The Aggregator — Operator Service Offer
Effective date: 20 July 2026 · Version: 2026-07-20-operator-v2
This Operator Service Offer ("Offer") constitutes a binding public offer by Xyro Gaming Limitada, cédula jurídica 3-102-930374, a company incorporated under the laws of the Republic of Costa Rica, with registered address at Puntarenas, Garabito, Jacó, Costado Este de la Municipalidad de Garabito (hereinafter "The Aggregator", "we", "us"), to any legal entity or authorised representative thereof ("Operator", "you") that registers for access to the Aggregator Service as a licensed online gaming operator. By completing the Operator registration process and confirming acceptance of this Offer, the Operator enters into a binding agreement ("Agreement") with The Aggregator on the terms set forth below.
The Aggregator is a software-as-a-service (SaaS) provider of computational infrastructure for API routing between game content providers and online gaming operators and a reseller of metered API-processing capacity. The Aggregator sells that capacity to Operators on a pre-paid Package basis and separately settles each Game Provider for Metered Successful API Calls. The Aggregator does not independently initiate a Real-Money Game Session or Game Round, determine a game outcome, accept a wager, maintain a Player wallet, or receive, hold, transmit, or settle Player funds. As at the Effective Date, The Aggregator does not hold a gaming licence and, based on the current design and operation of the Aggregator Service and the activities it presently performs, does not consider itself to operate or conduct gaming. Regulatory classification depends on the applicable jurisdiction and the activities actually performed; The Aggregator does not represent or warrant that no gaming-related licence, registration, approval, or other authorisation can ever be required. All player-facing gaming operations and the Operator's licensing and regulatory compliance remain the Operator's responsibility. Nothing in this Agreement creates a joint venture, partnership, agency, or employer–employee relationship between The Aggregator and the Operator.
---
1. Definitions
- "Aggregator Service" — the B2B SaaS service supplied by The Aggregator under this Agreement, comprising the API-routing, authentication, observability, and metering functionality controlled by The Aggregator, together with its dashboard, integration workspaces, onboarding tools, certification record store, telemetry, metering ledger, and related technical support services. The Aggregator Service does not include any Provider RGS, Operator system, Player-Facing Casino Environment, or other third-party system.
- "Effective Date" — the date on which this version becomes binding on the Operator following acceptance or continued use after any notice required by Section 16.1, and not the draft or proposed date shown above while this document remains marked for legal approval.
- "Intellectual Property Rights" — all copyrights, database rights, trade marks, service marks, trade names, patents, design rights, trade secrets, know-how, and other intellectual property or proprietary rights, whether registered or unregistered.
- "Operator Personal Data" — personal data processed by The Aggregator on behalf of the Operator under Section 12.6 and Schedule D.
- "Personal Data Breach" — a personal data breach within the meaning of GDPR Article 4(12) affecting Operator Personal Data.
- "Provider RGS" — the remote game server or other Provider-controlled backend that hosts Provider Content, maintains the authoritative game state, executes Game Rounds, and generates the related transaction and result communications.
- "Real-Money Game Session" or "Game Session" — a production gameplay session created or activated by a Provider RGS only after an authenticated session-initiation request is submitted by the Operator or its authorised player-facing system and routed through the Aggregator Service. The Aggregator cannot independently initiate a Game Session.
- "Game Round" or "Round" — a Provider-controlled gameplay cycle within a Game Session. A Round may involve multiple API Calls, including wager, result, win, refund, rollback, acknowledgement, and other technical communications before it is completed.
- "Spin" — a user-interface or commercial shorthand for a Game Round in slot-style Provider Content. A Spin is not, by itself, a separate metering unit. For a billable production Round, the single eligible successful
bet transaction described in Schedule A gives rise to one Metered Successful API Call; the other API Calls relating to that Round are not separately billed. - "API Call" — a single discrete API request-and-response or callback-and-acknowledgement transaction routed through the Aggregator Service, as further described in Schedule A.
- "Metered Successful API Call" — an API Call classified as Successful under Schedule A clause A.4. Only Metered Successful API Calls deduct from the Operator's Package balance.
- "Package" or "API Call Package" — a pre-paid bundle of API Calls purchased by the Operator at a Tier-specific per-Call rate, valid for six (6) months from purchase, governed by Section 8.
- "Tier" — STARTER, GROWTH, SCALE, PRO, or ENTERPRISE, as set out in Schedule A clause A.8.
- "Package Validity Period" — six (6) months from Package purchase.
- "Game Provider" or "Provider" — a game content provider contracted to The Aggregator under the Provider Service Offer.
- "Provider Content" — games, RNG outputs, live dealer feeds, configurations, mathematical models, art, audio, metadata, and certification records supplied by Providers.
- "Operator Workspace" — the Operator's isolated environment within the Aggregator Service, including API credentials, dashboard access, configuration, and integration settings.
- "Player-Facing Casino Environment" — the websites, applications, casino-management systems, wallets, user interfaces, and related systems used by or on behalf of the Operator to offer gaming services to Players. It excludes the Aggregator Service and each Provider RGS.
- "Player" — an individual end user of the Operator's Player-Facing Casino Environment.
- "Restricted Jurisdiction" — any jurisdiction (a) where online gambling is prohibited by law, (b) on the FATF high-risk-third-country list, (c) subject to UN, EU, US (OFAC), UK, or other applicable sanctions, or (d) where The Aggregator has determined services cannot be provided. The current list is maintained on the Operator dashboard.
- "SLA" — the Service Level Agreement set out in Schedule B.
- "DPA" — the inline Data Processing Agreement at Section 12.6 and Schedule D.
- "Money-Path Loss" — any Player payout, deposit, withdrawal, wager, win, Gross Gaming Revenue, bonus cost, wallet balance, settlement amount, gaming tax, or gaming-regulatory fine arising downstream of the API-Call layer.
- "Operator Activities" — the Operator's player-facing gaming operations, selection of Players and markets, initiation of Game Sessions, wallet and wager processing, KYC/AML and Responsible Gambling controls, regulatory submissions, and use of the Aggregator Service.
- "Affected Provider" — a Provider that suffers a covered loss directly arising from an Operator-attributable matter under Section 10 or Schedule C clause C.10(a).
- "Working Day" — a day other than a Saturday, Sunday, or public holiday in Costa Rica.
2. Scope of Services
2.1 Infrastructure-only positioning; pay-per-API-Call via pre-paid Packages
- The Aggregator provides SaaS computational infrastructure that authenticates, observes, meters, and routes API Calls between Operators and Provider RGSs. Services include API connectivity, an Operator dashboard, an integration workspace, technical onboarding support, and coordination with Game Providers.
- Each Game Session is initiated solely by the Operator or its authorised player-facing system through an authenticated request submitted using the Operator's credentials and routed to the applicable Provider RGS. The Provider RGS creates or activates the Game Session, executes each Round, maintains authoritative game state, and generates the related transaction and result communications. The Aggregator does not independently initiate or execute a Game Session or Round.
- The commercial model is pre-paid API Call Packages: the Operator purchases a Package upfront at a fixed per-API-Call rate corresponding to the Tier of the Package. The Operator's Package balance is drawn down by one (1) unit for each Metered Successful API Call routed through the Aggregator Service on the Operator's behalf in accordance with Schedule A. Failed API Calls do not deduct from the Package balance (symmetric refund — see Schedule A clause A.4).
- The fee paid under this Section is compensation for The Aggregator's computational, routing, metering, and operational resources, and is inclusive of all amounts payable by The Aggregator to Providers under the Provider Service Offer. No separate game-use royalty, GGR share, or content-licensing fee is payable by the Operator to any Provider in connection with API Calls routed via the Aggregator Service.
- There is no setup fee, no monthly minimum commitment, and no revenue share.
2.2 Game Provider Disclaimer
- The Aggregator acts as a technical service provider and reseller of metered API-processing capacity, providing API connectivity to Game Providers. Before enabling a Provider for production, The Aggregator performs the risk-based documentary checks described in the Provider Service Offer. Those checks do not constitute a legal opinion, certification, or guarantee of the Provider's continuing compliance status, licensing, RNG certification, fairness testing, or regulatory standing. The certification, RTP, mathematical model, RNG, and authoritative game state of Provider Content remain the responsibility of the relevant Provider.
- Provider Content is provided "as is" from the respective Providers. The Aggregator makes no representations or warranties regarding the accuracy of RTP values, game mathematics, payout models, or certification status.
- The Operator is solely responsible for verifying that any Provider Content integrated through the Aggregator Service meets the regulatory requirements of each jurisdiction in which the Operator offers such content to Players.
