1. Data Controller
SMGTY Europe OÜ
SMGTY is the data controller under the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).
Data protection contact: privacy@bizplay.app
2. Technical Security Measures
We implement the following technical controls to protect your data:
Encryption in Transit
TLS 1.3 for all data in transit; HTTPS enforced on all endpoints.
Encryption at Rest
AES-256 encryption for database storage and backups.
Access Control
Multi-factor authentication, role-based permissions, audit logs.
Pseudonymisation
Analytics data is pseudonymised before aggregation.
Vulnerability Management
Regular dependency audits and penetration testing schedule.
Backup & Recovery
Daily encrypted backups with tested restore procedures.
3. Organizational Measures
- Access control: role-based access to production systems; principle of least privilege enforced
- Employee training: all staff with data access receive annual data protection training
- Supplier assessment: third-party processors are evaluated for GDPR compliance before onboarding
- Data processing agreements: DPAs signed with all processors per GDPR Art. 28
- Incident response: documented procedure for detecting, containing, and reporting breaches within 72 hours (GDPR Art. 33)
- Records of processing: maintained per GDPR Art. 30
4. Cross-Border Data Transfers
When personal data is transferred outside the European Economic Area (EEA):
- We rely on European Commission adequacy decisions where available
- Otherwise we use Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfer impact assessments are conducted for high-risk transfers
5. Data Protection Impact Assessment (DPIA)
We conduct DPIAs for processing activities that are likely to result in a high risk to individuals, including:
- Large-scale processing of music playback behavioral data
- Introduction of new AI-based features that process user content
- New data sharing arrangements with third parties
DPIAs are reviewed when processing activities change materially.
6. Data Breach Notification
In the event of a personal data breach:
- Supervisory authority: We notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of the breach (GDPR Art. 33)
- Affected individuals: We notify without undue delay when the breach is likely to result in a high risk (GDPR Art. 34)
- Notifications include the nature of the breach, categories and approximate number of affected records, likely consequences, and measures taken
7. Exercising Your Rights
Submit data subject requests to privacy@bizplay.app or via our contact form.
We may require identity verification before fulfilling requests. If we cannot comply, we will explain why.
8. Contact & Supervisory Authority
SMGTY Europe OÜ: Data Protection Contact
Supervisory Authorities
Estonia (lead authority): Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): aki.ee
EU: the Data Protection Authority in your country of residence (find yours →)