflare's challenge, and Cloudflare processes technical signals such as the client IP address, TLS fingerprint, user-agent header, site key, associated origin and browser-environment signals. Cloudflare states that Turnstile does not access, store or transmit form entries, user communications or other page inputs. Cloudflare processes these signals as Rafflux's processor when protecting Rafflux and separately as a controller when improving Turnstile's bot-detection capability. Rafflux treats the protection as strictly necessary security processing and relies on legitimate interests in preventing abuse and protecting accounts; it is not used for advertising or optional marketing. Google sign-in is active as an optional account-entry route and Google can therefore receive the OAuth request and return identity and verified-email information to Supabase/Rafflux. Apple sign-in is visible only as an unavailable prepared option and does not receive an account request. If Apple is genuinely enabled and tested, this notice will be updated before use to identify Apple processing, including any private-relay email. A payment provider or other service remains inactive until its production data flow is configured and this notice/provider record is updated.
Rafflux uses the private Discord channel for generic staff-access and operational alerts and a configured Owner email recipient for critical operational or security alerts. Those external alerts contain only a generic event kind, severity, coarse time and a prompt to open the permission-controlled Radmin. They do not contain a member or staff name, email, phone, account identifier, raw IP, device or browser evidence, location, support content, audit reason, password, one-time code, credential, identity evidence or financial detail. Detailed evidence remains inside Radmin.
Rafflux may disclose data to professional advisers, auditors, insurers, couriers, prize suppliers, banks, payment networks, courts, regulators or law enforcement where reasonably necessary and lawful. It does not sell personal data.
14. International transfers
Some providers or subprocessors may process data outside Cyprus or the European Economic Area. Before activation, Rafflux must document the actual contracting entity, processing locations, subprocessors and transfer mechanism for each provider.
Where required, Rafflux will use an adequacy decision, approved Standard Contractual Clauses with supplementary measures, or another lawful safeguard. You may ask geobusiness05@outlook.com for information about the applicable safeguard. This candidate does not claim a transfer mechanism that has not yet been verified against the production contracts.
15. Retention schedule
Retention means the period for which Rafflux keeps each type of record before deleting it, anonymizing it or preserving it under a documented legal hold. Rafflux has adopted the baseline periods below for this effective notice. Current account and pre-launch procedures and provider settings must follow them; any future processing remains unavailable until its deletion, anonymization and staff procedures are configured and tested rather than relying on policy wording alone.
- Unfinished or unverified authentication identities: delete or anonymize after 30 days without activity, unless security evidence, a rights request or a documented legal hold requires a different period.
- Identifier-free browser OTP guard state: automatically becomes unusable after its short cooldown, lease and code lifecycle; stale values are sanitized locally.
- Active account and membership data: while active; delete or anonymize within 24 months after closure, subject to the narrower records and legal holds below.
- Policy, age and marketing consent or withdrawal evidence: up to 6 years after the relevant relationship or dispute where needed to prove compliance.
- Raw IP and device/browser security evidence: ordinarily no more than 90 days. A confirmed serious incident record may remain for up to 2 years; longer retention requires a documented legal hold.
- Consent-gated product analytics events: ordinarily up to 12 months; use aggregate reporting where possible and do not extend the lifetime merely because the dashboard can display a shorter window.
- Ordinary resolved support cases: 2 years after resolution. Cases connected to payments, disputes, winners or legal obligations: 6 years after resolution. A documented legal hold prevents scheduled deletion until it is released.
- Competition gameplay and integrity records: up to 6 years after settlement for audit, dispute and fraud evidence; public leaderboards use minimized public fields.
- Payment, refund, chargeback, tax and accounting records: the legally required period, commonly up to 6 years where the Cyprus record applies, without extending that period to unrelated profile data.
- Cyprus identity-card image or scan: assign an automated deadline no later than the end of the submission day in Cyprus; delete it through the server-mediated decision route or the verified cleanup worker. An AAL2 Owner may delay cleanup only for a listed exceptional law-enforcement, active-security-investigation or litigation-preservation reason, for no more than 24 hours at a time, with every hold or extension separately recorded.
- Minimized identity-verification outcome and purpose, time and access audit: ordinarily retain for up to 24 months after account closure, and longer only for an active investigation, legal claim, legal obligation or documented legal hold. These records are personal data but are not the identity-document image.
