Divine Interactive

Privacy Policy

Last updated: 12 October 2026

This Privacy Policy explains how Divine Interactive (“we”, “us” or “our”) collects, uses, stores and shares personal data when you visit our website, create an account, purchase products or use our services.

For the purposes of applicable data protection law, Divine Interactive acts as the data controller for the personal data described in this policy, except where another organisation acts as an independent controller for its own processing.

We handle personal data in accordance with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Personal Data We Collect

Depending on how you use our website and services, we may collect the following categories of personal data.

Account information

  • Name and email address.
  • Securely hashed passwords.
  • Authentication and account security information.
  • If two-factor authentication is enabled, an authenticator secret and recovery codes, protected using appropriate security measures.

Linked accounts

If you sign in with or link a third-party account, such as Discord, we may receive your account identifier, username, email address and other information made available through the relevant integration and permissions.

Orders and payments

  • Products or services purchased.
  • Order totals, payment status and transaction references.
  • Relevant billing or transaction information supplied by the payment provider.

Payments are processed by third-party providers such as PayPal or Tebex. We do not receive or store full payment card details where these are handled directly by the provider.

Projects, quotes and support

Information you provide through quote requests, project discussions, support tickets, contact forms and uploaded files. This may include contact details, project requirements and relevant technical information.

Usage and security information

We may collect technical and usage information, including pages visited, timestamps, security events, a random visitor identifier stored in your browser, and IP-related information used for security and abuse prevention.

Where IP addresses are transformed using hashing or similar techniques, the resulting information may still constitute personal data if it can be linked to an identifiable person.

2. How We Use Your Data

We process personal data for the following purposes:

  • Providing our services: Creating and managing accounts, delivering purchases and carrying out custom projects. Our lawful basis is the performance of a contract or taking steps at your request before entering into a contract.
  • Customer support: Responding to enquiries, managing support tickets and sending service-related messages, such as receipts and password resets. Our lawful basis is generally contractual necessity or legitimate interests, depending on the circumstances.
  • Security and fraud prevention: Protecting accounts, investigating suspicious activity, preventing abuse and enforcing our terms. Our lawful basis is legitimate interests, where those interests are not overridden by your rights and interests.
  • Website improvement: Understanding usage and improving our website and services. Where we rely on legitimate interests, we consider the impact on users and use appropriate safeguards. Any non-essential cookies or similar technologies are subject to applicable consent requirements.
  • Legal and financial obligations: Maintaining transaction records, handling tax matters and complying with legal requirements. Our lawful basis is compliance with a legal obligation where applicable.

We do not sell your personal data. We do not use your personal data for third-party advertising.

3. Who We Share Your Data With

We share personal data only where reasonably necessary for the purposes described in this policy, where required by law, or where otherwise permitted by applicable law.

Our service providers and other recipients may include:

  • PayPal and Tebex: To process payments and, where applicable, facilitate the sale and delivery of FiveM resources.
  • Discord: To support account linking, authentication or Discord-integrated support features that you choose to use.
  • Email providers: To deliver transactional emails and service notifications.
  • Hosting and infrastructure providers: To host our website, store information and maintain the security and availability of our services.
  • Professional advisers or authorities: Where necessary to obtain professional advice, establish or defend legal claims, or comply with legal obligations.

These organisations may process information under their own privacy policies and may act as independent data controllers for certain activities.

4. International Data Transfers

Some service providers may process personal data outside the United Kingdom.

Where personal data is transferred internationally, we will use an appropriate transfer mechanism where required by law. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another legally recognised safeguard.

You can contact us through our contact page if you would like further information about relevant international data transfers and safeguards.

5. How Long We Keep Your Data

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including legal, accounting, security and dispute-resolution requirements.

Our general retention approach is as follows:

  • Account information: While your account remains active and for a reasonable period afterwards where needed for security, legal compliance or dispute resolution.
  • Order and financial records: For the period required by applicable accounting and tax laws. Certain records may need to be retained for approximately six years, depending on the applicable requirements.
  • Support and project records: For as long as necessary to manage the relevant service, fulfil contractual obligations and handle potential disputes.
  • Usage and security logs: For a period appropriate to the relevant security or operational purpose, after which they may be deleted or anonymised where appropriate.

Actual retention periods may vary depending on the type of information, the reason it was collected and any applicable legal obligations.

6. How We Protect Your Data

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, disclosure or destruction.

These measures may include password hashing, access controls, encryption where appropriate, security monitoring and restricted access to sensitive information.

However, no method of storing or transmitting information over the internet can be guaranteed to be completely secure.

7. Your Data Protection Rights

Depending on the circumstances and applicable law, you may have the right to:

  • Access: Request a copy of your personal data.
  • Rectification: Ask us to correct inaccurate or incomplete information.
  • Erasure: Request deletion of your personal data where the legal requirements are met.
  • Restriction: Ask us to restrict certain processing.
  • Objection: Object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds to continue or another applicable legal basis permits it.
  • Data portability: Request certain information in a commonly used, machine-readable format where the right applies.
  • Withdraw consent: Where processing is based on consent, withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.

These rights are subject to applicable legal conditions and exemptions. We may need to retain certain information to meet legal obligations, prevent fraud or establish or defend legal claims.

To exercise your rights, contact us through our website's contact page. We may need to verify your identity before responding.

You also have the right to complain to the UK Information Commissioner's Office (ICO). Information is available at ico.org.uk.

8. Cookies and Similar Technologies

Our website may use cookies and similar technologies to maintain sessions, support authentication, protect accounts, remember preferences and understand website usage.

Where required by law, we will ask for your consent before using non-essential cookies or similar technologies. Essential technologies may be used where they meet the applicable legal requirements.

For more information about the technologies used on our website and the choices available to you, please read our Cookie Policy.

9. Third-Party Services

Our website may contain links to, or integrations with, third-party services such as PayPal, Tebex and Discord.

When you use these services, the relevant provider may collect and process your information under its own privacy policy and terms. We recommend reviewing those documents before using the relevant service.

We are not responsible for the independent privacy practices of third-party services.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our website, services, data processing activities or legal obligations.

The latest version will be published on our website, and the date at the top will indicate when it was last updated.

Where required by law, we will provide additional notice of significant changes.

11. Contact Us

If you have questions about this Privacy Policy, how we handle personal data or wish to exercise your data protection rights, please contact Divine Interactive through our website's contact page or support ticket system.