POLICY · LAST UPDATED 6 AUGUST 2026
Privacy policy
This policy explains what personal data Iudara collects, why, who we share it with, and what you can do about it. It covers this website and the Iudara compliance platform. We have written it to describe what the service actually does rather than to cover every theoretical possibility — if something here does not match your experience of the product, tell us and we will fix the policy.
Who is responsible for your data
The controller for this website and for the Iudara platform is [to be confirmed: registered company name], registered in [to be confirmed: country of incorporation] under number [to be confirmed: company registration number], registered office [to be confirmed: registered office address].
For privacy questions, contact [to be confirmed: privacy contact address]. Our data protection contact is [to be confirmed: DPO or data-protection contact, and whether a DPO is formally appointed].
Two different roles. When you browse this site, fill in our contact form, or use the platform as a named user, we are the controller of that data. When one of our clients uploads their own material into their workspace — records about their staff, officers, key-function holders and beneficial owners — we handle it as a processor on that client's instructions. If you are one of those individuals, your employer is the controller and you should approach them first; we will help them respond.
What we collect on this website
Contact form. The form on our contact page collects your email address and message (both required) and, if you choose to give them, your name, company, and the jurisdiction you are interested in. We store the submission, email it to our team, and send you an acknowledgement. Your email address is used as the reply-to address on the internal notification.
Jurisdiction finder. The four-question quiz on our home page stores only your answers and the recommendation it produced. It does not ask for your email address and does not link your answers to any other record — there is no email gate on it, by design.
Anti-spam and rate limiting. Both forms are protected by Cloudflare Turnstile, and both are rate limited. Your IP address is sent to Cloudflare as part of the Turnstile check and is used as the rate-limiting key in our Redis cache. Your IP address is not written to our database and not stored alongside your submission.
Booking a call. Our contact page offers a Calendly booking widget, which only loads if you click to open it. Anything you enter there goes to Calendly under Calendly's own privacy policy, not into our systems.
Analytics. We run our own Umami analytics installation on our own infrastructure, on the public marketing pages only. The signed-in platform is deliberately not tracked. It runs only if you accept it — the script is not loaded until you agree on the cookie banner, and it stops being loaded the moment you withdraw. See our cookies page for the full detail and the control that changes your choice.
Error monitoring. We use the Sentry SDK reporting into our own self-hosted error tracker. Reports are routed through our own domain rather than a third-party origin. Error events pass through a redaction step that strips values held under keys such as email, phone, password, token, passport, tax id and address before the event is sent. A sample of browser sessions is recorded for diagnosis (roughly one in ten sessions, and sessions in which an error occurs). Session recordings do not pass through the same redaction step, so [to be confirmed: confirmation of session-replay masking settings and whether replay should stay enabled].
What the platform holds
If you have an account, we hold your name, email address, and optionally a phone number and avatar, plus whether you have enrolled in multi-factor authentication and when you were last active. Invitations and password-reset links are stored as one-way hashes, never as usable tokens.
We keep an activity log of actions taken in the platform. Each entry records who acted, what changed (before and after), the IP address, and the browser user agent. This is a compliance control: an audit trail is what makes the evidence in the platform defensible to a regulator.
Client workspaces contain records about people connected to the client's business — a personnel register with names, work email addresses, roles, and employment dates; key-function and personal-licence holdings with reference numbers and approval and expiry dates; training records; policy acknowledgements; and risk and third-party ownership assignments. Invoices carry the client's billing name, address, and VAT number.
Uploaded documents. Licensing work involves identity and due-diligence documents — for example passport scans, proof of address, and beneficial-ownership paperwork. These are held as files in a private storage bucket, not as structured database fields. They are never publicly addressable: every download is a fresh signed link that expires after five minutes, and access is scoped to the workspace the document belongs to. Uploads are size-capped, content-type checked, hashed, and virus-scanned; anything that fails is quarantined rather than accepted.
External auditors. On a client's instruction we can issue an auditor a time-limited link to a defined set of finalised documents. Grants expire (by default after two weeks, and at most after ninety days), can be revoked immediately, and every view and download is logged with the auditor's IP address and user agent.
Why we are allowed to process it
The table below sets out our reading of the purposes and lawful bases. It has been drafted from how the system actually works and requires legal confirmation: [to be confirmed: counsel sign-off on lawful bases, and a legitimate-interests assessment where that basis is relied on].
| What we do | Why | Lawful basis |
|---|---|---|
| Respond to a contact-form enquiry | Answer your question and, if relevant, discuss working together | Steps taken at your request before entering a contract; legitimate interests |
| Store jurisdiction-finder answers | Understand which jurisdictions visitors are interested in and improve the tool | Legitimate interests |
| Turnstile checks and rate limiting | Keep the forms usable and block automated abuse | Legitimate interests |
| Run accounts, authentication, and MFA | Provide the platform you or your employer subscribed to | Performance of a contract |
| Maintain the activity log and auditor access log | Provide a defensible audit trail and detect misuse | Legitimate interests; our clients' legal obligations |
| Hold client licensing and due-diligence documents | Deliver the licensing and compliance service | Processed on our client's instructions as processor |
| Send service and billing email | Invitations, password resets, deadline and invoice reminders | Performance of a contract |
| Analytics on marketing pages | Understand which pages are useful | Consent, which you can withdraw at any time |
| Error monitoring | Find and fix faults | Legitimate interests |
Who else processes your data
We use the service providers below. Each is engaged under a written agreement and processes data only on our instructions. Whether a signed data processing agreement is on file with each of them is [to be confirmed: confirmation of executed DPAs and the transfer mechanism (for example standard contractual clauses) for each provider].
