AI
We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.
Access Control
Access is tightly monitored and controlled at our company. We are happy to provide more details about our access control practices upon request.
Endpoint Security
We follow industry best practices for endpoint security. We are happy to provide more details about our endpoint security practices upon request.
Network Security
We protect our corporate network against external & internal threats.
Corporate Security
We implement internal measures and practices to maintain a high standard of security.
Policies
We are currently working with experts to put together our company policies. Please contact us for more details.
Security Grades
We are constantly monitoring the security of our website. We will post our grades from public security rating agencies when they become available.
Incident Response
We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request.
Risk Management
We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.
Asset Management
We have strict asset management policies in place to ensure that all assets are accounted for and secure.
BC/DR
We have a business continuity plan in place to ensure that we can continue to operate in the event of a disaster.
Training
We provide security awareness training to all employees to ensure that they are aware of security best practices.
Physical & Environment
We have physical and environmental controls in place to ensure that our data centers are secure and reliable.
Continuous Monitoring
We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.
Subprocessors
- Who is PlayHQ's Data Protection Officer, and how can they be contacted?
- Which privacy and data protection regimes does PlayHQ comply with?
- Is PlayHQ a data controller or a data processor?
- Does PlayHQ use subprocessors, and how are they assessed?
- Does PlayHQ maintain a Record of Processing Activities?
Trust Center Updates
Updates to our privacy policy
We have updated our Privacy Policy to describe how eligibility to participate in a competition is verified. Where a sporting organisation has enabled international clearance checks, the policy now explains that a participant's declared nationality and country of birth may be used to confirm whether a clearance is required before they can register, names eligibility verification as a primary purpose for collecting that information, and records the legal basis and the sporting organisation's role as data controller. It also discloses the automated processing involved: the information used, the decisions made, and the fact that an affected registration is placed on hold for human review rather than automatically refused.
Updates to our subprocessors
We are updating our sub-processor register to disclose two additions to our sales enablement stack.
| Sub-processor | Purpose | Personal data processed | Storage location | Safeguards |
|---|---|---|---|---|
| Salesforce, Inc. | CRM — managing customer and prospect relationships | Business contact details and customer interaction records | United States | Data Processing Addendum executed, incorporated into our customer agreement, including EU Standard Contractual Clauses and the UK International Data Transfer Addendum |
| Gong.io, Inc. | Conversation intelligence and sales enablement — recording, transcription and analysis of sales calls | Business contact details, call recordings, transcripts and derived interaction data | United States | Data Processing Addendum executed, including EU Standard Contractual Clauses and the UK International Data Transfer Addendum |
Both vendors were assessed under our vendor risk assessment process before onboarding, and both are covered by a Data Processing Agreement that binds them to confidentiality, security and sub-processing obligations no less protective than our own. Transfers to the United States are made under the appropriate transfer mechanism for each region in which we operate, supported by a transfer impact assessment.

