Back to home

Legal

The Aggregator — Platform Partner Service Offer

Effective date: 23 July 2026 · Version: 2026-07-23-platform-v1

This Platform Partner Service Offer ("Offer") constitutes a binding public offer by Xyro Gaming Limitada, cédula jurídica 3-102-930374, a company incorporated under the laws of the Republic of Costa Rica, with registered address at Puntarenas, Garabito, Jacó, Costado Este de la Municipalidad de Garabito (hereinafter "The Aggregator", "we", "us"), to any legal entity or authorised representative thereof that develops, operates, licenses, or supplies a casino-management solution to online gaming operators and registers with The Aggregator as a platform partner ("Platform Partner", "you").

By completing the Platform Partner registration process and confirming acceptance of this Offer, the Platform Partner enters into a binding agreement with The Aggregator ("Agreement").

The Aggregator operates software-as-a-service (SaaS) computational infrastructure for authentication, observability, metering, and API routing between game content providers and the Platform Partner. The Aggregator purchases API-processing capacity from Game Providers and resells metered API-processing capacity to the Platform Partner on a pre-paid basis. The Platform Partner may incorporate that capacity into the casino-management services it independently supplies to its Platform Operators.

The Platform Partner is the contractual customer of The Aggregator for all API traffic transmitted under the Platform Partner's Platform ID. Platform Operators are not parties to this Agreement, do not accept an Operator Service Offer or another Service Offer from The Aggregator, and do not acquire a direct contractual relationship with The Aggregator solely because their traffic is transmitted through the Platform Partner System.

The Aggregator does not independently initiate a Real-Money Game Session or Game Round, determine a game outcome, accept a wager, maintain a Player wallet, or receive, hold, transmit, or settle Player funds. The Agreement does not presume which functions the Platform Partner performs for its Platform Operators. Each person remains responsible for the activities and systems it actually controls. As between The Aggregator and the Platform Partner, however, the Platform Partner is responsible for all use of the Aggregator Service under its Platform ID and associated Operator IDs.

As at the Effective Date, The Aggregator does not hold a gaming licence and, based on the current design and operation of the Aggregator Service and the activities it presently performs, does not consider itself to operate or conduct gaming. Regulatory classification depends on the applicable jurisdiction and the activities actually performed; The Aggregator does not represent or warrant that no gaming-related licence, registration, approval, or other authorisation can ever be required.

Nothing in this Agreement creates a partnership, joint venture, agency, employment, fiduciary, or franchise relationship between The Aggregator, the Platform Partner, a Provider, or a Platform Operator.


1. Definitions

  • "Aggregator Service" — the B2B SaaS service supplied by The Aggregator, comprising API routing, authentication, observability, metering, dashboards, integration workspaces, onboarding tools, certification records, telemetry, the metering ledger, Kill-Switch functionality, and related technical support. It excludes every Provider RGS, the Platform Partner System, every Platform Operator System, and every Player-Facing Casino Environment.
  • "Effective Date" — the date on which this version becomes binding on the Platform Partner following acceptance or continued use after any notice required by Section 17.1.
  • "Platform Partner" — the legal entity accepting this Offer.
  • "Platform ID" — the unique identifier assigned by The Aggregator to the Platform Partner and used to identify API traffic, configuration, metering, and responsibility attributable to that Platform Partner.
  • "Platform Partner System" — the casino-management, middleware, API-gateway, aggregation, back-office, wallet-interface, tenant-management, or related technical solution controlled by the Platform Partner and connected to the Aggregator Service.
  • "Platform Integration Layer" — the APIs, adapters, routing components, credentials, signing logic, tenant-isolation controls, acknowledgements, callbacks, and other components controlled by the Platform Partner between the Aggregator Service and Platform Operator Systems.
  • "Platform Operator" — an online gaming operator using the Platform Partner System. A Platform Operator is a customer or counterparty of the Platform Partner and is not a party to this Agreement.
  • "Operator ID" — the unique identifier assigned under the Platform ID to distinguish API traffic, configuration, Provider availability, territory restrictions, metering, and Incidents attributable to a particular Platform Operator.
  • "Platform Operator Agreement" — the agreement between the Platform Partner and a Platform Operator governing the Platform Partner's services and containing the relevant flow-down obligations described in Schedule E.
  • "Platform Operator System" — systems controlled by or specifically operated for a Platform Operator, including Player accounts, wallets, transaction ledgers, KYC/AML systems, and Player-facing services.
  • "Player-Facing Casino Environment" — websites, applications, user interfaces, wallets, and related systems through which a Platform Operator offers gaming services to Players.
  • "Provider" or "Game Provider" — a game content provider contracted with The Aggregator under the Provider Service Offer.
  • "Provider Content" — games, RNG outputs, live-dealer feeds, configurations, mathematical models, art, audio, metadata, and certification records supplied or controlled by a Provider.
  • "Provider RGS" — the Provider-controlled remote game server or other backend that hosts Provider Content, maintains authoritative game state, executes Game Rounds, and generates transaction and result communications.
  • "Player" — an individual end user of a Platform Operator's Player-Facing Casino Environment.
  • "Real-Money Game Session" or "Game Session" — a production gameplay session created or activated by a Provider RGS after an authenticated session-initiation request attributable to a Platform Operator is submitted through the Platform Partner System and routed through the Aggregator Service. The Aggregator cannot independently initiate a Game Session.
  • "Game Round" or "Round" — a Provider-controlled gameplay cycle within a Game Session. A Round may involve multiple API Calls, including wager, result, win, refund, rollback, acknowledgement, and related communications.
  • "Spin" — user-interface or commercial shorthand for a Round in slot-style Provider Content. A Spin is not independently a metering unit. Unless a Provider-specific addendum states otherwise, the single eligible successful bet transaction mapped to the Round produces one Metered Successful API Call.
  • "API Call" — a discrete API request-and-response or callback-and-acknowledgement transaction routed through the Aggregator Service.
  • "Metered Successful API Call" — an eligible production API Call classified as Successful under Schedule A.
  • "Tested Acceptance Point" — the endpoint, acknowledgement event, or other technical acceptance point agreed and validated during the Platform Partner's integration testing. It represents successful delivery for Aggregator metering purposes and may be controlled by the Platform Partner or, where the approved integration design provides, by a Platform Operator System.
  • "Prepaid Capacity" — the Platform Partner's non-monetary entitlement to a specified number of Metered Successful API Calls purchased in advance under the applicable Commercial Terms.
  • "Commercial Terms" — the confidential order, commercial schedule, dashboard terms, or written addendum specifying the applicable API Call rate, amount of Prepaid Capacity, payment method, validity period, and other commercial conditions. Commercial Terms form part of the Agreement but are not published in this Offer.
  • "Credit Line" — a separately approved facility that may in the future permit post-paid use of API-processing capacity. This Offer does not itself grant a Credit Line.
  • "Platform Partner Workspace" — the Platform Partner's isolated environment within the Aggregator Service, including credentials, configuration, Platform Operator records, Provider selections, metering information, and support facilities.
  • "Intellectual Property Rights" — all copyrights, database rights, trade marks, service marks, trade names, patents, design rights, trade secrets, know-how, and other intellectual property or proprietary rights, registered or unregistered.
  • "Operator Personal Data" — Player-related or Platform Operator-related personal data processed through the supply chain described in Schedule D.
  • "Personal Data Breach" — a personal data breach within the meaning of GDPR Article 4(12) affecting Operator Personal Data.
  • "Restricted Jurisdiction" — a jurisdiction where online gambling is prohibited, subject to applicable sanctions, restricted by a competent authority, or designated as unavailable by The Aggregator or a Provider for legal, regulatory, licensing, certification, or compliance reasons.
  • "Money-Path Loss" — any Player payout, deposit, withdrawal, wager, win, bonus cost, wallet balance, GGR, NGR, settlement amount, gaming tax, or gaming-regulatory fine downstream of the API-processing layer.
  • "Platform Partner Activities" — operation of the Platform Partner System; integration with the Aggregator Service; onboarding and administration of Platform Operators; transmission of session and transaction communications; tenant isolation; assignment and use of Operator IDs; and all use of the Aggregator Service under the Platform ID.
  • "Affected Provider" — a Provider suffering a covered loss directly arising from a Platform Partner-attributable matter.
  • "Affected Platform Partner" — a Platform Partner suffering a covered loss directly arising from a Provider-attributable matter covered by the Provider Service Offer.
  • "Incident", "Money-Path Incident", "RCA", "Incident Commander", and "Kill-Switch" have the meanings given in Schedule C.
  • "Working Day" — a day other than a Saturday, Sunday, or public holiday in Costa Rica.

