Data protection

Tychefy Privacy Policy

This policy explains how the platform processes personal data, on what legal bases such processing rests, and which safeguards and rights may apply when you use the service.

Last updated: 29/06/2026

This Privacy Policy explains how we process personal data when you use the Tychefy platform (the “Service”). Where the General Data Protection Regulation (GDPR) applies, processing is carried out in accordance with the principles of lawfulness, transparency, data minimisation, and security. In Cyprus, processing is also subject to Law 125(I)/2018 on the protection of natural persons with regard to the processing of personal data.

1. Data controller and contact details

The data controller for the operation of Tychefy is Acrossmedia241 LTD, registered at Kyriakou Matsi 3, 3040, Limassol, Cyprus with registration number HE 290075, VAT number CY10290075L For privacy-related matters, data protection requests, or questions about this Policy, please contact customers@tychefy.com.

2. Categories of data

  • Account and identification data: email address, user identifier, and authentication-related data handled through an identity provider, such as Clerk.
  • Subscription and billing data: subscription status, transaction identifiers, and payment event records. We do not store full card details, which are handled by the payment provider, such as Stripe.
  • Technical and operational data: IP address, where it appears in logs, user-agent, timestamps, application errors, and diagnostic information used for security and reliability purposes.
  • Usage data and user inputs: inputs that you submit, such as recent draw information or joker number values, as well as operational history files that you update through the Service.

3. Purposes of processing and legal bases

  • Provision of the Service (Article 6(1)(b) GDPR): account creation and management, access to platform features, and presentation of outputs.
  • Legitimate interests (Article 6(1)(f) GDPR): security, prevention of misuse, troubleshooting, and improvement of service reliability.
  • Legal obligation (Article 6(1)(c) GDPR): accounting, tax, and related compliance obligations where required.
  • Consent (Article 6(1)(a) GDPR): non-essential cookies and analytics, where consent is required by applicable law.

4. Cookies and similar technologies

We use technically necessary cookies and similar storage technologies for authentication, session continuity, security, and basic service operation. We also store the user’s cookie-banner choice locally in the browser in order to remember that preference on the same device and browser.

Where we use advertising or measurement technologies, this is described in the section “Advertising audiences and measurement on third-party platforms”, and any required consent is obtained beforehand.

5. Recipients and service providers

The Service relies on third-party providers for infrastructure and operational functionality, including Vercel for hosting and deployment, Clerk for authentication and identity services, and Stripe for payment processing and subscription-related billing events. For conversion measurement, as described in Section 4, event data are also transmitted to Google (Google Analytics 4) and Meta Platforms (Conversions API).

Depending on the relevant processing activity, such providers may act as processors on our behalf or, for limited parts of their own service operation, as independent controllers under their own legal documentation. Where required, appropriate contractual and transfer safeguards are applied.

6. Transfers outside the EEA

Where personal data are transferred outside the European Economic Area, appropriate safeguards, such as an adequacy decision of the European Commission (including the EU-US Data Privacy Framework, Commission Implementing Decision (EU) 2023/1795) or Standard Contractual Clauses, are applied where required.

7. Advertising audiences and measurement on third-party platforms

In addition to the conversion measurement described above, we may use certain personal data to create and manage advertising audiences on third-party advertising platforms, in particular Meta Platforms (Facebook and Instagram) and Google.

Specifically, we may upload a limited set of customer identifiers, such as email addresses, to Meta and Google in a hashed or pseudonymised form, so that these platforms can match them against existing accounts and allow us to show or withhold advertising to existing customers, and to create lookalike or similar audiences in order to reach new people whose characteristics resemble those of our existing customers.

We may also use website and app interaction data collected through advertising technologies, such as the Meta pixel and Google tags, where applicable consent has been obtained, to build audiences of visitors for remarketing and measurement purposes.

Where this processing requires consent under applicable law, such consent is obtained before the relevant data are used for these purposes, and you may withdraw it at any time. Where this processing is based on our legitimate interests (Article 6(1)(f) GDPR) in promoting the Service and reaching relevant audiences, you have the right to object to such processing at any time, including for direct-marketing purposes, in which case we will cease using your data for those purposes.

The identifiers we upload are transmitted in hashed form, and we do not transmit full payment-card details. Depending on the activity, Meta and Google may act as our processors or as independent controllers under their own legal terms. Appropriate contractual and international-transfer safeguards are applied where required, as described in Sections 5 and 6.

You can exercise your rights, including objection and withdrawal of consent, by contactingcustomers@tychefy.com. You may also adjust advertising preferences directly with the relevant platform through its own settings.

8. Retention period

We retain data for as long as necessary to provide the Service, to comply with legal obligations, and to address security or incident-resolution needs for a reasonable period. Following an account deletion request, data are deleted or anonymised where feasible, subject to any mandatory retention requirements.

9. Security

We implement technical and organisational measures, including access controls, encryption in transit, event logging, and limitation of privileges. No method of transmission or storage can, however, guarantee absolute security.

10. Data subject rights

Depending on the applicable legal framework, you may exercise rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You may also lodge a complaint with the competent supervisory authority. In Cyprus, this is the Commissioner for Personal Data Protection (www.dataprotection.gov.cy); if you reside in another Member State of the European Union, you may also contact the supervisory authority of your place of residence.

11. Automated decision-making

The Service generates probabilistic outputs for the purpose of supporting the organisation of selections and is not intended to produce legal effects or otherwise bind you. The final decision on whether and how to use any output remains exclusively your own.

12. Minors

The Service is not intended for minors. If we become aware that data relating to a minor have been collected, we will take steps to restrict processing or delete the relevant data.

13. Changes to this Policy

We may update this Privacy Policy from time to time. The current version will be published on this page together with the updated effective date.