← Back to Home

GDPR Information

Last updated: July 29, 2025

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018, in the European Union. It gives individuals greater control over their personal data and requires organizations to be more transparent about how they collect, use, and protect personal information.

Your Rights Under GDPR

1. Right to Access

You have the right to request a copy of all personal data we hold about you and information about how we process it.

2. Right to Rectification

You can request that we correct any inaccurate or incomplete personal data we hold about you.

3. Right to Erasure

You can request that we delete your personal data in certain circumstances (also known as the "right to be forgotten").

4. Right to Restrict Processing

You can request that we limit how we use your personal data in certain situations.

5. Right to Data Portability

You can request a copy of your personal data in a structured, machine-readable format.

6. Right to Object

You can object to our processing of your personal data in certain circumstances.

How We Process Your Data

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Consent: When you explicitly agree to our processing of your data
  • Contract: When processing is necessary to provide our services
  • Legitimate Interest: When processing is necessary for our legitimate business interests
  • Legal Obligation: When we are required to process data by law

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.

International Data Transfers

Cross-Border Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure that such transfers comply with GDPR requirements through:

  • Adequacy decisions by the European Commission
  • Standard contractual clauses approved by the European Commission
  • Binding corporate rules
  • Other appropriate safeguards as required by GDPR

Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our data protection practices and ensure compliance with GDPR:

Email: dpo@towerofluck.com

Address: Tower of Luck Data Protection Officer

Response Time: We aim to respond to all GDPR-related inquiries within 30 days

Exercising Your Rights

How to Make a Request

To exercise any of your GDPR rights, please contact us using one of the following methods:

Email Request

Send your request to: gdpr@towerofluck.com

Online Form

Use our GDPR request form on our website

What We Need from You

To process your request efficiently, please provide:

  • Your full name and contact information
  • Specific details about your request
  • Any relevant account information
  • Proof of identity (for security purposes)

Response Timeline

We will respond to your request within 30 days. In complex cases, we may extend this period by up to 60 days, but we will notify you of any extension.

Data Breach Notification

Our Commitment to Security

In the unlikely event of a data breach that affects your personal data, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Inform affected individuals without undue delay
  • Take immediate steps to contain and remediate the breach
  • Document all incidents and our response

Cookies and Tracking

We use cookies and similar technologies to enhance your experience on our website. You have the right to control how we use these technologies:

Essential Cookies

Required for basic website functionality. Cannot be disabled.

Analytics Cookies

Help us understand how visitors use our site. Can be disabled.

Marketing Cookies

Used for personalized advertising. Can be disabled.

You can manage your cookie preferences through your browser settings or our cookie consent banner.

Third-Party Services

We may use third-party services that process your personal data. These services include:

  • Analytics providers (Google Analytics, etc.)
  • Customer support platforms
  • Payment processors (if applicable)
  • Cloud hosting services

All third-party services are carefully selected and required to comply with GDPR requirements through appropriate data processing agreements.

Updates to This Information

We may update this GDPR information from time to time to reflect changes in our practices or applicable law. We will notify you of any material changes by posting the updated information on this page and updating the "Last updated" date.

Contact Information

If you have any questions about our GDPR compliance or wish to exercise your rights, please contact us:

Data Protection Officer

Email: dpo@towerofluck.com

Response time: 30 days

General GDPR Inquiries

Email: gdpr@towerofluck.com

Response time: 30 days

Supervisory Authority: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.