Categories of Personal Data We Collect
The Upgrader platform collects personal information in three broad categories: information provided directly by participants during account creation and use of the service; information received automatically as a result of platform interaction; and information obtained from third parties acting on behalf of the platform or the participant. Each category serves a defined operational purpose and remains subject to the retention and access controls documented within this policy.
| Category | Examples | Source |
|---|---|---|
| Account information | Steam identifier, email address if provided | Direct from participant via Steam OpenID |
| Identity verification data | Government-issued identification, address proof | Direct from participant when KYC applies |
| Transaction records | Deposit and withdrawal history, upgrade activity | Automatic from platform interaction |
| Technical data | IP address, device identifier, session logs | Automatic from platform interaction |
| Payment metadata | Transaction reference, cryptocurrency address | Third-party payment processors |

Lawful Bases and Processing Purposes
Processing occurs under several lawful bases recognised by applicable data protection frameworks. Contractual necessity supports processing required to operate the participant account, execute deposits and withdrawals, and deliver the upgrader service. Legal obligation covers processing associated with anti-money-laundering compliance, tax reporting, and cooperation with lawful requests from competent authorities. Legitimate interest applies to fraud prevention, service improvement, and security monitoring. Where none of the above apply, processing occurs on the basis of participant consent, which may be withdrawn at any time through the account settings interface without affecting the lawfulness of prior processing.

Sharing With Third Parties
Personal information may be shared with a limited set of third parties strictly for the purposes described in this policy. Payment processors receive the minimum information necessary to complete deposits and withdrawals. Identity verification providers process KYC documentation on behalf of the platform under formal data processing agreements. Cloud infrastructure providers host operational systems. Legal or regulatory authorities may receive information where a valid request compels disclosure. Personal information is not sold to any third party under any circumstances.
Every third-party recipient operates under contractual obligations that restrict their use of participant information to the specific purpose for which it was disclosed. Onward transfers to further parties are permitted only where the original purpose could not otherwise be satisfied and where equivalent protections apply at the recipient's end.

Retention Periods
Records are retained only for as long as necessary to fulfil the purpose for which they were collected, or as required by applicable law. Account information persists for the active life of the account and for a defined period thereafter to permit reactivation. Transaction and KYC records are retained for the period mandated by anti-money-laundering legislation applicable to the platform. Technical logs are retained for the shortest period consistent with security monitoring and incident investigation requirements. Upon expiry of the applicable retention period, records are either deleted or irreversibly anonymised.
Rights Available to Participants
Data protection frameworks applicable to Upgrader participants grant several rights over personal information held about them. These rights may be exercised by contacting the platform through the channels described in the contact section of this policy.
- Right to access the personal information held about the participant
- Right to rectification of inaccurate or incomplete records
- Right to erasure where continued processing is no longer justified
- Right to restriction of processing under specified circumstances
- Right to data portability in a machine-readable format
- Right to object to processing based on legitimate interest
- Right to withdraw consent where processing is based on consent
Requests are processed within the timeframes specified by applicable law, typically within thirty days from the date of receipt. Verification of the requester's identity is required before information is released to protect against fraudulent access.
Security, International Transfers, and Cookies
Technical and organisational measures are implemented to protect personal information against unauthorised access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, access controls limiting internal availability, and monitoring of system activity for anomalies. International transfers occur only where the destination jurisdiction provides an adequate level of protection or where appropriate safeguards such as standard contractual clauses are in place. Cookies and comparable technologies are used to maintain session state, remember participant preferences, and support security functions. Non-essential cookies operate only where consent has been provided through the cookie interface.
Contact and Regulatory Recourse
Enquiries relating to this privacy policy and requests to exercise data protection rights should be directed to the contact page maintained by the platform. Where a response is considered unsatisfactory, participants may lodge a complaint with the national supervisory authority responsible for data protection in their jurisdiction of residence. A list of national supervisory authorities is maintained by the relevant international associations and can be consulted for the appropriate point of contact.







