Security & data protection
Written for the person who approves vendors.
Everything your vendor-review checklist asks for, answered before you ask — and one structural advantage most providers can't offer: our scope excludes player personal data entirely, which removes most transfer and processing questions before they arise.
How your data is handled
- Data processing agreement executed before any access is granted, under GDPR
- Access through your systems, under your permissions model, on a least-privilege basis
- Role-based access control with documented approval and periodic review
- Access logging and audit trails
- Individual confidentiality obligations binding on every team member
- Documented offboarding: access revocation and data handling on termination
- Client audit and inspection rights, exercisable by you or your regulator
EU-ESTABLISHED, EEA BY DEFAULT
We are established in the EU and process data within the EEA by default. Our scope excludes player personal data entirely — where reporting derives from player activity, we work only with aggregated or anonymised datasets supplied by you.