- The Operator acknowledges that Provider Content availability may change at any time as a result of Provider-side availability adjustments, deprioritisation, certification changes, regulatory action, or termination, and The Aggregator bears no liability for such changes save as expressly provided in Schedule B.
2.3 Provider Relationship
- The Aggregator separately contracts with each Game Provider under the Provider Service Offer and pays each Provider on a per-Metered-Successful-API-Call basis. The economic terms between The Aggregator and any Provider are confidential and outside this Agreement.
- Except for the limited third-party-beneficiary rights expressly stated in Section 9.4, the Operator has no contractual privity with a Provider arising from API routing through the Aggregator Service. The Operator may submit a claim concerning Provider Content, certification, RNG, RTP, or Provider-attributable availability to The Aggregator, which shall coordinate the claim under the Provider Service Offer. Any direct enforcement is limited to the express indemnity right in Section 9.4 and remains subject to the procedures, defences, limitations, and dispute-resolution provisions specified there.
2.4 Integration Autopilot
- The Aggregator may offer an AI-powered Integration Autopilot ("Autopilot") to assist the Operator with codebase scanning, API integration, and technical onboarding. The Autopilot is optional and supplementary, supplied "as is" without warranty. The Operator is solely responsible for reviewing, testing, and validating all changes the Autopilot suggests or applies before deploying to production.
3. Operator Registration and Acceptance
- This Offer is accepted when the Operator completes the registration form through the Aggregator Service and confirms acceptance by selecting the corresponding checkbox. Registration constitutes the Operator's unconditional acceptance of all terms in this Offer.
- The Aggregator reserves the right to request additional documentation, including corporate certificates, gaming licence copies, beneficial-ownership declarations, and proof of authority, before granting or maintaining access.
4. Operator Representations and Warranties
By registering, the Operator represents and warrants that:
4.1 Corporate standing and authority
The Operator is a duly incorporated and validly existing legal entity, and the person completing registration has full authority to bind the Operator. Information supplied during registration is accurate, complete, and not misleading.
4.2 Licensing and regulatory compliance
The Operator holds all licences, permits, and regulatory approvals required to conduct online gambling operations in every jurisdiction where it offers gaming services to Players. The Operator shall provide copies of valid gaming licences on request and shall notify The Aggregator within five (5) Working Days of any licence suspension, revocation, restriction, or material change. The Operator shall not use the Aggregator Service to offer gaming services in any Restricted Jurisdiction.
4.3 Anti-Money Laundering and Counter-Terrorism Financing
The Operator maintains and enforces AML/CTF policies and procedures that comply with applicable laws, including customer due diligence (KYC), transaction monitoring, suspicious-activity reporting, and record-keeping. The Operator shall not use the Aggregator Service for money laundering, terrorist financing, fraud, or any other unlawful purpose, and shall cooperate fully with The Aggregator in any AML/CTF investigation or regulatory inquiry.
4.4 Sanctions compliance
Neither the Operator nor any of its beneficial owners, directors, or officers is listed on any sanctions list maintained by the United Nations, European Union, United States (OFAC), United Kingdom, or any other applicable sanctions authority. The Operator shall not provide access to Provider Content to any person or entity subject to sanctions.
4.5 Lawful use
The Operator shall use the Aggregator Service solely for lawful B2B gaming aggregation purposes consistent with this Agreement and shall not engage in any activity that could damage the reputation, security, or operational integrity of the Aggregator Service, The Aggregator, or any Provider.
4.6 Compliance audit rights
The Aggregator may, at any time, request evidence of the Operator's ongoing compliance, including current gaming licences, AML/CTF documentation, Responsible Gambling programme documentation, player-complaint handling procedures, and insurance evidence. The Operator shall respond within ten (10) Working Days. The Aggregator may, on reasonable notice and at its own expense, conduct or commission a third-party compliance audit to the extent it relates to the Operator's use of the Aggregator Service.
The Operator authorises The Aggregator to disclose to an affected Provider, subject to confidentiality and data-minimisation requirements, the Operator's verified corporate identity, declared operating territories, licence identifiers and stated status, the date and scope of The Aggregator's most recent documentary review, and redacted supporting evidence reasonably necessary for the Provider's own compliance assessment. The Aggregator shall not disclose beneficial-owner identity documents or other sensitive records unless required by law or separately authorised. A Provider may submit a reasonable additional-information request through The Aggregator and may restrict its Provider Content pending a satisfactory response.
4.7 Insurance
Operators are strongly recommended (but not contractually required) to maintain professional liability (errors and omissions) insurance, cyber liability insurance, and general commercial liability insurance adequate to the scale of operations, in particular Operators on the SCALE Tier or above.
4.8 Anti-corruption and anti-bribery
Each party warrants compliance with applicable anti-corruption and anti-bribery laws, including the UK Bribery Act 2010 and the US Foreign Corrupt Practices Act, and shall promptly notify the other of any actual or suspected violation.
4.9 Fraud, Abuse, and Security Monitoring
The Operator shall, on a continuous basis and at its own expense:
- (a) Anti-fraud programme. Maintain a documented anti-fraud, anti-abuse, and AML/CTF monitoring programme covering deposit/withdrawal anomalies, bonus abuse, multi-accounting, account takeover, identity fraud, payment-instrument fraud, chargeback fraud, attempts to access from Restricted Jurisdictions, and suspicious transactional patterns.
- (b) KYC / CDD. Operate Know-Your-Customer and Customer Due Diligence procedures on Players consistent with applicable AMLD5, AMLD6, FATF, and local gaming-regulator requirements, refreshed at intervals required by law and, in any event, no less frequently than every twelve (12) months for active accounts and immediately on any trigger event.
- (c) Security controls. Implement industry-standard security controls on systems integrating with the Aggregator Service, including: TLS 1.2+ on all API traffic, signed-request verification, IP allow-listing where supported, signing-key rotation no less than every 365 days, multi-factor authentication on all administrative access, role-based access control with documented entitlement reviews, and access-log retention for at least twelve (12) months.
- (d) Personnel training. Train staff with access to the Aggregator Service on phishing, social engineering, credential handling, and incident reporting at least annually.
- (e) Independent testing. Subject its production systems integrating with the Aggregator Service to independent penetration testing or equivalent assurance at least annually for Operators on the SCALE Tier or above (or at intervals required by the Operator's B2C licensing regime, whichever is more frequent).
- (f) Notification. Notify The Aggregator without undue delay (and in any event within the windows set out in Schedule C clause C.6) of any actual or suspected fraud, abuse, security incident, credential compromise, breach of confidentiality, AML/CTF concern, or sanctions hit affecting the Aggregator Service or arising from the Operator's use thereof.
- (g) Cooperation. Cooperate with The Aggregator, any affected Game Provider, and any competent authority in the investigation, containment, and remediation of any such incident in accordance with Schedule C clauses C.7 and C.8, including by preserving relevant logs, providing read-only forensic access on reasonable notice, and producing personnel for joint incident calls.
- (h) Responsibility. Bear sole responsibility for losses, regulatory fines, Player payouts, and remediation costs arising from fraud, abuse, or security failures originating in the Operator's systems or attributable to the Operator's failure to comply with this Agreement, subject to Section 10 (Indemnification) and Schedule C clause C.10 (Damage Allocation).
5. Access, Onboarding, and Environment Stages
- Access to the Aggregator Service is granted in stages: sandbox, staging, and production. The Aggregator determines the timing and conditions of progression. Sandbox and staging API Calls are non-billable.
- Before enabling production access, The Aggregator shall conduct a proportionate, risk-based documentary onboarding review that includes the Operator's corporate existence and authority, beneficial-ownership information, sanctions screening, declared operating territories, and evidence of the gaming licences or other lawful basis represented by the Operator as applicable to those territories. The Aggregator shall refresh the review periodically and following notice of a material change. The review is not a legal opinion or certification and does not warrant the authenticity, continuing validity, or legal sufficiency of information supplied by the Operator; The Aggregator warrants only that it performed the checks expressly described in this paragraph in good faith.
- The Aggregator reserves sole discretion to approve, delay, condition, or deny access at any stage.
6. Credentials, Security, and Workspace Integrity
- The Operator is solely responsible for safeguarding all credentials, API keys, signing secrets, tokens, wallet addresses, and authentication mechanisms associated with its Operator Workspace.
- The Operator shall implement reasonable security measures, including IP allow-listing, key rotation, access logging, and role-based access control within its systems.
- The Operator is fully responsible and liable for all activity conducted under its credentials, whether or not authorised.
- 6.1 Severity-graded notification. The Operator's notification obligations under this Section and Section 4.9(f) are subject to the severity-graded windows in Schedule C clause C.6. The notification clock begins on the earlier of (i) confirmed detection or (ii) the time at which a reasonable security-operations function would have had grounds for suspicion.
