Skip to content
Iudara

POLICY · LAST UPDATED 6 AUGUST 2026

Privacy policy

This policy explains what personal data Iudara collects, why, who we share it with, and what you can do about it. It covers this website and the Iudara compliance platform. We have written it to describe what the service actually does rather than to cover every theoretical possibility — if something here does not match your experience of the product, tell us and we will fix the policy.

Who is responsible for your data

The controller for this website and for the Iudara platform is [to be confirmed: registered company name], registered in [to be confirmed: country of incorporation] under number [to be confirmed: company registration number], registered office [to be confirmed: registered office address].

For privacy questions, contact [to be confirmed: privacy contact address]. Our data protection contact is [to be confirmed: DPO or data-protection contact, and whether a DPO is formally appointed].

Two different roles. When you browse this site, fill in our contact form, or use the platform as a named user, we are the controller of that data. When one of our clients uploads their own material into their workspace — records about their staff, officers, key-function holders and beneficial owners — we handle it as a processor on that client's instructions. If you are one of those individuals, your employer is the controller and you should approach them first; we will help them respond.

What we collect on this website

Contact form. The form on our contact page collects your email address and message (both required) and, if you choose to give them, your name, company, and the jurisdiction you are interested in. We store the submission, email it to our team, and send you an acknowledgement. Your email address is used as the reply-to address on the internal notification.

Jurisdiction finder. The four-question quiz on our home page stores only your answers and the recommendation it produced. It does not ask for your email address and does not link your answers to any other record — there is no email gate on it, by design.

Anti-spam and rate limiting. Both forms are protected by Cloudflare Turnstile, and both are rate limited. Your IP address is sent to Cloudflare as part of the Turnstile check and is used as the rate-limiting key in our Redis cache. Your IP address is not written to our database and not stored alongside your submission.

Booking a call. Our contact page offers a Calendly booking widget, which only loads if you click to open it. Anything you enter there goes to Calendly under Calendly's own privacy policy, not into our systems.

Analytics. We run our own Umami analytics installation on our own infrastructure, on the public marketing pages only. The signed-in platform is deliberately not tracked. It runs only if you accept it — the script is not loaded until you agree on the cookie banner, and it stops being loaded the moment you withdraw. See our cookies page for the full detail and the control that changes your choice.

Error monitoring. We use the Sentry SDK reporting into our own self-hosted error tracker. Reports are routed through our own domain rather than a third-party origin. Error events pass through a redaction step that strips values held under keys such as email, phone, password, token, passport, tax id and address before the event is sent. A sample of browser sessions is recorded for diagnosis (roughly one in ten sessions, and sessions in which an error occurs). Session recordings do not pass through the same redaction step, so [to be confirmed: confirmation of session-replay masking settings and whether replay should stay enabled].

What the platform holds

If you have an account, we hold your name, email address, and optionally a phone number and avatar, plus whether you have enrolled in multi-factor authentication and when you were last active. Invitations and password-reset links are stored as one-way hashes, never as usable tokens.

We keep an activity log of actions taken in the platform. Each entry records who acted, what changed (before and after), the IP address, and the browser user agent. This is a compliance control: an audit trail is what makes the evidence in the platform defensible to a regulator.

Client workspaces contain records about people connected to the client's business — a personnel register with names, work email addresses, roles, and employment dates; key-function and personal-licence holdings with reference numbers and approval and expiry dates; training records; policy acknowledgements; and risk and third-party ownership assignments. Invoices carry the client's billing name, address, and VAT number.

Uploaded documents. Licensing work involves identity and due-diligence documents — for example passport scans, proof of address, and beneficial-ownership paperwork. These are held as files in a private storage bucket, not as structured database fields. They are never publicly addressable: every download is a fresh signed link that expires after five minutes, and access is scoped to the workspace the document belongs to. Uploads are size-capped, content-type checked, hashed, and virus-scanned; anything that fails is quarantined rather than accepted.

External auditors. On a client's instruction we can issue an auditor a time-limited link to a defined set of finalised documents. Grants expire (by default after two weeks, and at most after ninety days), can be revoked immediately, and every view and download is logged with the auditor's IP address and user agent.

Why we are allowed to process it

The table below sets out our reading of the purposes and lawful bases. It has been drafted from how the system actually works and requires legal confirmation: [to be confirmed: counsel sign-off on lawful bases, and a legitimate-interests assessment where that basis is relied on].

Purposes and lawful bases
What we doWhyLawful basis
Respond to a contact-form enquiryAnswer your question and, if relevant, discuss working togetherSteps taken at your request before entering a contract; legitimate interests
Store jurisdiction-finder answersUnderstand which jurisdictions visitors are interested in and improve the toolLegitimate interests
Turnstile checks and rate limitingKeep the forms usable and block automated abuseLegitimate interests
Run accounts, authentication, and MFAProvide the platform you or your employer subscribed toPerformance of a contract
Maintain the activity log and auditor access logProvide a defensible audit trail and detect misuseLegitimate interests; our clients' legal obligations
Hold client licensing and due-diligence documentsDeliver the licensing and compliance serviceProcessed on our client's instructions as processor
Send service and billing emailInvitations, password resets, deadline and invoice remindersPerformance of a contract
Analytics on marketing pagesUnderstand which pages are usefulConsent, which you can withdraw at any time
Error monitoringFind and fix faultsLegitimate interests

Who else processes your data

We use the service providers below. Each is engaged under a written agreement and processes data only on our instructions. Whether a signed data processing agreement is on file with each of them is [to be confirmed: confirmation of executed DPAs and the transfer mechanism (for example standard contractual clauses) for each provider].

