Privacy Policy

Last updated: 26 July 2026

This policy explains what personal data Vokio collects, why, how it is protected, and the rights you have over it. It is written to meet the UK GDPR and the Data Protection Act 2018.

1. Who we are

Vokio is a live-interaction platform (anonymous-style suggestion boxes, live quizzes and word clouds) operated by Seb Nastarowicz, trading as dotright ("we", "us", "our"). We are the data controller for the personal data described in this policy.

  • Contact for privacy matters: sebnastarowicz@dotright.co.uk
  • ICO registration: registration application in progress - this notice will be updated with the registration number once the ICO confirms it.

2. Who this covers

Two groups use Vokio:

  • Administrators - people with an account who create and run sessions (create quizzes, manage teams, view results).
  • Participants - people who join a live session to answer a quiz or submit to a word cloud. Participants do not create an account; they join with a code and choose a nickname.

3. What we collect and why

Administrator accounts

  • Username, email address, display name and a securely hashed password.
  • An optional profile photo or emoji avatar.
  • Your interface preferences (such as light/dark theme) and last login time.

Purpose: to create and secure your account and let you operate the platform. Lawful basis: performance of a contract / our legitimate interest in providing the service.

Participants joining a session

  • The nickname you choose (please avoid using your full real name if you prefer to stay anonymous) and an optional emoji avatar.
  • Your answers, submitted words, scores and the time of each action.
  • A session-derived identifier that links your answers to your device for the duration of the game. This is pseudonymous: it lets the game work but is not published with your real identity.

Purpose: to run the live session and show results. Lawful basis: our legitimate interest in delivering the interactive session you chose to join.

Security and technical data

  • Login attempts, including the IP address and username used, to detect and block brute-force attacks.
  • An audit log of key account actions (logins, password changes, account and role changes, invitations) including the IP address, to keep the platform secure and accountable.
  • Standard server logs generated by our hosting for reliability and security.
  • If you choose to mark a device as trusted for two-factor authentication, a record of that device: a random token (stored only as a one-way hash), a short device description derived from your browser's user-agent, the IP address you were using when you marked it, and the dates it was added, last used, and expires. You can see and remove these at any time in My Account.

Purpose: security, fraud/abuse prevention and accountability. Lawful basis: our legitimate interest in keeping the service and its users safe, and our legal obligation to secure personal data.

4. Cookies

Vokio uses only essential and preference cookies - no analytics, advertising or tracking cookies. Full details are in our Cookie Policy.

5. Who we share data with

We do not sell your data or use it for advertising. We share it only with the service providers we need to run Vokio, acting as our processors:

  • Email delivery - we use an email provider (Brevo, or an SMTP service you configure) to send transactional emails such as password resets and admin invitations. Only the recipient's email address and the message are shared.
  • Hosting - the platform and database run on servers provided by IONOS (Fasthosts Internet Ltd), located in the United Kingdom.

We may also disclose data if required by law or to protect our legal rights.

6. International transfers

Our hosting and database are located in the United Kingdom, so your core data is not transferred abroad. Where a provider processes data outside the UK - for example our email provider within the EU - we rely on a UK adequacy decision or the UK International Data Transfer Agreement/Addendum to keep your data protected to UK standards.

7. How long we keep it

  • Administrator accounts - for as long as the account is active, and deleted on request.
  • Session and gameplay data (participants, answers, submissions) - retained for up to 12 months, then deleted or anonymised.
  • Login-attempt records - up to 90 days.
  • Audit logs - up to 12 months.
  • Password-reset and invitation tokens - deleted once used or expired.
  • Trusted-device records - up to 30 days, then deleted automatically. Removed sooner if you revoke the device or change your password.

8. Your rights

Under UK data protection law you have the right to access your data; to have inaccurate data corrected; to have your data erased; to restrict or object to processing; and to data portability. To exercise any of these, email sebnastarowicz@dotright.co.uk. We will respond within one month.

You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, though we would welcome the chance to resolve any concern first.

9. How we protect your data

We apply appropriate technical measures, including: encryption of traffic over HTTPS; passwords stored using strong one-way hashing (never in plain text); protection against cross-site request forgery; brute-force lockouts; role-based access controls; and a hardened content security policy.

Administrator accounts must use two-factor authentication. You may choose to skip the code prompt on a device you have marked as trusted; this does not switch two-factor authentication off, lasts at most 30 days, and can be revoked by you at any time.

10. Children

Vokio is intended for use in workplace and event settings and is not directed at children. If a session is run with participants under 13, the session organiser is responsible for obtaining any consent required.

11. Changes to this policy

We may update this policy from time to time. The "last updated" date above shows when it last changed. Material changes affecting administrators will be notified where practical.