Privacy and Data Processing Policy
Effective date: 02 January 2026
1. Introduction
This Global Privacy and Data Processing Policy explains how Zamo Media Ltd collects, receives, uses, retains, shares and otherwise processes personal data through its websites, landing pages, brands and promotional campaigns.
The brands covered by this Policy include:
Everyday Prizes;
DailySavingtips;
Energiepeiling;
Tariefchecker; and
any other website, campaign or promotional brand that identifies Zamo Media Ltd as its owner or operator.
In this Policy, references to “Zamo Media Ltd”, “we”, “us” or “our” include the brands listed above unless the context requires otherwise.
Everyday Prizes is no longer operating active consumer competitions or prize promotions. DailySavintips, Energiepeiling, Tariefchecker and other related brands may also have closed, changed or discontinued particular services or campaigns.
This Policy remains available to explain:
how personal data was historically collected;
how we continue to manage retained personal data;
how marketing preferences and unsubscribe requests are handled;
when personal data may be shared with service providers or selected partners;
the rights available to individuals; and
how our practices apply across the United Kingdom, Netherlands, Australia and other relevant territories.
2. Data Controller
The controller responsible for personal data covered by this Policy is:
Zamo Media Ltd
ICO registration number: ZB083749
For privacy enquiries, objections, complaints and rights requests, contact:
Data Protection Officer
Email: dpo@zamomedia.co.uk
Depending on the relevant campaign, another identified organisation may also have acted as an independent controller or joint controller.
An independent controller is responsible for its own purposes, lawful basis, privacy information and compliance.
3. Brands and Processing Activities Covered
3.1 Everyday Prizes
Everyday Prizes historically operated or sponsored:
competitions;
prize draws;
giveaways;
sweepstakes;
surveys;
sponsored promotions;
email campaigns; and
third-party campaigns where Everyday Prizes was identified as a sponsor, co-sponsor or promotional partner.
Personal data may have been collected directly through an Everyday Prizes form or received from a third-party campaign operator.
3.2 DailySavingtips
DailySavintips historically operated or promoted consumer campaigns in territories including:
the United Kingdom;
the Netherlands;
Australia; and
other territories identified in the relevant campaign.
DailySavintips activities may have included:
newsletters;
money-saving content;
competitions;
consumer surveys;
promotional offers;
product or service promotions;
sponsored campaigns;
lead-generation campaigns; and
selected third-party offers.
3.3 Energiepeiling
Energiepeiling historically operated or supported campaigns concerning:
household energy usage;
energy preferences;
current energy providers;
energy expenditure;
switching interest;
tariff preferences;
consumer research;
energy-related offers; and
contact from selected energy or service partners.
The information collected and the purpose of each campaign depended on the notice, questions and choices presented on the relevant form.
3.4 Tariefchecker
Tariefchecker historically operated or supported campaigns relating to:
tariffs;
household services;
utilities;
energy;
telecommunications;
insurance;
consumer services;
comparison interests;
promotional enquiries;
surveys; and
selected partner offers.
Tariefchecker may have collected information to identify consumer preferences or interest in receiving information or offers from relevant providers.
Unless expressly stated otherwise, Tariefchecker did not necessarily provide a whole-of-market comparison or regulated recommendation.
3.5 Other Zamo Media Ltd campaigns
This Policy also applies where:
Zamo Media Ltd was identified as the operator;
this Policy was linked or referenced;
one of the brands above was identified as a sponsor or partner;
Zamo Media Ltd received personal data through a documented partner campaign; or
a campaign-specific privacy notice stated that Zamo Media Ltd would process the information.
A campaign-specific notice may supplement this Policy.
4. Geographic Scope
Our brands and campaigns have historically involved individuals located in:
the United Kingdom;
the Netherlands;
Australia;
other EU or EEA countries; and
other countries identified in a campaign.
The law applying to a processing activity may depend on:
the individual’s location;
the country targeted by the campaign;
where the relevant organisation is established;
the brand or campaign involved;
the purpose of processing;
the communication channel; and
the role of each organisation.
5. Applicable Laws
Where relevant, we seek to process personal data in accordance with applicable privacy, data-protection, electronic-marketing, telecommunications and cookie laws.
These may include:
United Kingdom
the UK General Data Protection Regulation;
the Data Protection Act 2018;
the Privacy and Electronic Communications Regulations; and
other applicable UK privacy and marketing requirements.
Netherlands and European Economic Area
the European Union General Data Protection Regulation;
applicable Dutch laws supplementing the GDPR;
Dutch electronic-communications and direct-marketing requirements; and
equivalent national laws in other relevant EU or EEA countries.