2. Scope of Services

2.1 Contractual and technical supply chain

The legal relationship governed by the Service Offers remains three-sided:

> Provider — The Aggregator — Platform Partner

Platform Operators are not an additional contractual party in this relationship. Their rights and obligations are governed by their agreements with the Platform Partner.

The technical traffic chain may include:

> Provider RGS — Aggregator Service — Platform Partner System — Platform Operator System

The inclusion of a Platform Operator System in the technical flow does not create a contract between that Platform Operator and The Aggregator or a Provider.

2.2 The Aggregator's role

The Aggregator shall:

  • integrate with Provider RGSs;
  • authenticate, observe, meter, and route API Calls;
  • make Provider Content technically available through the Platform Partner Workspace;
  • maintain the API Call metering ledger;
  • operate Platform IDs and Operator IDs;
  • coordinate Provider restrictions, certification records, and Incident response;
  • settle Providers under the Provider Service Offer; and
  • provide technical support for the Aggregator Service.

2.3 Platform Partner's role

The Platform Partner shall:

  • integrate the Platform Partner System with the Aggregator Service;
  • complete required sandbox, staging, production, security, callback, acknowledgement, idempotency, metering, and tenant-isolation tests;
  • identify API traffic using its Platform ID and the relevant Operator ID;
  • transmit only authenticated Game Session requests attributable to its Platform Operators;
  • maintain reliable mapping between Operator IDs and the applicable Platform Operator;
  • transmit Provider-generated communications through its Platform Integration Layer;
  • return authentic and accurate acknowledgements;
  • maintain technical and Incident logs;
  • implement Provider, territory, regulatory, certification, and Kill-Switch restrictions; and
  • remain responsible to The Aggregator for all traffic transmitted under its Platform ID.

2.4 No independent initiation by The Aggregator

A Game Session is initiated by or on behalf of a Platform Operator through the Platform Partner System. The Aggregator only authenticates, observes, meters, and routes the resulting API communications. The Provider RGS creates or activates the Game Session, executes each Round, maintains authoritative game state, and generates the applicable transaction and result communications.

2.5 Functional neutrality of the Platform Partner

This Agreement does not prescribe how the Platform Partner structures its business or which services it supplies to Platform Operators. The Platform Partner may perform different functions for different Platform Operators. Its responsibilities are determined by the systems and functions it actually controls, the services it contractually undertakes, applicable law and licensing requirements, and its use of the Aggregator Service under the Platform ID.

Where a Player-facing, wallet, KYC/AML, Responsible Gambling, or other regulated function is performed exclusively by a Platform Operator, responsibility for that function remains with that Platform Operator under the Platform Operator Agreement and applicable law.

As between The Aggregator and the Platform Partner, the Platform Partner must nevertheless ensure that use of the Aggregator Service by its Platform Operators complies with this Agreement and remains responsible for resulting breaches, claims, and Incidents as provided in Sections 9 and 10.

2.6 Provider relationship

  • The Aggregator contracts and settles separately with each Provider.
  • For API traffic transmitted under a Platform ID, the Platform Partner is treated as the Operator-side contractual counterparty under the Provider Service Offer.
  • The Platform Partner may receive the limited Provider-related rights expressly granted by the Provider Service Offer.
  • Platform Operators receive no direct rights against a Provider under The Aggregator's Service Offers.
  • A claim relating to a Platform Operator shall be submitted and managed by the Platform Partner.
  • The Aggregator does not guarantee a Provider's performance, solvency, licensing, certification, or payment of an indemnity.

2.7 Integration Autopilot

The Aggregator may provide an optional AI-powered integration tool to assist with code analysis, mapping, configuration, and onboarding. It is supplied "as is". The Platform Partner remains responsible for reviewing, testing, approving, and validating every proposed change before production deployment.

3. Registration and Acceptance

  • This Offer is accepted when the Platform Partner selects Platform as its organisation type, completes registration, provides requested corporate and compliance information, confirms acceptance through the applicable electronic acceptance mechanism, and accepts the applicable Commercial Terms.
  • The acceptance record shall include the organisation and Platform ID, Offer version, Commercial Terms version where applicable, timestamp, accepting user, authentication evidence, and available technical audit data.
  • The Aggregator may provide sandbox access before final Commercial Terms are accepted. Production access requires acceptance of this Offer, cleared prepayment, completion of required integration testing, and successful provisioning of production credentials.
  • The Aggregator may request additional corporate, ownership, regulatory, financial, security, and technical documentation before granting or maintaining access.

