Legal
Data processing agreement.
When a brand runs games on Portico Play, the brand decides why and how its players’ data is used, and we process that data for it. Our data processing agreement (DPA) sets out the terms, as Article 28 GDPR requires. This page summarises it in plain words; the signed DPA is what binds.
Request the signed DPA
Email [email protected] with your company’s legal name, organisation number, address and the name of the person who will sign. We send the DPA, with its annexes, for signature. It forms part of your agreement for the Portico Play service and wins over it on anything about personal data.
1. Who is who
- You, the customer, are the controller for the personal data of your players.
- Luminbrane AB, trading as Portico Play, is the processor.
- We are a separate controller, outside the DPA, for our own product analytics on play pages (only with the player’s consent, see the Portico analytics notice), and for data about your staff who use the console, billing and running our customer relationship.
2. We act only on your instructions
Your instructions are the DPA, the main agreement and the settings you make in the console, such as the fields you collect, consent texts, retention periods, the consent mode, tags, webhooks and notifications. We tell you if we think an instruction breaks data protection law. We do not use your players’ data for our own purposes, do not sell it, and do not combine it with other customers’ data, except to protect the service from fraud and abuse.
3. Confidentiality and security
Everyone who handles your data is bound by confidentiality, and only staff who need it to run, support or secure the service have access. The DPA’s security annex lists our measures, including EU hosting, encryption in transit and at rest, row-level security, hashed IP addresses, an append-only audit log, backups and a breach response runbook. We may improve the measures, but never lower the overall level of security.
4. Subprocessors
You give general authorisation for the subprocessors on our subprocessor list. We give at least 30 days’ notice by email and on that list before adding or replacing one. You may object on reasonable data protection grounds; if we cannot agree, you may end the affected part of the service without penalty and get a pro-rata refund. Each subprocessor is bound by terms at least as protective as the DPA, and we remain liable for it.
5. Where the data is, and transfers
Your players’ data is stored in the EU, in Stockholm: the database and files with Supabase in eu-north-1, served on services.porticoplay.com, and the application servers with Fly.io. A transfer outside the EEA happens only on an adequacy decision (including the EU–US Data Privacy Framework), the EU standard contractual clauses (Module 3), or another Article 46 safeguard.
6. Helping with players’ rights
The console gives you tools to answer requests: access and export (JSON and CSV), erasure, correcting an email address, restriction, and consent history. Players can also use your “My data” page if you switch it on. If a player writes to us directly, we pass the request to you without undue delay.
7. Personal data breaches
We tell you without undue delay, and in any case within [24] hours of becoming aware of a breach that affects your data, with what we know and what we are doing about it. We send more as we learn it. We help you notify the authority and players where you need to.
8. Retention, deletion and return
While the agreement runs, we delete data on the schedules you set in the console. When it ends, you can export your data for 30 days; then we delete it within [60] days, unless the law requires us to keep it. Deleted data leaves our encrypted backups within [7/14/28] days. We confirm deletion in writing on request.
9. Audits and other help
We make available the information needed to show we comply. You may audit once a year, or after a breach or at an authority’s request, with 30 days’ notice. We may first offer documents, such as our security description and subprocessors’ certifications. We also help with data protection impact assessments, including our own assessment of the Rivals format.
10. Liability and law
Liability follows the main agreement. The DPA lasts as long as we process your data. Swedish law applies, with Stockholm District Court as the first instance, unless the main agreement says otherwise.