Australia
the Privacy Act 1988, where applicable;
the Australian Privacy Principles, where applicable;
the Spam Act 2003;
the Do Not Call Register Act 2006; and
other applicable Australian privacy and marketing requirements.
Other territories
Where another country’s law applies, we seek to meet the mandatory requirements relevant to that processing.
Nothing in this Policy is intended to reduce rights granted under mandatory local law.
6. Personal Data We May Hold
Depending on the brand, campaign and form, we may hold:
first and last name;
email address;
telephone or mobile number;
date of birth;
age or age-confirmation information;
postcode;
town or city;
region, state or territory;
country of residence;
homeownership or tenancy information;
household information;
competition or prize-draw entry details;
newsletter subscriptions;
survey responses;
energy usage information;
current or previous energy-provider information;
approximate energy expenditure;
tariff preferences;
switching intentions;
savings interests;
product or service interests;
telecommunications preferences;
insurance interests;
marketing choices;
communication preferences;
consent and opt-in records;
opt-out and withdrawal records;
the collection source;
campaign and publisher identifiers;
the date and time of collection;
the wording presented at collection;
IP address;
browser type;
device information;
cookie or similar identifiers;
website interaction data;
email interaction data;
records of enquiries and complaints;
unsubscribe and suppression records;
eligibility-verification information;
prize-fulfilment information; and
evidence demonstrating how and when personal data was collected.
We do not intentionally collect special-category or sensitive personal data unless it is necessary, clearly disclosed and supported by an appropriate legal condition.
7. Children’s Data
Our campaigns were generally intended for adults aged 18 or over.
We do not knowingly collect personal data from children through adult-only campaigns.
Where we learn that personal data was collected from an ineligible child, we will review and delete or restrict it where appropriate, subject to any legal requirement to retain a limited record.
8. How We Collected Personal Data
8.1 Directly from individuals
We may have collected personal data when an individual:
entered an Everyday Prizes promotion;
registered with DailySavintips;
completed an Energiepeiling survey;
submitted a Tariefchecker enquiry;
subscribed to a newsletter;
entered a competition or sweepstake;
completed a questionnaire;
expressed interest in a product or service;
selected marketing preferences;
contacted us;
used an unsubscribe facility; or
submitted a privacy request.
8.2 Through third-party campaigns
We may also have received personal data through:
third-party competitions;
sweepstakes;
surveys;
promotional publishers;
co-registration forms;
lead-generation partners;
sponsored landing pages;
comparison campaigns;
consumer-research campaigns; or
other partner-operated promotions.
This may have occurred where Everyday Prizes, DailySavintips, Energiepeiling, Tariefchecker or Zamo Media Ltd was identified as:
a sponsor;
a co-sponsor;
a participating brand;
a data recipient;
a promotional partner; or
an organisation that may contact the participant.
Depending on the arrangement, the original collector may have acted as:
an independent controller;
a joint controller;
a processor; or
a data supplier responsible for the initial collection.
Data supplied by a third party may have included:
personal details;
survey responses;
collection source;
campaign name;
collection date and time;
country;
consent wording;
privacy-notice wording;
selected partners or partner categories;
communication-channel choices; and
evidence supporting the stated lawful basis.
We expect third-party sources to collect and disclose information lawfully and transparently.
Receiving data from a third party does not automatically authorise every subsequent use. The original purpose, notice, lawful basis, partner wording, territory and communication channel must be reviewed.
8.3 Automatically collected data
When our websites or landing pages were active, technical information may have been collected through:
cookies;
pixels;
server logs;
analytics tools; and
similar technologies.
This may have included:
IP address;
device information;
browser information;
pages viewed;
referral source;
approximate location;
access time;
link interactions; and
campaign-performance data.
Where required, non-essential technologies were used only after consent.
9. Purposes of Processing
We may process personal data for purposes including:
administering historical competitions;
recording and validating entries;
verifying age, identity or residence;
preventing duplicate or fraudulent submissions;
selecting and contacting winners;
arranging prize fulfilment;
providing requested newsletters or content;
responding to savings, tariff or service enquiries;
recording consumer preferences;
conducting consumer research;
identifying interest in products or services;
responding to enquiries and complaints;
handling rights requests;
administering unsubscribe requests;
maintaining suppression records;
preserving evidence of data sources and permissions;
checking data provenance;
checking accuracy and permitted uses;
conducting partner or supplier due diligence;
monitoring compliance;
improving data quality;
securing systems and records;
preventing fraud and misuse;
complying with legal obligations;
establishing, exercising or defending legal claims;
analysing historical campaign performance;
producing aggregated or anonymised statistics;
sending marketing where legally permitted;
introducing or referring an interested individual to an authorised partner;
sharing information with a partner where legally permitted; and
preventing data from being used outside its authorised scope.