4. Representations, Warranties, and Compliance

4.1 Corporate standing

The Platform Partner is duly incorporated and validly existing. The accepting person has authority to bind it. Information supplied to The Aggregator is accurate, complete, current, and not misleading.

4.2 Platform Partner System

The Platform Partner owns or holds sufficient rights to operate and license the Platform Partner System and to perform the integration contemplated by this Agreement. The Platform Partner System shall not knowingly infringe third-party Intellectual Property Rights.

4.3 Licensing

The Platform Partner shall obtain and maintain every B2B supplier licence, software-supplier authorisation, registration, approval, or other permission legally required for the Platform Partner Activities it actually performs. This Agreement does not presume that the Platform Partner requires or does not require a particular licence.

The Platform Partner shall notify The Aggregator within five (5) Working Days of any suspension, revocation, expiry, investigation, restriction, or material change affecting its regulatory status.

4.4 Platform Operator notification

The Platform Partner may begin provisioning a Platform Operator without obtaining The Aggregator's prior discretionary approval, provided that:

  • the Platform Partner notifies The Aggregator before production traffic begins;
  • the Platform Operator is assigned a unique Operator ID under the Platform ID;
  • the Platform Partner supplies required identity, territory, and licence-status information;
  • the Operator ID is included in production API traffic; and
  • the Platform Operator is not subject to an existing restriction or veto.

Notification is not approval, certification, endorsement, or a legal opinion by The Aggregator.

4.5 Aggregator veto and restriction rights

The Aggregator may review a Platform Operator before or after production traffic begins and may request its verified legal identity, declared operating territories, licence identifiers and stated status, beneficial-ownership information where proportionate, sanctions-screening evidence, relevant compliance contacts, and other information reasonably necessary for Provider, regulatory, security, or sanctions purposes.

The Aggregator may veto, suspend, restrict, or require removal of a Platform Operator or Operator ID for licensing or regulatory concerns, sanctions, suspected fraud or unlawful activity, security compromise, Provider territorial restrictions, a competent-authority request, material breach, or material legal or reputational risk.

Because each Platform Operator is identified by an Operator ID, such action may be limited to the affected Platform Operator without suspending the entire Platform ID where technically and legally appropriate.

4.6 Downstream contractual control

Before enabling production access for a Platform Operator, the Platform Partner shall have a binding Platform Operator Agreement covering the matters in Schedule E. The Platform Partner shall ensure it has sufficient contractual rights to obtain compliance and licensing information; suspend or disable the Platform Operator; investigate Incidents; obtain relevant logs and records; impose Provider and territory restrictions; protect Provider Content and Aggregator IP; meet data-protection obligations; and recover losses for which the Platform Operator is responsible.

4.7 AML, sanctions, and lawful use

The Platform Partner shall maintain risk-appropriate AML/CTF and sanctions controls concerning its own organisation, counterparties, and Platform Operators. It does not automatically become responsible for Player KYC, wallet monitoring, or Responsible Gambling merely because it supplies software. If it performs any such function, it is responsible for that function to the extent of its actual involvement and applicable law.

The Platform Partner shall not knowingly enable a sanctioned party, Restricted Jurisdiction, or unlawful gaming activity and shall cooperate with The Aggregator, affected Providers, and competent authorities in relevant inquiries.

4.8 Audit rights

The Aggregator may request evidence of continuing compliance. The Platform Partner shall respond within ten (10) Working Days or sooner where required by an Incident or regulatory deadline.

The Aggregator may conduct or commission one compliance audit per calendar year on reasonable notice and at its own expense. Additional audits may be conducted following a material Incident, competent-authority request, reasonable evidence of material non-compliance, or material failure of Operator ID segregation.

4.9 Insurance

The Platform Partner is strongly recommended to maintain professional liability, technology errors-and-omissions, cyber liability, and general commercial liability insurance appropriate to its territories, traffic, and Platform Operator base.

4.10 Anti-corruption

Each party shall comply with applicable anti-corruption and anti-bribery laws and promptly notify the other of an actual or suspected violation materially connected with this Agreement.

4.11 Security and monitoring

The Platform Partner shall maintain TLS 1.2 or higher; multi-factor authentication for administrative access; role-based access controls; signing-key rotation; secure storage of credentials; tenant and Operator ID isolation; idempotency protection; audit logging; monitoring of signature failure, replay, duplicates, and abnormal request rates; and a 24/7 Incident contact for Critical and High Incidents.

5. Access, Integration, and Testing

5.1 Environment stages

Access is supplied in sandbox, staging, and production stages. Sandbox and staging traffic is non-billable unless otherwise stated in the Commercial Terms.

5.2 Integration testing

The Platform Partner shall complete tests covering authentication and signatures; Game Session initiation; Provider RGS routing; bet, win, refund, rollback, and related communications; idempotency and retries; Tested Acceptance Point acknowledgements; Operator ID segregation; tenant isolation; metering reconciliation; Kill-Switch functionality; failure and timeout handling; Incident contacts; and production credential security.

The Aggregator determines whether the integration has passed the required tests. Passing integration testing confirms only technical compatibility with the tested specification. It is not a legal, licensing, compliance, financial, or security certification of the Platform Partner or a Platform Operator.

5.3 Operator ID provisioning

Every Platform Operator shall have a distinct Operator ID under the Platform ID. The Platform Partner shall not reuse an Operator ID for an unrelated operator; omit or falsify an Operator ID; transmit traffic under an Operator ID assigned to another Platform Operator; or circumvent an Operator-specific suspension or restriction.

5.4 Tested Acceptance Point

The Tested Acceptance Point is identified and validated during integration testing. A Metered Successful API Call is completed when the eligible transaction reaches that point and receives the agreed successful acknowledgement.

If the Tested Acceptance Point is controlled by the Platform Partner, subsequent delivery or processing inside the Platform Partner System or Platform Operator System is outside the Aggregator-controlled metering event.

