GDPR Compliance
Last updated: June 22, 2026
1. Our Commitment to Data Protection
H&T GAMING LTD, operating GAM Sentinel, is committed to full compliance with the European Union's General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and the United Kingdom's Data Protection Act 2018 ("UK GDPR"). As a UK-registered company processing data of EEA and UK residents, we adhere to both regulatory frameworks. This page outlines our technical and organizational measures, your rights as a data subject, and how we handle personal data.
Our primary data processing infrastructure is located within the European Union (Germany), ensuring that EU personal data remains within jurisdictions with adequate protection levels. For UK data subjects, the EU has been granted adequacy status, and vice versa, ensuring seamless lawful transfers between the UK and EU.
2. GDPR Principles We Follow
All data processing at GAM Sentinel adheres to the seven GDPR principles:
- Lawfulness, fairness, and transparency: We process data only with a valid legal basis and are transparent about our practices through this policy, our Privacy Policy, and our Cookie Policy.
- Purpose limitation: Data is collected for specific, explicit purposes (ad monitoring, compliance, analytics) and not processed in ways incompatible with those purposes.
- Data minimization: We collect only the data necessary to deliver our services. We do not request access to GAM data beyond what our features require.
- Accuracy: We synchronize data with the Google Ad Manager API on a regular schedule to ensure reporting accuracy.
- Storage limitation: Data is retained only as long as necessary for service delivery, then securely deleted per our retention schedules.
- Integrity and confidentiality: Enterprise-grade security measures protect data at rest and in transit (see Section 5).
- Accountability: We maintain records of processing activities, conduct impact assessments, and can demonstrate compliance upon request.
3. Legal Bases for Processing
Under Article 6 of the GDPR, we rely on the following legal bases:
| Processing Activity | Legal Basis | GDPR Article |
|---|---|---|
| Account creation and management | Performance of contract | Art. 6(1)(b) |
| GAM data fetching and monitoring | Performance of contract | Art. 6(1)(b) |
| Alert notifications via email | Performance of contract | Art. 6(1)(b) |
| Website analytics | Legitimate interest | Art. 6(1)(f) |
| Security logging and fraud prevention | Legitimate interest | Art. 6(1)(f) |
| Marketing communications | Consent | Art. 6(1)(a) |
| Legal and regulatory compliance | Legal obligation | Art. 6(1)(c) |
4. Your Data Subject Rights
As a data subject under GDPR, you have the following rights. We respond to all valid requests within 30 days (extendable by 60 days for complex requests, with prior notification):
4.1 Right of Access (Art. 15)
You may request a complete copy of all personal data we process about you, including the purposes of processing, categories of data, recipients, and retention periods. We will provide this in a commonly used electronic format (JSON or CSV).
4.2 Right to Rectification (Art. 16)
You may request correction of inaccurate personal data or completion of incomplete data. For account details, you can update most fields directly in your dashboard settings.
4.3 Right to Erasure (Art. 17)
You may request deletion of your personal data when:
- The data is no longer necessary for its original purpose
- You withdraw consent (where consent was the legal basis)
- You successfully object to processing
- The data was unlawfully processed
Note: We may retain certain data where required by law (e.g., billing records for tax purposes) or to exercise/defend legal claims.
4.4 Right to Restriction (Art. 18)
You may request that we restrict processing of your data while: (a) you contest its accuracy; (b) you object to processing pending our assessment; or (c) processing is unlawful but you prefer restriction over erasure.
4.5 Right to Data Portability (Art. 20)
You may receive your personal data in a structured, commonly used, machine-readable format (JSON). This includes account data, alert configurations, and any data you provided to us. We can transmit this directly to another controller upon request.
4.6 Right to Object (Art. 21)
You may object to processing based on legitimate interest (Art. 6(1)(f)). We will cease processing unless we demonstrate compelling legitimate grounds that override your interests. You may object to direct marketing at any time, and we will cease immediately.
4.7 Right Against Automated Decision-Making (Art. 22)
GAM Sentinel's smart alerts use automated rules to detect anomalies. However, these alerts are informational — they notify you of potential issues. Automated compliance actions (like account withdrawal) are opt-in and only execute rules you have explicitly configured and enabled. You can disable automated actions at any time.
How to Exercise Your Rights
Submit requests to:
- Email: gdpr@hntgaming.me
- Subject line: "GDPR Rights Request — [Your Right]"
We will verify your identity before processing requests. For account holders, verification is through your registered email. For non-account holders, we may request government-issued ID.
