Our commitment to GDPR
Cluevo is designed with GDPR in mind. We are committed to helping our players and adventure organisers meet their obligations under the General Data Protection Regulation (EU) 2016/679 and Greek Law 4624/2019.
Roles: controller and processor
For adventures organised by an event organiser — for example a company running a team offsite that uses Cluevo — the organiser acts as the data controller for the participants they invite; Cluevo acts as the data processor, processing that data only on the organiser's documented instructions.
For data collected directly through cluevo.app or by individual players creating their own account, Cluevo acts as the data controller. See our Privacy Policy for detail.
Data Processing Agreement (DPA)
We offer a Data Processing Agreement to any organiser who requests one, as required by GDPR Article 28. The DPA sets out our obligations as a data processor: sub-processor disclosure, security measures, breach notification timelines, and how data subject requests are handled. Contact privacy@cluevo.app to request your DPA.
EU data residency
All personal data processed by Cluevo is stored exclusively within the European Union. Our infrastructure runs on Google Cloud Platform in the europe-west4 region (the Netherlands). No personal data is transferred to third countries without appropriate safeguards (Standard Contractual Clauses).
Sub-processors
We use the following sub-processors to deliver the Service:
- Google LLC (Firebase / Google Cloud) — cloud infrastructure, database, authentication, cloud functions, storage, and push notifications on Android. Covered by Google's EU Standard Contractual Clauses.
- Expo — push notification token registration on iOS and Android.
- Plausible Analytics — cookieless website analytics. No personal data leaves the EU.
We will notify customers of any intended changes to sub-processors with at least 14 days' advance notice.
Data subject rights
Cluevo provides tools in the mobile app and admin console to help you exercise your rights:
- Right of access — export your player profile and session history.
- Right to rectification — edit your profile fields at any time.
- Right to erasure — permanently delete your account from Settings.
- Right to restrict processing — pause or abandon a session.
- Right to data portability — request an export in a standard format.
For any request, email privacy@cluevo.app.
Security measures
We implement appropriate technical and organisational measures: encryption of all data in transit (TLS 1.2+) and at rest (AES-256); role-based access with least-privilege; audit logging of admin actions; server-side validation of every submission; and rate-limiting to deter abuse. Photos uploaded for photo checkpoints are held in access-controlled Firebase Storage buckets.
Data breach notification
In the event of a personal data breach that is likely to result in a risk to individuals, we will notify affected users and the Hellenic Data Protection Authority without undue delay and within 72 hours of becoming aware, as required by GDPR Article 33.
Contact
For GDPR-related enquiries, a DPA request, or to exercise data subject rights, contact privacy@cluevo.app. You may also complain to the Hellenic Data Protection Authority.