6. Credentials and Platform Integrity

  • The Platform Partner is responsible for credentials, keys, signing secrets, endpoint configurations, tokens, and administrative access associated with its Platform ID.
  • Activity authenticated under Platform Partner credentials is treated as authorised by the Platform Partner unless directly caused by a verified Aggregator security failure.
  • The Platform Partner shall prevent credentials from being exposed to Players or unauthorised Platform Operators; maintain separate non-production and production credentials; validate applicable signatures; preserve idempotency; maintain accurate Operator ID mapping; ensure acknowledgements accurately reflect processing at the Tested Acceptance Point; and notify The Aggregator of suspected compromise within Schedule C deadlines.
  • Where the Platform Partner acknowledges a transaction before completing downstream processing, it assumes responsibility for onward delivery, deduplication, reconciliation, and any loss caused after that acknowledgement.
  • Immediately on becoming aware of an Incident, the Platform Partner shall preserve relevant logs, mappings, configurations, transaction records, communications, and metadata for not less than twelve (12) months or such longer period as required by law or the Incident Commander.

7. Intellectual Property and Technical Rights

7.1 Aggregator IP

All Intellectual Property Rights in the software and technology comprising the Aggregator Service remain the exclusive property of The Aggregator. The Platform Partner receives a limited, non-exclusive, non-transferable, and revocable licence to use the Aggregator Service and documentation solely under this Agreement.

7.2 Platform Partner IP

All Intellectual Property Rights in the Platform Partner System remain with the Platform Partner or its licensors. The Platform Partner grants The Aggregator the limited right to connect to, test, authenticate with, route communications to, and monitor the Platform Integration Layer as necessary to supply the Aggregator Service.

7.3 Provider Content permission

Subject to Provider restrictions, The Aggregator passes through the minimum permission required for the Platform Partner to receive and transmit Provider API payloads; display Provider names, thumbnails, and metadata; configure Provider availability by Operator ID; make Provider-hosted Provider Content available through the Platform Partner System; and enable Platform Operators to access that content through the Aggregator Service and Provider RGS.

The Platform Partner shall not grant standalone Provider Content rights; appoint another aggregator or sub-distributor; modify, decompile, reverse engineer, or create derivative works of Provider Content; distribute Provider Content outside approved territories; train models on Provider Content; use Provider Content for unrelated purposes; or bypass Aggregator metering.

7.4 Non-circumvention

The Platform Partner shall not route production traffic outside the Aggregator Service to avoid metering for integrations established or migrated through The Aggregator. This does not restrict integrations independently developed without use of Aggregator confidential information or Provider connections supplied through The Aggregator.

7.5 Marks

Each party may use the other's name and logo solely to identify the relationship. Campaigns, press releases, case studies, and pitch materials require prior written consent.

8. Prepayment and Commercial Terms

8.1 No public API Call price

This Offer does not state the price payable by the Platform Partner for a Metered Successful API Call. The confidential rate, amount of Prepaid Capacity, currency, payment method, and other commercial conditions are stated in the Commercial Terms.

8.2 Prepaid model

  • The Platform Partner purchases Prepaid Capacity before production use.
  • Prepaid Capacity is activated only after receipt of cleared funds.
  • The Platform Partner's balance is denominated in API Calls, not cash.
  • One unit is deducted for each Metered Successful API Call.
  • Failed and non-billable API Calls do not deduct from the balance.

8.3 No current Credit Line

The Aggregator does not currently grant a Credit Line under this Offer. When available Prepaid Capacity reaches zero, new billable API Calls may be automatically suspended; no overage is supplied; no post-paid debt is automatically created; and service resumes after a successful top-up.

The Aggregator may later introduce a standard Credit Line product for Operators and Platform Partners. A Credit Line applies only after the product has been formally introduced, the Platform Partner has passed any applicable eligibility review, separate Credit Line terms have been accepted, and a credit limit has been expressly activated. Continued use of this Offer alone does not constitute approval of a Credit Line.

8.4 Capacity validity

Unless the Commercial Terms expressly state another period, Prepaid Capacity is valid for six (6) months from purchase. Unused capacity expires at the end of that period and is non-refundable and non-transferable, except for verified metering corrections, mandatory law, or an express Commercial Terms provision.

8.5 Balance and top-up

The Aggregator shall make balance and usage information available through the Platform Partner Workspace. The Platform Partner may top up manually or enable an approved Auto Top-Up mechanism and remains responsible for maintaining sufficient capacity for all Operator IDs under its Platform ID.

8.6 GGR independence

Amounts payable to The Aggregator are based on Metered Successful API Calls and are independent of wager value, Player win or loss, GGR or NGR, deposits or withdrawals, wallet balances, gaming tax, revenue share, and the commercial model between the Platform Partner and Platform Operators.

8.7 Platform Operator collection risk

The Platform Partner independently determines how it charges and collects from Platform Operators. Its payment obligations to The Aggregator are not conditional on payment by a Platform Operator. The Aggregator does not collect from, extend credit to, or guarantee a Platform Operator.

8.8 Metering disputes and reconciliation

A reasoned dispute must be raised within thirty (30) calendar days after the relevant statement. The parties shall conduct a joint reconciliation using Aggregator metering records, correlation IDs, Platform ID and Operator ID, Tested Acceptance Point records, and relevant Platform Partner logs.

Following agreement or final determination, erroneous deductions shall be restored; an additional valid deduction may be applied; a corrected statement shall be issued; and no party may recover twice for the same discrepancy.

8.9 Taxes

Each party is responsible for taxes legally imposed on it. The Platform Partner bears taxes, VAT, duties, and similar charges attributable to its purchase or downstream supply, except taxes on The Aggregator's net income.

8.10 Provider settlement

The Aggregator separately settles Providers under the Provider Service Offer. The Platform Partner does not pay Providers under this Agreement, has no right to audit Provider payout rates or Aggregator margin, is not a Provider payment agent, and remains liable for its prepayment regardless of The Aggregator's separate settlement with Providers.

8.11 No Player funds

Payments under this Agreement are payments for prepaid API-processing capacity. They are not Player deposits, wagers, wins, withdrawals, wallet balances, or gaming settlements.

9. Liability and Disclaimer

9.1 Allocation by controlled activity

Responsibility is allocated according to activities and systems actually controlled:

  • Provider: Provider Content, Provider RGS, RNG, game state, mathematics, and certification;
  • The Aggregator: Aggregator Service routing, authentication, observability, and metering;
  • Platform Partner: Platform Partner System, Platform Integration Layer, Platform ID, Operator ID segregation, acknowledgements, and use of the Aggregator Service under its Platform ID; and
  • Platform Operator: Player-facing operations and any wallet, KYC/AML, Responsible Gambling, Player-support, or regulated activity it controls.

