Our GDPR Commitment
Game Set Engage LLC ("GSE") is committed to protecting the privacy and data rights of all individuals, including those in the European Union and the United Kingdom. We have implemented comprehensive measures to ensure compliance with the General Data Protection Regulation (EU GDPR) and the UK General Data Protection Regulation (UK GDPR).
This page supplements our Privacy Policy, which applies to all users globally. If you are located in the EU or UK, the rights and protections described here apply to you in addition to those in our Privacy Policy.
Controller and Processor Roles
Understanding who controls and processes your data is important under GDPR:
- GSE as Controller: For data we collect directly (account information, usage data, analytics), GSE acts as the data controller
- GSE as Processor: When clubs use our platform to manage fan data, GSE acts as a data processor on behalf of the club (data controller). In this case, the club determines the purposes and means of processing, and GSE processes data on their instructions
- Joint controllership: For certain activities (such as engagement points calculation and campaign analytics), GSE and the club may act as joint controllers under Article 26
Data Processing Agreements
Clubs operating in the EU/EEA or processing data of EU/EEA residents can request a Data Processing Addendum (DPA) that complies with GDPR Article 28 requirements. Contact dpo@gamesetengage.com to request a DPA.
Legal Basis for Processing
We process personal data based on the following legal grounds, mapped to specific processing activities:
Contract Performance (Article 6(1)(b))
- Account creation and management
- Processing subscription payments via Stripe
- Delivering the Service (dashboard, events, campaigns)
- Customer support and communication
- Club-fan subscription management
Consent (Article 6(1)(a))
- Collection of precise geolocation data during campaign check-ins
- Marketing communications and newsletters (via SendGrid)
- Non-essential cookies and analytics tracking (see our Cookie Policy)
- Push notifications on mobile devices
- Optional profile enrichment features
Legitimate Interests (Article 6(1)(f))
- Platform security and fraud prevention (including detection of location spoofing)
- Aggregated analytics and platform performance optimization
- Marketing to existing customers (with easy opt-out)
- Improving and developing new Service features
We have conducted legitimate interest assessments for each of the above activities and can provide these upon request.
Legal Obligation (Article 6(1)(c))
- Tax record retention (billing data retained for 7 years)
- Responding to law enforcement requests
- Compliance with applicable regulations
Your Rights Under GDPR
As a data subject in the EU or UK, you have the following rights:
- Right of Access (Article 15): Request a copy of all personal data we hold about you, including campaign participation records and engagement data
- Right to Rectification (Article 16): Correct inaccurate or incomplete personal data. You can update most information directly in your account settings
- Right to Erasure (Article 17): Request deletion of your personal data. Note: some data may be retained where we have a legal obligation
- Right to Restrict Processing (Article 18): Limit how we process your data while we verify its accuracy or assess your objection
- Right to Data Portability (Article 20): Receive your data in a structured, commonly used, machine-readable format (JSON or CSV)
- Right to Object (Article 21): Object to processing based on legitimate interests, including profiling for engagement scoring
How to Exercise Your Rights
To exercise any of your GDPR rights, you can:
- Contact our Data Protection Officer at dpo@gamesetengage.com
- Use the privacy controls in your account settings (for access, rectification, and data export)
- Submit a request through our support system with the subject "GDPR Request"
We will verify your identity before processing your request. We aim to respond within 30 days. For complex requests or a high volume of requests, we may extend this period by up to 60 days, and will notify you of any extension within the initial 30-day period, as permitted by GDPR.
There is no fee for exercising your rights. However, we may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive.
Data Protection Measures
Technical Safeguards
- TLS/SSL encryption for all data in transit
- Encryption at rest for personal data in our Supabase PostgreSQL database
- Hashed password storage (bcrypt via Devise)
- Role-based access controls with seven distinct permission levels
- JWT-based authentication for mobile API with token expiration
- Regular security audits and penetration testing
- Automated backup and disaster recovery systems
Organizational Safeguards
- Privacy by design and by default principles applied in product development
- Regular staff training on data protection obligations
- Data Protection Impact Assessments (DPIAs) for high-risk processing activities
- Vendor due diligence and data processing agreements with all sub-processors
- Incident response and breach notification procedures
- Records of Processing Activities maintained under Article 30
Data Protection Impact Assessments
We have conducted DPIAs for the following high-risk processing activities, as required by GDPR Article 35:
- Location-based check-in campaigns: Collection and processing of precise geolocation data to determine fan presence at stadiums, partner venues, or home
- Engagement scoring and profiling: Automated calculation of engagement points based on campaign participation, location, and activity patterns
- Three-way data sharing: Data flows between clubs, fans, and partner venues through the campaign partnership model
DPIAs are reviewed annually or when significant changes are made to the relevant processing activities. Summaries are available upon request from our DPO.
