Privacy Policy
This notice explains what personal data ATOMICKEYS LTD collects when you visit atomickeys.com or buy from us, why we collect it, who we share it with, how long we keep it, and the rights you have over it under the UK GDPR and the Data Protection Act 2018.
Who is responsible for your data
ATOMICKEYS LTD is the data controller for the personal data described in this notice. That means we decide why and how it is processed, and we are accountable for it.
- Controller
- ATOMICKEYS LTD
- Company number
- 17384807 (England and Wales)
- Registered office
- 167–169 Great Portland Street, 5th Floor, London, England, W1W 5PF
- Privacy contact
- privacy@atomickeys.com
- Website
- atomickeys.com
We are not required to appoint a statutory Data Protection Officer, but a named member of our team is responsible for data protection and can be reached at the address above.
The short version
- We collect what we need to sell you a digital key and to stop fraud — not more.
- We never sell your personal data, and we do not share it for anyone else’s advertising.
- Your card details are handled by our payment provider. We never see or store your full card number.
- We currently run no advertising trackers and no third-party analytics on the Site.
- You can ask for a copy of your data, or ask us to delete it, at any time.
The rest of this notice sets out the detail. If anything is unclear, email privacy@atomickeys.com and we will explain it in plain language.
What personal data we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Identity data | First and last name; the username on your account | You, at checkout or registration |
| Contact data | Email address; billing address; telephone number if you give it | You |
| Order data | Products ordered; order number and date; price paid; currency; keys issued to you; invoices | Generated when you buy |
| Payment data | Payment method type, last four digits, authorisation result, transaction reference. We do not receive or store your full card number, expiry date or security code. | Our payment provider |
| Account data | Password (stored only as a salted hash); order history; wishlist; saved addresses; email preferences | You and your activity |
| Technical data | IP address; browser type and version; operating system; device type; time zone; approximate country derived from IP | Collected automatically |
| Usage data | Pages viewed; products viewed; basket contents; how you reached the Site | Collected automatically |
| Security data | Login attempts, blocked requests, bot-check results, fraud-screening scores and flags | Our security and anti-fraud tools |
| Communications data | Emails, contact-form messages, support tickets and our replies | You |
| Marketing data | Whether you have opted in to our emails, and whether you have opened or clicked them | You and your interaction |
Data we do not collect
We do not deliberately collect special category data (such as data about health, race, religion, politics, sexual orientation or trade union membership), and we ask you not to send it to us. We do not collect criminal offence data. We do not knowingly collect data from children — see Children.
Why we use it and our lawful basis
Under the UK GDPR we must have a lawful basis for each use of your data. Ours are set out below.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and managing your account | Identity, contact, account | Performance of a contract |
| Taking payment and issuing your key | Identity, contact, order, payment | Performance of a contract |
| Sending order confirmations, keys and invoices | Identity, contact, order | Performance of a contract |
| Handling refunds, replacements and support requests | Identity, contact, order, communications | Performance of a contract; legal obligation |
| Preventing fraud, chargeback abuse and key reselling | Identity, payment, technical, security | Legitimate interests (protecting our business and honest customers); legal obligation |
| Keeping the Site secure and available | Technical, security | Legitimate interests (network and information security) |
| Meeting tax, accounting and company-law duties | Identity, contact, order, payment | Legal obligation |
| Showing prices and availability for your region | Technical (approximate country from IP) | Legitimate interests (relevant shopping experience) |
| Sending marketing emails about offers and new releases | Identity, contact, marketing | Consent, or legitimate interests under the soft opt-in for existing customers |
| Improving the Site and our product range | Usage, order (aggregated where possible) | Legitimate interests (running and improving our business) |
| Establishing, exercising or defending legal claims | Any relevant category | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment to satisfy ourselves that our interests do not override your rights and freedoms. You can ask us for a summary of that assessment at any time, and you have the right to object — see Your rights.
Marketing communications
We will only send you marketing emails where you have opted in, or where you have bought from us before and we are marketing similar products under the soft opt-in permitted by the Privacy and Electronic Communications Regulations 2003.
Every marketing email contains a one-click unsubscribe link. You can also opt out at any time by emailing privacy@atomickeys.com or by changing your preferences in your account.
Opting out of marketing does not stop service messages — order confirmations, key delivery, invoices, refund notices and security alerts. We must send those to fulfil the contract with you.
International transfers
Our servers are located within Europe. Some of our suppliers, however, operate globally, which means your data may be transferred outside the United Kingdom or the European Economic Area.
Where that happens, we make sure at least one of the following safeguards is in place:
- the country has been found by the UK government or the European Commission to provide an adequate level of protection;
- the transfer is covered by the International Data Transfer Agreement, the UK Addendum, or the EU Standard Contractual Clauses; or
- the recipient is certified under an approved framework such as the UK Extension to the EU–US Data Privacy Framework.
You may request a copy of the safeguards we rely on by writing to privacy@atomickeys.com.