| Provider | What it does for us | Where it runs |
|---|---|---|
| Supabase | Database, authentication, and file storage | London (eu-west-2) |
| Vercel | Website and application hosting | London (lhr1) |
| Upstash | Redis cache — rate-limit counters keyed by IP address, and a short-lived cache of your profile (name, phone, role) held for up to sixty seconds | Stockholm (arn1) |
| Resend | Sending transactional and notification email | [to be confirmed: region] |
| Cloudflare | Turnstile anti-abuse checks on public forms; receives your IP address | [to be confirmed: region] |
| Cloudmersive | Virus scanning of uploaded documents | [to be confirmed: region] |
| Sanity | Content management for marketing pages | [to be confirmed: region] |
| Calendly | Optional call booking, only if you open the widget | [to be confirmed: region] |
| Self-hosted Umami and error tracker | Analytics and error monitoring on our own infrastructure | [to be confirmed: hosting location of the self-hosted analytics and error servers] |
We do not sell personal data, and we do not share it for advertising. We may disclose data where the law requires it, or to a regulator or professional adviser in connection with a client engagement.
How long we keep it
The table below is our retention schedule. A job runs every day and applies it: where a period is stated, records past that period are deleted from the live system automatically. Where a period is still being decided, nothing is deleted — we keep the data until the period is set, rather than pick a number in the meantime.
| What | How long we keep it | Why |
|---|---|---|
| Audit trail — a record of actions taken in the platform: who did what, to which record, and from which IP address | 7 years from the date of the action. Records are copied to cold storage before they are removed from the live system | An audit trail is what lets a licensing decision be reconstructed years later, and gambling regulators expect it to still exist. Whether a shorter or longer floor applies in a particular jurisdiction is [to be confirmed: confirmation of the per-jurisdiction audit-trail retention minimums that apply to us (for example UK and Estonia), and whether 7 years satisfies all of them. Until this is confirmed, records are kept, never removed early] |
| Scheduled-job records — which automated jobs ran, when, and whether they succeeded | 90 days | Operational monitoring only. These records contain no information about you. |
| Password reset links | 30 days after the link expires | A reset link is single-use and valid for thirty minutes. Once it has expired it cannot do anything, so we keep only a short window in which a reset can still be investigated. |
| Records of requests you make about your data (export, correction, deletion) | Kept — no deletion period is set | Deleting the record of a deletion request would destroy the evidence that we honoured it. Any period here is [to be confirmed: how long records of data-subject requests should be kept after they are completed] |
| Contact-form enquiries and jurisdiction-quiz answers | Kept — no deletion period is set | How long an enquiry that did not become an engagement should be kept is [to be confirmed: the retention period for unconverted enquiries and quiz responses, ideally split between those we have replied to and those we have not] |
| In-app notifications | Kept — no deletion period is set | A notification can be the only surviving record that you were told something on a given day, so we have not treated it as disposable. The period is [to be confirmed: the retention period for in-app notifications] |
| Records our clients have archived or deleted inside the product — staff and officer records, counterparties, risk registers, engagement documents | Kept — no deletion period is set | These are the anti-money-laundering and due-diligence records our clients are required by their own licences to retain, and the minimum differs by jurisdiction. The period is [to be confirmed: the per-jurisdiction record-keeping minimums for client due-diligence material, and how long archived or deleted records are held after an engagement ends] |
Some categories have a floor set by law rather than by us — accounting records, and the anti-money-laundering and due-diligence records our clients are required to keep. Where a client instructs us to delete something we hold as processor, we will do so unless we are required to keep it.
Every run of the retention job is itself recorded in the audit trail, including what it removed.
Your rights
If the GDPR or the UK GDPR applies to you, you can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop certain processing, object to processing based on legitimate interests, and ask for your data in a portable format. You can also complain to a supervisory authority — the relevant one is [to be confirmed: lead supervisory authority].
If you have an account: the data and privacy page in your settings is the way to raise a request. You can request an export of your data, lodge a rectification notice, or request account deletion, and you can withdraw a request while it is still pending. Everyday corrections — your name, phone number — you can make yourself in settings without raising anything.
If you do not have an account: write to the privacy contact above, or use the contact form.
Requests raised through the platform are recorded and acknowledged immediately; the export, correction, or deletion itself is carried out by our team. Our target and maximum times for completing a request are [to be confirmed: the response timescale we commit to. The statutory maximum is one month; the platform records requests but does not yet fulfil them automatically, so this must reflect the manual process].
Automated decisions
We do not make decisions about you by automated means that produce legal effects. The jurisdiction finder is an indicative tool built from the criteria our advisors weigh in discovery; it produces a suggestion, not a decision, and it does not profile you as an individual. Compliance checks in the platform evaluate a client's own records against deadlines and requirements — they flag work to be done, they do not decide anything about a person.
How we protect it
- Multi-factor authentication is enforced: every account must enrol, and reaching protected areas requires a second factor.
- Data is separated per client workspace at the database level, with row-level security in addition to application checks.
- Files live in a private bucket. There are no public file URLs; downloads use links that expire after five minutes.
- Uploads are checked for size and real content type, hashed, and virus-scanned, with failures quarantined.
- Invitation, password-reset, and auditor tokens are stored only as hashes. Password resets expire after thirty minutes and sign you out everywhere when used.
- The site is served over HTTPS only, with a content security policy, clickjacking protection, and browser features such as camera, microphone, geolocation, payment and interest-based advertising topics switched off.
- Actions are recorded in an append-only activity log.
No system is perfect. If you believe you have found a security problem, please report it to the address published in our security.txt rather than testing against live data.
Children
Iudara is a business tool sold to licensed gaming operators and their advisers. It is not directed at children and we do not knowingly collect data from anyone under 18.
Changes to this policy
The date at the top of this page shows when this policy last changed. Material changes are announced to account administrators by email before they take effect.
