Privacy Policy
Version 1.0 — Last updated April 2026
1. Who We Are
Kamma Sangham UK (“KSUK”, “we”, “us”) operates the KSUK Prize Draw. We are the data controller responsible for your personal data collected through this service.
2. Data We Collect
When you enter the prize draw, we collect the following personal information:
- First name and last name — to identify your entry and announce winners
- Email address — to communicate entry confirmation, draw results, and prize notifications
- Phone number — to contact you if you win a prize
- Payment reference — to match your bank transfer to your entry
3. Legal Basis for Processing
We process your personal data on the following legal bases under the UK GDPR:
- Contract: Processing is necessary to administer your entry in the prize draw, including payment verification and prize distribution.
- Consent: You provide explicit consent when accepting these terms during entry. You may withdraw consent at any time by contacting us.
- Legitimate interest: We may use aggregated, anonymised data to improve the prize draw experience.
4. How We Use Your Data
Your personal data is used to:
- Process and confirm your prize draw entry
- Match bank transfer payments to entries
- Notify you of draw results and prize winnings
- Display winner names at community events and on the website
- Comply with legal and regulatory obligations
5. Data Sharing
We do not sell, rent, or trade your personal data. Your data may be shared with:
- Supabase (data hosting): Our database is hosted on Supabase infrastructure in the EU region, with encryption at rest and in transit.
- Vercel (website hosting):Pages are served via Vercel’s edge network. No personal data is stored by Vercel.
6. Data Retention
We retain your personal data as follows:
- Entry data: Retained for 12 months after the draw date for audit and dispute resolution purposes, then anonymised or deleted.
- Winner data: Winner names may be retained indefinitely for historical records of community events.
- Account data: If you request deletion, we will remove your personal data within 30 days, except where retention is required by law.
7. Your Rights
Under the UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate data
- Erasure— request deletion of your data (“right to be forgotten”)
- Restriction — request limitation of processing
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interest
To exercise any of these rights, contact us at prizedraw@ksuk.uk. We will respond within 30 days.
8. Cookies
This website uses essential cookies only, required for authentication and session management. We do not use tracking cookies, analytics cookies, or third-party advertising cookies.
9. Security
We take appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest (database-level encryption)
- Row-Level Security (RLS) policies restricting data access
- Admin-only access to personal data via authenticated server actions
10. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via the website. The version number and date at the top of this page indicate when the policy was last updated.
11. Complaints
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
12. Contact
For questions about this privacy policy or your personal data, contact us at prizedraw@ksuk.uk.