Data processing addendum
The reference version of the processing terms that apply where Scalara acts as a processor for an operator. Publishing it here does not execute it. A signed copy is issued on request, and the signed copy is the one that governs.
Version in force
In force from .
Last updated on .
The version published here is the version in force. We do not keep a private copy that says something different.
What this addendum is
The reference text, published so it can be read before a contract. The copy signed for your deployment governs where the two differ.
Publication does not execute this addendum
This is the reference version, published so your legal team can read it before a first call rather than after a contract. It creates no obligation on either side until a copy is signed by both. Ask us and we will issue one.
Who this applies to, and when
This addendum applies where an operator is the controller of personal data and Scalara processes that data on the operator's instructions.
On the Turnkey Platform route that is the ordinary position: you hold the licence and the player relationship, so you are the controller and we are your processor for the platform.
On the White Label route the picture is shared. The brand trades under our gaming licence, so we carry obligations of our own as licensee alongside yours, and the split is set out in the signed contract rather than assumed from this page. Where we act as a controller for part of the processing, this addendum does not apply to that part, and the contract says which part.
For anything you send through this website, we are the controller and the privacy policy applies instead.
Subject matter, duration, nature and purpose
Subject matter. The provision of the Scalara casino platform, and the operational, compliance and support functions that go with it.
Duration. For as long as the platform agreement is in force, and afterwards for the period the deletion and return clause allows.
Nature and purpose. Hosting and operating the platform, holding player accounts and their compliance state, processing wallet and transaction records, running identity and screening checks through the named providers, delivering game content, maintaining the audit trail, and providing support.
Categories of data subject, and of personal data
Data subjects. Players registered on a brand you operate on the platform, your own staff who use the back office, and your contacts who deal with us commercially.
Personal data. Identity and contact data; account credentials and authentication state; verification data including identity documents, selfies and the outcome of a check; source of funds evidence; compliance tier and standing; wallet, deposit, withdrawal and bonus records; gameplay and session records; support conversations; and technical data including network address, device and location derived from the network address.
Special category data is not sought. Where an identity document contains it as an artefact of the document itself, it is handled under the verification provider's controls and not used for any other purpose.
Instructions
We process personal data only on your documented instructions, which include the instructions embedded in the configuration you set for your brands, unless a law that applies to us requires otherwise. Where a law requires otherwise, we tell you before processing unless that law prohibits telling you.
If we consider an instruction to infringe data protection law, we say so.
Confidentiality
Everyone we authorise to process personal data is bound by a duty of confidentiality, is given access only to what their role needs, and joins by scoped invitation rather than by shared credentials.
Security
We take technical and organisational measures appropriate to the risk, and the ones that matter most here are structural rather than promissory.
- Every brand runs on its own login and account system, so player credentials are walled off between brands even inside one operator group.
- Internal systems authenticate to each other on every request. Nothing inside the platform is implicitly trusted.
- The wallet checks a player's compliance standing before money moves, so a payment cannot route around a compliance state.
- Every action by every player, staff member and system is recorded in one central, searchable audit stream, enriched with location and device.
- Staff receive precisely scoped roles, down to individual permissions.
Our information security programme is run with SPACE Admins, our ISO/IEC 27001 partner. The certificate is theirs. We describe the arrangement that way and make no certification claim of our own. The technical architecture is described on the security page.
Sub-processing
You give general authorisation for us to appoint sub-processors. We impose data protection obligations on each one that are no less protective than these, and we remain responsible for their performance.
The current register is published on our data protection page, with what each sub-processor does and where it processes. Before a sub-processor is added or replaced we notify you, and you have a reasonable period to object on genuine data protection grounds. If you object and we cannot resolve it, you may terminate the affected part of the service without penalty.
Publishing the register rather than releasing it on request is deliberate. A list you have to ask for is a list you check once.
International transfers
The licensed entity is registered in Saint Lucia, which is not the subject of a European Commission adequacy decision and is not covered by United Kingdom adequacy regulations.
