1. Introduction and scope
1.1
PlatformPapa operates an independent iGaming B2B directory. We do not operate gambling services or process player account data on behalf of casinos.
1.2
This policy applies to visitors, quote requesters, listing-owner Account holders, provider contacts, and administrators of platformpapa.com. It should be read with our Terms and Conditions and Cookie Policy.
2. Data controller and contacts
2.1
The data controller responsible for personal data described in this policy is PlatformPapa, contactable at privacy@platformpapa.com.
2.2
We have not appointed a mandatory Data Protection Officer. Privacy enquiries may be directed to the contact details in Section 18.
3. Definitions
3.1
- “Personal data”
- Any information relating to an identified or identifiable natural person, as defined under applicable privacy law.
- “Processing”
- Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
- “Processor”
- A third party that processes personal data on our documented instructions.
- “Sell / Share (US)”
- Has the meanings given under CCPA/CPRA. We do not sell personal data for monetary consideration. Limited affiliate click measurement may constitute sharing for cross-context behavioural advertising under some US state laws — see Section 12.
4. Personal data we process
4.1
Depending on your interaction, we may process:
- Identity & contact data — name, business email, company name, role, phone if provided.
- Quote & commercial data — budget range, target markets, licence status, project requirements, messages you submit.
- Technical & usage data — IP address, truncated or hashed IP derivatives, browser type, device identifiers, referrer URL, pages viewed, timestamps, server logs.
- Affiliate & click data — outbound link slug, click time, referrer, anonymized IP hash for reporting.
- Cookie & consent data — cookie preference selections stored locally and associated consent timestamps.
- Administration data — credentials and session identifiers for authorized admin users only.
- Account & claim data — account name, business email, password hash, session identifiers, listing claimed, domain, DNS verification token, verification attempts, status, and timestamps.
4.2
We do not intentionally collect special category data (e.g., health, biometric, political opinions). Please do not submit such data in free-text fields.
5. Sources of personal data
5.1
- Directly from you when you submit forms, email us, or communicate with us.
- Automatically through cookies, analytics (where consented), and server logs.
- From publicly available business sources when maintaining directory listings.
- From listed providers where you have asked us to facilitate an introduction.
- From public DNS responses when you ask us to verify control of a listing domain.
6. Purposes and legal bases
6.1
For visitors in the EEA and UK, we rely on GDPR Article 6 legal bases as summarised below:
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Operate the website, deliver directory content, maintain security | Legitimate interests (Art. 6(1)(f)) — balanced against your rights |
| Respond to quote requests and share leads with selected providers | Contract / pre-contract steps (Art. 6(1)(b)) and consent where required |
| Affiliate click logging and commission reporting | Legitimate interests (Art. 6(1)(f)) |
| Analytics to improve content and navigation | Consent (Art. 6(1)(a)) — optional cookies only |
| Comply with law, enforce terms, defend legal claims | Legal obligation (Art. 6(1)(c)) / legitimate interests (Art. 6(1)(f)) |
| Admin authentication | Legitimate interests / performance of internal administration |
| Create listing-owner accounts, process claims, and verify domain control | Contract / pre-contract steps (Art. 6(1)(b)) and legitimate interests in directory integrity (Art. 6(1)(f)) |
| Send transactional account, claim, verification, and quote emails | Contract / pre-contract steps and legitimate interests in service communications |
6.2
Where we rely on legitimate interests, you may object as described in Section 11. We will assess objection requests in line with GDPR requirements.
7. Recipients and processors
7.1
Personal data may be disclosed to:
- Infrastructure providers — Hetzner Online GmbH (European Union (Germany)) for hosting and database services under data processing terms.
- Analytics providers — Google Analytics when you opt in via cookie settings.
- Email delivery providers — SMTP and transactional-email infrastructure used to deliver account, claim, and enquiry notices.
- Listed B2B providers — when you request quotes and authorize lead sharing.
- Professional advisers — lawyers, accountants, or insurers under confidentiality obligations.
- Authorities — where required by applicable law or court order.
7.2
We require processors to implement appropriate safeguards and process data only on our instructions.
8. International transfers
8.1
We primarily store data in the European Union. Some recipients (for example Google LLC in the United States) may process data outside your country.
8.2
Where GDPR or UK GDPR applies, we implement appropriate safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent mechanisms approved under applicable law.
9. Retention
9.1
| Data category | Typical retention |
|---|---|
| Quote requests & lead records | Up to 36 months after last interaction, unless longer retention is required by law or dispute |
| Server & security logs | Up to 90 days, unless needed for incident investigation |
| Affiliate click logs | Up to 24 months for reporting and audit |
| Analytics data (Google) | Per provider settings, typically 14–26 months when enabled |
| Cookie consent records | Until you clear site data or withdraw consent |
| Listing-owner account | For the life of the account and ordinarily up to 36 months after closure, subject to security, dispute, and legal needs |
| Listing claims & DNS verification | For the life of the claim and up to 36 months afterward for ownership history, fraud prevention, and dispute handling |
9.2
We may retain anonymized or aggregated data that no longer identifies you without limit.
10. Security measures
10.1
We implement technical and organizational measures appropriate to the risk, including access controls, encrypted transport (HTTPS), hashed credentials for protected accounts, and least-privilege administration. No method of transmission or storage is completely secure.
11. Your rights — EEA & UK
11.1
Subject to conditions and exceptions in GDPR / UK GDPR, you may have the right to:
- request access to personal data we hold about you;
- request rectification of inaccurate data;
- request erasure ('right to be forgotten');
- request restriction of processing;
- object to processing based on legitimate interests;
- request data portability for data you provided in structured form;
- withdraw consent at any time for consent-based processing;
- lodge a complaint with a supervisory authority.
11.2
To exercise these rights, email privacy@platformpapa.com. We may need to verify your identity before responding. We aim to respond within one month, extendable where permitted by law.
12. Your rights — United States
12.1
Residents of California and certain other US states may have rights to know, access, delete, and correct personal information, and to opt out of sale or sharing for cross-context behavioural advertising.
12.2
Notice at collection. We collect the categories described in Section 4 for the business purposes in Section 6. We do not sell personal information for money. Server-side affiliate measurement may be considered sharing under CCPA/CPRA; you may opt out by contacting privacy@platformpapa.com or disabling non-essential cookies where applicable.
12.3
We will not discriminate against you for exercising privacy rights. Authorized agents may submit verified requests on your behalf where permitted by law.
14. Children
14.1
The Service is directed to business users aged eighteen (18) or older. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data and we will take appropriate steps to delete it.
15. Automated decision-making
15.1
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. Directory scores and rankings are editorial/analytical outputs for information only.
16. Changes to this policy
16.1
We may update this Privacy Policy to reflect legal, technical, or business changes. Material updates will be posted on this page with a revised “Last updated” date. Where required by law, we will provide additional notice or request consent.
17. Complaints and supervisory authorities
17.1
You may lodge a complaint with your local supervisory authority. Examples include:
- Ireland: Data Protection Commission — dataprotection.ie
- United Kingdom: Information Commissioner's Office — ico.org.uk
- European Union: your national data protection authority — EDPB member list
18. Contact
18.1
Privacy requests: privacy@platformpapa.com. General enquiries: quote form(include “Privacy request”).
Schedule C — Summary — CCPA categories (California)
During the preceding twelve months we may have collected identifiers, commercial information (quote details), internet activity (logs, analytics if consented), and professional information. Sources and purposes are described in Sections 5–6. We disclose data to service providers and, with your direction, listed B2B vendors. We do not sell personal information for monetary consideration.