← BACK TO HOME

The Aggregator - Privacy Policy

Effective date: 19 August 2026

1. Controller Identity

Xyro Gaming Limitada, cédula jurídica 3-102-930374, a company incorporated under the laws of the Republic of Costa Rica, with registered address at Puntarenas, Garabito, Jacó, Costado Este de la Municipalidad de Garabito ("The Aggregator", "we", "us") is the data controller for business-contact, account, website, billing, and support data processed for its own purposes as described in this Privacy Policy. Where an Operator instructs us to route Player-adjacent personal data through the Platform, the Operator is controller and we act as processor under Schedule D of the Operator Service Offer. A selected Game Provider may act as our sub-processor for that routed data or, for a distinct purpose it independently determines, as an independent controller under applicable law.

Contact for data protection inquiries: legal@aggregator.gg

2. Scope

This Privacy Policy applies to all personal data processed by The Aggregator in connection with:

  • The Aggregator Platform, including the API, dashboard, and integration workspace.
  • The operator registration process and ongoing account management.
  • The Provider registration process and ongoing account management.
  • The Aggregator website at https://aggregator.gg.
  • Interactions with The Aggregator's Telegram bot (@aggregator_aibot), including messages, commands, and metadata provided during conversations.
  • Technical data transmitted through the Platform while routing API requests, callbacks, responses, and acknowledgements between Operators and selected Provider RGSs.

This Privacy Policy does not govern processing independently determined by Operators or Game Providers for their own gaming, content, certification, regulatory, or player-facing purposes. They must provide their own privacy information for such processing.

3. Categories of Personal Data

3.1 Operator and Provider Registration Data

  • Contact person name
  • Company name and registered address
  • Email address
  • Phone number
  • Telegram handle
  • Cryptocurrency wallet address (if provided)

3.2 Account and Transaction Data

  • API usage logs and Metered Successful API Call counts
  • Invoice and payment records
  • Support and communication history
  • Platform access logs (login timestamps, IP addresses)

3.3 Incidental Technical Data (Player-Adjacent)

To the extent the following data is included in API requests, callbacks, responses, or acknowledgements routed between an Operator and a selected Provider RGS, The Aggregator may process:

  • IP addresses
  • Session identifiers
  • Device fingerprints and technical metadata
  • Transaction, Round, wager, win, refund, balance, currency, jurisdiction, and result fields strictly required by the applicable Provider API

The Aggregator does not request Player names, personal email addresses, or payment-instrument credentials and does not maintain an authoritative Player profile or wallet. For this category of data, The Aggregator acts as processor on behalf of the Operator under Section 12.6 and Schedule D of the Operator Service Offer. A Provider selected by the Operator receives only the data routed to its Provider RGS and is subject to the data-processing terms in the Provider Service Offer.

3.4 Website Visitor Data

  • IP address and approximate geolocation
  • Browser type and device information
  • Pages visited and interaction data
  • Referral source

3.5 Inquiry and Demo Request Data

When a visitor submits a pricing inquiry or demo request prior to registration, the following data may be collected:

  • Contact person name
  • Company name
  • Email address, phone number, Telegram handle
  • Source page and locale preference
  • Where the visitor books a demonstration call: the selected date, time, and time zone, together with any note the visitor adds to the booking form

This data is collected to respond to a business inquiry initiated by the data subject.

Demonstration calls are scheduled through a third-party scheduling service embedded in the website. When the booking section loads, that service receives the technical data described in Section 3.4 (including IP address and browser information), whether or not a booking is made. If the visitor completes a booking, it additionally receives the name, work email address, company name, selected date, time, and time zone, and any note added to the booking form, in order to record the booking and send the confirmation. The resulting calendar entry and video-meeting link are created in the scheduling service and in The Aggregator's calendar tools, which receive the visitor's name and email address as an invited participant. These services are identified at https://aggregator.gg/legal/sub-processors.

3.6 Telegram Bot Interaction Data

When interacting with The Aggregator's Telegram bot (@aggregator_aibot), the following data may be processed:

  • Telegram user ID and username
  • Message content and timestamps
  • Any business information voluntarily shared during conversations
PurposeData categoriesLegal basis (GDPR)
Operator and Provider registration and onboarding3.1Performance of a contract where the data subject is personally party (Art. 6(1)(b)); otherwise legitimate interests in administering the B2B relationship (Art. 6(1)(f))
Service delivery, billing, and invoicing3.1, 3.2Performance of a contract where applicable (Art. 6(1)(b)); otherwise legitimate interests in administering and documenting the B2B relationship (Art. 6(1)(f))
Platform security and fraud prevention3.1, 3.2, 3.4Legitimate interests (Art. 6(1)(f))
Regulatory compliance and AML/CTF3.1, 3.2Legal obligation where a specific law applies (Art. 6(1)(c)); otherwise legitimate interests in risk, fraud, and counterparty management (Art. 6(1)(f))
Routing and transmission of gameplay-related API requests and responses3.3Determined by the Operator as controller; processed by The Aggregator under documented DPA instructions
Marketing communications (opt-in only)3.1Consent (Art. 6(1)(a))
Website analytics and improvement3.4Legitimate interests (Art. 6(1)(f))
Responding to pricing/demo inquiries3.5Legitimate interests (Art. 6(1)(f))
Telegram bot interactions and support3.6Legitimate interests (Art. 6(1)(f)); performance of a contract (Art. 6(1)(b)) where applicable

5. Data Sharing and Sub-Processors

The Aggregator may share personal data with the following categories of recipients:

  • Cloud infrastructure providers for hosting and data storage.
  • Payment processors for billing and invoicing.
  • Game Providers selected or enabled by an Operator to the extent necessary for the Provider RGS to execute Provider Content and return transaction or result communications. Their identity, processing location, and available transfer information are shown in the Operator Workspace before production data is routed.
  • Scheduling, calendar, and video-conferencing providers for booking and holding pre-sales demonstration calls, limited to the booking data and technical data identified at https://aggregator.gg/legal/sub-processors.
  • Professional advisors (legal, accounting, audit) under confidentiality obligations.
  • Regulatory authorities and law enforcement where required by applicable law.

