DATA PROTECTION POLICY
SHINECODING LTD
12A Goldhurst Terrace, NW6 3HU, London, United Kingdom
Last Updated: April 26, 2026
1. PURPOSE
This Data Protection Policy describes how SHINECODING LTD processes personal information in compliance with UK GDPR and Data Protection Act 2018. This policy is provided for transparency and regulatory compliance purposes.
2. DATA PROTECTION PRINCIPLES
SHINECODING LTD operates under the following data protection framework:
1. Lawfulness and Fairness
Processing occurs only where a legal basis exists; transparency requirements are met as outlined in this policy.
2. Purpose Limitation
Data is processed for specified service delivery purposes only; secondary uses require separate legal basis.
3. Data Minimization
Collection is limited to data necessary for service operations.
4. Accuracy
Data accuracy is maintained; you are responsible for providing accurate information.
5. Storage Limitation
Retention periods are determined by legal requirements and service necessity.
6. Integrity and Confidentiality
Technical and organizational security measures are implemented; however, no system is completely secure.
7. Accountability
Processing activities are documented internally.
3. SECURITY MEASURES
SHINECODING LTD implements security measures including:
- Encryption of data in transit and at rest using industry-standard methods
- Role-based access controls and principle of least privilege
- Regular security assessments and testing
- Staff training on data protection protocols
- Secure data deletion procedures
- Incident response procedures
SHINECODING LTD is not liable for unauthorized access resulting from user negligence, weak passwords, or failure to secure account credentials. You are solely responsible for maintaining password confidentiality.
Data breaches resulting from circumstances beyond reasonable control (natural disasters, sophisticated cyberattacks, force majeure) are excluded from liability except where gross negligence by SHINECODING LTD is proven.
4. THIRD-PARTY PROCESSORS
SHINECODING LTD engages third parties for service delivery:
- Apple, Google, Stripe (payment processing)
- AWS, Google Cloud (hosting and infrastructure)
- Google Analytics (analytics)
All third parties are bound by Data Processing Agreements requiring data protection obligations. SHINECODING LTD remains liable for processor compliance with GDPR.
4.1 Artificial Intelligence Model Training
SHINECODING LTD maintains proprietary artificial intelligence models that are trained on data collected from SnapQuest users. AI processing is conducted as follows:
Processing Purpose:
- Personalizing user experience
- Recommending quests tailored to individual preferences and abilities
- Improving service quality and performance
Data Processing:
- Your quest participation history, snap submissions, profile information, and usage patterns are used as input to train and improve our AI models
- AI processing occurs on SHINECODING LTD's own systems and infrastructure
Legal Basis:
AI model training is based on legitimate interests in improving SnapQuest.
You have the right to object to this processing at any time by contacting admin@snapquest.uk.
5. DATA SUBJECT RIGHTS
You have rights under UK GDPR:
Right of Access
You can request a copy of your personal data. Contact admin@snapquest.uk.
Right to Rectification
You can request corrections to inaccurate data.
Right to Erasure
You can request deletion of your data, subject to legal retention requirements (financial records retained 6 years, settlement records retained 6 years, smart contract data permanent).
Right to Restrict Processing
You can request that we limit how we use your data.
Right to Data Portability
You can request your data in a portable format.
Right to Object
You can object to processing based on legitimate interests.
Automated Decision-Making
You have rights regarding decisions based solely on automated processing.
All requests should be sent to admin@snapquest.uk. We will respond within 30 days.
6. DATA BREACHES
SHINECODING LTD will notify the Information Commissioner's Office (ICO) within 72 hours if a breach poses risk to individual rights. Affected individuals will be notified without undue delay where high risk is identified.
You acknowledge that data loss may occur due to circumstances beyond reasonable control. SHINECODING LTD is not liable for losses from events such as natural disasters, cyberattacks, or force majeure unless gross negligence is proven.
7. INTERNATIONAL TRANSFERS
Personal data may be transferred to and processed in countries outside the UK, including by cloud providers and payment processors. Transfers are authorized under UK GDPR Article 46 (Adequacy Decisions or Standard Contractual Clauses). By using SnapQuest, you consent to such transfers.
8. LEGITIMATE INTERESTS ASSESSMENT
SHINECODING LTD has assessed that its legitimate interests in operating SnapQuest, improving services, and detecting fraud are not overridden by individual privacy rights. This assessment is documented internally and updated periodically.
9. CONSENT-BASED PROCESSING
Where consent is the legal basis (such as marketing communications), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
10. DATA RETENTION
SHINECODING LTD retains personal data as follows:
- Account data: Duration of account plus 3 years for legal compliance
- Financial records: 6 years as required by UK tax law
- Quest settlement records: 6 years for financial compliance and dispute resolution
- Anonymized data: Indefinitely for analytics and service improvement
- Smart Contract data: Indefinitely (immutable public record)
- Data subject to legal holds: Until legal proceedings conclude
Upon account deletion, personal identifiers are removed; anonymized transaction data may be retained indefinitely for analytics and reporting.
11. GOVERNANCE
SHINECODING LTD designates a Data Protection Lead (admin@snapquest.uk) responsible for:
- GDPR compliance monitoring
- Data subject requests handling
- Breach investigation and response
- Data Protection Impact Assessments (DPIAs)
DPIAs are conducted for:
- AI model training and deployment
- New large-scale data collection initiatives
- New third-party processor integration
- Changes to data retention or transfer practices
12. CONTACT
For data subject requests or policy questions:
Email: admin@snapquest.uk
Address: SHINECODING LTD, 12A Goldhurst Terrace, NW6 3HU, London, United Kingdom
Complaints may be lodged with the Information Commissioner's Office (ICO):
Website: https://ico.org.uk