A revised version of this Policy does not retrospectively expand the permissions originally given by an individual.
10. Lawful Bases Under UK and EU Data-Protection Law
Where the UK GDPR or EU GDPR applies, we rely on one or more of the following lawful bases.
10.1 Consent
We may rely on consent where an individual made a freely given, specific, informed and unambiguous choice.
Consent may relate to:
receiving marketing from Everyday Prizes;
receiving marketing from DailySavintips;
receiving communications concerning Energiepeiling;
receiving communications concerning Tariefchecker;
receiving marketing from Zamo Media Ltd;
receiving marketing from an identified partner;
sharing data with named organisations;
sharing data with clearly described partner categories;
particular sectors or topics; or
specified communication channels.
Consent for one brand, purpose, country, partner or communication channel does not automatically authorise another.
Consent may be withdrawn at any time.
10.2 Contractual necessity
We may process personal data where necessary to:
administer a competition;
verify eligibility;
contact a winner;
deliver a prize;
respond to a requested service; or
take steps requested by an individual before entering a contract.
10.3 Legitimate interests
Where permitted, we may rely on legitimate interests for:
fraud prevention;
information security;
internal administration;
maintaining accurate records;
proving data provenance;
responding to enquiries;
suppression-list management;
compliance checking;
partner due diligence;
protecting legal rights;
preventing unauthorised marketing; and
limited direct-marketing activities where consent is not required by local law.
Before relying on legitimate interests, we consider:
the interest pursued;
whether the processing is necessary;
whether a less intrusive approach is available;
the person’s reasonable expectations;
the nature and source of the information; and
the impact on the individual.
Legitimate interests are not used to avoid a legal requirement for consent.
10.4 Legal obligations
We may process information to comply with legal, regulatory, accounting, tax or law-enforcement obligations.
10.5 Legal claims
We may process or retain information to establish, exercise or defend legal claims.
11. Processing Under Australian Privacy Requirements
Where Australian privacy law applies, we seek to process personal information in accordance with applicable Australian Privacy Principles and marketing legislation.
Depending on the circumstances, we may collect, use or disclose information where:
it is reasonably necessary for our functions or activities;
the individual has consented;
the individual would reasonably expect the use or disclosure;
the use is related to the original purpose;
applicable direct-marketing and opt-out requirements are met;
processing is required or authorised by law; or
another permitted exception applies.
Email, SMS and telephone marketing to Australian recipients must also comply with applicable identification, unsubscribe and do-not-call requirements.
12. Direct Marketing
Where permitted, marketing communications may concern:
competitions;
prize draws;
newsletters;
savings information;
energy products;
utility tariffs;
telecommunications;
insurance;
consumer services;
surveys;
product offers;
service offers;
sponsored promotions; or
partner offers.
Whether marketing is permitted depends on:
the recipient’s country;
the relevant brand;
the communication channel;
the wording presented at collection;
the individual’s choices;
the identity or category of the sender;
the relationship between the parties; and
whether a statutory exception applies.
United Kingdom
Electronic marketing may require consent under applicable UK electronic-communications rules unless a specific exception applies.
Netherlands and EEA
Digital direct marketing to individuals generally requires consent unless an applicable legal exception exists.
Australia
Direct marketing must comply with applicable Australian privacy principles, spam legislation and do-not-call requirements.
The presence of an individual in a database does not automatically authorise every organisation to contact that person through every channel.
Marketing communications must identify the sender and provide an effective unsubscribe or opt-out method.
13. Sharing Personal Data with Commercial Partners
Subject to applicable law and the permissions attached to the relevant record, personal data may be shared with carefully selected commercial, promotional or data partners.
Depending on the original campaign, partners may include organisations operating in sectors such as:
energy;
utilities;
telecommunications;
insurance;
home services;
financial products;
consumer products;
retail;
leisure;
competitions;
market research;
savings services; or
another sector disclosed at the point of collection.
Recipients may include:
competition sponsors;
promotional partners;
publishers;
advertisers;
lead-generation partners;
marketing agencies;
energy providers;
utility providers;
comparison services;
telecommunications providers;
insurers;
survey providers;
prize providers; and
organisations specifically identified or adequately described when the data was collected.
