How FaceProtect Limited uses personal data collected through fractstandard.com

1. Introduction and scope

1.1 This Privacy Notice explains how FaceProtect Limited collects, uses, shares and protects personal data about visitors to and users of the website at fractstandard.com (the “Website”), and about people who contact us through the Website. It also explains your rights under data protection law and how to exercise them.

1.2 We are committed to protecting your personal data and to handling it in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (“PECR”).

1.3 This Notice applies to personal data we collect through the Website. It does not apply to any other website, product or service, or to the personal data practices of the self-exclusion schemes, gambling operators or venues that deploy facial recognition technology (see paragraph 2).

2. Important note: FRACT does not process biometric or self-exclusion data

2.1 The FRACT Standard is a voluntary governance standard for the ethical, lawful and technically robust deployment of facial recognition technology in land-based gambling self-exclusion schemes. FaceProtect and the FRACT Standard do not operate any facial recognition system through the Website, and we do not collect, store or otherwise process the facial images, biometric data or self-exclusion records of individuals who are subject to those schemes as a result of your visiting the Website.

2.2 If you are a member of a self-exclusion scheme, or you wish to understand how your image or biometric data is used by a particular scheme, operator or venue, or you wish to exercise your rights in relation to that data, you should contact the relevant scheme, gambling operator or venue directly. Each of them is responsible, as an independent data controller, for its own processing of that data and for providing its own privacy information.

2.3 The remainder of this Notice concerns only the personal data we process about visitors to, and enquirers through, the Website.

3. Who we are – the data controller

3.1 The data controller for personal data collected through the Website is FaceProtect Limited, a company incorporated in England and Wales with company number 16817787, whose registered office is at Connect House, 133–137 Alexandra Road, Wimbledon, London SW19 7JY.

3.2 FaceProtect is registered with the Information Commissioner’s Office (the “ICO”) under registration number Z044679.

3.3 If you have any questions about this Notice or about how we handle your personal data, you can contact us by email at dpo@faceprotect.co.uk, or by writing to The Data Protection Contact, FaceProtect Limited, Connect House, 133–137 Alexandra Road, Wimbledon, London SW19 7JY.

3.5 The ownership and stewardship of the FRACT Standard is in the process of being transferred to the scheme owners of land-based self-exclusion schemes. If, as a result, responsibility for the Website passes to a successor organisation, we will update this Notice to identify the new data controller and, where required, we will let you know.

4. The personal data we collect

4.1 We collect and use the following categories of personal data about visitors to and enquirers through the Website:

CategoryWhat this includesSource
Enquiry / contact dataThe information you provide when you complete the contact form or otherwise contact us, such as your name, email address, contact number, organisation details, and the content of your message and our correspondence with you.Provided by you
Technical and usage dataInformation collected automatically when you visit, such as your internet protocol (IP) address, browser type and version, device information, operating system, and information about how you use the Website.Collected automatically
Cookie dataInformation collected through cookies and similar technologies. (See Section 8 for more information on the cookies we use)Collected automatically

4.2 We do not intentionally collect special category personal data (such as data concerning health, or biometric data used to identify a person) through the Website. Please do not include special category data in the free-text fields of the contact form unless it is necessary; if you do, you consent to us using it to respond to your enquiry.

4.3 The Website is not directed at children and we do not knowingly collect personal data about children through it.

5. How and why we use your personal data

5.1 Under data protection law, we must have a lawful basis for processing your personal data. The table below sets out the purposes for which we use your personal data and the lawful basis we rely on for each purpose.

PurposeType of dataLawful basis
To respond to your enquiries, provide the information you request and correspond with youEnquiry / contact dataOur legitimate interests (to respond to enquiries and manage our relationships with interested parties and stakeholders), and, where relevant, to take steps at your request prior to entering into any arrangement
To operate, maintain and secure the Website and to prevent and detect fraud or misuseTechnical and usage data; cookie dataOur legitimate interests (to keep the Website and our systems secure and working properly)
To understand how the Website is used and to improve itTechnical and usage data; cookie dataYour consent (for non-essential/analytics cookies), obtained through our cookie banner
To comply with our legal and regulatory obligations, and to establish, exercise or defend legal claimsAny of the aboveCompliance with a legal obligation; and our legitimate interests (to protect our legal position)

5.2 Where we rely on our legitimate interests, we have considered whether those interests are overridden by your interests, rights and freedoms, and we have concluded that they are not. You have the right to object to processing based on legitimate interests (see section 11).

5.3 Where we rely on your consent (for example for non-essential cookies), you can withdraw that consent at any time (see sections 8 and 11). Withdrawing consent does not affect the lawfulness of any processing carried out before you withdraw it.

6. Who we share your personal data with

6.1 We do not sell your personal data. We share it only in the following circumstances:

Service providers (processors). We use third parties to provide and support the Website and our operations, for example our website hosting provider, email provider (Microsoft), Google Analytics and Hubspot. These providers process personal data on our behalf, under written contracts that require them to keep it secure and to use it only as we instruct.