As between The Aggregator and Platform Partner, activity routed under the Platform ID remains attributable to the Platform Partner, including where the immediate cause originated in a Platform Operator System.

9.2 Availability boundaries

The Aggregator SLA applies only to Aggregator-controlled infrastructure. Provider failures remain Provider matters. Platform Partner System and Platform Integration Layer failures remain Platform Partner matters. Platform Operator System failures are managed by the Platform Partner under its downstream relationship and do not count against Aggregator availability.

9.3 Aggregator liability cap

  • (a) Aggregate cap. To the maximum extent permitted by law, The Aggregator's aggregate liability shall not exceed the greater of (i) USD 250,000 and (ii) amounts paid or payable by the Platform Partner to The Aggregator during the six (6) months preceding the event giving rise to the claim.
  • (b) Money-Path Loss. The Aggregator's Incident liability is limited to correction of affected metering and API-processing charges and does not include Money-Path Loss unless the multi-source RCA establishes that such loss was directly and solely caused by a verified Aggregator routing or metering fault. The sole-fault exception does not apply where an act or omission of the Platform Partner, a Platform Operator, Provider, Player, or third party materially contributed.
  • (c) No consequential damages. Except for an express indemnity, the sole-fault exception, or liability that cannot lawfully be excluded, The Aggregator is not liable for indirect, incidental, special, consequential, or punitive losses.
  • (d) Carve-out. The limitations do not apply to fraud, wilful misconduct, gross negligence, or liability that cannot lawfully be limited.

9.4 Limited third-party rights

Each Affected Provider is an intended third-party beneficiary solely of the Platform Partner's indemnity obligations under Section 10.1 and Schedule C. The Platform Partner is correspondingly an intended third-party beneficiary of a Provider's indemnity for Provider-attributable matters to the extent expressly granted in the Provider Service Offer.

Platform Operators are not third-party beneficiaries of the Provider Service Offer or this Agreement. A Platform Operator loss or claim shall be managed through the Platform Partner under the Platform Operator Agreement. The Platform Partner may then pursue its own covered claim against The Aggregator or exercise its limited Provider beneficiary right.

The beneficiary takes its limited right subject to the same notice, defence-control, causation, mitigation, no-double-recovery, limitation, governing-law, and dispute-resolution provisions that would apply between the parties. The Aggregator does not guarantee Provider performance or solvency.

9.5 Regulatory classification

The Platform Partner shall not make a materially false or misleading statement concerning The Aggregator's activities. The Platform Partner indemnity applies only to the extent a regulatory matter concerning The Aggregator is directly caused by breach of this Agreement, unlawful or unlicensed Platform Partner Activities, activity transmitted under the Platform ID for which the Platform Partner is responsible, or a false or misleading statement by the Platform Partner.

The Platform Partner is not liable to the extent the matter results from The Aggregator's own services, conduct, representations, or failure to obtain an authorisation legally required for its own activities.

10. Indemnification

10.1 By the Platform Partner

The Platform Partner shall indemnify, defend, and hold harmless The Aggregator, its affiliates, and each Affected Provider from third-party claims and documented direct losses, liabilities, legally indemnifiable fines, and reasonable external legal and remediation costs directly caused by:

  • material breach of the Agreement;
  • infringement by the Platform Partner System;
  • unlawful or unlicensed Platform Partner Activities;
  • unauthorised or restricted use of Provider Content;
  • failure to identify traffic using the correct Operator ID;
  • failure of tenant isolation or Platform-controlled acknowledgements;
  • a claim arising from Player-facing or regulated activity transmitted under the Platform ID;
  • fraud, sanctions evasion, money laundering, or unlawful activity transmitted under the Platform ID;
  • a Platform Partner-attributable Incident under Schedule C; or
  • circumstances described in Section 9.5.

For purposes of this indemnity, an act or omission of a Platform Operator relating to traffic under the Platform ID is treated as an act or omission attributable to the Platform Partner in its relationship with The Aggregator. The Platform Partner may seek recovery from the Platform Operator under their separate agreement.

10.2 By The Aggregator

The Aggregator shall indemnify, defend, and hold harmless the Platform Partner from third-party claims and documented direct losses directly caused by The Aggregator's gross negligence or wilful misconduct; infringement by the software and technology comprising the Aggregator Service, excluding Provider Content and Platform Partner technology; material breach of Section 12 or Schedule D; a materially false statement by The Aggregator to an authority concerning the Platform Partner; or a substantiated claim that The Aggregator failed to obtain an authorisation legally required for its own activities.

For the last category, defence costs begin when a substantiated allegation is made. Final indemnification applies only after a final decision or approved settlement establishes the requirement and failure. This does not make The Aggregator a guarantor of a Provider or Platform Operator. This indemnity is subject to Section 9.3 except to the extent its carve-out applies.

10.3 Procedure

The indemnified party shall give prompt notice, provide evidence, mitigate avoidable loss, and reasonably cooperate. Delay reduces liability only to the extent it materially prejudices the defence.

The indemnifying party may control the defence with qualified counsel reasonably acceptable to the indemnified party but may not settle in a manner that admits fault by, imposes a non-monetary obligation on, or fails to release the indemnified party without prior consent. No person may recover twice for the same loss. Incident causation is determined by an agreed RCA allocation, settlement, final judgment, or arbitral award.

11. Suspension and Termination

11.1 Suspension by The Aggregator

The Aggregator may immediately suspend the Platform ID or a specific Operator ID, Provider, game, geography, or route if:

  • fraud, AML, sanctions evasion, or unlawful activity is reasonably suspected;
  • a relevant licence is suspended, revoked, or expires;
  • the Platform Partner breaches a material term;
  • continued service creates material regulatory, legal, security, or reputational risk;
  • a competent authority requests suspension;
  • Platform Partner credentials or tenant isolation are compromised;
  • a Provider restriction applies;
  • an Operator ID is false, missing, or used to circumvent a restriction;
  • Prepaid Capacity is depleted; or
  • the Kill-Switch is activated.

Where reasonably practicable, suspension shall be limited to the affected Operator ID rather than the whole Platform ID.

11.2 Platform Partner operational control

The Platform Partner may stop submitting new Game Sessions or API traffic for any Operator ID at any time. It may immediately isolate systems or suspend an Operator ID, Provider, game, geography, or route where necessary for security, unlawful use, sanctions or licensing concerns, Provider or certification restrictions, competent-authority instructions, or protection of Players or systems.