- 6.2 Evidence-preservation hold. Immediately on becoming aware of any Incident, the Operator shall apply an evidence-preservation hold to all logs, configurations, KYC records, transaction logs, audit trails, communications, and metadata reasonably relevant to the Incident, for not less than twelve (12) months or such longer period as required by applicable law or by written request of the Incident Commander.
7. Intellectual Property and Content Restrictions
- All Intellectual Property Rights in the software and technology comprising the Aggregator Service remain the exclusive property of The Aggregator. All Intellectual Property Rights in Provider Content remain the property of the respective Providers.
- The Operator receives (a) a limited, non-exclusive, non-transferable, revocable licence to use the software and technology comprising the Aggregator Service, and (b) the limited technical permission passed through by The Aggregator under the Provider Service Offer to access, display, and use Provider-hosted Provider Content through the Aggregator Service and the applicable Provider RGS solely for delivering gaming services to Players in authorised jurisdictions. This permission does not transfer Provider IP, permit standalone distribution, or create a right to exploit Provider Content outside the Aggregator Service.
- The Operator shall not: (a) sublicense, resell, redistribute, or re-aggregate Provider Content to any third party; (b) reverse engineer, decompile, or attempt to extract the source code of the software comprising the Aggregator Service; (c) modify, adapt, or create derivative works of the software comprising the Aggregator Service or Provider Content; (d) use The Aggregator's trademarks without prior written consent; (e) circumvent any technical protection measures, rate limits, or access controls.
7.1 Non-circumvention of the Aggregator Service
- The Operator shall not route real API traffic outside the Aggregator Service to circumvent metering, in respect of integrations established or migrated through The Aggregator.
- During the term and for twelve (12) months thereafter the Operator shall not solicit any employee, contractor, or agent of The Aggregator, save in response to a general non-targeted job advertisement.
8. Financial Terms and Payment
8.1 Package purchase and pre-payment
- The Operator purchases an API Call Package by selecting a Tier in the dashboard, accepting the published rate card (Schedule A clause A.8), and remitting the amount in advance. Access to the purchased Package balance is provisioned upon receipt of cleared funds.
- Tier rates are published in the dashboard and at https://aggregator.gg/pricing. The Aggregator may amend the rate card prospectively under §16.1 with not less than thirty (30) days' notice; rates applicable to Packages already purchased shall not change retroactively until those Packages are depleted or expire.
- Packages are priced in United States Dollars (USD). EUR and supported cryptocurrencies (including USDT during the bootstrap phase) may be accepted at the prevailing exchange rate disclosed in the dashboard. The Operator bears all FX and blockchain transaction costs.
8.2 API Call metering and Package draw-down
- API Call counts are recorded by The Aggregator's metering systems per Schedule A and shall be the authoritative source for Package draw-down and for the count of Metered Successful API Calls. The Operator's Package balance is decremented by one (1) unit per Metered Successful API Call. Failed API Calls and non-billable categories (Schedule A clauses A.3 and A.4) do not decrement the Package balance.
- The Operator may dispute a Package draw-down by written notice within thirty (30) calendar days after the relevant monthly usage statement is made available, identifying the affected period, transaction identifiers where available, and reasonable supporting evidence. On at least thirty (30) calendar days' notice, the Operator may commission one independent audit per calendar year for a disputed period. The Aggregator shall correct every verified over-deduction, irrespective of percentage, by restoring the corresponding units to an active Package balance or, if no active Package exists, to a replacement balance with the remaining validity that applied when the units were deducted. If the audit establishes an over-deduction exceeding five percent (5%) of the disputed period's draw-down in the Operator's favour, The Aggregator shall also reimburse the Operator's reasonable, documented external audit cost. No SLA credit arises from a metering correction.
8.3 Package validity, forfeiture, and non-transferability
- Each Package is valid for six (6) months from the date of purchase. Any unused API Calls remaining at the end of the Package Validity Period shall be forfeited, with no refund or credit. Packages are non-transferable to another Operator, another brand under the Operator's control, or any third party. Packages cannot be merged with other Packages save by Auto Top-Up under clause 8.5.
8.4 Balance alerts and top-up
- The Aggregator shall notify the Operator via Telegram, email, and any configured webhook on or before the Balance Alert Threshold, defined as the earlier of (i) the remaining Package balance falling to thirty percent (30%) of original Package size, or (ii) rolling seven-day usage velocity projecting depletion within five (5) calendar days.
- On notification the Operator may (a) purchase a new Package manually via the dashboard, or (b) elect Auto Top-Up per clause 8.5. A manual top-up provisions additional balance immediately upon cleared funds and is added to the existing balance.
8.5 Auto Top-Up
- The Operator may elect, via the dashboard, for The Aggregator to automatically purchase a new Package of equivalent or higher Tier on the Operator's behalf when the Balance Alert Threshold is reached, charging the Operator's stored payment method. Enabling Auto Top-Up constitutes binding authorisation for such recurring purchase. The Operator may disable Auto Top-Up at any time; any Package already purchased under Auto Top-Up is non-refundable.
8.6 Fully Prepaid Service — No Overage, No Credit, No Cash on Balance
- The Aggregator Service operates on a strictly pre-paid model. The Operator's available API Call balance equals the unused portion of the Package and is denominated in API Calls (not cash).
- No overage. When the Package balance reaches zero, service is suspended automatically as of the next API Call attempt. The Aggregator does not continue serving API Calls on a post-paid basis. No overage rate applies and no overage invoice is issued.
- No credit line. The Aggregator does not extend credit. The Aggregator is not engaged in a regulated lending activity and shall not advance, finance, or front API Calls in any form.
- No cash on balance, no cash refund. The Operator's balance is a non-monetary entitlement to a number of API Calls valid for six (6) months per clause 8.3. Any unused API Calls at the end of the Package Validity Period are forfeited. The Aggregator shall not refund, redeem, transfer, exchange, or otherwise monetise an unused API Call balance, save as expressly required by mandatory consumer-protection law (which does not generally apply to B2B operator relationships).
- Top-up to restore service. To resume service after depletion, the Operator must purchase a new Package, manually or under Auto Top-Up.
8.7 No mid-cycle Tier change
- Once a Package is purchased, the Operator cannot upgrade or downgrade to a different Tier mid-cycle. The next-Tier rate applies only from the next Package purchase.
8.8 Late payment of separately agreed invoice-based amounts
- Packages are activated only after cleared pre-payment. If the parties separately agree in writing that an ancillary amount is payable by invoice, late payment of that amount beyond fifteen (15) calendar days accrues simple interest at 1.5% per month (or the maximum rate permitted by law, whichever is lower). The Aggregator may suspend access to the Aggregator Service if such an invoice remains unpaid for more than fifteen (15) calendar days past its due date and may engage third-party collection agents; the Operator bears reasonable collection costs. This clause does not create post-paid Package usage or an Operator credit line.
8.9 Chargebacks
- The Operator shall not initiate chargebacks, payment reversals, or payment disputes through payment processors without first attempting resolution through The Aggregator's dispute process under clause 8.2. Unauthorised chargebacks constitute a material breach and may result in immediate suspension.
9. Limitation of Liability and Disclaimer
9.1 Role of The Aggregator
The Aggregator Service is designed and operated as SaaS API-routing and metering infrastructure, and The Aggregator acts as a reseller of metered API-processing capacity. The Aggregator does not independently initiate Game Sessions or Rounds, determine game outcomes, accept wagers, maintain Player wallets, or accept, hold, route, escrow, transmit, or settle Player or Operator gaming funds. The limited technical permission concerning Provider Content is described in Section 7 and does not make The Aggregator the author of, or authoritative game-state system for, Provider Content. The per-API-Call Package fee paid under Section 8 is independent of wager value, Player win or loss, GGR, NGR, revenue share, wallet balance, or any other Money-Path metric.
The Operator acknowledges that The Aggregator bears no responsibility for: (a) Operator compliance with gaming regulation, licensing, or Responsible Gambling; (b) Operator player-facing operations, including deposits, withdrawals, bonuses, complaints, or player protection; (c) the fairness, RTP, RNG, or mathematical model of Provider Content; (d) Operator tax obligations on gaming revenue; (e) any harm or loss suffered by Players in connection with Operator gaming services; (f) any regulatory classification of the Operator's use of the Aggregator Service as a gambling activity.
9.2 Service availability — Aggregator infrastructure only; games availability is Provider's sole responsibility
- Service availability of The Aggregator's own API-routing infrastructure is governed by Schedule B (Service Level Agreement). The Aggregator shall use commercially reasonable efforts to meet the Routing Layer availability target of 99.9% measured at its edge (aggregator.gg / api.aggregator.gg). The target is an operational objective, not a warranty or guaranteed minimum.
