Skip to content
porticoplay
Our gamesThe platformSolutionsPricingThe studio
Let’s talk →Get started ↗
Our gamesThe platformSolutionsPricingThe studioGet started ↗Let’s talkRetail campaignsPlayable templatesSeasonal looksDraft with AIEvent activationsB2B lead generationSports & fan engagementMedia & publishingRetention & loyaltyRivals: social competitionAgencies & client workEmployee engagementiGaming campaigns
Home/Legal/Data processing agreement

Legal

Data processing agreement.

Last updated 4 October 2026

When a brand runs games on Portico Play, the brand decides why and how its players’ data is used, and we process that data for it. Our data processing agreement (DPA) sets out the terms, as Article 28 GDPR requires. This page summarises it in plain words; the signed DPA is what binds.

Request the signed DPA

Email [email protected] with your company’s legal name, organisation number, address and the name of the person who will sign. We send the DPA, with its annexes, for signature. It forms part of your agreement for the Portico Play service and wins over it on anything about personal data.

1. Who is who

  • You, the customer, are the controller for the personal data of your players.
  • Luminbrane AB, trading as Portico Play, is the processor.
  • We are a separate controller, outside the DPA, for our own product analytics on play pages (only with the player’s consent, see the Portico analytics notice), and for data about your staff who use the console, billing and running our customer relationship.

2. We act only on your instructions

Your instructions are the DPA, the main agreement and the settings you make in the console, such as the fields you collect, consent texts, retention periods, the consent mode, tags, webhooks and notifications. We tell you if we think an instruction breaks data protection law. We do not use your players’ data for our own purposes, do not sell it, and do not combine it with other customers’ data, except to protect the service from fraud and abuse.

3. Confidentiality and security

Everyone who handles your data is bound by confidentiality, and only staff who need it to run, support or secure the service have access. The DPA’s security annex lists our measures, including EU hosting, encryption in transit and at rest, row-level security, hashed IP addresses, an append-only audit log, backups and a breach response runbook. We may improve the measures, but never lower the overall level of security.

4. Subprocessors

You give general authorisation for the subprocessors on our subprocessor list. We give at least 30 days’ notice by email and on that list before adding or replacing one. You may object on reasonable data protection grounds; if we cannot agree, you may end the affected part of the service without penalty and get a pro-rata refund. Each subprocessor is bound by terms at least as protective as the DPA, and we remain liable for it.

5. Where the data is, and transfers

Your players’ data is stored in the EU, in Stockholm: the database and files with Supabase in eu-north-1, served on services.porticoplay.com, and the application servers with Fly.io. A transfer outside the EEA happens only on an adequacy decision (including the EU–US Data Privacy Framework), the EU standard contractual clauses (Module 3), or another Article 46 safeguard.

6. Helping with players’ rights

The console gives you tools to answer requests: access and export (JSON and CSV), erasure, correcting an email address, restriction, and consent history. Players can also use your “My data” page if you switch it on. If a player writes to us directly, we pass the request to you without undue delay.

7. Personal data breaches

We tell you without undue delay, and in any case within [24] hours of becoming aware of a breach that affects your data, with what we know and what we are doing about it. We send more as we learn it. We help you notify the authority and players where you need to.

8. Retention, deletion and return

While the agreement runs, we delete data on the schedules you set in the console. When it ends, you can export your data for 30 days; then we delete it within [60] days, unless the law requires us to keep it. Deleted data leaves our encrypted backups within [7/14/28] days. We confirm deletion in writing on request.

9. Audits and other help

We make available the information needed to show we comply. You may audit once a year, or after a breach or at an authority’s request, with 30 days’ notice. We may first offer documents, such as our security description and subprocessors’ certifications. We also help with data protection impact assessments, including our own assessment of the Rivals format.

10. Liability and law

Liability follows the main agreement. The DPA lasts as long as we process your data. Swedish law applies, with Stockholm District Court as the first instance, unless the main agreement says otherwise.

porticoplay

Playful experiences.
Purposeful campaigns.

PROMOTIONAL GAMES FOR BUSINESS

Explore

Portico PromosPlatform featuresTemplatesSeasonal looksIntegrationsShopify integrationDraft with AIFairness & transparencyPricingCreate an organisation ↗Console login ↗

Games

Welcome WheelMystery BoxesPlinkoScratch CardReelsFree KickMatch PointBowlingTap to RiskWildhuntQuizPredictionMemorySliding PuzzlePollSurveyCalculatorRecommendation

Studio & solutions

Retail & e-commerceRestaurants & QSREvents & sponsorshipB2B & lead generationSports & fan engagementMedia & publishingRetention & loyaltyRivals: social competitionAgenciesEmployee engagementiGamingAbout usContact
© 2026 Portico PlayBuilt byLuminbrane

B2B promotional game software. Nobody pays to play, and we are not a consumer gambling business.

LegalPrivacyCookiesTerms