How long we keep it
We keep personal data only for as long as we need it for the purpose we collected it for, plus any period we are required to keep it by law.
| Record | Retention period | Why |
|---|---|---|
| Order records, invoices and payment records | 7 years from the end of the relevant tax year | UK tax and accounting requirements |
| Account data for an active account | For as long as the account remains open | To provide the service |
| Account data after closure | Deleted or anonymised within 12 months, apart from records we must retain for tax | No longer needed |
| Dormant accounts with no orders | Reviewed and deleted after 3 years of inactivity | Data minimisation |
| Support and complaint correspondence | 3 years from resolution (6 years where a dispute arises) | Service quality and limitation periods |
| Marketing consent and opt-out records | Until you withdraw consent; opt-out records kept indefinitely | To honour your choice and evidence compliance |
| Fraud and chargeback records | 6 years | Fraud prevention and defence of claims |
| Server and security logs | Typically 30–90 days | Security monitoring |
Where data is no longer needed but cannot easily be deleted from backups, we isolate it and stop actively using it until deletion is possible.
How we protect your data
We take appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, including:
- encryption of all traffic in transit using TLS;
- passwords stored only as salted hashes, never in readable form;
- a web application firewall and malware scanning on the Site;
- bot protection and rate limiting on login and checkout;
- a hidden administrator login path and restricted administrative access;
- role-based access, so staff see only the data they need;
- regular software and security updates, and monitored server backups.
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours of becoming aware of it and, where the risk is high, notify you directly without undue delay.
Fraud screening and automated decisions
Because digital keys are delivered instantly and cannot be recovered once issued, orders are screened automatically for signs of fraud. The screening considers factors such as the country of the IP address compared with the billing address, the payment result, order value and patterns of previous activity.
A high-risk score may cause an order to be held for manual review or cancelled and refunded. Where a decision has a significant effect on you and is made solely by automated means, you have the right to ask for human review, to express your point of view and to contest the decision. Email privacy@atomickeys.com quoting your order number and a member of our team will look at it personally.
We do not carry out profiling for advertising purposes.
Your rights
Under the UK GDPR you have the following rights. They are free to exercise.
| Right | What it lets you do |
|---|---|
| Access | Get confirmation that we hold data about you and receive a copy of it |
| Rectification | Have inaccurate data corrected and incomplete data completed |
| Erasure | Ask us to delete your data where we no longer have a good reason to keep it |
| Restriction | Ask us to pause processing while a dispute about accuracy or legitimate interests is resolved |
| Portability | Receive the data you gave us in a structured, machine-readable format, or have it sent to another controller |
| Object | Object to processing based on legitimate interests, and object to direct marketing at any time (this one is absolute) |
| Withdraw consent | Withdraw consent where we rely on it, without affecting processing already carried out |
| Human review | Ask for a human decision where an automated one has significantly affected you |
| Complain | Lodge a complaint with a supervisory authority |
How to exercise them
Email privacy@atomickeys.com with the subject line “Data rights request”, telling us which right you want to use and, where relevant, which data you mean.
- We will respond within one month. If your request is complex we may extend this by up to two further months and will tell you why within the first month.
- We may ask for information to confirm your identity. This protects your data from being disclosed to someone else.
- Requests are free. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if so.
Some rights are not absolute. For example, we may be unable to erase order and invoice data that we are legally required to keep for tax purposes. Where we cannot fully meet a request, we will tell you why and do as much as we lawfully can.
Children
The Site is not directed at children. You must be at least 18 to buy from us, or 16 or 17 with the consent of a parent or guardian.
We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact privacy@atomickeys.com and we will delete it promptly.
Links to other sites
The Site links to third-party platforms such as Steam, Epic Games Store and publisher websites. Those services have their own privacy policies and we are not responsible for how they handle your data. Please read their notices before providing personal data to them.
Changes to this notice
We review this notice regularly and will update it when our processing changes or the law requires it. The current version is always published on this page and the “last updated” date at the top shows when it last changed.
Where a change is significant — for example a new purpose for your data, or a new category of recipient — we will bring it to your attention by email or by a prominent notice on the Site before it takes effect.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first at privacy@atomickeys.com. We take privacy complaints seriously and aim to resolve them quickly. Our escalation process is set out in the Complaints Policy.
You also have the right to complain to the supervisory authority at any time.
- Authority
- Information Commissioner’s Office (ICO)
- Address
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
- Helpline
- 0303 123 1113
- Website
- ico.org.uk/make-a-complaint
If you live in the European Economic Area, you may instead complain to the data protection authority in your country of residence.
Contact us about privacy
- privacy@atomickeys.com
- Post
- Data Protection, ATOMICKEYS LTD, 167–169 Great Portland Street, 5th Floor, London, England, W1W 5PF
- General support
- info@atomickeys.com
Document control. Privacy Policy, version 2.0, published 25 August 2026 by ATOMICKEYS LTD (company number 17384807). Prepared in accordance with the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003.
