GAM SentinelBack

Legal

Privacy PolicyTerms of ServiceCookie PolicyGDPR Compliance

GDPR Compliance

Last updated: June 22, 2026

1. Our Commitment to Data Protection

H&T GAMING LTD, operating GAM Sentinel, is committed to full compliance with the European Union's General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and the United Kingdom's Data Protection Act 2018 ("UK GDPR"). As a UK-registered company processing data of EEA and UK residents, we adhere to both regulatory frameworks. This page outlines our technical and organizational measures, your rights as a data subject, and how we handle personal data.

Our primary data processing infrastructure is located within the European Union (Germany), ensuring that EU personal data remains within jurisdictions with adequate protection levels. For UK data subjects, the EU has been granted adequacy status, and vice versa, ensuring seamless lawful transfers between the UK and EU.

2. GDPR Principles We Follow

All data processing at GAM Sentinel adheres to the seven GDPR principles:

  • Lawfulness, fairness, and transparency: We process data only with a valid legal basis and are transparent about our practices through this policy, our Privacy Policy, and our Cookie Policy.
  • Purpose limitation: Data is collected for specific, explicit purposes (ad monitoring, compliance, analytics) and not processed in ways incompatible with those purposes.
  • Data minimization: We collect only the data necessary to deliver our services. We do not request access to GAM data beyond what our features require.
  • Accuracy: We synchronize data with the Google Ad Manager API on a regular schedule to ensure reporting accuracy.
  • Storage limitation: Data is retained only as long as necessary for service delivery, then securely deleted per our retention schedules.
  • Integrity and confidentiality: Enterprise-grade security measures protect data at rest and in transit (see Section 5).
  • Accountability: We maintain records of processing activities, conduct impact assessments, and can demonstrate compliance upon request.

3. Legal Bases for Processing

Under Article 6 of the GDPR, we rely on the following legal bases:

Processing ActivityLegal BasisGDPR Article
Account creation and managementPerformance of contractArt. 6(1)(b)
GAM data fetching and monitoringPerformance of contractArt. 6(1)(b)
Alert notifications via emailPerformance of contractArt. 6(1)(b)
Website analyticsLegitimate interestArt. 6(1)(f)
Security logging and fraud preventionLegitimate interestArt. 6(1)(f)
Marketing communicationsConsentArt. 6(1)(a)
Legal and regulatory complianceLegal obligationArt. 6(1)(c)

4. Your Data Subject Rights

As a data subject under GDPR, you have the following rights. We respond to all valid requests within 30 days (extendable by 60 days for complex requests, with prior notification):

4.1 Right of Access (Art. 15)

You may request a complete copy of all personal data we process about you, including the purposes of processing, categories of data, recipients, and retention periods. We will provide this in a commonly used electronic format (JSON or CSV).

4.2 Right to Rectification (Art. 16)

You may request correction of inaccurate personal data or completion of incomplete data. For account details, you can update most fields directly in your dashboard settings.

4.3 Right to Erasure (Art. 17)

You may request deletion of your personal data when:

  • The data is no longer necessary for its original purpose
  • You withdraw consent (where consent was the legal basis)
  • You successfully object to processing
  • The data was unlawfully processed

Note: We may retain certain data where required by law (e.g., billing records for tax purposes) or to exercise/defend legal claims.

4.4 Right to Restriction (Art. 18)

You may request that we restrict processing of your data while: (a) you contest its accuracy; (b) you object to processing pending our assessment; or (c) processing is unlawful but you prefer restriction over erasure.

4.5 Right to Data Portability (Art. 20)

You may receive your personal data in a structured, commonly used, machine-readable format (JSON). This includes account data, alert configurations, and any data you provided to us. We can transmit this directly to another controller upon request.

4.6 Right to Object (Art. 21)

You may object to processing based on legitimate interest (Art. 6(1)(f)). We will cease processing unless we demonstrate compelling legitimate grounds that override your interests. You may object to direct marketing at any time, and we will cease immediately.

4.7 Right Against Automated Decision-Making (Art. 22)

GAM Sentinel's smart alerts use automated rules to detect anomalies. However, these alerts are informational — they notify you of potential issues. Automated compliance actions (like account withdrawal) are opt-in and only execute rules you have explicitly configured and enabled. You can disable automated actions at any time.

How to Exercise Your Rights

Submit requests to:

  • Email: gdpr@hntgaming.me
  • Subject line: "GDPR Rights Request — [Your Right]"

We will verify your identity before processing requests. For account holders, verification is through your registered email. For non-account holders, we may request government-issued ID.

