Our commitment to GDPR

Cluevo is designed with GDPR in mind. We are committed to helping our players and adventure organisers meet their obligations under the General Data Protection Regulation (EU) 2016/679 and Greek Law 4624/2019.

Roles: controller and processor

For adventures organised by an event organiser — for example a company running a team offsite that uses Cluevo — the organiser acts as the data controller for the participants they invite; Cluevo acts as the data processor, processing that data only on the organiser's documented instructions.

For data collected directly through cluevo.app or by individual players creating their own account, Cluevo acts as the data controller. See our Privacy Policy for detail.

Data Processing Agreement (DPA)

We offer a Data Processing Agreement to any organiser who requests one, as required by GDPR Article 28. The DPA sets out our obligations as a data processor: sub-processor disclosure, security measures, breach notification timelines, and how data subject requests are handled. Contact privacy@cluevo.app to request your DPA.

EU data residency

All personal data processed by Cluevo is stored exclusively within the European Union. Our infrastructure runs on Google Cloud Platform in the europe-west4 region (the Netherlands). No personal data is transferred to third countries without appropriate safeguards (Standard Contractual Clauses).

Sub-processors

We use the following sub-processors to deliver the Service:

We will notify customers of any intended changes to sub-processors with at least 14 days' advance notice.

Data subject rights

Cluevo provides tools in the mobile app and admin console to help you exercise your rights:

For any request, email privacy@cluevo.app.

Security measures

We implement appropriate technical and organisational measures: encryption of all data in transit (TLS 1.2+) and at rest (AES-256); role-based access with least-privilege; audit logging of admin actions; server-side validation of every submission; and rate-limiting to deter abuse. Photos uploaded for photo checkpoints are held in access-controlled Firebase Storage buckets.

Data breach notification

In the event of a personal data breach that is likely to result in a risk to individuals, we will notify affected users and the Hellenic Data Protection Authority without undue delay and within 72 hours of becoming aware, as required by GDPR Article 33.

Contact

For GDPR-related enquiries, a DPA request, or to exercise data subject rights, contact privacy@cluevo.app. You may also complain to the Hellenic Data Protection Authority.