Before disclosure, we may assess whether:
the information came from a documented source;
suitable privacy information was provided;
the recipient or category of recipient was adequately identified;
the intended purpose is compatible with the original purpose;
the permission covers the proposed use;
consent exists where required;
legitimate interests can validly be relied upon where permitted;
the intended communication channel is authorised;
the use is lawful in the target country;
opt-outs, objections and suppression records have been applied;
the information remains relevant and sufficiently accurate;
suitable contractual controls exist; and
the recipient has completed appropriate compliance checks.
A recipient may act as:
an independent controller;
a joint controller; or
a processor.
An independent controller is responsible for:
providing its own privacy information;
identifying its lawful basis;
complying with marketing laws;
handling individual rights;
maintaining suppression records;
securing personal data; and
limiting use to authorised purposes.
This Policy does not independently create permission to sell, share or use personal data. Each disclosure must be supported by the relevant collection records and applicable law.
14. Referrals and Partner Contact
Where an individual requested or validly agreed to contact concerning a tariff, energy product, service or offer, we may have:
passed the enquiry to an appropriate partner;
asked a partner to contact the individual;
matched the individual’s stated interests with a relevant provider; or
disclosed information needed to respond to the request.
A referral did not guarantee:
acceptance by a provider;
a particular tariff;
a saving;
eligibility;
a quotation;
availability of a product; or
completion of a transaction.
The receiving partner was responsible for its own quotation, product terms, regulatory obligations and subsequent processing.
15. Service Providers
We may share personal data with service providers supporting activities such as:
hosting;
cloud storage;
database management;
customer relationship management;
email distribution;
SMS delivery;
analytics;
security;
fraud prevention;
eligibility verification;
customer support;
legal services;
accounting;
auditing;
prize fulfilment; and
compliance services.
Processors acting for us must process personal data only on authorised instructions and maintain appropriate confidentiality and security.
16. Corporate and Legal Disclosures
We may disclose personal data:
where required by law;
in response to a court or regulator;
to law-enforcement authorities where permitted;
to establish or defend legal rights;
to prevent fraud;
to protect individuals or property;
to professional advisers; or
in connection with a genuine sale, restructuring, investment or acquisition.
Any disclosure will be limited to what is reasonably necessary.
17. International Transfers
Because our brands have operated across the UK, Netherlands, Australia and other territories, personal data may be transferred internationally.
Where UK- or EEA-protected data is transferred outside the relevant territory, we use an appropriate mechanism where required, including:
an adequacy decision or regulation;
European Commission Standard Contractual Clauses;
the UK International Data Transfer Agreement;
the UK Addendum;
binding corporate rules;
another approved safeguard; or
a legally permitted derogation.
Where appropriate, we assess the destination country and apply additional contractual, technical or organisational measures.
Where Australian personal information is disclosed overseas, we assess applicable Australian cross-border requirements and the recipient’s role.
Information about safeguards relevant to a particular transfer may be requested at dpo@zamomedia.co.uk.
18. Data Accuracy and Minimisation
We seek to ensure that personal data is:
adequate;
relevant;
limited to what is necessary;
sufficiently accurate;
linked to available source and permission records;
not used beyond its authorised scope; and
corrected, restricted or deleted where a material issue is identified.
Historical information may become outdated.
Partners receiving data must conduct appropriate checks before relying upon it.
19. Retention
We retain personal data only for as long as reasonably necessary.
Factors considered include:
the collection date;
the original purpose;
the brand and campaign;
whether a consent remains valid;
whether the information remains accurate;
the individual’s reasonable expectations;
legal limitation periods;
audit and complaint requirements;
contractual obligations;
compliance-record requirements; and
legal claims.
Marketing information will not be retained indefinitely merely because it was once collected.
Information no longer required will be:
securely deleted;
anonymised;
restricted; or
removed from active use.
Where an individual unsubscribes or objects to marketing, we may retain a minimal suppression record to ensure the request continues to be respected.
20. Security
We use proportionate technical and organisational measures designed to protect personal data from:
accidental loss;
unauthorised access;
misuse;
alteration;
unlawful disclosure; and
destruction.
Measures may include:
access controls;
authentication;
encryption;
secure-transfer methods;
activity logging;
supplier checks;
confidentiality requirements;
staff training;
data-minimisation controls;
incident-response procedures; and
periodic security reviews.
No electronic system can be guaranteed to be completely secure.
Where a personal-data breach occurs, we assess it and notify affected individuals or regulators where required.
21. Cookies and Similar Technologies
Our current or historical websites and landing pages may use:
cookies;
pixels;
server logs;
analytics technologies; and
similar tools.
These may have been used for:
essential website operation;
security;
fraud prevention;
remembering preferences;
analytics;
measuring campaign performance; and
advertising measurement.
