GDPR & Your Rights

Last updated: 12 March 2026

Draw Theory respects and upholds your rights under the General Data Protection Regulation (EU GDPR) and UK GDPR. This page explains those rights in plain English and how to exercise them.


Who This Applies To

These rights apply to all users of Draw Theory based in the European Economic Area (EEA) and the United Kingdom. Users in other regions may also have similar rights under their local privacy laws (e.g. CCPA in California).


Legal Basis for Processing

Where we process any personal data, we do so under the following legal bases:

We do not process special categories of personal data. We do not carry out automated decision-making or profiling with legal or similarly significant effects.


Your Rights Under GDPR

👁️
Right of Access (Article 15)

You have the right to request a copy of any personal data we hold about you. Given our minimal data collection, this will typically consist of server log entries (if any) associated with your IP address during your visit window.

✏️
Right to Rectification (Article 16)

If any personal data we hold is inaccurate or incomplete, you have the right to request it be corrected. Contact us at hello@drawtheory.com with the details.

🗑️
Right to Erasure / "Right to Be Forgotten" (Article 17)

You may request deletion of any personal data we hold about you. Server logs are automatically deleted after 30 days. We will action any manual deletion request within 30 days of receipt. Note: anonymised aggregate data (e.g. platform-wide ticket counts) cannot be erased as it contains no personal data.

⏸️
Right to Restriction of Processing (Article 18)

You may request that we restrict processing of your personal data in certain circumstances — for example, while you contest the accuracy of data or have objected to processing.

📦
Right to Data Portability (Article 20)

You have the right to receive any personal data you have provided to us in a structured, machine-readable format. Your saved lottery picks are already stored locally on your own device in localStorage — they are yours entirely and never transmitted to us.

Right to Object (Article 21)

You may object to processing of your personal data where we rely on legitimate interests as our legal basis. We will stop processing unless we can demonstrate compelling legitimate grounds that override your rights.

🤖
Rights Re: Automated Decision-Making (Article 22)

Draw Theory does not make automated decisions about individuals that produce legal or similarly significant effects. The AI pick feature generates lottery number suggestions for entertainment only — it does not affect your rights, eligibility for services, or any consequential decisions.


How to Exercise Your Rights

📧 Submit a Request

Email us at hello@drawtheory.com with the subject line "GDPR Request" and describe your request clearly. We will respond within 30 days. We may need to verify your identity before acting on the request.


Data Transfers Outside the UK/EEA

When you use the AI Pick feature, draw statistical data is sent to Anthropic's API (based in the United States). This transfer is made under standard contractual clauses and Anthropic's data processing terms. No personal data is included in these API calls — only aggregated draw history and statistical signals.

Google Fonts requests may also be processed by Google's servers outside the EEA. See Google's Privacy Policy for details.


Right to Lodge a Complaint

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with your national supervisory authority:

We would always prefer to resolve any concern directly — please contact us first at hello@drawtheory.com.


Data Protection Officer

Draw Theory is a small independent platform and is not required to appoint a formal Data Protection Officer under current thresholds. All data protection enquiries are handled directly by the platform operator. Contact: hello@drawtheory.com.


See also our full Privacy Policy and Terms & Conditions.