5. Technical and Organizational Measures (Art. 32)

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk:

5.1 Encryption

  • In transit: Industry-standard TLS encryption for all API communications and web traffic
  • At rest: Strong encryption for sensitive data fields in the database
  • Passwords: Hashed using industry-standard algorithms, never stored in plaintext

5.2 Access Control

  • Role-based access control (RBAC) with multiple permission tiers
  • Token-based authentication with short-lived access tokens and automatic rotation
  • Key-based server access with password authentication disabled
  • Least-privilege access policies across all systems
  • Automated intrusion detection and prevention

5.3 Infrastructure Security

  • Servers hosted within the EU (Germany)
  • Network and host-level firewalls with default-deny policies
  • Continuous monitoring of sensitive system activity
  • Regular malware and integrity scanning
  • Hardened server configuration with restricted outbound access

5.4 Operational Measures

  • Regular security audits of application code
  • Dependency vulnerability scanning
  • Incident response plan with 72-hour breach notification procedure
  • Staff training on data protection
  • Data Processing Agreements (DPAs) with all sub-processors

6. Data Processing Agreements

We maintain signed DPAs with all sub-processors that handle personal data on our behalf:

Sub-ProcessorPurposeLocation
Hetzner Online GmbHServer hosting and infrastructureGermany (EU)
Amazon Web Services (AWS)Cloud infrastructure and hostingEU & US (SCCs in place)
Google Cloud Platform (GCP)Cloud services and API infrastructureEU data processing (SCCs in place)
Contabo GmbHServer hosting and computeGermany (EU)
Hostinger International LtdWeb hosting and DNSEU (Lithuania)
Google LLC (Ad Manager API)Ad data source via APIEU data processing (SCCs in place)
Google LLC (Analytics)Website usage analyticsEU data processing (IP anonymization enabled)
Google Workspace (SMTP)Email delivery for notificationsEU data processing

7. International Data Transfers

H&T GAMING LTD is a UK-registered company. Our servers are located in Germany (EU). The UK and EU maintain mutual adequacy decisions, meaning data flows freely between the UK and EEA. For any transfer of personal data outside the UK/EEA, we ensure appropriate safeguards are in place:

  • EU-US Data Privacy Framework: For US-based sub-processors certified under the framework
  • Standard Contractual Clauses (SCCs): For EU transfers to countries without an adequacy decision
  • UK International Data Transfer Agreement (IDTA): For UK-governed transfers outside the UK
  • Supplementary measures: Technical measures (encryption) to ensure data protection in transit

8. Data Protection Impact Assessments (Art. 35)

We conduct DPIAs for processing activities that are likely to result in high risk to data subjects. Our assessments cover:

  • Large-scale processing of ad performance data (systematic monitoring)
  • Automated decision-making for compliance actions
  • Processing of data relating to vulnerable categories (if applicable)

DPIA results are reviewed annually and updated when processing activities change materially.

9. Breach Notification (Art. 33 & 34)

In the event of a personal data breach:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (Art. 33)
  • If the breach is likely to result in high risk to data subjects, we will notify affected individuals without undue delay (Art. 34)
  • Notification will include: nature of the breach, categories of data affected, likely consequences, and measures taken to mitigate harm

10. Data Protection Officer

For GDPR inquiries, data subject access requests, or to report a concern:

  • Email: gdpr@hntgaming.me
  • Response time: Within 5 business days for general inquiries, 30 days for formal rights requests

11. Supervisory Authorities

If you are unsatisfied with our response to a data protection request, you have the right to lodge a complaint with the relevant supervisory authority:

For UK residents:

  • Information Commissioner's Office (ICO)
  • Website: ico.org.uk
  • Helpline: 0303 123 1113

For EEA residents:

You may contact your local data protection authority. For users whose data is processed in Germany, the relevant authority is:

  • Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI)
  • Website: www.bfdi.bund.de

We encourage you to contact us first at gdpr@hntgaming.me so we can resolve any concerns directly.

12. Record of Processing Activities (Art. 30)

We maintain a comprehensive Record of Processing Activities (ROPA) documenting all data processing operations, their purposes, legal bases, data categories, retention periods, and security measures. This record is available to supervisory authorities upon request.

13. Updates

This GDPR compliance page is reviewed and updated at least annually, or whenever there are material changes to our processing activities. All updates are reflected in the "Last updated" date at the top of this page.

© 2026 H&T GAMING LTD. All rights reserved.

Questions? legal@hntgaming.me