Version: 2026-09-01 | Last updated: 1 September 2026
1. Who we are
Service provider: Oktcom LTD
Contact: contact@combivend.co.uk
Business address: 67 crescent drive north, Brighton, United Kingdom, BN2 6SL
Company number: 14560946
Registered in: England and Wales
Oktcom LTD operates the Combivend platform. Combivend acts as a controller for platform administration, account access, security, audit, support, and service communications. For individual campaigns, the client business named on the QR entry page is normally the promoter and controller for its campaign entry data, prize fulfilment, and marketing choices. Combivend may process campaign data on the client's behalf and may also use limited records for platform security, abuse prevention, audit, and legal compliance.
2. Personal data we process
- Customer campaign entry data, including email address, entry time, campaign, store, prize result, winner status, and the unlock-code email status.
- Premium campaign fields where enabled by the client, such as first name, phone number, postcode, and separate marketing consent choices. Phone number and postcode are optional unless a campaign clearly marks them as required.
- Client account data, including company name, legal name, region, group reference, contract reference, contract start date, billing interval, billing notes, OAuth email, limited-company or registration number, company address, contact name, campaign allowances, enabled features, account status, and account requests.
- User access data, including invited user name, email address, Google sign-in identity, role, company membership, store assignments, permission flags, session records, and account status.
- Technical, security, and audit data, including session identifiers, protected IP or network identifiers, browser user agent, CSRF data, login attempts, entry attempts, duplicate-entry checks, rate-limit records, system events, and error logs.
- Support and correspondence data, including account updates, requests to cancel or change subscriptions, invitation messages, operational notices, and any information sent to Combivend for support.
3. Why we use data
- To provide client and platform dashboards, Google sign-in, role-based access, store assignments, account administration, and subscription or feature requests.
- To run QR prize-entry pages, validate submissions, enforce campaign entry limits, record win or non-win outcomes, and email unlock codes to winners.
- To support store operations while restricting customer-entry data to authorised roles. Store users should only see winning data needed for fulfilment.
- To send transactional emails, including winner unlock-code emails, account invitations, account updates, request updates, security messages, and service notices.
- To prevent fraud, abuse, duplicate entries, unauthorised access, and misuse of the platform.
- To comply with legal, tax, accounting, regulatory, dispute, audit, or insurance obligations where they apply.
- To send marketing only where valid consent or another lawful permission applies and only for the channel selected.
Where UK or EU data-protection law applies, the lawful bases may include contract, legitimate interests, legal obligation, and consent. Consent is used for optional marketing permissions and can be withdrawn. Legitimate interests include operating a secure prize-box platform, preventing misuse, supporting clients and customers, and keeping reliable audit records.
4. Who data is shared with
- The client promoter responsible for the relevant campaign, so it can administer prizes, support winners, and manage its lawful promotion records.
- Postmark or another configured email provider, to deliver unlock-code emails, account invitations, request updates, and service messages.
- Google, when invited users use Google sign-in.
- Hosting, database, backup, monitoring, security, analytics, and professional service providers where needed to operate and protect Combivend.
- Authorities, regulators, courts, insurers, accountants, or legal advisers where required by law, regulation, dispute handling, fraud prevention, or to defend legal rights.
5. International transfers
Some providers may process data outside the UK, EU, US, or Canada. Where transfer safeguards are required, Combivend relies on appropriate provider terms, adequacy arrangements, standard contractual clauses, or equivalent safeguards required by applicable law.
6. Retention
Combivend keeps personal data only for as long as needed for the purposes described in this notice, then deletes, anonymises, or restricts it where appropriate. Normal retention targets are:
- Campaign entry, winner, unlock-code email, audit, and dispute records: normally up to 24 months after the campaign unless a longer legal, tax, audit, fraud-prevention, or dispute period is needed.
- Client account, contract, billing, user-access, and account-request records: while the account relationship is active, then normally up to 7 years where needed for contract, tax, accounting, legal, or dispute reasons.
- Security, session, login, rate-limit, and entry-attempt records: normally up to 24 months unless needed to investigate abuse, fraud, security incidents, or legal claims.
- Email delivery records and support correspondence: for as long as needed to confirm delivery, resolve support issues, maintain account records, or deal with disputes.
7. Cookies and security
Combivend uses essential cookies and similar technologies for login sessions, QR entry security, CSRF protection, rate limiting, and fraud or abuse prevention. These are needed for the service to work safely. We do not currently set advertising or marketing tracking cookies. If non-essential cookies are introduced later, we will explain them and ask for consent where required.
We use technical and organisational measures intended to protect personal data, including encryption for sensitive customer entry data, role-based access, store-scoped permissions, secure session cookies in production, CSRF protection, rate limiting, audit logs, and restricted admin/client access. No online service can be guaranteed completely secure, so please contact us promptly if you believe an account or entry record may be at risk.
8. Regional rights and marketing rules
- UK entrants and users may have UK GDPR rights to be informed, access, rectification, erasure, restriction, objection, portability and withdrawal of consent, and can complain to the Information Commissioner's Office. UK electronic marketing must follow PECR and UK GDPR consent or soft opt-in rules.
- EU and EEA entrants and users may have GDPR rights to be informed, access, rectification, erasure, restriction, objection, portability and withdrawal of consent, and can complain to their local supervisory authority. Electronic marketing should follow GDPR and applicable ePrivacy rules.
- US entrants and users may have rights under applicable state privacy laws, including rights to know, access, correct, delete, limit certain sensitive-data uses, and opt out of sale, sharing, targeted advertising or profiling where those laws apply. Commercial email should follow CAN-SPAM, and automated SMS or telephone marketing may require prior express written consent for the identified seller.
- Canadian entrants and users may request access or correction and may withdraw consent where appropriate under PIPEDA. Commercial electronic messages should follow CASL consent, sender-identification, proof-of-consent and unsubscribe rules.
9. Your choices
You can contact us using the details above to ask about access, correction, deletion, restriction, objection, portability, withdrawal of consent, or another privacy request. We may need to verify your identity and may need to keep some records for security, audit, legal, tax, accounting, fraud-prevention, or dispute reasons.
Marketing consent can be withdrawn by using any unsubscribe method provided in a message or by contacting the promoter or Combivend. Withdrawing marketing consent does not cancel a valid competition entry or prevent necessary transactional emails such as winner unlock-code messages.
10. Updates
We will update this notice when the platform, providers, lawful bases, retention approach, regional wording, or data use changes. Material changes may be brought to affected users before or when the change takes effect.