- The availability and correct functioning of any specific game, RNG output, payout calculation, or other Provider Content remain the responsibility of the relevant Game Provider and are outside the Routing Layer target. Where a game appears unavailable, slow, or returns errors due to a Provider RGS, the Operator may submit the matter to The Aggregator for coordination under the Provider Service Offer and may exercise the limited third-party indemnity right in Section 9.4 where its conditions are met.
- The Aggregator shall not be liable for downtime, latency, or service interruptions caused by: (a) scheduled or emergency maintenance under Schedule B; (b) third-party infrastructure failures (cloud providers, CDNs, DNS); (c) Provider backend issues; (d) force majeure events; (e) the Operator's own systems, network, or integration.
- No cash or in-kind service credit, additional API Call, token, refund, liquidated damages, or penalty accrues solely because an operational target in Schedule B is missed. This does not prevent correction of an erroneous metering entry, termination for a separate uncured material breach, or liability that cannot lawfully be excluded. Any enhanced ENTERPRISE objective shall be set out in a Tier-specific addendum.
9.3 Limitation of liability — API-Call cost ceiling; no Money-Path Loss save sole-fault
- (a) Aggregate cap. To the maximum extent permitted by applicable law, The Aggregator's total aggregate liability under or in connection with this Agreement, whether in contract, tort, strict liability, or otherwise, shall not exceed the greater of (i) USD 250,000 and (ii) the total API-Call infrastructure amounts paid or payable in respect of the affected Metered Successful API Calls in the six (6) months preceding the event giving rise to the claim.
- (b) Money-Path Loss limitation, with a sole-fault exception. Notwithstanding any other provision of this Agreement, The Aggregator's financial liability arising out of or in connection with any Incident, fraud, abuse, or security event shall be limited to correction of the affected metering entries and the API-Call charges attributable to them and shall not extend to any Money-Path Loss, except where the multi-source root-cause analysis under Schedule C establishes that the Money-Path Loss was directly and solely caused by a verified routing or metering fault of The Aggregator's own infrastructure. In that case, The Aggregator shall bear the Money-Path Loss so caused, subject to the aggregate liability cap in clause 9.3(a). Where the Money-Path Loss arises from any combination of causes, or from any act or omission of the Operator, any Provider, a Player, or a third party in addition to a routing or metering fault, the sole-fault exception does not apply and apportionment under Schedule C clause C.10 governs.
- (c) Participation preserved. The limitation in clause 9.3(b) does not relieve The Aggregator of its obligation to participate fully in incident detection, support handling, the joint investigation, the Incident Report (including contribution of its API-Call metering ledger), the RCA, and the damage-allocation Sync-Up under Schedule C, nor of its obligation to implement the API-Call-cost remediation and the security improvements attributed to it.
- (d) No consequential damages. Except for direct Money-Path Loss covered by clause 9.3(b), an express indemnity under Section 10, or liability that cannot lawfully be excluded, The Aggregator shall not be liable for indirect, incidental, special, consequential, or punitive damages, including indirect loss of profits, revenue, data, goodwill, business opportunity, or reputation.
- (e) Carve-out. Clauses 9.3(a)–(d) do not apply to liability that cannot be excluded or limited by applicable law, including liability for The Aggregator's own gross negligence, wilful misconduct, or fraud.
9.4 Limited third-party-beneficiary rights
Except as expressly stated in this clause, this Agreement is solely for the benefit of its parties. Each Affected Provider is an intended third-party beneficiary solely of the Operator's indemnity obligations under Section 10.1 and Schedule C clause C.10(a) and may enforce those obligations directly. An Affected Provider takes that limited benefit subject to the same notice, defence-control, causation, mitigation, no-double-recovery, limitation, governing-law, and dispute-resolution provisions that would apply if The Aggregator enforced the obligation. No Player, end user, regulatory authority, or other third party receives any right, and no broader contractual privity between the Operator and a Provider is created.
The Operator is, correspondingly, an intended third-party beneficiary solely of a Provider's indemnity for Provider-attributable Incidents to the extent expressly granted in the Provider Service Offer. The Aggregator shall, following a substantiated claim and subject to confidentiality and applicable law, provide the affected parties with the identity and relevant contractual extract reasonably necessary to exercise the limited beneficiary right.
An Affected Provider accepts the limited benefit by giving written claim notice to The Aggregator at legal@aggregator.gg and to the Operator at the notice address The Aggregator supplies for that claim. By enforcing the benefit, the Affected Provider accepts Section 15 and may commence or be joined to an arbitration solely for the covered claim. Before such acceptance, the parties may amend or revoke the benefit; after acceptance, they may not revoke an accrued claim without the Affected Provider's consent.
9.5 Regulatory classification shield
The parties acknowledge that regulatory classification depends on the applicable jurisdiction and the activities actually performed. The Operator shall not make a materially false or misleading statement to an authority concerning The Aggregator's activities. The Operator shall indemnify The Aggregator under Section 10 only to the extent a regulatory claim, investigation, requirement, or classification is directly caused by (a) the Operator's material breach of this Agreement or applicable law; (b) unlawful, unlicensed, or non-compliant Operator Activities; or (c) a materially false or misleading statement made by or on behalf of the Operator concerning The Aggregator. The Operator has no liability under this clause to the extent the matter results from The Aggregator's own services, conduct, documentation, representations, or failure to obtain an authorisation legally required for The Aggregator's own activities.
10. Indemnification
10.1 By the Operator
The Operator shall indemnify, defend, and hold harmless The Aggregator, its affiliates, and each Affected Provider from and against third-party claims and documented direct losses, damages, liabilities, regulatory fines to the extent legally indemnifiable, and reasonable external legal and remediation costs, in each case to the extent directly caused by: (a) the Operator's material breach of this Agreement; (b) the Operator's violation of applicable law, regulation, or licence condition; (c) unlawful, unlicensed, or non-compliant Operator Activities; (d) a claim by a Player or authority concerning the Operator's player-facing gaming operations; (e) unauthorised use of the Aggregator Service or Provider Content; (f) fraud, money laundering, sanctions evasion, or illegal activity originating in systems controlled by the Operator; (g) an Operator-attributable Incident under Schedule C clause C.10(a); or (h) the regulatory-classification circumstances described in Section 9.5. The indemnity includes amounts that The Aggregator is legally required to pay an Affected Provider under the Provider Service Offer for the same Operator-attributable matter.
10.2 By The Aggregator
The Aggregator shall indemnify, defend, and hold harmless the Operator from third-party claims and documented direct losses to the extent directly caused by: (a) The Aggregator's gross negligence or wilful misconduct; (b) infringement of third-party Intellectual Property Rights by the software and technology comprising the Aggregator Service, excluding Provider Content; (c) The Aggregator's material breach of Section 12; (d) a materially false statement made by The Aggregator to an authority concerning the Operator; or (e) a claim or regulatory process alleging that The Aggregator failed to obtain a licence, registration, approval, or authorisation legally required for The Aggregator's own activities. For paragraph (e), the duty to defend and bear reasonable covered defence costs begins when a substantiated allegation is made; the duty to indemnify a final liability applies only to the extent the required authorisation and The Aggregator's failure to obtain it are established by a final decision or a settlement approved under Section 10.3. This indemnity is subject to the liability cap in Section 9.3(a), except to the extent Section 9.3(e) applies.
10.3 Indemnity procedure
An indemnified person shall give prompt written notice of a claim, provide reasonable supporting evidence, mitigate avoidable loss, and provide reasonable cooperation at the indemnifying party's expense. Delay in notice reduces liability only to the extent it materially prejudices the defence. The indemnifying party may control the defence with qualified counsel reasonably acceptable to the indemnified person, but may not settle a claim in a manner that admits fault by, imposes a non-monetary obligation on, or fails to give a full release to the indemnified person without that person's prior written consent, not to be unreasonably withheld. No person may recover more than once for the same loss. For an Incident, the final RCA, agreed allocation, settlement, or arbitral award shall determine causation and allocation; participation in a Sync-Up is not an admission of liability.
11. Suspension and Termination
11.1 Suspension by The Aggregator
The Aggregator may immediately suspend the Operator's access, without prior notice, if:
- (a) fraud, AML, or illegal activity is reasonably suspected;
- (b) the Operator's gaming licence is suspended, revoked, or expires;
- (c) the Operator breaches a material term;
- (d) continued service exposes The Aggregator to regulatory, legal, or reputational risk;
- (e) a competent authority requests suspension;
- (f) an invoice is overdue by more than fifteen (15) calendar days;
- (g) The Aggregator detects, on its anti-fraud or anti-abuse telemetry, a pattern of API Calls under the Operator's credentials that materially threatens the Aggregator Service, Player funds, or any Provider's content;
- (h) the Operator has been compromised in a manner that requires immediate isolation.
