Last updated 11 August 2026
This page is written for the person doing your security review. It says what we run, who else touches your data, what is encrypted, and — in the last section — what we do not have yet. If something you need is missing, email support@ggrify.com.
We are push-only. Your platform sends us events and player attributes over HTTPS to a REST endpoint, authenticated with a bearer token you generate and can revoke. We do not connect to your database, we do not poll a replica, we do not require a VPN, and we do not need an inbound firewall rule on your side. You choose which fields to send; we never reach in and take more.
This is a deliberate difference from how this category usually works. The common pattern — a read replica polled several times a minute, or a nightly ETL built by the vendor’s engineers — requires your DBA, your network team, and a standing credential into your estate. Ours requires an API key and an HTTP client.
fra (Frankfurt, EU).The complete list of third parties that may process data on our behalf. Each is named with what it actually touches, rather than a generic category.
Not on this list, deliberately: your email and SMS providers. Sending credentials are configured per workspace and per brand and belong to you — we hold them encrypted and use them to send on your behalf. We do not resell a sending relationship, and we are not in the delivery path of any provider you have not chosen.
Suppression is enforced by the platform, not by campaign configuration. Events that mean a player must not be marketed to — self-exclusion, cooling-off periods, reality checks, account closure — are marked as suppressing in our event vocabulary, and every outbound message passes through a single gate that reads it. The gate fails closed: if a contact’s status cannot be established, nothing is sent, and the reason is recorded against the dispatch.
Above that, you can author your own send rules — jurisdictional freezes, KYC requirements, risk flags — which apply to every campaign and journey rather than having to be remembered on each one. Those also fail closed on missing data by default.
The honest limit: today our suppression is as current as the last event your platform sent us. Verifying a player’s status against your system at send time is on the roadmap and is not shipped. If your compliance posture requires it, say so and we will discuss timing rather than imply we already have it.
We do not currently operate an automated retention window that expires old events on a schedule. If your licence requires a specific retention period, that is a contractual term we should agree rather than something to assume.
Stated plainly, because you will find out anyway and because a vendor who hides one gap has probably hidden others.
A Data Processing Agreement is available on request. Ask and we will send the current version for your legal team to review.
Email support@ggrify.com. Please include enough detail to reproduce. We will acknowledge receipt, and we will not pursue action against good-faith research that avoids privacy violations, service degradation and data destruction.