Where required by law, non-essential technologies were used only after consent.
Any active website using non-essential cookies should provide an appropriate cookie notice and consent-management tool.
22. Automated Processing
We may use automated checks to:
detect duplicate entries;
identify invalid submissions;
detect potential fraud;
record preferences;
apply suppression records;
route an enquiry to an appropriate campaign; or
support data-quality checks.
We do not intend to make solely automated decisions producing legal or similarly significant effects unless:
the processing is lawful;
appropriate information has been provided; and
required safeguards are available.
23. Rights Under UK and EU Data-Protection Law
Where the UK GDPR or EU GDPR applies, an individual may have the right to:
confirmation that personal data is processed;
access to personal data;
correction of inaccurate information;
deletion in applicable circumstances;
restriction of processing;
objection to processing based on legitimate interests;
objection at any time to direct marketing;
withdrawal of consent;
data portability;
information about the source of indirectly collected data;
information about recipients;
protection against certain automated decisions; and
complaint to a supervisory authority.
These rights are subject to applicable legal conditions and exceptions.
24. Rights Under Australian Privacy Law
Where applicable Australian privacy law applies, an individual may have the right to:
request access to personal information;
request correction;
opt out of direct marketing;
request the source of information used for direct marketing where applicable;
request that we stop facilitating marketing by another organisation where applicable; and
make a privacy complaint.
Australian recipients may also use the unsubscribe method in an electronic communication or applicable do-not-call mechanisms.
25. Exercising Your Rights
Requests may be sent to:
Data Protection Officer
Email: dpo@zamomedia.co.uk
The request should provide enough information to identify:
the individual;
the relevant email address or telephone number;
the relevant brand;
the approximate collection date;
the campaign involved; and
the nature of the request.
We may request proportionate proof of identity before disclosing personal data.
We will respond within the period required by applicable law.
26. Unsubscribing and Objecting to Marketing
To stop marketing associated with Everyday Prizes, DailySavintips, Energiepeiling, Tariefchecker or another Zamo Media Ltd brand, an individual may:
use the unsubscribe link in an email;
use the opt-out process in a message;
submit an unsubscribe request through the relevant website, where available; or
contact dpo@zamomedia.co.uk.
The scope of an unsubscribe request will be respected according to the wording of the request and applicable law.
An unsubscribe from Zamo Media Ltd does not necessarily unsubscribe an individual from an independent partner acting as a separate controller.
The individual should also use the unsubscribe method provided by that partner.
Where legally required, we may inform relevant recipients of a withdrawal, objection, correction or deletion request.
27. Complaints
We encourage individuals to contact us first so we can investigate and attempt to resolve a concern.
United Kingdom
Individuals may complain to the Information Commissioner’s Office where UK law applies.
Netherlands
Individuals may complain to the Autoriteit Persoonsgegevens where Dutch or EU data-protection law applies.
Australia
Individuals may complain to the Office of the Australian Information Commissioner where Australian privacy law applies.
Other countries
Individuals may contact the privacy or data-protection regulator responsible for their country, place of residence, place of work or the location of the alleged infringement.
28. EU or EEA Representative
Where Article 27 of the EU GDPR requires Zamo Media Ltd to appoint a representative in the European Union or European Economic Area, the representative’s contact details must be published here once appointed.
Privacy enquiries may be sent to:
This contact does not remove a legal obligation to appoint a representative where one is required.
29. Australian Contact
Questions concerning information collected through Australian-facing campaigns may be directed to:
Where a campaign involved an independent Australian publisher, sponsor or service provider, that organisation may also be responsible for its own processing and complaint handling.
30. Third-Party Websites
Our brands and campaigns may link to websites operated by independent third parties.
Those third parties may process information under their own privacy policies.
We are not responsible for an independent party’s processing where that organisation determines its own purposes and methods.
Individuals should review the privacy notice displayed on the website or form through which they submit information.
31. Changes to This Policy
We may update this Policy to reflect:
changes in law;
regulatory guidance;
changes to our brands;
campaign closures;
changes to processing practices; or
changes to partner and supplier arrangements.
The current version will be published with its effective date.
A revised policy does not retrospectively expand a historical consent or data-sharing permission.
32. Contact Details
For privacy questions, rights requests, objections, unsubscribe requests or complaints, contact:
Data Protection Officer
Zamo Media Ltd
Brands include Everyday Prizes, DailySavingtips, Energiepeiling and Tariefchecker
ICO registration number: ZB083749
Email: dpo@zamomedia.co.uk