Service providers
ProviderWhat it does for usWhere it runs
SupabaseDatabase, authentication, and file storageLondon (eu-west-2)
VercelWebsite and application hostingLondon (lhr1)
UpstashRedis cache — rate-limit counters keyed by IP address, and a short-lived cache of your profile (name, phone, role) held for up to sixty secondsStockholm (arn1)
ResendSending transactional and notification email[to be confirmed: region]
CloudflareTurnstile anti-abuse checks on public forms; receives your IP address[to be confirmed: region]
CloudmersiveVirus scanning of uploaded documents[to be confirmed: region]
SanityContent management for marketing pages[to be confirmed: region]
CalendlyOptional call booking, only if you open the widget[to be confirmed: region]
Self-hosted Umami and error trackerAnalytics and error monitoring on our own infrastructure[to be confirmed: hosting location of the self-hosted analytics and error servers]

We do not sell personal data, and we do not share it for advertising. We may disclose data where the law requires it, or to a regulator or professional adviser in connection with a client engagement.

How long we keep it

The table below is our retention schedule. A job runs every day and applies it: where a period is stated, records past that period are deleted from the live system automatically. Where a period is still being decided, nothing is deleted — we keep the data until the period is set, rather than pick a number in the meantime.

Retention schedule
WhatHow long we keep itWhy
Audit trail — a record of actions taken in the platform: who did what, to which record, and from which IP address7 years from the date of the action. Records are copied to cold storage before they are removed from the live systemAn audit trail is what lets a licensing decision be reconstructed years later, and gambling regulators expect it to still exist. Whether a shorter or longer floor applies in a particular jurisdiction is [to be confirmed: confirmation of the per-jurisdiction audit-trail retention minimums that apply to us (for example UK and Estonia), and whether 7 years satisfies all of them. Until this is confirmed, records are kept, never removed early]
Scheduled-job records — which automated jobs ran, when, and whether they succeeded90 daysOperational monitoring only. These records contain no information about you.
Password reset links30 days after the link expiresA reset link is single-use and valid for thirty minutes. Once it has expired it cannot do anything, so we keep only a short window in which a reset can still be investigated.
Records of requests you make about your data (export, correction, deletion)Kept — no deletion period is setDeleting the record of a deletion request would destroy the evidence that we honoured it. Any period here is [to be confirmed: how long records of data-subject requests should be kept after they are completed]
Contact-form enquiries and jurisdiction-quiz answersKept — no deletion period is setHow long an enquiry that did not become an engagement should be kept is [to be confirmed: the retention period for unconverted enquiries and quiz responses, ideally split between those we have replied to and those we have not]
In-app notificationsKept — no deletion period is setA notification can be the only surviving record that you were told something on a given day, so we have not treated it as disposable. The period is [to be confirmed: the retention period for in-app notifications]
Records our clients have archived or deleted inside the product — staff and officer records, counterparties, risk registers, engagement documentsKept — no deletion period is setThese are the anti-money-laundering and due-diligence records our clients are required by their own licences to retain, and the minimum differs by jurisdiction. The period is [to be confirmed: the per-jurisdiction record-keeping minimums for client due-diligence material, and how long archived or deleted records are held after an engagement ends]

Some categories have a floor set by law rather than by us — accounting records, and the anti-money-laundering and due-diligence records our clients are required to keep. Where a client instructs us to delete something we hold as processor, we will do so unless we are required to keep it.

Every run of the retention job is itself recorded in the audit trail, including what it removed.

Your rights

If the GDPR or the UK GDPR applies to you, you can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop certain processing, object to processing based on legitimate interests, and ask for your data in a portable format. You can also complain to a supervisory authority — the relevant one is [to be confirmed: lead supervisory authority].

If you have an account: the data and privacy page in your settings is the way to raise a request. You can request an export of your data, lodge a rectification notice, or request account deletion, and you can withdraw a request while it is still pending. Everyday corrections — your name, phone number — you can make yourself in settings without raising anything.

If you do not have an account: write to the privacy contact above, or use the contact form.

Requests raised through the platform are recorded and acknowledged immediately; the export, correction, or deletion itself is carried out by our team. Our target and maximum times for completing a request are [to be confirmed: the response timescale we commit to. The statutory maximum is one month; the platform records requests but does not yet fulfil them automatically, so this must reflect the manual process].

Automated decisions

We do not make decisions about you by automated means that produce legal effects. The jurisdiction finder is an indicative tool built from the criteria our advisors weigh in discovery; it produces a suggestion, not a decision, and it does not profile you as an individual. Compliance checks in the platform evaluate a client's own records against deadlines and requirements — they flag work to be done, they do not decide anything about a person.

How we protect it

  • Multi-factor authentication is enforced: every account must enrol, and reaching protected areas requires a second factor.
  • Data is separated per client workspace at the database level, with row-level security in addition to application checks.
  • Files live in a private bucket. There are no public file URLs; downloads use links that expire after five minutes.
  • Uploads are checked for size and real content type, hashed, and virus-scanned, with failures quarantined.
  • Invitation, password-reset, and auditor tokens are stored only as hashes. Password resets expire after thirty minutes and sign you out everywhere when used.
  • The site is served over HTTPS only, with a content security policy, clickjacking protection, and browser features such as camera, microphone, geolocation, payment and interest-based advertising topics switched off.
  • Actions are recorded in an append-only activity log.

No system is perfect. If you believe you have found a security problem, please report it to the address published in our security.txt rather than testing against live data.

Children

Iudara is a business tool sold to licensed gaming operators and their advisers. It is not directed at children and we do not knowingly collect data from anyone under 18.

Changes to this policy

The date at the top of this page shows when this policy last changed. Material changes are announced to account administrators by email before they take effect.

Stay licensed.

Book a demo →

We’d like to run our own analytics on these pages. Nothing loads unless you accept, and we store your choice in this browser. See Cookies.