Where technically safe and legally permissible, an already accepted Round should be allowed to reach a consistent final state.

11.3 Termination

  • Either party may terminate on thirty (30) calendar days' written notice.
  • The Aggregator may terminate immediately following a Section 11.1 event.
  • The Platform Partner may terminate for a material Aggregator breach remaining uncured for ten (10) Working Days after detailed written notice.
  • No cure period applies where the breach is incapable of cure, law requires immediate termination, or the breach creates imminent material harm.

11.4 Effects

On termination, production access ends; no new traffic may be transmitted under the Platform ID; unused Prepaid Capacity is forfeited unless Commercial Terms or mandatory law state otherwise; metering disputes are reconciled; the Platform Partner ceases use of Aggregator and Provider rights; confidential information is returned or deleted subject to lawful retention; and Operator Personal Data is handled under Schedule D.

Sections 7–10, 12–17 and Schedules A, C, D, and E survive to the extent required for accrued rights, reconciliation, data protection, or Incident handling.

12. Data Protection and Privacy

12.1 Business-contact data

Each party acts as an independent controller for business-contact, registration, billing, compliance, and account-administration personal data it processes for its own purposes.

12.2 Legal-role neutrality

This Agreement does not predetermine the Platform Partner's data-protection role for every implementation. The role is determined by the purposes, means, instructions, and processing actually performed.

12.3 Expected processing chain

Where a Platform Operator determines the purposes of Player-related processing and appoints the Platform Partner:

  • Platform Operator acts as controller;
  • Platform Partner acts as processor;
  • The Aggregator acts as the Platform Partner's sub-processor; and
  • the selected Provider acts as a further sub-processor where it processes data solely to execute Provider Content.

The Platform Operator remains outside the Service Offer relationship but supplies its instructions and authorisation through the Platform Operator Agreement.

12.4 Platform Partner authority

The Platform Partner warrants that it has obtained all instructions and authorisations required to appoint The Aggregator and disclosed Providers. The Aggregator may rely on instructions communicated by the Platform Partner without independently contracting with the Platform Operator.

12.5 Independent-controller activities

Where the Platform Partner independently determines a processing purpose, including its own fraud monitoring, analytics, account administration, or legal compliance, it acts as controller for that purpose. Where a Platform Operator performs the function independently, responsibility remains with the Platform Operator.

12.6 Data Processing Agreement (Inline DPA)

Schedule D forms the applicable processor-to-sub-processor agreement and is intended to satisfy GDPR Article 28 requirements where GDPR applies.

12.7 Regulatory cooperation

If The Aggregator receives a regulatory request relating to the Platform Partner, it shall notify the Platform Partner promptly unless prohibited, provide reasonable cooperation as required by law, and disclose data only as legally required.

13. Confidentiality

Each party shall protect the other's confidential information, including Commercial Terms, API specifications, Provider commercial information, Platform Operator identities and commercial arrangements, security information, source code and architecture, certification and compliance documents, business strategies, and Incident evidence.

Confidentiality survives for five (5) years after termination. Trade-secret obligations survive while the information remains a trade secret. Disclosure is permitted to personnel, advisers, auditors, Providers, Platform Operators, and authorities only where necessary, legally permitted, and subject to appropriate confidentiality duties.

14. Non-Solicitation

During the term and for twelve (12) months afterwards, neither party shall directly solicit specifically identified employees or contractors of the other party to terminate their engagement, except through general non-targeted recruitment.

This clause does not restrict ordinary commercial communication with Providers or Platform Operators and does not prevent a Platform Operator from independently approaching The Aggregator.

15. Marketing Communications

Product and commercial communications may be sent where the Platform Partner opts in or where otherwise legally permitted. Use of names, logos, testimonials, case studies, traffic volumes, or relationship details in public marketing requires prior written consent.

16. Governing Law and Dispute Resolution

16.1 Governing law

This Agreement is governed by the laws of the Republic of Costa Rica, without regard to conflict-of-law principles.

16.2 Dispute resolution

The parties shall attempt good-faith negotiation for thirty (30) calendar days. Unresolved disputes shall be finally settled under the ICC Arbitration Rules in English, with the seat in San José, Costa Rica, before one arbitrator. Either party may seek urgent injunctive relief from a competent court.

A limited third-party beneficiary enforcing a right under this Agreement accepts this dispute-resolution provision for that claim.

17. General Provisions

17.1 Amendments

  • Non-material corrections or clarifications may take effect on publication with dashboard notice.
  • Material amendments require at least thirty (30) calendar days' prior written notice. The Platform Partner may terminate during that period.
  • Confidential pricing changes are governed by the Commercial Terms and cannot be introduced merely by changing the public Offer.

17.2 Assignment

The Platform Partner may not assign the Agreement without prior written consent. The Aggregator may assign it to an affiliate or as part of a merger, acquisition, corporate reorganisation, or sale of substantially all relevant assets.

17.3 Order of precedence

In case of conflict, the order of precedence is: signed or electronically accepted Commercial Terms; a signed Platform-specific addendum; Schedule D for data-protection matters; Schedule C for Incident procedures; the main body of this Offer; the remaining Schedules; and technical documentation.

Commercial Terms may override commercial mechanics but may not silently expand Provider Content rights or reduce mandatory compliance and data-protection obligations.

17.4 Entire agreement

This Offer, its Schedules, accepted Commercial Terms, and signed addenda form the entire agreement between the parties concerning its subject. Platform Operator Agreements and Provider agreements are separate contracts and are not incorporated except where expressly stated.

17.5 Severability

Invalid or unenforceable provisions shall be limited or severed while the remainder continues.

17.6 No waiver

Failure or delay in exercising a right is not a waiver.

17.7 Force majeure

Neither party is liable for delay caused by events beyond reasonable control, excluding payment obligations already accrued. The affected party shall notify the other and take reasonable mitigation steps.

17.8 Notices

Formal notices shall be sent through the Platform Partner Workspace and to registered email addresses. Legal notices to The Aggregator shall be sent to legal@aggregator.gg.

17.9 Language

The Agreement is in English. The English version prevails over translations.

17.10 Electronic records

Electronic acceptance, communications, audit records, and signatures satisfy contractual writing requirements to the extent permitted by applicable law.