11.2 Termination
- Either party may terminate this Agreement by providing thirty (30) calendar days' written notice.
- The Aggregator may terminate immediately without notice on any event in §11.1.
- The Operator may terminate for a material breach by The Aggregator that remains uncured ten (10) Working Days after The Aggregator receives a written notice describing the breach in reasonable detail. No cure period applies where the breach is incapable of cure or applicable law requires immediate termination.
11.3 Effects of termination
- Upon termination, the Operator's access ceases immediately; outstanding amounts become immediately due; the Operator ceases use of Aggregator IP and API; and each party deletes or returns confidential information subject to Schedule D. Sections 7, 8 (to the extent of accrued rights and reconciliation), 9, 10, 12, 13, 15, and 16, and Schedules A, C, and D, survive. Schedule B survives only for calculation or review of a pre-termination period.
- Forfeiture on termination. For the avoidance of doubt, any unused API Call balance as at the effective termination date is forfeited and is not refundable in cash or any other form, except for units that must be restored as a verified metering correction under Section 8.2 or where mandatory law requires otherwise.
- Upon termination for any reason other than fraud, AML violations, or illegal activity by the Operator, The Aggregator shall provide thirty (30) calendar days of read-only export of configuration data and transaction logs subject to payment of outstanding fees.
12. Data Protection and Privacy
12.1 B2B data processing
Registration data is processed for operator identification and verification, workspace activation, onboarding, billing, operational communications, and legal/regulatory compliance. Legal bases under GDPR: Art. 6(1)(b) performance of contract, 6(1)(f) legitimate interests (fraud prevention, security), 6(1)(c) legal obligation.
12.2 Data retention
Operator registration, contract, billing, and non-payload metering records processed by The Aggregator as controller are retained in accordance with the Privacy Policy and for any longer period required by applicable tax, audit, or other law. Operator Personal Data contained in API payloads or diagnostic logs is retained only for the periods in the Privacy Policy and is deleted or returned under Schedule D. A legal or Incident hold applies to Operator Personal Data only on the Operator's documented instruction or where a law binding on The Aggregator requires retention; retained data shall be isolated from ordinary processing and used only for the hold or legal purpose. Anonymised or lawfully aggregated data may be retained indefinitely.
12.3 Data subject rights
Data subjects may exercise rights under applicable data-protection law (GDPR Arts. 15–22 and equivalents) by contacting The Aggregator at the address in Section 16.10.
12.4 Player data
The Operator is the controller of Player personal data for its player-facing activities. The Aggregator does not request Player names or payment-instrument credentials and does not maintain an authoritative Player profile or wallet. It may transiently receive or process pseudonymised identifiers, IP addresses, device or session metadata, wager-value fields, and other technical fields strictly required by the applicable Provider API. For that processing, The Aggregator acts as the Operator's processor under Schedule D. A Provider selected or enabled by the Operator may act as The Aggregator's sub-processor for the routed data, subject to Schedule D and the Provider Service Offer, or as an independent controller only for a distinct purpose it determines under applicable law.
12.5 Security measures
The Aggregator implements appropriate technical and organisational measures to protect data, including encryption in transit (TLS 1.2+), encryption at rest, access controls, append-only audit logging, and continuous monitoring.
12.6 Data Processing Agreement (Inline DPA)
The inline DPA at Schedule D satisfies the requirements of GDPR Article 28 for any personal data The Aggregator processes on behalf of the Operator.
12.7 Regulatory cooperation
If The Aggregator receives a regulatory request relating to the Operator, it shall (a) notify the Operator promptly unless prohibited, (b) provide cooperation as required by law, (c) disclose Operator data as legally required.
13. Confidentiality
Each party shall maintain the confidentiality of the other party's confidential information, including pricing (in particular the Operator-paid Package rates), technical specifications, API documentation, business strategies, and proprietary systems. Obligations survive termination for five (5) years; trade-secret status survives indefinitely.
14. Marketing Communications
If the Operator opts in during registration, The Aggregator may send product updates, release announcements, and commercial communications. Marketing consent is voluntary and may be withdrawn.
15. Governing Law and Dispute Resolution
15.1 Governing law
This Agreement shall be governed by the laws of the Republic of Costa Rica, without regard to conflict-of-law provisions.
15.2 Dispute resolution
The parties shall first attempt good-faith negotiation for thirty (30) calendar days. Failing resolution, disputes shall be submitted to binding arbitration under the ICC rules, conducted in English, seat in San José, Costa Rica, sole arbitrator. Either party may seek injunctive relief from a court of competent jurisdiction to prevent irreparable harm.
16. General Provisions
16.1 Amendments
- The Aggregator may amend this Offer by publishing an updated version through the Aggregator Service.
- Non-material changes (corrections, clarifications, formatting) take effect upon publication with dashboard notification.
- Material changes (pricing, liability, scope, data processing, or any term materially affecting Operator rights or obligations) require at least thirty (30) calendar days' prior written notice. The Operator may terminate without penalty within that notice period.
- Material pricing changes shall not apply to prepaid Packages until their depletion or expiry.
16.2 Assignment
The Operator may not assign without The Aggregator's prior written consent. The Aggregator may assign to an affiliate or in connection with a merger, acquisition, or sale of substantially all of its assets.
16.3 Severability
If any provision is invalid or unenforceable, the remaining provisions continue in full force.
16.4 Entire agreement
This Offer, together with all Schedules, pricing documentation, and any written addenda, constitutes the entire agreement and supersedes prior negotiations.
16.5 Waiver
No failure or delay in exercising any right is a waiver.
16.6 Force majeure
Neither party is liable for failure or delay caused by events beyond reasonable control, including natural disasters, war, terrorism, sanctions, pandemics, cyberattacks beyond commercially reasonable security measures, or failure of third-party infrastructure not caused by the affected party's negligence.
16.7 Notices
Notices shall be sent to the contact details on registration (Operator) or to the address below (Aggregator).
16.8 Language
This Agreement is in English. The English version prevails in the event of any translation.
16.9 Electronic records
Electronic communications, signatures, and records (including acceptance via the registration checkbox) satisfy any legal writing or signature requirement.
- Legal entity: Xyro Gaming Limitada, cédula jurídica 3-102-930374
- Address: Puntarenas, Garabito, Jacó, Costado Este de la Municipalidad de Garabito, Costa Rica
- Email: legal@aggregator.gg
- Website: https://aggregator.gg
---
Schedule A — API Call Specification & Metering
A.1 API traffic and Game Rounds. A Game Session begins only when an authenticated session-initiation request from a provisioned Operator or its authorised player-facing system is routed to the applicable Provider RGS. Within that Game Session, the Provider RGS executes each Game Round and may generate multiple API Calls, including bet, win, refund, result, acknowledgement, balance, rollback, or other technical communications. These individual communications do not each become billable merely because they are successfully routed. The category labels describe the purpose of routed messages; they do not mean that The Aggregator authorises a wager, determines an outcome, maintains a wallet, or effects a gaming settlement.
A.2 Eligible billable API Call. One Metered Successful API Call is recorded for one unique production bet or equivalent wager/debit transaction representing a billable Game Round where all of the following occur: (a) the Provider RGS sends an authenticated, schema-compliant transaction bearing a unique Provider transaction identifier and a Round identifier, or another documented identifier that uniquely maps that transaction to one Round; (b) the Aggregator Service routes it to the Operator's designated wallet or callback endpoint; (c) that endpoint accepts it with the success status specified in the API documentation; and (d) the Aggregator Service records the request and corresponding acknowledgement within the same trace context. Each eligible transaction carries an Aggregator correlation ID (x-aggregator-call-id). Absent a signed provider-specific addendum expressly defining a multi-wager Round, neither the same Provider transaction nor the same Round may produce more than one Metered Successful API Call.
A.3 Non-billable categories. The following are not Metered Successful API Calls and do not deduct from a Package: Game Session launch, resume, or end requests; balance queries; win, payout, result, settlement-status, refund, rollback, or void communications; free-round or promotional transactions identified as non-billable under the API specification; health checks and Aggregator Service monitoring; retries within the documented retry window; idempotent duplicates; calls rejected before reaching the intended endpoint; and sandbox, staging, or integration-validation traffic. These communications may still be logged as technical API traffic for security, support, and incident reconstruction.
