GDPR - Your Data Protection Rights

Placeholder content - have this reviewed by qualified legal counsel for your jurisdiction before launch.

If you're located in the European Union, the United Kingdom, or another jurisdiction with similar data protection law, the General Data Protection Regulation (GDPR) and equivalent frameworks give you specific rights over your personal data beyond what's described generally in our Privacy Policy. This page explains those rights in the context of how Z2Deal actually works, rather than as abstract legal boilerplate.

The legal bases we rely on

We process your personal data under a few different legal bases depending on the purpose. Processing necessary to perform our contract with you - creating your account, processing an order, holding escrow, paying out a seller - relies on contractual necessity. Identity verification for sellers and certain withdrawals relies on legal obligation, since anti-money-laundering rules require it. Fraud prevention and basic security monitoring rely on our legitimate interest in keeping the Platform safe, balanced against your own privacy interests. Optional communications, like promotional announcements you can opt out of, rely on consent.

Your right to access

You can request a copy of the personal data we hold about you. Much of this is already visible directly in your account - order history, messages, listings if you're a seller - but if you want a more complete export including data not normally surfaced in the interface, contact us and we'll provide it within the timeframe required by applicable law.

Your right to rectification

If information we hold about you is inaccurate or incomplete, you can correct most of it yourself directly from your account settings - display name, country, language, and currency preference are all self-service. For anything that isn't editable directly in the interface (an error in your transaction history, for instance), contact us and we'll correct it where appropriate, though some financial records can't simply be deleted or rewritten after the fact due to our own record-keeping obligations - in those cases we'll add a correction note rather than altering the historical record itself.

Your right to erasure ("right to be forgotten")

You can request deletion of your personal data, and we'll honor this where we're not separately required to retain it. In practice this means: account profile information, messages, and browsing-related data can typically be deleted on request. Completed transaction records, however, often need to be retained for a period even after a deletion request, due to financial recordkeeping, tax, and anti-money-laundering obligations that don't disappear just because you've asked to close your account - in those cases, we'll anonymize what we can while retaining the minimum necessary for compliance.

Your right to restrict processing

You can ask us to pause certain processing of your data while a dispute about its accuracy or legitimacy is being resolved - for example, if you contest the legal basis for a particular use of your data. We'll restrict that specific processing while we look into your request, rather than continuing as normal in the meantime.

Your right to data portability

Where processing is based on consent or contract and carried out by automated means, you can request your data in a structured, commonly used, machine-readable format so you can transfer it elsewhere if you choose. This typically applies most cleanly to things like your order history and profile data, rather than internal records like fraud-review notes.

Your right to object

You can object to processing based on our legitimate interest - certain fraud-prevention or analytics processing, for example - and we'll stop unless we can demonstrate compelling legitimate grounds that override your objection, or where the processing is necessary for a legal claim. You can always object to direct marketing without needing to justify why; we'll simply stop sending it.

Automated decision-making

Some fraud-detection processes use automated signals to flag unusual activity for human review - an unusual login pattern, for instance. We don't make final account-suspension or withdrawal-denial decisions purely through automation without a human reviewing the case; automated flags trigger review, they don't trigger an irreversible outcome on their own.

How to exercise these rights

Contact us through our Contact page with "Data Protection Request" in the subject, specifying which right you're exercising and any relevant account details. We may need to verify your identity before acting on certain requests, to make sure we're not handing over or deleting someone else's data by mistake. We aim to respond within the timeframe required by applicable law, typically one month, extendable in genuinely complex cases with notice to you.

Your right to complain to a supervisory authority

If you believe we've mishandled your personal data and you're not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority, independent of any resolution attempt with us directly. We'd genuinely prefer the chance to fix a problem first, but this right exists regardless of whether you give us that chance.

Data Protection Officer / responsible contact

Depending on the scale of our processing, we may be required to designate a formal Data Protection Officer, or we may handle these responsibilities through a designated internal contact instead where the law permits it for an organization of our size. Either way, requests sent through our Contact page with "Data Protection Request" in the subject reach whoever is currently responsible for this area.

Special category data

We don't intentionally collect special category data (health information, religious beliefs, political opinions, and similar sensitive classifications) as part of normal platform use. The identity documents collected for seller verification may incidentally reveal certain characteristics depending on what a government ID happens to show, but we don't process that incidental information for any purpose beyond confirming identity, and we don't extract or analyze it separately.

Data Protection Impact Assessments

Where we introduce a new feature that involves higher-risk processing of personal data - a significant change to how identity verification works, for example - we assess the privacy impact before launch and adjust the design where the assessment identifies a meaningful risk that can reasonably be reduced. This isn't a one-time exercise; it's revisited whenever a feature touching personal data changes substantially.

Sub-processors and data sharing

We share data with a limited number of service providers necessary to operate the Platform - payment processors to handle transactions, identity verification services to process seller KYC documents, hosting providers to actually run the site. Each of these is bound by their own data protection obligations, and we choose providers who meet a reasonable standard of data protection rather than the cheapest option regardless of practice. We don't share your data with providers for purposes unrelated to running the Platform itself.

Last updated: July 2026