17.11 Contact

  • Legal entity: Xyro Gaming Limitada
  • Cédula jurídica: 3-102-930374
  • Address: Puntarenas, Garabito, Jacó, Costado Este de la Municipalidad de Garabito, Costa Rica
  • Email: legal@aggregator.gg
  • Website: https://aggregator.gg

Schedule A — API Call Specification and Metering

A.1 API flow. A Game Session begins when an authenticated request attributable to a Platform Operator is transmitted through the Platform Partner System and routed by the Aggregator Service to the Provider RGS. The Provider RGS executes each Round and may generate multiple technical communications.

A.2 Eligible transaction. One Metered Successful API Call is recorded for one unique production bet or equivalent wager/debit transaction representing a billable Round where: (a) the Provider RGS sends an authenticated, schema-compliant transaction; (b) the transaction contains a unique Provider transaction and Round identifier; (c) The Aggregator routes it under the applicable Platform ID and Operator ID; (d) the transaction reaches the integration-specific Tested Acceptance Point; (e) that point returns the agreed successful acknowledgement; and (f) The Aggregator records the transaction and acknowledgement in one trace context.

Absent a written Provider-specific addendum for a multi-wager Round, the same transaction or Round may not generate more than one Metered Successful API Call.

A.3 Non-billable categories. Session launch, resume, or end; balance queries; result, win, payout, refund, rollback, void, or settlement-status communications; retries within the idempotency window; duplicates; monitoring and health checks; rejected or unauthenticated calls; free-round transactions identified as non-billable; sandbox, staging, and integration-validation traffic; and calls that do not receive the required successful acknowledgement are not separately billable.

A.4 Successful and Failed. An eligible API Call is Successful only if all A.2 conditions are satisfied. It is Failed where it times out, fails validation, cannot be routed, receives a non-success or malformed acknowledgement, or is identified as an idempotent duplicate. A Failed API Call is not deducted from Prepaid Capacity and is not payable to the Provider.

A.5 Platform acknowledgement risk. If the Tested Acceptance Point is controlled by the Platform Partner, its successful acknowledgement constitutes acceptance for Aggregator metering. A later failure to transmit, post, reconcile, or apply the transaction within the Platform Partner System or Platform Operator System does not retrospectively make the API Call Failed unless the original acknowledgement was established to have been invalid or incorrectly recorded.

A.6 Metering ledger. The Aggregator ledger is authoritative for API Call classification and Prepaid Capacity deduction, but not for Player wallet, GGR, game state, RNG, or Provider settlement.

A.7 Corrections. Verified duplicate, reversal, refund, routing, or classification discrepancies shall be corrected under Section 8.8.


Schedule B — Service Level Agreement

B.1 Aggregator Routing Layer. The Aggregator shall use commercially reasonable efforts to achieve 99.9% monthly availability for routing, authentication, metering, and observability components it controls. This is an operational target, not a guaranteed minimum.

B.2 Exclusions. Aggregator Unavailable Minutes exclude scheduled maintenance notified at least seventy-two (72) hours in advance; emergency maintenance; Provider RGS failure; Platform Partner System failure; Platform Operator System failure; third-party infrastructure beyond reasonable Aggregator control; force majeure; and Incident containment.

B.3 Platform Integration Layer. The Platform Partner shall maintain commercially reasonable availability, redundancy, monitoring, and support for the Platform Integration Layer appropriate to its traffic and Operator base. Unless Commercial Terms state otherwise, it should target 99.9% monthly availability for its production Tested Acceptance Points.

B.4 No automatic credits. No cash credit, additional API Call, refund, payout adjustment, or penalty arises solely because an SLA target is missed. This does not prevent a metering correction, liability for an independently established breach, termination for chronic uncured failure, or a remedy expressly included in Commercial Terms.

B.5 Support targets.

SeverityExampleFirst-response target
Critical / P0Routing unavailable, active Money-Path safety event, tenant crossover30 minutes
High / P1Significant degradation, suspected compromise2 hours
Medium / P2Non-blocking integration defect8 hours
Low / P3Documentation or cosmetic issue2 Working Days

Schedule C — Fraud, Abuse, Security, and Incident Response

C.1 Legal participants. The Service Offer Incident relationship contains three participants: Provider, The Aggregator, and Platform Partner. A Platform Operator is not a fourth party to the Service Offer Incident process. The Platform Partner is responsible for obtaining from the relevant Platform Operator the records, personnel, and cooperation needed to investigate traffic under its Operator ID.

C.2 Definitions.

  • "Incident" — an event involving unauthorised access, data loss, fraud, sanctions evasion, credential compromise, tenant crossover, signature forgery, replay, Provider Software Defect, RNG anomaly, game-state corruption, or another event requiring regulatory or data-protection notification.
  • "Money-Path Incident" — an Incident causing or threatening more than USD 100,000 in one event or more than USD 500,000 across a rolling thirty-day period.
  • "RCA" — the multi-source root-cause analysis coordinated under C.8.
  • "Incident Commander" — the person designated to coordinate joint Incident response. Failing agreement, The Aggregator acts as Incident Commander pro tem.
  • "Kill-Switch" — a mechanism capable of suspending a Provider, Provider Content, Operator ID, geography, route, or supported session identifier.

C.3 Multi-source reconstruction. No party's ledger is authoritative for every part of the supply chain. Provider records govern game state, RNG, mathematics, certification, and Provider RGS activity. Aggregator records govern routing, metering, correlation IDs, Platform ID, Operator ID, and Kill-Switch activity. Platform Partner records govern the Tested Acceptance Point, Platform Integration Layer, tenant mapping, onward transmission, and available records obtained from the relevant Platform Operator.

C.4 Continuous obligations. The Aggregator shall monitor its Routing Layer and metering integrity. The Platform Partner shall monitor credentials, signatures, tenant separation, Operator ID routing, acknowledgements, and onward transmission and shall use its downstream contractual rights to obtain relevant Player-level, wallet, KYC/AML, sanctions, and Responsible Gambling evidence when required for an Incident. Providers remain responsible for Provider RGS integrity, game state, RNG, certification, and Provider-controlled fraud.

C.5 Kill-Switch. The Aggregator and Platform Partner shall support controls capable of suspending a Provider, item of Provider Content, Operator ID, geography, route, or supported session identifier. Emergency authenticated instructions shall be acted upon as soon as commercially reasonable and logged.

C.6 Notification.

SeverityNotice deadlineChannel
Critical / P01 hourEmergency contact, email, dashboard
High / P18 hoursEmail and dashboard
Medium / P224 hoursEmail or dashboard
Low / P35 Working DaysDashboard

Notification does not require conclusive attribution. The Platform Partner shall obtain and relay relevant Platform Operator information within the applicable deadline or as soon as reasonably available.