A.4 Successful versus Failed eligible API Call. An eligible API Call is Successful only if it satisfies every condition in clause A.2, including acceptance by the Operator's designated endpoint. It is Failed if it times out, fails authentication or schema validation, receives a non-success or malformed acknowledgement, cannot be routed to the designated endpoint, or is subsequently identified as an idempotent duplicate. A Failed eligible API Call produces no Package deduction and no Provider payout. A verified reversal or refund of a previously recorded eligible transaction is handled as a metering correction under Sections 8.2 and A.6, not as an SLA service credit.
A.5 Metering ledger. The metering ledger is append-only, tamper-evident, and stored with periodic integrity checks. It is the authoritative source for the count of Metered Successful API Calls and Package draw-down. For Incident attribution, money-path questions, and game-outcome questions, the multi-source reconstruction rule in Schedule C applies.
A.6 Audit and correction. The Operator may audit a disputed period and obtain correction of every verified discrepancy in accordance with Section 8.2.
A.7 Outage exclusion. Periods during which the metering layer is itself unavailable, and flagged as such in the Schedule B SLA report, are reconciled retrospectively, with any verified Package restoration shown on the next usage statement.
A.8 Rate card. Current rate card published at https://aggregator.gg/pricing and on the Operator dashboard:
| Tier | Volume per Package | Per-API-Call rate | Package total |
|---|
| STARTER | 100,000 | $0.0025 | $250 |
| GROWTH | 1,000,000 | $0.0022 | $2,200 |
| SCALE | 10,000,000 | $0.0019 | $19,000 |
| PRO | 100,000,000 | $0.0015 | $150,000 |
| ENTERPRISE | 500,000,000+ | Custom | Custom |
All Packages are valid for six (6) months from purchase. No overage. Service suspends on depletion until top-up.
---
Schedule B — Service Level Agreement
B.0 Scope and nature of SLA. This Schedule sets operational service-level objectives for The Aggregator's own API Routing Layer infrastructure. It does not govern the availability, correctness, RTP, fairness, or playability of Provider Content. The availability and correct functioning of Provider Content are addressed under the Provider Service Offer. A Provider-RGS failure does not count against the Routing Layer target. The Aggregator will, on reasonable request, provide available telemetry identifying whether an outage appears attributable to its Routing Layer, a Provider RGS, the Operator, or an excluded dependency. All availability, response, and resolution figures in this Schedule are targets to which the relevant party shall use commercially reasonable efforts to aspire; they are not warranties or guaranteed minimums unless a signed addendum expressly states otherwise.
B.0.1 Measurement definitions. "Routing Layer" means the authentication, routing, metering, and observability components controlled by The Aggregator that form the API-facing boundary of the Aggregator Service. "Total Routing Minutes" means the total clock minutes in the relevant calendar month. "Unavailable Minutes" means whole minutes during which the Routing Layer is materially unable to authenticate and route eligible production API traffic at the Routing Layer, excluding the circumstances in clause B.2.
B.1 Routing Layer availability target — 99.9%. The Aggregator shall use commercially reasonable efforts to achieve monthly availability of at least 99.9%, measured at the Routing Layer:
> Availability% = (Total Routing Minutes − Unavailable Minutes) ÷ Total Routing Minutes × 100
B.2 Exclusions. Unavailable Minutes do not include: scheduled maintenance announced ≥ 72 hours in advance, ≤ 6 hours/week and ≤ 24 windows/year; emergency maintenance announced as soon as practicable; failure of any Provider's backend; failure of the Operator's own systems; force majeure; failure of named sub-processors listed at https://aggregator.gg/legal/sub-processors that propagates beyond The Aggregator's reasonable control.
B.3 Nature of targets; no SLA credits. No cash or in-kind service credit, additional API Call, token, payout adjustment, refund, liquidated damages, or penalty accrues solely because a target in this Schedule is missed. The parties shall cooperate in good faith on incident review and a proportionate remediation plan where a target is materially or repeatedly missed. This clause does not prevent correction of an erroneous metering entry, termination for a separate uncured material breach, or liability for fraud, wilful misconduct, gross negligence, or any matter that cannot lawfully be excluded.
B.4 Enterprise Tier enhanced objective. An ENTERPRISE-Tier addendum may state an enhanced target and any expressly agreed remedies. No enhanced target or remedy applies unless contained in an addendum signed by both parties.
B.5 Support tiers.
- Sandbox & integration — email + ticketing, business hours (Mon–Fri 09:00–19:00 UTC), first response within one (1) Working Day.
- Production non-emergency — ticketing, business hours, first response within four (4) hours.
- Production emergency — 24/7 on-call, severity-driven, channel published on the dashboard.
B.6 Severity levels.
| Severity | Definition | First response | Resolution target |
|---|
| Critical / P0 | Routing Layer down, metering ledger unavailable, active money-path safety event | 30 minutes | 4 hours |
| High / P1 | Significant degradation, partial outage, fraud incident | 2 hours | 8 hours |
| Medium / P2 | Non-blocking integration issue, documentation gap, performance regression | 8 hours | 5 Working Days |
| Low / P3 | Cosmetic, low-impact feature request | 2 Working Days | Best efforts |
B.7 Ticket information. Correlation ID(s), UTC timestamps to the minute, expected vs. observed behaviour, severity classification, reproduction steps.
B.8 Reporting. Monthly SLA report on the Operator dashboard showing availability percentage, P0/P1 incidents, scheduled maintenance, and remediation status for material target misses.
---
Schedule C — Fraud, Abuse, and Incident Response
C.1 Purpose and scope. This Schedule sets out the parties' obligations to monitor, prevent, detect, contain, investigate, and remediate fraud, abuse, and security incidents affecting the Aggregator Service, the Operator's use of the Aggregator Service, the Operator's Players, or any Game Provider's content delivered to the Operator through the Aggregator Service. This Schedule supplements §4.9, §6, §10, and §11.1. In conflict with another provision, this Schedule prevails for incident-handling procedures only.
C.2 Definitions.
- "Incident" — any event involving (a) actual or suspected unauthorised access, modification, exfiltration, or destruction of data on any party's systems related to the Aggregator Service; (b) actual or suspected fraud, AML violation, sanctions evasion, or other unlawful activity routed through the Aggregator Service; (c) actual or suspected exploitation of a Software Defect, RNG anomaly, or game-state corruption; (d) credential compromise, replay, or signature forgery affecting API Calls; (e) any security event requiring notification under the Operator's gaming-licence conditions or applicable data-protection law.
- "Money-Path Incident" — an Incident causing or likely to cause actual or threatened loss greater than USD 100,000 in a single event or greater than USD 500,000 in aggregate across a 30-day rolling window in Player payouts, Operator wallet balances, or other monetary outcomes downstream of the Aggregator Service.
- "Money-Path Loss" — as defined in Section 1.
- "Forensic Window" — the 90-day period following confirmed detection of an Incident.
- "Incident Commander" — the natural person designated under clause C.7 to coordinate joint incident response.
- "RCA" — root-cause analysis report under clause C.9.
- "Kill-Switch" — the mechanism in the dashboard to immediately halt delivery of specified Provider Content, in whole or for specified Operator routes or geographies.
- "Large Win" — a single Player win on Provider Content that exceeds USD 100,000 (or its currency equivalent).
- "Software Defect" — a defect or error in Provider Content that materially affects RTP, fairness, or settlement integrity.
C.2.1 Multi-source incident reconstruction; no single authoritative end-to-end record. The Aggregator operates at the API-routing and metering layer. It may transiently process wager, win, refund, balance, or result fields carried in routed API payloads, but it does not maintain the authoritative Player-wallet, GGR, settlement, RNG, or game-state ledger; calculate GGR; determine game outcomes; or control Player funds. Accordingly, no single party holds an authoritative end-to-end record of an Incident. Each party to this Agreement shall contribute its own records. The Aggregator shall use its contractual rights under the Provider Service Offer to request corresponding records from an affected Provider, and shall assemble the RCA from all records reasonably available.
The scope of authoritativeness is split:
- API-Call billing disputes (the count and classification of Metered Successful API Calls) — the Aggregator's metering ledger remains authoritative as set out in Schedule A clause A.5;
- Incident attribution, money-path, GGR, game-outcome, and Player-harm questions — the multi-source reconstruction in this clause applies, and no party's ledger is solely authoritative.