5. Technical and Organizational Measures (Art. 32)
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk:
5.1 Encryption
- In transit: Industry-standard TLS encryption for all API communications and web traffic
- At rest: Strong encryption for sensitive data fields in the database
- Passwords: Hashed using industry-standard algorithms, never stored in plaintext
5.2 Access Control
- Role-based access control (RBAC) with multiple permission tiers
- Token-based authentication with short-lived access tokens and automatic rotation
- Key-based server access with password authentication disabled
- Least-privilege access policies across all systems
- Automated intrusion detection and prevention
5.3 Infrastructure Security
- Servers hosted within the EU (Germany)
- Network and host-level firewalls with default-deny policies
- Continuous monitoring of sensitive system activity
- Regular malware and integrity scanning
- Hardened server configuration with restricted outbound access
5.4 Operational Measures
- Regular security audits of application code
- Dependency vulnerability scanning
- Incident response plan with 72-hour breach notification procedure
- Staff training on data protection
- Data Processing Agreements (DPAs) with all sub-processors
6. Data Processing Agreements
We maintain signed DPAs with all sub-processors that handle personal data on our behalf:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting and infrastructure | Germany (EU) |
| Amazon Web Services (AWS) | Cloud infrastructure and hosting | EU & US (SCCs in place) |
| Google Cloud Platform (GCP) | Cloud services and API infrastructure | EU data processing (SCCs in place) |
| Contabo GmbH | Server hosting and compute | Germany (EU) |
| Hostinger International Ltd | Web hosting and DNS | EU (Lithuania) |
| Google LLC (Ad Manager API) | Ad data source via API | EU data processing (SCCs in place) |
| Google LLC (Analytics) | Website usage analytics | EU data processing (IP anonymization enabled) |
| Google Workspace (SMTP) | Email delivery for notifications | EU data processing |
7. International Data Transfers
H&T GAMING LTD is a UK-registered company. Our servers are located in Germany (EU). The UK and EU maintain mutual adequacy decisions, meaning data flows freely between the UK and EEA. For any transfer of personal data outside the UK/EEA, we ensure appropriate safeguards are in place:
- EU-US Data Privacy Framework: For US-based sub-processors certified under the framework
- Standard Contractual Clauses (SCCs): For EU transfers to countries without an adequacy decision
- UK International Data Transfer Agreement (IDTA): For UK-governed transfers outside the UK
- Supplementary measures: Technical measures (encryption) to ensure data protection in transit
8. Data Protection Impact Assessments (Art. 35)
We conduct DPIAs for processing activities that are likely to result in high risk to data subjects. Our assessments cover:
- Large-scale processing of ad performance data (systematic monitoring)
- Automated decision-making for compliance actions
- Processing of data relating to vulnerable categories (if applicable)
DPIA results are reviewed annually and updated when processing activities change materially.
9. Breach Notification (Art. 33 & 34)
In the event of a personal data breach:
- We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (Art. 33)
- If the breach is likely to result in high risk to data subjects, we will notify affected individuals without undue delay (Art. 34)
- Notification will include: nature of the breach, categories of data affected, likely consequences, and measures taken to mitigate harm
10. Data Protection Officer
For GDPR inquiries, data subject access requests, or to report a concern:
- Email: gdpr@hntgaming.me
- Response time: Within 5 business days for general inquiries, 30 days for formal rights requests
11. Supervisory Authorities
If you are unsatisfied with our response to a data protection request, you have the right to lodge a complaint with the relevant supervisory authority:
For UK residents:
- Information Commissioner's Office (ICO)
- Website: ico.org.uk
- Helpline: 0303 123 1113
For EEA residents:
You may contact your local data protection authority. For users whose data is processed in Germany, the relevant authority is:
- Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI)
- Website: www.bfdi.bund.de
We encourage you to contact us first at gdpr@hntgaming.me so we can resolve any concerns directly.
12. Record of Processing Activities (Art. 30)
We maintain a comprehensive Record of Processing Activities (ROPA) documenting all data processing operations, their purposes, legal bases, data categories, retention periods, and security measures. This record is available to supervisory authorities upon request.
13. Updates
This GDPR compliance page is reviewed and updated at least annually, or whenever there are material changes to our processing activities. All updates are reflected in the "Last updated" date at the top of this page.