- Secret-keyed HMAC duplicate-prevention token and the minimum non-redeemable pre-launch reward anti-repeat evidence: retain for up to 6 years after account closure or the end of the relevant relationship where needed to prove compliance and prevent duplicate benefit abuse, subject to applicable correction, objection and erasure rights and any overriding legal obligation. Rafflux does not retain the raw identity-document number in that record.
- Winner delivery, tax, prize-transfer and claim evidence: retain only for the applicable accounting, claim or legal period; this does not justify retaining the identity-document image.
- Host ownership, agreement, promotion-proof, settlement, reserve, payout and adjustment evidence: retain only for the applicable contract, accounting, tax, fraud, dispute or legal period, commonly up to 6 years where the Cyprus record applies.
- Marketing contact: until withdrawal or the purpose ends; a minimal suppression record may remain to honor the withdrawal.
- Backups: the final effective notice must state the verified backup cycle and deletion treatment; approved deletions must not be restored into ordinary use without applying the deletion again.
16. Security and access
Rafflux uses role-based access, row-level database controls, hosted authentication, verified contact channels, provider and local rate limits, least-privilege admin capabilities, audit records and encrypted transport. Identity-document access is limited to the Owner or an active Admin and adds AAL2 authentication, a structured purpose, a short-lived in-page viewer and an append-only access audit. Secrets and raw document numbers must remain out of public code, logs, screenshots and support messages; only the server creates the secret-keyed HMAC duplicate-prevention token.
No system is perfectly secure. Rafflux must maintain incident assessment, restoration and breach documentation procedures and notify the Cyprus supervisory authority and affected people when the GDPR requires it. Users should secure their devices and report suspected compromise promptly.
17. Your data-protection rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or objection; withdraw consent; and ask for human intervention regarding a qualifying automated decision. Some rights are limited where Rafflux must keep evidence, protect another person or comply with law.
Send a request to geobusiness05@outlook.com. Rafflux may request proportionate identity verification and must act without undue delay and, at the latest, within one month after receiving the request. Where the GDPR permits an extension, Rafflux must notify you within that first month and explain the reasons. You may complain to the Office of the Commissioner for Personal Data Protection in Cyprus and may use any other court or supervisory remedy available to you.
18. Automated decisions and profiling
The current website uses automated validation, authentication, rate limits and fraud signals. Future games use deterministic scoring. These tools can prevent a technically invalid request or calculate a result, but the identity workflow does not use OCR, biometric analysis or automated rejection, and a duplicate-prevention token match requires recorded human resolution. Rafflux does not intend these tools to make a solely automated decision with legal or similarly significant effects about disqualification, identity, payment holds or winner entitlement.
If Rafflux later introduces qualifying solely automated decision-making, this notice must explain the logic, significance, likely consequences and available safeguards before use.
19. Children
Rafflux is restricted to people aged 18 or older and is not directed to children. If Rafflux learns that a person under 18 supplied personal data, it will restrict the identity and review deletion while preserving only what law, safety or fraud prevention requires.
20. Cookies and local storage
The current website uses browser storage that is strictly necessary for authentication, security, requested preferences and OTP abuse protection. It does not currently use advertising, behavioural profiling, heatmaps or session-replay storage. The Cookie and Local Storage Notice lists the current categories and durations.
Non-essential analytics or advertising storage must not be activated until the inventory and notice are updated and a valid consent control is available where required. Rejecting non-essential storage must be as accessible as accepting it.
21. Further processing and notice changes
If Rafflux wants to use data for a materially different purpose, it will assess compatibility and provide any new information or choice required before that use. Material notice changes are versioned and dated. A new privacy acknowledgment may be requested when necessary, but acknowledgment is not converted into marketing consent.
22. Complaints and contact
Contact geobusiness05@outlook.com with a privacy question, complaint, rights request or ordinary account/service matter. You may also call +357 95788101. Do not include a password, OTP, full payment card number or unnecessary identity document in an email.
The Controller’s full legal identity and geographic contact appear in section 1. The Cyprus supervisory authority is the Office of the Commissioner for Personal Data Protection; its current contact and complaint procedure are available from dataprotection.gov.cy.