A current list of infrastructure sub-processors and information about selected Game Providers is maintained at https://aggregator.gg/legal/sub-processors and in the Operator Workspace. Intended additions or replacements of generally authorised infrastructure sub-processors are notified to affected Operators with at least thirty (30) calendar days' notice. A Game Provider is specifically authorised when the Operator selects or enables it after the relevant processing information is displayed.

6. International Transfers

The Aggregator's primary data processing infrastructure is located in the European Union. To the extent personal data is transferred outside the European Economic Area (including to Costa Rica where The Aggregator is incorporated), appropriate safeguards are applied, including:

  • European Commission Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914.
  • Assessment of the legal framework in the recipient country to ensure an essentially equivalent level of protection.

Operators may request a copy of the applicable SCCs and transfer details by contacting legal@aggregator.gg. Website visitors whose data is transferred outside the European Economic Area, including through the scheduling service described in Section 3.5, may request the same information at the same address.

7. Data Retention

Data categoryRetention period
Operator and Provider registration dataDuration of the Agreement + 5 years (regulatory, tax, and audit requirements)
Transaction and billing dataDuration of the Agreement + 5 years
Full API payload and technical diagnostic logs (3.3), where retainedUp to 90 days in identifiable or pseudonymised form unless an Incident, legal hold, or law requires longer
Metering ledger entries and billing transaction identifiersDuration of the Agreement + not less than 12 months, or longer where required for tax, audit, dispute, or legal obligations
Support communicationsDuration of the Agreement + 2 years
Website visitor data12 months
Inquiry and demo request data (3.5), including demonstration-call bookings2 years from submission, or until registration (whereupon it becomes registration data). Booking records held by the scheduling service and the corresponding calendar entries are retained for the same period and deleted on request
Telegram bot interaction data (3.6)Duration of the Agreement + 2 years; pre-registration interactions retained for 2 years
Marketing consent recordsDuration of consent + 3 years

Anonymized or aggregated data may be retained indefinitely for analytics and service improvement.

8. Data Subject Rights

Under applicable data protection law (including GDPR and, where applicable, CCPA), you have the following rights:

  • Right of access (GDPR Art. 15): obtain confirmation of whether your data is processed and request a copy.
  • Right to rectification (GDPR Art. 16): correct inaccurate or incomplete data.
  • Right to erasure (GDPR Art. 17): request deletion of your data, subject to legal retention obligations.
  • Right to restriction (GDPR Art. 18): restrict processing in certain circumstances.
  • Right to data portability (GDPR Art. 20): receive your data in a structured, machine-readable format.
  • Right to object (GDPR Art. 21): object to processing based on legitimate interests or for direct marketing.
  • Right to withdraw consent (GDPR Art. 7(3)): withdraw marketing consent at any time without affecting prior processing.

For California residents under CCPA: you have the right to know what personal information is collected, to request deletion, and to opt out of the sale of personal information. The Aggregator does not sell personal information.

To exercise rights concerning account, contact, website, billing, or support data for which The Aggregator is controller, contact legal@aggregator.gg. A request concerning Player-adjacent data processed for an Operator will be forwarded to the relevant Operator, and The Aggregator will act on that Operator's documented instructions unless applicable law requires otherwise.

Requests will be responded to within thirty (30) days (GDPR) or forty-five (45) days (CCPA) of receipt. Identity verification may be required before processing requests.

9. Security Measures

The Aggregator implements appropriate technical and organizational measures to protect personal data, including:

  • Encryption in transit (TLS 1.2+) and at rest.
  • Access controls and role-based authentication.
  • Infrastructure monitoring and intrusion detection.
  • Regular security assessments and vulnerability management.
  • Employee and contractor confidentiality obligations.

10. Cookies and Tracking

The Aggregator website may use essential cookies for session management and authentication. Analytics cookies, if any, are deployed only with user consent where required by applicable law (ePrivacy Directive).

The Platform dashboard uses session cookies necessary for authentication and security. These are strictly necessary and do not require consent.

The booking section of the website embeds a third-party scheduling service. Loading that section causes the visitor's browser to connect to the provider identified at https://aggregator.gg/legal/sub-processors, which may set storage or cookies on its own domain. Where consent is required by applicable law for such an embed, it is obtained before the section loads.

11. Children

The Aggregator services are directed at business entities (B2B). We do not knowingly collect personal data directly from individuals under the age of 18. Operators are responsible for age controls required by their licences and applicable law. If you believe that data from a minor has been provided to us, contact legal@aggregator.gg.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to affected Operators and Providers through the Platform dashboard and their registered email at least thirty (30) calendar days before taking effect. The date at the top identifies the applicable or proposed version status.

13. Contact and Complaints

  • Data controller: Xyro Gaming Limitada, cédula jurídica 3-102-930374
  • Address: Puntarenas, Garabito, Jacó, Costado Este de la Municipalidad de Garabito, Costa Rica
  • Email: legal@aggregator.gg
  • Website: https://aggregator.gg

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

This document is available in English only. The English version is the legally binding version.