Data Protection

Security measures, GDPR obligations, and your data rights.

Last updated: June 1, 2026

This translation is an informational draft pending legal review. The Turkish version is the binding version.

1. Data Controller

SMGTY Europe OÜ

SMGTY is the data controller under the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).

Data protection contact: privacy@bizplay.app

2. Technical Security Measures

We implement the following technical controls to protect your data:

Encryption in Transit

TLS 1.3 for all data in transit; HTTPS enforced on all endpoints.

Encryption at Rest

AES-256 encryption for database storage and backups.

Access Control

Multi-factor authentication, role-based permissions, audit logs.

Pseudonymisation

Analytics data is pseudonymised before aggregation.

Vulnerability Management

Regular dependency audits and penetration testing schedule.

Backup & Recovery

Daily encrypted backups with tested restore procedures.

3. Organizational Measures

  • Access control: role-based access to production systems; principle of least privilege enforced
  • Employee training: all staff with data access receive annual data protection training
  • Supplier assessment: third-party processors are evaluated for GDPR compliance before onboarding
  • Data processing agreements: DPAs signed with all processors per GDPR Art. 28
  • Incident response: documented procedure for detecting, containing, and reporting breaches within 72 hours (GDPR Art. 33)
  • Records of processing: maintained per GDPR Art. 30

4. Cross-Border Data Transfers

When personal data is transferred outside the European Economic Area (EEA):

  • We rely on European Commission adequacy decisions where available
  • Otherwise we use Standard Contractual Clauses (SCCs) approved by the European Commission
  • Transfer impact assessments are conducted for high-risk transfers

5. Data Protection Impact Assessment (DPIA)

We conduct DPIAs for processing activities that are likely to result in a high risk to individuals, including:

  • Large-scale processing of music playback behavioral data
  • Introduction of new AI-based features that process user content
  • New data sharing arrangements with third parties

DPIAs are reviewed when processing activities change materially.

6. Data Breach Notification

In the event of a personal data breach:

  • Supervisory authority: We notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of the breach (GDPR Art. 33)
  • Affected individuals: We notify without undue delay when the breach is likely to result in a high risk (GDPR Art. 34)
  • Notifications include the nature of the breach, categories and approximate number of affected records, likely consequences, and measures taken

7. Exercising Your Rights

Submit data subject requests to privacy@bizplay.app or via our contact form.

RightResponse Time
Access / Data Copy30 days
Rectification30 days
Erasure30 days
Data Portability30 days
Objection30 days
RestrictionImmediate on request

We may require identity verification before fulfilling requests. If we cannot comply, we will explain why.

8. Contact & Supervisory Authority

SMGTY Europe OÜ: Data Protection Contact

privacy@bizplay.app

Supervisory Authorities

Estonia (lead authority): Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): aki.ee

EU: the Data Protection Authority in your country of residence (find yours →)

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.