C.3 Continuous monitoring obligations of The Aggregator. The Aggregator shall, at its own expense and on a continuous basis:
- (a) operate anomaly-detection telemetry on API-Call traffic, including abnormal request rates, geographic clustering, IP-address concentration, signature-failure rates, duplicate or replay patterns, and, only where the relevant fields are present in routed traffic, statistical anomalies in transaction or result metadata;
- (b) maintain its API-Call metering ledger in an append-only, tamper-evident store, with periodic integrity checks;
- (c) maintain a 24/7 security incident-response capability reachable through the published support channels;
- (d) conduct independent penetration testing of the Aggregator Service at least annually and share executive-summary findings with the Operator on reasonable request under confidentiality;
- (e) share known vulnerabilities and threat intelligence arising from the partner ecosystem (Operators and Providers) with the affected parties, to contribute to collective security improvement, save where such sharing would itself create a security risk or breach confidentiality or law;
- (f) operate a Vulnerability Disclosure Policy and a
/.well-known/security.txt endpoint, accept responsible-disclosure submissions, and acknowledge credible reports within five (5) Working Days.
C.4 Continuous monitoring obligations of the Operator. In addition to §4.9, the Operator shall:
- (a) operate Player-level anti-fraud monitoring (KYC, ongoing CDD, transaction monitoring, source-of-funds verification, bonus-abuse detection, geolocation enforcement);
- (b) operate sanctions and Restricted-Jurisdiction screening on Players and on the Operator's own counterparties, refreshed at the cadence required by applicable law; the Operator acknowledges that The Aggregator does not perform proactive sanctions screening of API-Call traffic and is not the ecosystem sanctions gatekeeper;
- (c) implement Responsible Gambling controls, self-exclusion mechanisms, and deposit/loss limits consistent with applicable law;
- (d) detect and prevent multi-accounting, account takeover, identity theft, payment-instrument fraud, and chargeback fraud;
- (e) maintain its own transaction, wallet, and GGR ledger and preserve KYC documents, transaction logs, audit trails, and Player communications for the period required by applicable law (statutory retention prevails over the 12-month contractual floor), and make the relevant excerpts available for multi-source incident reconstruction under clause C.2.1;
- (f) maintain information-security controls aligned with ISO 27001 / SOC 2 or an equivalent recognised framework (recommended, not a precondition to use of the Aggregator Service).
C.5 Kill-Switch. The Aggregator maintains a Kill-Switch capable of (a) globally pausing delivery of any Provider Content to the Operator within sixty (60) seconds, (b) selectively pausing specific games, Providers, or Operator routes, and (c) blocking specific Player session identifiers. The Aggregator shall give effect to a verified Operator Kill-Switch request within sixty (60) minutes. The Aggregator may activate the Kill-Switch on its own initiative in any circumstance in §11.1.
C.6 Detection and notification matrix. On the earlier of (i) confirmed detection or (ii) the time a reasonable security-operations function would have had grounds for suspicion, the detecting party shall raise the Incident through the published support channels and notify all materially affected parties within:
| Severity | Trigger examples | Notice window | Channel |
|---|
| Critical / P0 | Money-Path Incident; confirmed Personal Data Breach affecting Operator Personal Data; confirmed credential compromise with active exploitation; Kill-Switch event | 1 hour | Emergency phone + Telegram + email + dashboard |
| High / P1 | Suspected compromise; fraud-pattern detection; failed sanctions screen; sub-processor breach notification | 8 hours | Telegram + email + dashboard |
| Medium / P2 | Single-event anomaly under investigation; loss of authenticator by privileged user | 24 hours | Email + dashboard |
| Low / P3 | Routine vulnerability disclosure; threat-intelligence sharing; post-incident reports | 5 Working Days | Dashboard |
Notifications are mutual, parallel, and do not depend on conclusive attribution of fault. "Reported, Cause Under Investigation" may be used without prejudice to subsequent attribution.
C.7 Support handling and containment. Following detection, the Incident is handled by each party's support/security function according to its role and the SLAs in clause C.6 and Schedule B. (a) Each party may, without breach, immediately isolate its own systems. (b) The Aggregator may, without breach, exercise the Kill-Switch unilaterally per clause C.5. (c) The Operator may request emergency suspension of a specific game, Provider, route, or session via the incident channel; The Aggregator shall act within sixty (60) minutes of a verified request. (d) Within four (4) hours of Critical/High notification the parties shall designate an Incident Commander; failing agreement, The Aggregator acts as Incident Commander pro tem. (e) Containment durations are excluded from Schedule B availability calculations during the Forensic Window. (f) Each party shall apply an evidence-preservation hold for not less than twelve (12) months, or such longer period as required by law or the Incident Commander.
C.8 Incident Reports. Within seventy-two (72) hours of Critical/High containment (and within five (5) Working Days for Medium), each party to this Agreement that is materially involved shall submit a written Incident Report to the Incident Commander. The Aggregator shall use its contractual rights under the Provider Service Offer to request a corresponding report from an affected Provider. Each Incident Report shall contain, at minimum:
Common contents (all parties): 1. Incident reference ID and the reporting party's internal reference; 2. Reporting party, named incident contact, and 24/7-reachable channel; 3. Detection: timestamp (UTC, minute precision), method (telemetry / human report / third-party / regulator), and detecting system; 4. Incident category (per C.2) and severity classification with written justification; 5. Chronological timeline of all known events (UTC, minute precision); 6. Affected scope: counterparties, games, routes, pseudonymised Player/session identifiers, API-Call correlation IDs, estimated monetary exposure; 7. The reporting party's own ledger/log excerpt covering the Incident window; 8. Containment actions taken with timestamps; 9. Preliminary cause hypothesis and confidence level; 10. Evidence-preservation confirmation: what is held, where stored, and retention-end date; 11. Regulatory-notification status; 12. Known or suspected impact on other parties; 13. Remediation actions taken and planned with owners and target dates; 14. Open questions and information requested from other parties.
The Aggregator's additional contents: API-Call metering-ledger excerpt; Routing-Layer health during the window; Kill-Switch invocation log; relevant sub-processor status.
The Operator's additional contents: Player wallet/transaction/GGR ledger excerpt; pseudonymised KYC status of affected accounts; geolocation and sanctions-screening results for affected sessions; bonus/promotion context; chargeback and AML flags; estimated Player-payout exposure.
The Provider's additional contents: game-state and RNG audit excerpt; certification status of affected Provider Content; settlement ledger excerpt; backend health during the window; any Software Defect linkage; mathematical-model integrity attestation.
A party that cannot meet a contents item shall state the reason and a remediation date; omissions are weighed against the omitting party at the Sync-Up.
C.9 RCA and Sync-Up. Within thirty (30) days of containment, The Aggregator shall use commercially reasonable efforts to assemble the available Incident Reports into one written RCA covering timeline, cause, scope, contributing factors, mitigation actions, and recommended permanent remediations. Within ten (10) Working Days after circulation, The Aggregator shall convene a damage-allocation Sync-Up among the parties bound to participate under their respective Service Offers. The Operator shall participate; The Aggregator shall use its rights under the Provider Service Offer to procure the affected Provider's participation. Minority statements may be annexed. No non-party becomes bound to this Agreement merely by participating.
C.10 Damage allocation framework. Determined at the Sync-Up on the basis of the multi-source reconstruction, not on any single party's ledger. The Aggregator's liability remains subject to Section 9.3; the Operator's and any Provider's obligations are governed by Section 10 of the respective Service Offer:
- (a) Operator-attributable Incidents — Operator credential compromise through Operator-side negligence, KYC failure, Operator-side AML/sanctions breach, or fraud via systems controlled by the Operator: the Operator bears the Money-Path Loss and costs to the extent caused by that matter and indemnifies The Aggregator and each Affected Provider under Section 10.1. An Affected Provider may enforce only the limited beneficiary right in Section 9.4.
- (b) Provider-attributable Incidents — Software Defect, RNG anomaly, certification breach, Provider-RGS compromise, or fraud via systems controlled by a Provider: the relevant Provider bears the loss and costs to the extent provided in the Provider Service Offer. The Operator may enforce the limited third-party-beneficiary indemnity expressly granted there, subject to its terms.
- (c) Aggregator-attributable Incidents — where the RCA establishes that Money-Path Loss was directly and solely caused by a verified routing or metering fault of The Aggregator's infrastructure, The Aggregator bears that Money-Path Loss subject to the Section 9.3(a) aggregate cap, except where Section 9.3(e) applies. In every other Aggregator-related scenario, including mixed or partial cause, The Aggregator's exposure is limited to correction of affected metering entries and the API-Call charges attributable to them, and the remaining loss is allocated according to proven causation. The Aggregator participates fully in the investigation, RCA, and Sync-Up under Section 9.3(c).
- (d) External-attack Incidents, all parties compliant with C.3/C.4 — each party bears its own loss, save where insurance recovers it; The Aggregator's exposure remains limited under §9.3(b).