Sub-Processors
We use the following sub-processors to deliver our Service. Each is bound by a data processing agreement:
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| Supabase | Database hosting (PostgreSQL) | United States |
| Amazon Web Services (AWS) | File storage (S3 — avatars, uploads) | United States |
| Stripe | Payment processing, subscription billing | United States |
| SendGrid (Twilio) | Transactional and marketing email | United States |
| Google (Places API) | Address geocoding and location services | United States |
| Redis (hosting provider) | Caching, Action Cable real-time messaging | United States |
We will notify affected customers before adding new sub-processors or making material changes to existing ones, providing a reasonable opportunity to object.
International Data Transfers
GSE is based in the United States. When we transfer personal data from the EEA or UK to the United States or other countries without an adequacy decision, we ensure adequate protection through:
- Standard Contractual Clauses (SCCs): We use the European Commission's standard contractual clauses (June 2021 version) for transfers to all sub-processors
- UK International Data Transfer Addendum: For transfers of UK personal data, we supplement SCCs with the UK Addendum as required by the ICO
- Transfer Impact Assessments: We have assessed the legal framework of each destination country and implemented supplementary technical measures where necessary
- Adequacy decisions: Where the European Commission or UK Secretary of State has issued an adequacy decision for a destination country, we rely on that decision
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Account data: Until account deletion, which takes effect immediately and cannot be undone
- Billing data: 7 years for tax and accounting obligations
- Campaign participation data: Life of account; anonymized upon deletion
- Marketing consent records: Until consent is withdrawn, or 3 years of inactivity
- Analytics data: 26 months from collection
- Server logs: 90 days
Automated Decision-Making and Profiling
We use automated processing in the following areas:
- Engagement point calculation: Points are automatically calculated based on your check-in location (5x stadium, 3x venue, 1x home) and campaign type. This is based on objective rules and does not involve subjective profiling
- Fraud prevention: Automated detection of location spoofing and suspicious check-in patterns. Flagged accounts are reviewed by a human before any action is taken
- Content recommendations: Suggesting relevant clubs and campaigns based on your location and subscription history
None of these automated processes produce legal effects or similarly significantly affect you within the meaning of Article 22. You have the right to request human intervention in any automated decision-making process, express your point of view, and contest the decision by contacting our DPO.
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (Article 33)
- Inform affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms (Article 34)
- Provide clear information about the nature and scope of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken to address the breach
- Document all breaches regardless of risk level, including those not reported to the supervisory authority, in our internal breach register
EU Representative
As GSE is established outside the EU, we have appointed an EU representative in accordance with GDPR Article 27. Our EU representative can be contacted for any GDPR-related matters:
EU Representative Email: eu-representative@gamesetengage.com For data subject requests and supervisory authority inquiries regarding EU GDPR
UK Representative
For individuals in the United Kingdom, we have appointed a UK representative in accordance with UK GDPR Article 27:
UK Representative Email: uk-representative@gamesetengage.com For data subject requests and ICO inquiries regarding UK GDPR
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with GDPR requirements. You can contact:
- EU residents: Your local data protection authority. A full list is available on the European Data Protection Board website
- UK residents: The Information Commissioner's Office (ICO) at ico.org.uk
We encourage you to contact our DPO first so we can try to resolve your concern directly.
Records of Processing Activities
In accordance with Article 30, we maintain comprehensive records of our processing activities, including the purposes of processing, categories of data subjects and personal data, categories of recipients, international transfers, retention periods, and technical and organizational security measures. These records are available to supervisory authorities upon request.
Contact Our Data Protection Officer
For any GDPR-related questions, requests, or concerns, please contact our Data Protection Officer:
Data Protection Officer Game Set Engage LLC Email: dpo@gamesetengage.com Subject: GDPR Request — [Type of Request]