Privacy Policy

Last updated: 9 July 2026

This Privacy Policy explains how Jammy Limited (company number 15558191) of 128 City Road, London EC1V 2NX (“we”, “us”, “our”) collects, uses and protects personal data in connection with the random number generator service made available at www.purerandom.com (the “Service”).

We are the data controller in respect of the personal data described in this Policy. This Policy should be read together with our Terms & Conditions.

AT A GLANCE
  • We collect only what we need to operate, secure and support the Service.
  • We do not sell your personal data, and we do not use it for advertising.
  • Data is hosted on Amazon Web Services (AWS) infrastructure located in the United Kingdom.
  • We use privacy-friendly, cookieless analytics.
  • You have rights over your personal data, including access, correction and erasure.
  1. Who we are and how to contact us

    1. Data controller
    2. Jammy Limited is the data controller for personal data processed through the Service.
    3. Contact
    4. If you have any questions about this Policy, or wish to exercise any of your rights, you can contact us at mail@purerandom.com or by writing to us at 128 City Road, London EC1V 2NX.
    5. Regulator
    6. We are registered with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, under registration number CSN8005360.
  2. Who this Policy applies to

    1. Business users
    2. The Service is made available to business users only, as set out in our Terms & Conditions. This Policy nevertheless applies to personal data relating to identifiable individuals who use the Service, including individuals acting on behalf of a business.
    3. Age
    4. The Service is not intended for, and must not be used by, anyone under the age of 18. We do not knowingly collect personal data relating to children.
  3. Personal data we collect

    1. Data you provide to us
    2. When you create an account, we collect your email address. If you contact us, we collect the contact details and any information you choose to include in your message.
    3. Data collected automatically when you use the Service
    4. When you access the Service, we automatically collect technical information, including your IP address, browser and device information (user agent), the date and time of your requests, the pages or endpoints accessed, and the response status and timing of those requests.
    5. Account and authentication data
    6. Where you hold an account, we process a unique account identifier assigned to you by our authentication provider, together with your account status and any attributes we assign to your account (for example, a display name associated with your organisation).
    7. Draw and usage data
    8. Where you hold an account, we store a record of the draws you generate through the Service, including the parameters you selected, the results produced, and the associated audit identifier, linked to your account identifier.
    9. Audit records
    10. Every draw generated by the Service is recorded in an immutable audit record for the purposes of independent verification and certification integrity. Audit records include the draw parameters, the result, a timestamp and a unique audit identifier. Audit records generated by anonymous use of the Service are not linked to any individual.
    11. Analytics data
    12. We use privacy-friendly analytics to understand aggregate usage of the Service. This is described in clause 7.
  4. How and why we use your personal data

    1. We process personal data for the following purposes, on the following lawful bases under the UK GDPR:
    Providing the ServiceTo operate the Service, authenticate you, and make your draw history available to you. Lawful basis: performance of a contract, and/or our legitimate interests in operating the Service.
    Security and abuse preventionTo protect the Service against misuse, fraud, abuse and unauthorised access, to apply rate limits, and to investigate suspected misuse. Lawful basis: our legitimate interests in securing the Service and protecting our users and infrastructure.
    Audit and certification integrityTo maintain an immutable, independently verifiable record of every draw, as required by our certification and by the verifiable nature of the Service. Lawful basis: our legitimate interests, and compliance with our certification obligations.
    Troubleshooting and supportTo diagnose faults, respond to support requests and improve reliability. Lawful basis: our legitimate interests.
    AnalyticsTo understand aggregate usage patterns and improve the Service. Lawful basis: our legitimate interests. See clause 7 — our analytics are cookieless and do not track individuals.
    Legal and regulatory complianceTo comply with our legal obligations and to establish, exercise or defend legal claims. Lawful basis: compliance with a legal obligation, and/or our legitimate interests.
    1. Legitimate interests
    2. Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms, and we have concluded that they are not. You may object to processing based on legitimate interests — see clause 9.
    3. No marketing or advertising
    4. We do not use your personal data for advertising, and we do not sell, rent or trade your personal data to third parties.
  5. Where your data is stored and processed