- (e) External-attack Incidents, one party non-compliant with C.3/C.4 in a manner that materially contributed: that party bears the proportion of Money-Path Loss reasonably attributable to its non-compliance; The Aggregator's exposure remains limited under §9.3(b).
- (f) Mixed-cause / unattributable Incidents — the Sync-Up shall attempt a good-faith allocation for thirty (30) calendar days. The Sync-Up does not create a contract between an Operator and a Provider. Any unresolved claim shall be brought by or against The Aggregator, or by an express limited third-party beneficiary, under the dispute-resolution clause of the agreement that grants the relevant right. The Aggregator's exposure remains limited under Section 9.3(b).
C.11 Money-Path-specific procedures (Large Win, Software Defect).
- Large Win. The Operator shall notify The Aggregator within twelve (12) hours after becoming aware of a Large Win, via a P0 ticket per Schedule B. The Aggregator shall use its rights under the Provider Service Offer to request the corresponding Provider notice and records and shall, within forty-eight (48) hours, use commercially reasonable efforts to complete its own investigation and provide available signed metering-ledger evidence. The Aggregator shall not be liable for the Large Win except where the multi-source RCA establishes it was directly and solely caused by a verified malfunction of The Aggregator's own routing or metering layer (see Section 9.3(b)).
- Software Defect. The Aggregator shall use its rights under the Provider Service Offer to require the affected Provider to notify, remediate, and authorise suspension of the affected Provider Content. This Operator Agreement does not itself impose an obligation on a Provider.
- Player payouts subject to investigation. The Operator alone determines whether it may suspend a Player payout under applicable law, its licence conditions, and its end-user terms. Neither The Aggregator nor a Provider has authority under this Agreement to suspend or release Player funds.
C.12 Sanctions and AML escalation. The Aggregator is an API-routing infrastructure provider and does not operate proactive sanctions or AML screening of all API-Call traffic and is not the ecosystem sanctions or AML gatekeeper. Sanctions and AML compliance on the underlying gaming activity is the Operator's responsibility under Section 4.4 and clause C.4 of this Offer and the Provider's responsibility under Section 4.4 and clause C.4 of the Provider Service Offer.
Where The Aggregator becomes aware — through a binding legal order, a sanctions designation, a competent-authority instruction, or its own anomaly telemetry — that specific API-Call traffic is associated with a sanctioned party, a Restricted Jurisdiction, or unlawful activity, The Aggregator may block or suspend the affected traffic; such blocked calls are classified as Failed under Schedule A clause A.4 (symmetric refund). The Aggregator shall report such determinations to the affected parties and, where required by law, to the relevant authority.
C.13 Regulatory notification. Each party is solely responsible for identifying and making the regulatory, supervisory, data-protection, financial-intelligence, sanctions, and law-enforcement notifications that apply to it under the laws of the jurisdictions in which it operates and under the licences and authorisations it holds. No party is responsible for, or warrants the sufficiency of, another party's regulatory analysis or filings. The parties shall cooperate in good faith and without undue delay to provide one another with the factual information reasonably necessary for each to meet its own notification obligations within the applicable statutory windows (including, where relevant, the 72-hour personal-data-breach window under GDPR Article 33). No party shall make a public statement about an Incident that identifies another party without that party's prior written consent (not to be unreasonably withheld), except where, and to the extent, disclosure is required by law, court order, or a competent authority.
C.14 Records retention and continuous improvement.
- (a) Each party shall retain Incident-related records — including its own ledger segment, Kill-Switch logs, anomaly-detection alerts, Incident Reports, and the RCA — for not less than twelve (12) months from Incident closure.
- (b) Each party shall apply a per-Incident evidence-preservation hold for not less than twelve (12) months, or longer if required by law or by written request of the Incident Commander.
- (c) Statutory retention prevails. Where a record type carries an independent statutory or licence-condition retention obligation on a party (for example, AML/KYC and transaction records the Operator or Provider must retain under AMLD5/AMLD6 or gaming-licence conditions, which commonly require five (5) years or more), that statutory period prevails over the contractual twelve-month floor and remains that party's sole responsibility.
- (d) The Aggregator is not required to retain the full per-call metering ledger beyond the twelve-month floor; low-volume aggregated billing summaries may be retained longer for tax and audit purposes under §12.2.
- (e) Each material RCA shall produce a remediation plan with measurable milestones, owners, and target dates. The Aggregator shall publish an aggregated quarterly Incident report (anonymised) covering Incident frequency by category, mean-time-to-detect, mean-time-to-contain, and remediation status.
---
Schedule D — Inline DPA (Operator Side)
To the extent The Aggregator processes personal data on behalf of the Operator as a processor under GDPR Article 4(8), the following terms form a data processing agreement under Article 28. The parties' labels do not override the role each party has under applicable law for a particular processing activity.
- Roles. The Operator is controller for Player-facing gaming activities and determines the purposes of the relevant processing. The Aggregator is processor when it routes and technically observes Operator Personal Data on the Operator's documented instructions. A Provider selected or enabled by the Operator is authorised as a sub-processor to the extent its Provider RGS receives or processes that data solely to execute Provider Content and return transaction or result communications. A Provider acts as an independent controller only for a distinct processing purpose it independently determines and must disclose under applicable law.
- Subject matter and duration. Routing, transient processing, security logging, and metering of technical Game Session and transaction data through the Aggregator Service for the term of this Agreement and the limited retention periods stated in Section 12 and the Privacy Policy.
- Nature and purpose. Automated authentication, routing, delivery, observability, security, incident response, and metering of API Calls. No use for unrelated marketing, model training on Provider Content, or decisions producing legal effects on Players.
- Types of personal data. Pseudonymised Player, session, Round, and transaction identifiers; IP address and device or security metadata if included; wager, win, refund, balance, currency, jurisdiction, and result fields strictly required by the relevant Provider API; and related timestamps and correlation identifiers. The Aggregator does not request Player names, personal email addresses, or payment-instrument credentials.
- Categories of data subjects. Players and authorised test users of the Operator, to the extent their data is included in API Calls.
- Documented instructions. This Agreement, the Operator's configuration and Provider selections in the Operator Workspace, and lawful written support instructions constitute documented instructions. The Aggregator shall promptly inform the Operator if, in its reasonable opinion, an instruction infringes applicable data-protection law, unless prohibited by law.
- Processor obligations. The Aggregator shall: (a) process personal data only on documented instructions and only as necessary to provide the Aggregator Service; (b) ensure authorised persons are bound by confidentiality; (c) implement appropriate Article 32 technical and organisational measures; (d) assist, taking into account the nature of processing, with data-subject requests, breach notification, DPIAs, prior consultation, and evidence of compliance; (e) at the Operator's choice, delete or return Operator Personal Data within thirty (30) calendar days after termination of the relevant processing service, including from active copies and, at the end of the ordinary backup cycle, backups, and certify deletion on request, unless a law binding on The Aggregator requires specified retention; any retained data shall be isolated and not otherwise processed; and (f) make available information reasonably necessary to demonstrate Article 28 compliance.
- Sub-processors. The Operator gives general written authorisation for infrastructure sub-processors listed at https://aggregator.gg/legal/sub-processors, subject to at least thirty (30) calendar days' prior notice of an intended addition or replacement and a right to object on reasonable data-protection grounds before the change takes effect. A Game Provider is specifically authorised when the Operator selects or enables it after the Provider's identity, processing location, onward sub-processors, and available transfer information are displayed in the Operator Workspace. The Operator may withdraw that authorisation by disabling the Provider before further Player data is routed. The Aggregator shall impose the same data-protection obligations required by Article 28(4) on each sub-processor and remains responsible to the Operator for the sub-processor's performance to the extent required by law.
- Personal data breach. "Personal Data Breach" has the meaning in GDPR Article 4(12). The Aggregator shall notify the Operator without undue delay and, in any event, within forty-eight (48) hours after becoming aware of a Personal Data Breach affecting Operator Personal Data, and shall provide information reasonably available for the Operator's assessment and notifications. If Schedule C requires a shorter notice for the same event, the shorter deadline prevails.
- International transfers. Where GDPR Chapter V applies to a transfer outside the EEA and no adequacy decision or other lawful mechanism applies, the relevant modules of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference, supplemented by the parties' transfer details and any required supplementary measures. The Operator may request those details through legal@aggregator.gg.
- Audit rights. Once per calendar year on thirty (30) calendar days' notice, at the Operator's expense, unless a personal data breach or reasonable evidence of material non-compliance justifies an additional audit. Audits shall protect other customers' confidentiality and Aggregator Service security.
---
End of Operator Service Offer (v2 — effective 20 July 2026).
This document is available in English only. The English version is the legally binding version.