Speciality Promotions

Privacy Policy

Last updated: 16 March 2026

This privacy notice applies to the promotion: Win With Westland, hosted at https://winwithwestland.co.uk.

1. Who We Are

Speciality Promotions (“we”, “us”, “our”) operates prize promotions and competitions on behalf of client companies (“Promoter”). We act as a data processor on behalf of the Promoter who is the data controller for this promotion.

Contact us at: gary@specialitypromotions.com
Website: specialitypromotions.com

2. What Personal Data We Collect

When you enter a promotion we may collect:

DataPurposeRequired?
First name & last nameIdentify your entry; contact if you winAlways
Email addressSend entry confirmation; notify winners; detect duplicate entriesAlways
Phone numberContact if you win (where enabled by the Promoter); detect duplicate entries via a one-way hash of the last 10 digits (we cannot reverse this to recover the number)Required for this promotion
Entry codeVerify promotional eligibility (where applicable)Required for this promotion
IP address hashFraud prevention and duplicate detection (one-way hash only; we cannot reverse this)Automatic
Browser / device fingerprint hashFraud prevention (one-way hash; not used for tracking)Automatic
Marketing preferencesTo contact you about future offers (only if you opt in)Optional
Post Code Additional information requested by the Promoter for this promotion Required for this promotion

3. Legal Basis for Processing

4. How We Protect Your Data

All personally identifiable information is encrypted at rest using AES-256-GCM encryption. Email addresses and phone numbers (where collected) are additionally stored as a one-way HMAC for duplicate detection — we cannot reverse these to recover the original values. Phone numbers are normalised to their last 10 digits before hashing, so different formats of the same number (e.g. 01642 880512 and +44 1642 880512) are treated as equivalent. Data is stored on servers within the United Kingdom.

This application is built to align with the OWASP Application Security Verification Standard (ASVS), fully meeting Levels 1 and 2 and substantially meeting Level 3. PHPStan static analysis is run against the full codebase prior to every deployment. ASVS is an internationally recognised framework for web application security. Full details of the controls in place are available on request.

The application is subject to regular independent penetration testing carried out by North IT (www.northit.co.uk). Security findings are remediated before any promotion goes live.

5. Data Retention

Entry data is deleted 90 days after a promotion closes, except for:

You can request deletion of your data at any time by contacting us at gary@specialitypromotions.com.

6. Who We Share Your Data With

7. Cookies

This website uses the following cookies:

CookiePurposeDuration
SPSESSSession management — required for form security (CSRF protection) and tracking whether you have already entered. This is a strictly necessary cookie.Session (deleted when browser closes)
__promo_tidA randomly generated identifier used solely to detect duplicate entries within this promotion. It contains no personal data and cannot be used to track you across other websites. This is a strictly necessary cookie for the fair administration of the promotion.12 months
sp_cookie_consentStores your acknowledgement of this cookie notice so we do not show it again.12 months

We do not use advertising cookies or third-party analytics cookies.

Email open tracking

Confirmation emails sent to you may include a small invisible image (a tracking pixel) provided by our email delivery service, SendGrid. This allows us to detect whether a confirmation email was successfully opened. We use this solely for operational purposes (e.g. verifying delivery) and not for advertising or profiling. You can prevent this by disabling image loading in your email client.

Human Verification (Altcha)

To protect this website from automated abuse, we use Altcha — a privacy-respecting, self-hosted proof-of-work challenge. Unlike reCAPTCHA or hCaptcha:

The SPSESS cookie is strictly necessary for the website to function and does not require your consent. You may block it in your browser settings, but this will prevent you from entering the promotion.

8. Your Rights

Under UK GDPR and the Data Protection Act 2018 you have the right to:

To exercise any of these rights, contact: gary@specialitypromotions.com

9. Contact

Gary Bottrill
Speciality Promotions
gary@specialitypromotions.com
+44 (0) 7785 227 980