Security & data protection

Written for the person who approves vendors.

Everything your vendor-review checklist asks for, answered before you ask — and one structural advantage most providers can't offer: our scope excludes player personal data entirely, which removes most transfer and processing questions before they arise.

How your data is handled

  • Data processing agreement executed before any access is granted, under GDPR
  • Access through your systems, under your permissions model, on a least-privilege basis
  • Role-based access control with documented approval and periodic review
  • Access logging and audit trails
  • Individual confidentiality obligations binding on every team member
  • Documented offboarding: access revocation and data handling on termination
  • Client audit and inspection rights, exercisable by you or your regulator

EU-ESTABLISHED, EEA BY DEFAULT

We are established in the EU and process data within the EEA by default. Our scope excludes player personal data entirely — where reporting derives from player activity, we work only with aggregated or anonymised datasets supplied by you.

Book a scoping call