    1. Hosting
    2. The Service is hosted on Amazon Web Services (AWS) infrastructure located in the United Kingdom. AWS acts as our data processor and processes personal data on our instructions under a written data processing agreement.
    3. International transfers
    4. Personal data processed in connection with the Service is stored in the United Kingdom. Where any transfer of personal data outside the UK is necessary (for example, in connection with support or administration by a service provider), we will ensure that appropriate safeguards are in place as required by the UK GDPR, such as an adequacy decision or the International Data Transfer Agreement (IDTA) or UK Addendum.
  6. Retention

    1. General principle
    2. We retain personal data only for as long as necessary for the purposes set out in this Policy, or for as long as required by law.
    3. Specific retention periods
    Account dataRetained for as long as your account is active, and for a reasonable period afterwards to handle any queries or disputes.
    Access and security logsTechnical access logs (which include IP address and browser information) are retained for 12 months, after which they are automatically deleted.
    Draw history (account holders)Retained for as long as your account is active, so that your history remains available to you.
    Audit recordsAudit records are immutable and permanent. They exist so that any draw can be independently verified at any time, which is fundamental to the integrity of the Service. Audit records do not contain IP addresses, browser information or contact details. Audit records for anonymous draws contain no personal data.
    1. Audit records and access logs are separate
    2. Our permanent audit records and our technical access logs are distinct. The audit record is the certified, immutable record of a draw — it contains the draw parameters, the result, a timestamp and an audit identifier, and it is retained permanently because the verifiable integrity of the Service depends on it. The access log is a separate, operational security record which contains technical identifiers such as IP address; it is retained only for as long as necessary for security, abuse prevention and support purposes, and is then deleted. Deleting an access log has no effect on the integrity or verifiability of any draw.
  7. Cookies, local storage and analytics

    1. We do not use tracking or advertising cookies
    2. We do not use cookies for advertising, profiling or cross-site tracking.
    3. Local storage (strictly necessary)
    4. When you sign in, we store authentication tokens in your browser’s local storage. These are strictly necessary to keep you signed in and to allow the Service to authenticate your requests. They are not used for tracking or analytics. Clearing your browser storage, or signing out, removes them.
    5. Analytics
    6. We use Plausible Analytics, a privacy-friendly analytics service. Plausible does not use cookies, does not collect personal data for the purposes of tracking individuals, and does not track you across websites or over time. It records aggregate information such as page views, referring website and general country-level location. IP addresses are processed transiently to derive that aggregate information and are not stored by Plausible in a form that identifies you.
  8. Who we share personal data with

    1. Service providers
    2. We share personal data with a small number of service providers who process it on our behalf, under written agreements requiring them to protect it and to process it only on our instructions. These include our hosting and infrastructure provider (AWS) and our analytics provider (Plausible).
    3. Legal disclosures
    4. We may disclose personal data where required to do so by law, by a court order, or by a regulator, or where necessary to establish, exercise or defend legal claims.
    5. Business transfers
    6. If we sell, transfer or reorganise our business, personal data may be transferred as part of that transaction, subject to the protections in this Policy.
    7. No sale of personal data
    8. We do not sell your personal data.
  9. Your rights

    1. Under the UK GDPR you have the following rights in relation to your personal data:
    AccessTo obtain a copy of the personal data we hold about you.
    RectificationTo have inaccurate personal data corrected.
    ErasureTo have your personal data deleted in certain circumstances.
    RestrictionTo ask us to restrict processing in certain circumstances.
    ObjectionTo object to processing carried out on the basis of our legitimate interests.
    PortabilityTo receive certain personal data in a structured, commonly used, machine-readable format.
    ComplaintTo lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk. We would ask that you contact us first so that we can try to resolve your concern.
    1. Exercising your rights
    2. To exercise any of these rights, contact us at mail@purerandom.com. We will respond within one month. We may need to verify your identity before acting on your request. Exercising these rights is free of charge, unless your request is manifestly unfounded or excessive.
  10. Access to your data by our staff

    1. Access to personal data within our systems is restricted to those who need it to operate, support and secure the Service. Administrative access to stored draw history and account data is technically possible and is used only where necessary for support, security, troubleshooting or legal compliance. Access to our systems is logged.
  11. Security

    1. We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls operating on a least-privilege basis, network isolation, immutable audit logging and monitoring. No system can be guaranteed to be completely secure, but we take security seriously and review our measures regularly.
  12. Changes to this Policy

    1. We may update this Policy from time to time. Where changes are material, we will take reasonable steps to bring them to your attention. The date at the top of this Policy shows when it was last updated.