Where personal data originating in the European Economic Area or the United Kingdom is transferred to us, or onward to a sub-processor outside those areas, the transfer relies on the European Commission's Standard Contractual Clauses, with the United Kingdom International Data Transfer Addendum applied where the data originates in the United Kingdom. A transfer risk assessment is carried out for each recipient, and supplementary measures are applied where it calls for them.
Where a sub-processor's processing location is not yet fixed for your deployment, it is settled in the signed addendum rather than assumed here. Ask for the current position and we will send it in writing.
Assisting you with data subject requests
Player facing requests reach you first, because the player relationship is yours. We give you the tools to answer them from the back office, and we assist with anything the tools do not cover.
Where a request reaches us directly, we do not answer it on your behalf. We tell you without undue delay and wait for your instruction, unless a law that applies to us requires us to respond.
Assisting you with Articles 32 to 36
We assist you, taking into account the nature of the processing and the information available to us, with: keeping the processing secure under Article 32; notifying and communicating a personal data breach under Articles 33 and 34; carrying out a data protection impact assessment under Article 35; and any prior consultation with a supervisory authority under Article 36.
Breach notification. We notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know at the time, and we keep you updated as we learn more rather than waiting until we have a complete picture.
Audit
We make available the information reasonably needed to demonstrate compliance with these obligations, and we allow and contribute to an audit conducted by you or an auditor you appoint.
In practice, most of what an audit asks for is already in the platform. The audit trail is append only, it covers player, staff and system actions together, and a regulator evidence pack is built from it in one action rather than assembled by hand. Where a documentary answer will do, we prefer to give it, because it is faster for both of us than an on-site visit.
Audits are on reasonable notice, during business hours, no more than once a year unless a supervisory authority or a breach requires otherwise, and subject to confidentiality.
Deletion or return
On termination, and at your choice, we delete or return the personal data we process for you, and delete existing copies, unless a law that applies to us requires us to keep it. Where we are required to keep something, we tell you what and why, and we keep processing it only for that purpose.
The period allowed for deletion or return, and the format of a return, are set out in the signed copy.
How to get the signed version
Write to contact@scalaralabs.com with "DPA" in the subject line, and tell us the entity name and the route you are on. We issue the signed copy for that deployment, with the sub-processor register and the transfer position attached to it.
If your legal team needs a redline against your own template, send the template. We would rather work through it before a contract than discover a disagreement afterwards.
The sub-processor register
The list this addendum refers to, published rather than released on request. You are notified before one is added or replaced.
CloudWalker
Provides the infrastructure a platform deployment runs on, which is where player records for that deployment are stored.
Processing location: Set in the signed addendum for your deployment
GitHub
Stores the content of this website and the editorial history behind it. It holds no player data and no enquiry data.
Processing location: United States
MiFinity
Processes fiat deposits and withdrawals, and the account data a payment needs in order to settle.
Processing location: Set in the signed addendum for your deployment
NOWPayments
Processes crypto deposits and the transaction data that confirms them against a player wallet.
Processing location: Set in the signed addendum for your deployment
Resend
Delivers the internal notification and the acknowledgement email that follow an enquiry sent through a form on this site.
Processing location: United States
Slotegrator
Carries game aggregation, and the session data a game round needs in order to be settled against a player account.
Processing location: Set in the signed addendum for your deployment
Sumsub
Runs identity verification, source of funds checks and AML screening for players on a brand hosted on the platform.
Processing location: Set in the signed addendum for your deployment
Tugi Tark
Provides TUGI AI player support, and processes the content of a player conversation with it, including anything the player types.
Processing location: Set in the signed addendum for your deployment
Vercel
Hosts this website and the endpoint a form posts to, and delivers the pages you are reading. It sees the technical data any web request carries.
Processing location: United States
The same register is published on the data protection page, with its review date.
Publishing this does not execute it. Ask for the signed copy.
If your legal team needs a redline against your own template, send the template.