C.7 Containment and Incident Reports. Each party may immediately isolate systems it controls. Where technically safe, accepted Rounds should be allowed to reach a consistent state. Player payout decisions remain exclusively with the person legally responsible for the relevant Player-facing service.

For Critical or High Incidents, materially involved parties shall provide a written report within seventy-two (72) hours after containment. The Platform Partner report shall include Platform ID and Operator ID; affected Provider and games; Tested Acceptance Point records; tenant and routing mapping; acknowledgement and onward-delivery records; relevant Platform Partner System logs; available wallet or transaction excerpts obtained from the Platform Operator; containment; estimated exposure; regulatory-notification status; and remediation.

C.8 RCA and Sync-Up. The Aggregator shall use commercially reasonable efforts to assemble an RCA within thirty (30) days after containment. A damage-allocation Sync-Up shall be convened within ten (10) Working Days after circulation. The Platform Partner shall participate and procure necessary information and participation from the relevant Platform Operator under Schedule E without making that Platform Operator a party to the Service Offer relationship.

C.9 Damage allocation.

  • Provider-attributable — Provider Software Defect, RNG anomaly, certification breach, Provider RGS compromise, or Provider-controlled fraud. Provider indemnity applies to The Aggregator and the Affected Platform Partner under the Provider Service Offer.
  • Aggregator-attributable — verified fault in Aggregator-controlled routing or metering. Liability is governed by Section 9.3.
  • Platform Partner-attributable — Platform credentials, Platform Integration Layer, tenant isolation, Operator ID mapping, Tested Acceptance Point, onward transmission, or activity originating through a Platform Operator and attributed to the Platform Partner under this Agreement. Platform Partner indemnity applies to The Aggregator and the Affected Provider.
  • External attack with all parties compliant — each contractual party bears its own loss, subject to applicable insurance.
  • Mixed cause — allocation follows proven causation. Unresolved claims proceed under the applicable Agreement's dispute-resolution clause.

A Platform Operator loss is addressed between that Platform Operator and the Platform Partner. It does not create a direct claim by the Platform Operator against The Aggregator or Provider.

C.10 Regulatory notification. Each party is responsible for notifications applicable to its own activities. The parties shall provide factual cooperation necessary for another party to meet a legal deadline. No party may identify another publicly without consent unless required by law or a competent authority.

C.11 Records. Incident evidence shall be retained for at least twelve (12) months after closure or longer where required by law, licence conditions, litigation hold, or Incident Commander instruction.


Schedule D — Inline DPA

Where The Aggregator processes Operator Personal Data as sub-processor to the Platform Partner:

  • Roles. Where a Platform Operator determines the processing purposes, the Platform Operator is controller, the Platform Partner is processor, The Aggregator is the Platform Partner's sub-processor, and a selected Provider is a further sub-processor to the extent it processes data solely to execute Provider Content. Actual roles under applicable law prevail.
  • Authority. The Platform Partner warrants that the Platform Operator Agreement gives it the instructions and authorisations required to appoint The Aggregator and disclosed Providers. The Aggregator may rely on instructions communicated by the Platform Partner without contracting directly with the Platform Operator.
  • Instructions. The Platform Partner's instructions, this Agreement, Operator ID configuration, Provider selection, and API specification constitute documented instructions.
  • Purpose. Processing is limited to authentication, routing, observability, security, metering, Provider execution, transaction and result communication, support, and Incident response.
  • Data. Data may include pseudonymised Player, session, Round, transaction, IP, device, wager, win, refund, balance, currency, jurisdiction, timestamp, and correlation data. Player names, personal email addresses, and payment credentials are not required unless separately approved with an identified lawful basis.
  • Confidentiality and security. Authorised personnel shall be bound by confidentiality and appropriate GDPR Article 32 measures shall be maintained.
  • Sub-processors. Disclosed infrastructure sub-processors are generally authorised subject to thirty (30) days' notice and a reasonable objection right. A Provider is specifically authorised when enabled by the Platform Partner after its identity, location, and available transfer information are disclosed.
  • Further flow-down. The Aggregator shall impose materially equivalent data-protection obligations on authorised further sub-processors and remains responsible to the Platform Partner for their performance to the extent required by law.
  • Personal Data Breach. The Aggregator shall notify the Platform Partner without undue delay and no later than twenty-four (24) hours after becoming aware of a Personal Data Breach affecting Operator Personal Data. A shorter Schedule C deadline prevails.
  • Assistance. The Aggregator shall reasonably assist with data-subject requests, breach response, DPIAs, prior consultation, audits, deletion, return, and regulatory response.
  • Deletion or return. On instruction reflecting the Platform Operator's choice, relevant data shall be deleted or returned within thirty (30) days after processing ends, subject to lawful retention and ordinary backup cycles.
  • International transfers. Transfers subject to GDPR Chapter V require an adequacy basis, applicable safeguard, or relevant Standard Contractual Clauses and supplementary measures.
  • Audit. Audit rights apply once per calendar year on thirty (30) days' notice at the Platform Partner's expense, with additional audits following a breach or reasonable evidence of material non-compliance.
  • Independent processing. A party using data for an independently determined purpose acts as controller for that processing and must separately establish its compliance.

Schedule E — Platform Operator Flow-Down Requirements

The Platform Partner shall ensure that its arrangements with Platform Operators enable it to comply with this Agreement, including rights to:

  • verify operator identity, licences, and territories;
  • assign and require use of an Operator ID;
  • prevent Restricted-Jurisdiction traffic;
  • impose Provider and certification restrictions;
  • suspend or disable the Platform Operator;
  • obtain Incident and transaction records;
  • protect Provider Content and Aggregator IP;
  • prohibit resale, redistribution, re-aggregation, reverse engineering, and metering circumvention;
  • obtain necessary data-processing instructions and sub-processor authorisations;
  • require Player-facing regulatory, wallet, KYC/AML, sanctions, Responsible Gambling, and Player-protection compliance from the person actually performing those functions;
  • recover Platform Operator-attributable losses; and
  • procure cooperation with Provider–Aggregator–Platform Partner Incident investigations.

These obligations do not make the Platform Operator a party or third-party beneficiary under an Aggregator Service Offer.


End of Platform Partner Service Offer (v1 — effective 23 July 2026).

This document is available in English only. The English version is the legally binding version.

Other documents Terms of UseOperator Service OfferProvider Service OfferPrivacy PolicySub-ProcessorsAffiliate Program Terms