Compliance & Data Protection

At 24Lottos, protecting user data and communicating responsibly are core parts of how our service operates. This page explains, in clear terms, how we comply with applicable data protection and email communication laws, including the EU General Data Protection Regulation (GDPR) and the U.S. CAN-SPAM Act.

This page is intended to be read together with our Privacy Policy and Terms & Conditions, which set out the legal framework governing your use of our services.

Our Role and Responsibility

24Lottos operates as a lottery messenger service, purchasing lottery tickets on behalf of users based on their instructions. In order to deliver this service, we must collect and process certain personal data.

For data protection purposes, 24Lottos acts as a data controller for information collected through our website and services. We process personal data only to the extent necessary to provide our services, comply with legal obligations, and maintain the security and integrity of our platform.

What Personal Data We Process

Depending on how you use our services, we may process the following categories of data:

  • Account information such as email address, username, and login credentials
  • Transaction and payment-related information required to purchase tickets and process winnings
  • Identity and verification information when required by lottery operators, insurers, or legal authorities
  • Technical data such as IP address, browser type, device information, and usage logs
  • Communication data when you contact our support team or receive service-related notifications

We do not collect personal data that is unnecessary for service delivery or legal compliance.

Legal Basis for Processing (GDPR)

Under GDPR, personal data must be processed on a lawful basis. Depending on the context, 24Lottos processes personal data under one or more of the following legal grounds:

  • Performance of a contract—to purchase lottery tickets, manage accounts, notify users of results, and process winnings
  • Consent—where users choose to receive marketing communications or optional updates
  • Legal obligations—including tax, anti-fraud, identity verification, and regulatory requirements
  • Legitimate interests—such as service security, fraud prevention, customer support, and service improvement

Where consent is required, it can be withdrawn at any time.

Email Communications and CAN-SPAM Compliance

24Lottos sends different types of emails, each governed by clear rules:

Transactional emails

These are essential for service delivery and may include:

  • Ticket purchase confirmations
  • Draw results and winning notifications
  • Account, security, and withdrawal updates
  • Requests for verification or documentation

Transactional emails are sent regardless of marketing preferences, as they are required to provide the service.

Marketing and promotional emails

These may include information about new services, offers, or updates. Marketing emails:

  • Are sent only to users who have provided consent or have an existing customer relationship
  • Always identify 24Lottos as the sender
  • Include a clear and functional unsubscribe option
  • Honor unsubscribe requests promptly

24Lottos does not sell, rent, or purchase email lists and does not send unsolicited bulk emails.

Managing Your Preferences and Rights

Users have full control over their personal data and communication preferences.

You may:

  • Access or update your account information
  • Withdraw consent for marketing communications
  • Request a copy of the personal data we hold about you
  • Request correction or deletion of your personal data
  • Object to certain types of processing
  • Request restriction or portability of your data

Requests can be made by contacting our support or privacy team using the details listed below.

Data Retention

Personal data is retained only for as long as necessary to:

  • Provide the requested services
  • Comply with legal, tax, and regulatory obligations
  • Resolve disputes and enforce agreements

Retention periods may vary depending on the type of data and applicable legal requirements. Data that is no longer required is securely deleted or anonymized.

Data Security Measures

24Lottos uses industry-standard security measures to protect personal data, including:

  • Encrypted connections (HTTPS/SSL)
  • Restricted internal access to personal information
  • Secure payment and processing partners
  • Regular review of access controls and system integrity

While no system can guarantee absolute security, we take reasonable and appropriate measures to safeguard user data.

Third-Party Service Providers and International Processing

To operate our services, we work with trusted third-party providers such as payment processors, email delivery services, hosting providers, and insurance partners.

Where personal data is processed outside the user’s country of residence, we ensure that appropriate safeguards are in place in accordance with applicable data protection laws.

Third-party providers are permitted to process personal data only for the purposes specified by 24Lottos and in accordance with contractual and legal obligations.

Children’s Data

24Lottos services are intended only for users aged 18 and above. We do not knowingly collect or process personal data from children.

Contact and Privacy Requests

For questions about data protection, privacy rights, or this compliance information, you can contact us via the details provided on our Contact Us page.

Privacy-related requests will be handled promptly and in accordance with applicable law.

Updates to This Page

We may update this Compliance Resources page from time to time to reflect legal, regulatory, or operational changes. The latest version will always be available on our website.