This Privacy Policy explains how Simulant Systems Ltd (“we”, “us”, “our”) collects and uses personal data when you use Addict Media (the “Website”), including when you browse, place an order, download digital products, create an account, or subscribe to ongoing billing.

1) Stripe payments and saved payment methods (tokenised)

We use Stripe as our payment merchant/provider to process payments on the Website.

Paying for an order

When you pay at checkout, your payment is processed securely by Stripe. We do not receive or store your full card number. Your card/payment details are entered into Stripe’s secure payment process.

Saving a payment method for subscriptions (your choice + consent)

If you purchase a subscription (or any product/service with ongoing billing) you may be offered the option to save a payment method for future subscription charges. If you choose to do this, Stripe stores a tokenised version of your payment method. Tokenisation means your payment details are replaced with a secure reference (“token”), allowing future charges without us storing your raw card details.

Where you have authorised ongoing billing, we (via Stripe) may charge the saved payment method:

You can choose not to save a payment method (where available), but that may limit or prevent ongoing subscription billing.

What we receive from Stripe

We typically receive limited information such as:

Stripe’s own processing

Stripe processes personal data to provide payment services, maintain security, prevent fraud, and comply with law. Stripe may process some data for its own purposes (for example, fraud prevention). Please refer to Stripe’s own privacy information on their website for full details.


2) Who we are (data controller) and how to contact us

Data controller: Simulant Systems Ltd (trading as Addict Media)

Contact (privacy enquiries): Please use our Contact Form.

We do not publish a postal address in this policy. If we need to verify identity for a data request, we will explain the process when you contact us.


3) The personal data we collect

a) Data you provide to us

Depending on what you do on the Website, we may collect:

b) Data we collect automatically

When you use the Website, we may collect:

c) Data we receive from third parties


4) How we use your data (purposes and lawful bases)

We only use personal data where we have a lawful basis under UK GDPR.

a) To run the Website and provide accounts

Purpose: site operation, account login, customer service
Lawful basis: Legitimate interests (running and improving our Website) and Contract (where you create an account)

b) To process and fulfil orders (physical and digital)

Purpose: take and manage orders, send order confirmations, provide digital products, ship physical products, handle returns/refunds
Lawful basis: Contract (to perform the sale contract)

c) To process payments and manage subscriptions

Purpose: payment processing, subscription renewals, handling failed payments, invoicing
Lawful basis: Contract and Legitimate interests (ensuring payment and preventing abuse)
Saved payment methods: where you choose to save a payment method for subscriptions, Stripe stores a tokenised payment method based on your authorisation.

d) To comply with legal obligations

Purpose: accounting, tax/VAT records, responding to lawful requests
Lawful basis: Legal obligation

e) Security and fraud prevention

Purpose: protect accounts, prevent fraud, secure the Website and transactions
Lawful basis: Legitimate interests (and in some cases Legal obligation)

f) Marketing (our internal mailing list)

Purpose: sending newsletters or updates
Lawful basis: Consent (where required) and/or Legitimate interests (limited, where permitted)

You can opt out at any time by using the unsubscribe link (if provided) or contacting us via the Website Contact Form.


5) Who we share data with

We share personal data only where necessary to operate the store and deliver your order:

We do not sell your personal data.


6) International transfers

Some service providers may process data outside the UK. Where this happens, we use appropriate safeguards required under UK GDPR (for example, adequacy regulations or contractual protections).


7) How long we keep your data (retention)

We keep personal data only as long as necessary for the purposes described:

If you request deletion, we will comply where we can, but we may need to retain some information for legal obligations (e.g., tax) or to establish/exercise/defend legal claims.


8) Cookies and similar technologies

We use cookies and similar technologies for:

Where required, we will request consent before using non-essential cookies/technologies. You can also control cookies through your browser settings.


9) Your rights (UK GDPR)

You may have the right to:

To exercise your rights, contact us via the Website Contact Form.

You also have the right to complain to the Information Commissioner’s Office (ICO) if you believe your data has been handled improperly.


10) Security

We use appropriate technical and organisational measures to protect personal data. Payment card details are handled by Stripe; we do not store full card numbers on our servers.

No online service is completely secure, but we work to protect your information and reduce risk.


11) Children

Our Website is not intended for children. If you believe a child has provided personal data to us, please contact us via our Contact Form and we will take appropriate steps.


12) Changes to this policy

We reserve the right to periodically update this Privacy Policy.