01Scope and controller
This Privacy Policy applies to the website fairplaywatch.com and to every service offered through it, including the case-reporting form, the contact form and the self-assessment tool. It does not apply to third-party websites that we link to; those operate under their own policies.
For the purposes of the General Data Protection Regulation (EU) 2016/679 and equivalent national legislation, the data controller is:
- Legal name
- JABJAB-IT
- Trading name
- FairPlayWatch (fairplaywatch.com)
- Legal form
- Société à responsabilité limitée à associé unique (SARLU / EURL) under French law
- Share capital
- EUR 1
- SIREN
- 933 875 536
- SIRET (head office)
- 933 875 536 00015
- NAF / APE code
- 6201Z — Computer programming
- Register
- Registre national des entreprises (INPI), registered on 10 October 2024
- Registered office
- 228 bis avenue de l'Argonne, 33700 Mérignac, France
- Legal representative
- Julien Martin, Gérant — director of publication
- Contact
- [email protected]
- Supervisory authority
- Commission nationale de l'informatique et des libertés (CNIL), France
Company details as recorded in the Registre national des entreprises. A daily-updated extract is available at data.inpi.fr.
As the controller is established in France, the competent supervisory authority is the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr. This does not prevent you from complaining to the authority in your own country of residence.
By using this website you acknowledge that you have read this policy. Where we rely on your consent, using the site is not consent — consent is only given by an explicit, separate action such as ticking a box on a form.
02Data we collect
We distinguish three categories.
2.1 Data you provide voluntarily
- Identification data: the name or pseudonym and email address you enter into a form.
- Case data: the operator name, your account reference with that operator, dates, amounts in dispute, and the free-text description you write.
- Attachments: any documents or screenshots you choose to send by email, together with whatever metadata those files contain.
- Correspondence: the content of messages you send us and our replies.
2.2 Data collected automatically
- Server log data: truncated IP address, request timestamp, requested URL, HTTP status code, referring page and browser user-agent string. Logs are generated by our hosting provider for security and availability purposes.
- Technical characteristics: approximate region derived from the truncated IP, screen size and language preference, used only in aggregate to keep the site usable.
2.3 Data we deliberately do not collect
- Passwords, PINs, one-time codes or full payment card numbers. If you send them to us anyway, we delete them on sight and ask you to change the credential.
- Special categories of data under Article 9 GDPR, unless you volunteer them inside a case description and they are strictly necessary to assess it.
- Advertising identifiers, cross-site tracking cookies and social network pixels. None are present on this site.
03Purposes and legal bases
We process personal data only where a lawful basis applies:
| Purpose | Data used | Legal basis |
|---|---|---|
| Receiving and assessing a case report | Identification and case data | Consent (Art. 6(1)(a)) and public-interest task (Art. 6(1)(e)) |
| Replying to a general enquiry | Name, email, message | Legitimate interest in answering correspondence (Art. 6(1)(f)) |
| Referring a file to a regulator | Case data, identification where you consented | Consent, or legal obligation where mandatory reporting applies |
| Publishing aggregated research | Anonymised statistics only | Public interest; no personal data remains after anonymisation |
| Site security, abuse prevention, backups | Server log data | Legitimate interest in protecting our infrastructure (Art. 6(1)(f)) |
| Meeting statutory record-keeping duties | Case metadata | Legal obligation (Art. 6(1)(c)) |
Where processing rests on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and it may mean we can no longer continue an open case.
04Case reports
A case report is the most sensitive thing you can send us, so it receives specific handling.
- Reports are stored in a restricted case system accessible only to assigned reviewers.
- We disclose your identity to an operator only where you have given explicit consent at submission, and then only the minimum needed for them to locate the account.
- You may file anonymously. We will still record and analyse the report, but we cannot pursue an individual remedy on your behalf or update you on progress.
- Published findings never identify a reporting player. Quotations from case files are paraphrased and stripped of identifying detail.
- If a report discloses a credible risk of serious harm to you or another person, we may contact an appropriate authority or support service. This is the one circumstance in which we may act without your prior agreement.
07International transfers
Our infrastructure is located within the European Economic Area. Where a transfer outside the EEA becomes necessary — for example when referring a case to a regulator in another jurisdiction — we rely on one of the following safeguards:
- an adequacy decision of the European Commission for the destination country;
- Standard Contractual Clauses approved by the Commission, supplemented by a transfer impact assessment; or
- your explicit, informed consent for that specific transfer.
You may request a copy of the safeguards applied to a transfer affecting your data.
08Retention periods
| Record | Retention | Then |
|---|---|---|
| Open case file | Duration of the assessment | Moves to closed-file retention |
| Closed case file | 24 months from closure | Anonymised; statistics retained |
| Case referred to a regulator | 6 years from referral | Deleted, subject to the authority's own rules |
| General correspondence | 12 months from last message | Deleted |
| Server access logs | 90 days | Deleted automatically |
| Encrypted backups | 35 days rolling | Overwritten |
Where you exercise the right to erasure, deletion from live systems takes place within 30 days; residual copies inside encrypted backups are removed as those backups rotate out.
09Security measures
We apply technical and organisational measures proportionate to the risk, including:
- TLS 1.3 encryption for all data in transit and encryption at rest for stored case files;
- role-based access control, with case data visible only to assigned reviewers;
- mandatory multi-factor authentication for every staff account;
- logging of access to case records, reviewed on a monthly cycle;
- annual independent penetration testing and a documented patching schedule;
- staff confidentiality undertakings and periodic data protection training.
No system is perfectly secure. In the event of a personal data breach likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours and inform you directly without undue delay where the risk is high.
10Your rights
Subject to the conditions in applicable law, you have the right to:
- Access
- Obtain confirmation of whether we process your data and receive a copy of it.
- Rectification
- Have inaccurate data corrected and incomplete data completed.
- Erasure
- Have your data deleted where there is no overriding legal ground to keep it.
- Restriction
- Require that we stop processing while a dispute about accuracy or legitimacy is resolved.
- Portability
- Receive the data you provided in a structured, machine-readable format.
- Objection
- Object at any time to processing based on legitimate interests or public interest.
- Withdrawal of consent
- Withdraw consent at any time, with future effect.
- Complaint
- Lodge a complaint with the supervisory authority in your country of residence.
Write to [email protected] to exercise any of these rights. We reply within one month; where a request is complex we may extend this by two further months and will tell you why. Requests are free of charge unless manifestly unfounded or repetitive. We may ask for proof of identity where we cannot otherwise confirm that a request comes from you.
11Minors
This website is intended for adults. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has submitted data to us, contact [email protected] and we will delete the record without delay.
Reports about a minor's exposure to gambling products are welcome and are handled with heightened confidentiality, because protecting minors is a core part of our remit.
12Automated decisions
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not profile individuals. Case assessments are prepared and signed off by human reviewers. Automated tools are used only to sort incoming reports by topic; the classification is advisory and never determines an outcome.
13Changes to this policy
We review this policy at least annually. When we make a material change we update the version number and effective date above, publish the revision at this address, and — where the change concerns processing we carry out on the basis of your consent — ask for consent again. Previous versions are archived and available on request.
14Contact and complaints
Questions, requests and complaints about data protection should go to our Data Protection Office at [email protected]. Please state clearly which right you wish to exercise so we can route the request correctly.
If you are not satisfied with our response, you are entitled to lodge a complaint with the data protection supervisory authority in your country of residence or place of work. Doing so does not affect any other legal remedy available to you.
See also our Terms & Conditions, which govern your use of this website.