Privacy Policy

Last updated: 26 September 2025

Who we are

Websome Awards (the “Service”) is operated by [Company Legal Name], registered in [Country], with registered address [Address]. Data Controller: [Company Legal Name]. Contact: privacy@yourdomain.com.

What we collect

  • Account data: email, username, avatar, password (stored as a salted hash; never in plain text).
  • Technical data: IP address, device/browser information, timestamps and server logs.
  • Cookies & local storage: we use a strictly necessary HTTP-only access token for authentication and may persist non-essential UI preferences in local storage. For full details, see our Cookie Policy. See the Cookie Policy.

Why we process your data (legal bases)

  • Provide and operate the Service, manage your account and sessions. (GDPR Art. 6(1)(b) – contract)
  • Transactional communications: email verification, password reset, essential service emails. (Art. 6(1)(b))
  • Service notifications related to awards (e.g., results such as “Website of the Day”). (Art. 6(1)(f) – legitimate interests)
  • Security, fraud prevention, troubleshooting and service integrity. (Art. 6(1)(f))
  • Compliance with legal obligations. (Art. 6(1)(c))
  • Optional marketing (if enabled in the future) only with consent. (Art. 6(1)(a))

How long we keep your data

  • Account data: kept while your account is active and for a reasonable period thereafter or until you request deletion.
  • Security and server logs: retained for a limited period necessary for security and diagnostics (e.g., 90 days) or as required by law.
  • Email delivery metadata: retained by our email provider according to their retention terms.

Sharing and processors

We use trusted service providers (hosting, email delivery, storage, security) under data-processing agreements. They process data only on our instructions and for the purposes described here.

International transfers

If personal data is transferred outside the EEA/UK, we rely on appropriate safeguards (e.g., Standard Contractual Clauses) and supplementary measures where necessary.

Your rights

You can request access, rectification, erasure, restriction, and portability of your data, and you may object to processing based on legitimate interests. When we rely on consent, you can withdraw it at any time.

To exercise your rights, contact us at privacy@yourdomain.com. You may also lodge a complaint with your local data protection authority.

Security

We use industry-standard measures to protect personal data (e.g., TLS in transit; passwords stored using strong hashing such as Argon2/bcrypt). No method of transmission or storage is 100% secure.

Children

The Service is not intended for individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it.

Changes to this Policy

We may update this Policy from time to time. We will post the new effective date above and, where appropriate, notify you within the Service.

Contact

Data Controller: [Company Legal Name] — [Address] — privacy@yourdomain.com

Privacy Policy | Websome Awards | Websome Awards