Professional advisers. We may share personal data with our legal, insurance and other professional advisers where necessary.

Governance and stewardship. As part of the transfer of stewardship of the FRACT Standard, we may share enquiry data with the relevant FRACT governance body or successor organisation where necessary to respond to your enquiry, subject to appropriate safeguards.

Legal and regulatory. We may disclose personal data where we are required to do so by law, by a court, or by a regulator, or to establish, exercise or defend legal rights.

Business transfers. If our business or assets (including the Website) are transferred to another organisation, personal data may be transferred as part of that arrangement.

7. International transfers

7.1 We aim to keep your personal data within the United Kingdom. Where a transfer outside the UK does take place, we will ensure an appropriate safeguard is in place, such as the UK’s adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. You can ask us for more information about the safeguards we use.

8. Cookies and similar technologies

8.1 Cookies are small text files placed on your device when you visit a website. Some cookies are strictly necessary for the Website to work; others help us understand how the Website is used or provide additional functionality. Under PECR, we can place strictly necessary cookies without your consent, but we will place non-essential cookies (such as analytics or marketing cookies) only where you have given your consent.

8.2 We use the following categories of cookies, in line with the categories shown in our cookie consent tool:

Necessary cookies, which are required for the Website to function and cannot be switched off (for example, cookies that remember your cookie consent choices).

Analytics cookies (such as Google Analytics), which help us understand how visitors use the Website so we can improve it. These are only set with your consent.

Functional, performance, and advertising cookies. We do not currently use cookies in these categories. If this changes, they will only be set with your consent, obtained through our cookie banner.

8.3 A full, up-to-date list of the specific cookies used on the Website — including their name, provider, purpose, and duration — is available at any time by clicking the cookie icon in the bottom-left corner of the Website and selecting “Customize”/”Preferences”. This list reflects the cookies currently in use on the Website and may change from time to time.

8.4 You can view, accept, reject, or change your cookie preferences at any time via the same cookie icon. You can also control cookies through your browser settings; however, blocking some cookies may affect how the Website works. For general information about cookies, see the ICO’s guidance at ico.org.uk.

9. How long we keep your personal data

9.1 We keep your personal data only for as long as we need it for the purposes set out in this Notice, including to satisfy any legal, accounting or reporting requirements.

9.2 In general: enquiry and contact data is kept for up to 2 years after our last contact with you, unless we need to keep it longer to deal with an ongoing matter or to comply with a legal obligation; and technical, usage and cookie data is kept for the periods shown in the cookie banner referred to in Section 8, which do not exceed 13 months. Server access logs maintained by our hosting provider are retained in line with their own retention policy. When we no longer need personal data, we will securely delete or anonymise it.

10. How we protect your personal data

10.1 We have put in place appropriate technical and organisational measures to protect your personal data against accidental or unlawful loss, access, alteration or disclosure. We also limit access to your personal data to those who have a genuine business need to access it. Where we use third-party service providers, we require them to maintain appropriate security measures.

11. Your rights

11.1 Under data protection law, you have the following rights in relation to your personal data:

Right to be informed – to be told how we use your personal data (which is the purpose of this Notice).

Right of access – to request a copy of the personal data we hold about you.

Right to rectification – to ask us to correct personal data that is inaccurate or incomplete.

Right to erasure – to ask us to delete your personal data in certain circumstances.

Right to restrict processing – to ask us to limit how we use your personal data in certain circumstances.

Right to data portability – to ask us to transfer certain personal data to you or another organisation in certain circumstances.

Right to object – to object to our processing of your personal data where we rely on legitimate interests, and to object to direct marketing at any time.

Right to withdraw consent – where we rely on your consent, to withdraw it at any time.

Rights relating to automated decision-making – we do not carry out any automated decision-making or profiling that produces legal or similarly significant effects through the Website.

11.2 To exercise any of these rights, please contact us at dpo@faceprotect.co.uk. We will respond within the time limits set by law (usually one month). We will not normally charge a fee, and we may need to verify your identity before we act on your request.

12. How to complain

12.1 If you have any concerns about how we handle your personal data, please contact us first so that we can try to resolve the matter.

12.2 You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection. You can contact the ICO by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; by telephone on 0303 123 1113; or online at ico.org.uk.

13. Third-party links

13.1 The Website may contain links to other websites. This Notice does not apply to those websites, and we are not responsible for their content or privacy practices. We encourage you to read the privacy notice of every website you visit.

14. Changes to this Notice

14.1 We may update this Notice from time to time to reflect changes in our practices or in the law, including any change in the ownership or stewardship of the Website or the FRACT Standard. When we make changes, we will update the “last updated” date below and, where the changes are significant, we will take reasonable steps to bring them to your attention.

Last updated: 17 July 2026 • Version: 1.0