NORTHVERIS LTD | Reg. No. 17256543 | Effective: June 2026
Data Controller: NORTHVERIS LTD | Contact: privacy@lucky-rule.r-one.dev
This Privacy Policy explains how NORTHVERIS LTD ("we", "us", "our") collects, uses, stores, and protects your personal data when you use the Lucky Rule platform. We are committed to complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
The data controller is NORTHVERIS LTD, registered in England and Wales (No. 17256543), Dept 6842, 196 High Road, Wood Green, London, United Kingdom, N22 8HH. For all data protection enquiries, contact us at privacy@lucky-rule.r-one.dev.
2. Personal Data We Collect
We collect the following categories of personal data:
• Account Data: email address, username, date of birth, country of residence, registration date and timestamp.
• Transaction Data: purchase history, transaction reference numbers, amounts, timestamps, transaction status and limited payment identifiers received from our payment service provider.
• Technical Data: IP address, device type, operating system, browser type and version, session identifiers, country-level geolocation, access logs and device identifiers or fingerprints where used for security and fraud-prevention purposes.
• Gameplay Data: game sessions, Virtual Coin balances, win/loss records and in-game activity logs.
• Communications: the content of support emails, enquiries and any other correspondence you send to us.
3. Age Restriction
Lucky Rule is intended only for users aged 18 or over. We do not knowingly allow minors to create or use accounts on the Platform. If we become aware that a user is under 18, we may suspend or close the account and delete or restrict the related personal data, unless retention is required for legal, fraud-prevention or dispute-resolution purposes.
4. Legal Bases and Purposes of Processing
We process your personal data on the following legal bases:
• Contract Performance (Art. 6(1)(b) UK GDPR): to create and manage your account, process Virtual Coin purchases, deliver gameplay access and provide customer support.
• Legal Obligation (Art. 6(1)(c) UK GDPR): to keep accounting and tax records and respond to lawful requests from public authorities where required by applicable law.
• Legitimate Interests (Art. 6(1)(f) UK GDPR): to maintain Platform security, detect and prevent fraud and abuse, manage chargeback disputes, enforce our Terms of Use, enforce the 18+ restriction and improve Platform performance. Our legitimate interests do not override your fundamental rights and freedoms.
• Consent (Art. 6(1)(a) UK GDPR): where required for non-essential cookies or similar technologies.
5. Payment Card Data
NORTHVERIS LTD does not store full payment card numbers, CVVs, bank account details or sensitive authentication data. When you make a purchase, payment card data is processed by a third-party payment service provider through its secure payment environment. We may receive only limited payment information, such as transaction reference, amount, timestamp, status and the last four digits of the card where supplied by the provider, for record-keeping, fraud-prevention, refund and chargeback-management purposes.
6. Fraud Prevention and Chargeback Management
We process account, transaction and technical data, including IP addresses, device identifiers or fingerprints where used, and transaction patterns, for the purpose of:
• detecting and preventing fraudulent transactions and account abuse;
• contesting fraudulent or unsubstantiated chargeback claims;
• complying with reasonable requests from our payment service provider, financial institutions or public authorities where legally required.
In the event of a chargeback dispute, we may share relevant personal data, including transaction records, IP address, account registration data and device information, with our payment service provider and, where required by law, with financial institutions or law enforcement agencies.
7. Data Sharing
We share your personal data only with the following categories of recipients:
• Payment service provider — for transaction processing, refunds, fraud prevention and chargeback management.
• Hosting and cloud infrastructure providers — for Platform operation and data storage.
• Analytics providers — for Platform usage analytics, using aggregated or pseudonymised data where possible.
• Law enforcement and regulatory authorities — where required by applicable law, court order or lawful request.
• Professional advisers — lawyers and accountants, under confidentiality obligations.
We do not sell, rent or otherwise transfer your personal data to third parties for marketing purposes.
8. International Transfers
Your data is primarily processed within the United Kingdom. Where we transfer personal data outside the UK, we use appropriate safeguards in accordance with UK GDPR requirements, such as adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to standard contractual clauses, where applicable.
9. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy:
• Account data: for the duration of your account and up to 12 months after closure, unless a longer period is required for legal, fraud-prevention or dispute-resolution purposes.
• Transaction and tax records: 6 years from the date of the transaction.
• Basic account identifiers and dispute records: up to 6 years after account closure where necessary to establish, exercise or defend legal claims, manage chargebacks or prevent repeat abuse.
• Gameplay logs: 12 months, unless needed for fraud prevention, disputes or legal claims.
• IP address and access logs: 90 days, unless needed for security, fraud investigation or legal claims.
• Support correspondence: 3 years from the date of the last communication.
Following the applicable retention period, data is securely deleted or irreversibly anonymised.
10. Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
• Right of Access — to obtain a copy of your personal data.
• Right to Rectification — to correct inaccurate or incomplete data.
• Right to Erasure — to request deletion of your data in certain circumstances.
• Right to Restriction — to restrict processing in certain circumstances.
• Right to Data Portability — to receive your data in a structured, machine-readable format.
• Right to Object — to object to processing based on legitimate interests.
• Right to Withdraw Consent — where processing is based on consent.
To exercise any of these rights, contact us at privacy@lucky-rule.r-one.dev. Where necessary, we may request information to verify your identity. We will respond within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk).
11. Automated Decision-Making
We do not use personal data for solely automated decision-making that produces legal or similarly significant effects for users. Fraud-prevention indicators may be used to support Platform security reviews, account protection and chargeback management.
12. Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction or disclosure. These include encrypted data transmission (TLS), access controls, server-side security configurations and regular security reviews. Despite these measures, no transmission over the internet is completely secure.
13. Cookies
We use cookies and similar technologies as described in our Cookie Policy, available on the Platform. Non-essential cookies are used only where permitted by applicable law and, where required, based on your consent.
14. Changes to This Policy
We may update this Policy to reflect changes in our practices or legal requirements. Material changes will be communicated via the Platform. The effective date at the top of this Policy indicates when it was last revised.