DATA PROTECTION POLICY

SHINECODING LTD

12A Goldhurst Terrace, NW6 3HU, London, United Kingdom

Last Updated: April 26, 2026

1. PURPOSE

This Data Protection Policy describes how SHINECODING LTD processes personal information in compliance with UK GDPR and Data Protection Act 2018. This policy is provided for transparency and regulatory compliance purposes.

2. DATA PROTECTION PRINCIPLES

SHINECODING LTD operates under the following data protection framework:

1. Lawfulness and Fairness

Processing occurs only where a legal basis exists; transparency requirements are met as outlined in this policy.

2. Purpose Limitation

Data is processed for specified service delivery purposes only; secondary uses require separate legal basis.

3. Data Minimization

Collection is limited to data necessary for service operations.

4. Accuracy

Data accuracy is maintained; you are responsible for providing accurate information.

5. Storage Limitation

Retention periods are determined by legal requirements and service necessity.

6. Integrity and Confidentiality

Technical and organizational security measures are implemented; however, no system is completely secure.

7. Accountability

Processing activities are documented internally.

3. SECURITY MEASURES

SHINECODING LTD implements security measures including:

  • Encryption of data in transit and at rest using industry-standard methods
  • Role-based access controls and principle of least privilege
  • Regular security assessments and testing
  • Staff training on data protection protocols
  • Secure data deletion procedures
  • Incident response procedures

SHINECODING LTD is not liable for unauthorized access resulting from user negligence, weak passwords, or failure to secure account credentials. You are solely responsible for maintaining password confidentiality.

Data breaches resulting from circumstances beyond reasonable control (natural disasters, sophisticated cyberattacks, force majeure) are excluded from liability except where gross negligence by SHINECODING LTD is proven.

4. THIRD-PARTY PROCESSORS

SHINECODING LTD engages third parties for service delivery:

  • Apple, Google, Stripe (payment processing)
  • AWS, Google Cloud (hosting and infrastructure)
  • Google Analytics (analytics)

All third parties are bound by Data Processing Agreements requiring data protection obligations. SHINECODING LTD remains liable for processor compliance with GDPR.

4.1 Artificial Intelligence Model Training

SHINECODING LTD maintains proprietary artificial intelligence models that are trained on data collected from SnapQuest users. AI processing is conducted as follows:

Processing Purpose:

  • Personalizing user experience
  • Recommending quests tailored to individual preferences and abilities
  • Improving service quality and performance

Data Processing:

  • Your quest participation history, snap submissions, profile information, and usage patterns are used as input to train and improve our AI models
  • AI processing occurs on SHINECODING LTD's own systems and infrastructure

Legal Basis:

AI model training is based on legitimate interests in improving SnapQuest.

You have the right to object to this processing at any time by contacting admin@snapquest.uk.

5. DATA SUBJECT RIGHTS

You have rights under UK GDPR:

Right of Access

You can request a copy of your personal data. Contact admin@snapquest.uk.

Right to Rectification

You can request corrections to inaccurate data.

Right to Erasure

You can request deletion of your data, subject to legal retention requirements (financial records retained 6 years, settlement records retained 6 years, smart contract data permanent).

Right to Restrict Processing

You can request that we limit how we use your data.

Right to Data Portability

You can request your data in a portable format.

Right to Object

You can object to processing based on legitimate interests.

Automated Decision-Making

You have rights regarding decisions based solely on automated processing.

All requests should be sent to admin@snapquest.uk. We will respond within 30 days.

6. DATA BREACHES

SHINECODING LTD will notify the Information Commissioner's Office (ICO) within 72 hours if a breach poses risk to individual rights. Affected individuals will be notified without undue delay where high risk is identified.

You acknowledge that data loss may occur due to circumstances beyond reasonable control. SHINECODING LTD is not liable for losses from events such as natural disasters, cyberattacks, or force majeure unless gross negligence is proven.

7. INTERNATIONAL TRANSFERS

Personal data may be transferred to and processed in countries outside the UK, including by cloud providers and payment processors. Transfers are authorized under UK GDPR Article 46 (Adequacy Decisions or Standard Contractual Clauses). By using SnapQuest, you consent to such transfers.

8. LEGITIMATE INTERESTS ASSESSMENT

SHINECODING LTD has assessed that its legitimate interests in operating SnapQuest, improving services, and detecting fraud are not overridden by individual privacy rights. This assessment is documented internally and updated periodically.

9. CONSENT-BASED PROCESSING

Where consent is the legal basis (such as marketing communications), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.

10. DATA RETENTION

SHINECODING LTD retains personal data as follows:

  • Account data: Duration of account plus 3 years for legal compliance
  • Financial records: 6 years as required by UK tax law
  • Quest settlement records: 6 years for financial compliance and dispute resolution
  • Anonymized data: Indefinitely for analytics and service improvement
  • Smart Contract data: Indefinitely (immutable public record)
  • Data subject to legal holds: Until legal proceedings conclude

Upon account deletion, personal identifiers are removed; anonymized transaction data may be retained indefinitely for analytics and reporting.

11. GOVERNANCE

SHINECODING LTD designates a Data Protection Lead (admin@snapquest.uk) responsible for:

  • GDPR compliance monitoring
  • Data subject requests handling
  • Breach investigation and response
  • Data Protection Impact Assessments (DPIAs)

DPIAs are conducted for:

  • AI model training and deployment
  • New large-scale data collection initiatives
  • New third-party processor integration
  • Changes to data retention or transfer practices

12. CONTACT

For data subject requests or policy questions:

Email: admin@snapquest.uk

Address: SHINECODING LTD, 12A Goldhurst Terrace, NW6 3HU, London, United Kingdom

Complaints may be lodged with the Information Commissioner's Office (ICO):

Website: https://ico.org.uk