Data Compliance

Last updated: June 16, 2026

KickOff OS is committed to protecting personal information and complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Brazil's LGPD, Canada's PIPEDA, and similar frameworks. This page summarizes our compliance posture and is intended to complement, not replace, our Privacy Policy and Terms of Use.

1. Roles

  • Controller: For account, billing, marketing, and product-improvement data, KickOff OS acts as the data controller.
  • Processor: When venues use KickOff OS to engage their guests, KickOff OS acts as a processor on behalf of the venue with respect to guest activity collected inside that venue's sessions.

2. Lawful Bases for Processing

  • Contract: to deliver the Services you request.
  • Legitimate interests: to secure the Services, prevent fraud, debug, and improve features.
  • Consent: for optional analytics, marketing emails, and any processing that requires consent under local law.
  • Legal obligation: to meet tax, accounting, and regulatory requirements.

3. Your Rights

Subject to local law, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Delete your personal information ("right to be forgotten").
  • Restrict or object to processing.
  • Receive a portable copy of your information in a machine-readable format.
  • Withdraw consent at any time where processing is based on consent.
  • Opt out of "sale" or "sharing" of personal information (CCPA/CPRA). We do not sell personal information.
  • Be free from discrimination for exercising privacy rights.
  • Appeal a denial of your request where required by law.
  • Lodge a complaint with your local supervisory authority.

Submit requests to privacy@kickoff-os.com. We verify your identity and respond within the timeframe required by applicable law (typically 30–45 days). You may authorize an agent to submit requests on your behalf.

4. International Data Transfers

Personal information may be processed in countries other than your own. Where required, we rely on appropriate safeguards including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and supplementary measures based on transfer-impact assessments.

5. Subprocessors

We use vetted third-party providers to deliver the Services. Current subprocessors include cloud hosting, database and authentication infrastructure, payment processing, email delivery, error monitoring, and analytics. Each subprocessor is subject to a data-processing agreement that requires equivalent protection of personal information.

6. Data Retention

We retain personal information only as long as necessary for the purposes for which it was collected, including legal, accounting, and reporting requirements. Live match-session data (votes, chat) is short-lived and may be deleted or anonymized after a match ends. Account and billing records are retained while the account is active and for a reasonable period thereafter as required by law.

7. Security Program

  • Encryption in transit (TLS) for all client–server traffic.
  • Encryption at rest for our managed database and storage.
  • Row-level security on user-facing tables, with role-based access from server-side code.
  • Least-privilege access controls for engineering and support staff.
  • Logging, monitoring, and automated security scanning of code and dependencies.
  • Background checks and confidentiality obligations for personnel with access to production systems.
  • Incident response and breach-notification procedures consistent with applicable law.

8. Breach Notification

If we become aware of a personal data breach affecting your information, we will notify affected users and applicable authorities without undue delay where required, and in the timeframe required by law (e.g. within 72 hours under GDPR where feasible).

9. Children

The Services are not directed to children under 16. We do not knowingly collect personal information from children. If we learn we have collected such information, we will delete it.

10. Accessibility

We strive to make the Services accessible to users with disabilities. If you encounter accessibility barriers, contact us so we can address them.

11. Cookies and Tracking

We use strictly necessary cookies to operate the Services. Optional analytics and preference cookies are used only with consent where required. You can manage cookies through your browser settings.

12. Data Processing Agreements (DPA)

Business customers and venue operators that require a DPA may request one at privacy@kickoff-os.com. Our standard DPA incorporates the latest Standard Contractual Clauses where applicable.

13. Updates

We update this page as our practices evolve. The "Last updated" date reflects the latest revision.

14. Contact

For any compliance, privacy, or security inquiry, contact privacy@kickoff-os.com.