Skip to content

DPA & GDPR

Fanzava acts as a data processor for participant data on your hub. You (the hub admin’s organisation) are the data controller. Fanzava processes participant data only on your documented instructions and within the bounds of our Data Processing Agreement.

Fanzava’s Data Processing Agreement is incorporated into the Terms of Service for all paid plans. If you need a separately executed DPA (common for enterprise procurement) contact your account manager.

Enterprise customers can request a DPA countersigned by Fanzava within five business days. The DPA includes the EU Standard Contractual Clauses by default, which apply to any processing of EU residents’ data outside the EU.

Requirement How Fanzava addresses it
Lawful basis Your organisation establishes the lawful basis for processing (typically legitimate interest or contract). Fanzava processes only on your instructions.
Data minimisation Fanzava collects only the data needed to operate competitions: email, display name, timezone preference, and tipping or bracket activity. UTM acquisition data is anonymised after 90 days. No unnecessary profiling.
Right of access Participants can export their own data from their profile. Hub admins can export per-participant data from the admin panel.
Right to rectification Participants can correct their own profile data at any time. Hub admins can correct participant data via Admin → Participants.
Right to erasure See Participant data deletion below for the full workflow.
Right to data portability Participant data is exportable as CSV or JSON in machine-readable form.
Right to object / restrict Participants can disable email notifications, opt out of analytics, or have their account suspended pending review on request.
Sub-processors Fanzava’s sub-processors are listed on the Fanzava sub-processors page and updated with 30 days’ notice of any change.
Data transfers Data is stored in the region your hub is placed in. Australia and the European Union are live today; see Data residency. EU Standard Contractual Clauses are included in the DPA for any cross-border transfers.
Breach notification Fanzava notifies affected hub admins within 72 hours of a confirmed breach, as required by GDPR Article 33.
Privacy Impact Assessments Fanzava can provide its own DPIA documentation for Enterprise customers undertaking their own assessments. Contact your account manager.

UK GDPR is a legally distinct framework following the UK’s exit from the EU. Fanzava’s controls apply equally to UK data subjects:

  • The UK Government’s adequacy decision regarding the EU means EU-region storage is compliant for UK residents
  • Fanzava’s DPA explicitly addresses UK data subjects under UK GDPR terms
  • The breach notification commitment applies for UK residents under both UK and EU rules

For hubs primarily serving UK participants, select the European Union region. The United Kingdom region is an email sending zone rather than a live data region, so a hub placed there has its mail sent from London and its data held in Australia. The European Union region is the residency choice that holds UK participants’ data in Europe.

The Schrems II ruling established that transfers of EU residents’ personal data to jurisdictions without adequate protection (notably the US) require additional safeguards beyond Standard Contractual Clauses alone. Fanzava addresses this through:

  • Regional storage: a hub on the European Union region holds its participant data in an EU database, in an EU cell, with its own background jobs. Sports reference data is replicated into the same cell. See Data residency
  • Regional sending: mail for an EU hub is sent from an EU region
  • Standard Contractual Clauses: included in the DPA for any residual transfers
  • Technical and organisational measures: documented in the DPA Annex II

Fanzava does not offer customer-managed encryption keys, and does not claim that decryption of EU data is technically impossible outside the EU. Keys are held by the underlying provider in the region the data sits in. If your assessment depends on a stronger key-custody control than that, raise it before signing.

Fanzava complies with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs):

  • Data is stored in Australia by default for AU/NZ hubs
  • Participant data is not used for direct marketing without consent
  • Data retention is configurable on Enterprise plans: contact your account manager to set custom retention periods

Fanzava complies with the Notifiable Data Breaches (NDB) scheme. In the event of a breach likely to result in serious harm to affected individuals, Fanzava will:

  • Notify affected hub admins within 72 hours of confirming the breach
  • Provide the information required for hub admins (as APP entities) to make their own NDB notifications to the OAIC and to affected individuals
  • Preserve evidence and assist with any subsequent investigation

Fanzava does not store payment card details. Payment processing is handled by Stripe, which is PCI DSS Level 1 certified. Fanzava receives only the Stripe customer ID, billing email, and high-level subscription metadata, never the card number, CVV, or expiry. This keeps Fanzava out of PCI scope as a processor of card data.

Right of erasure is implemented as a phased deletion workflow rather than an instant operation, to ensure clean deletion across all systems while preserving the integrity of historical data the deleted participant has already affected.

To trigger deletion:

  1. Go to Admin → Participants
  2. Find the participant
  3. Click Delete participant
  4. Confirm

Once confirmed, the following sequence runs automatically:

Stage Timing Effect
Logout Immediate All active sessions for the participant are revoked
Leaderboard removal Within 24 hours Participant is removed from public leaderboards; historical scores are anonymised to “Deleted participant”
PII scrub Within 7 days All personal identifiers (email, display name, profile photo, timezone, IP hashes) are removed from the active database
Backup scrub Within 30 days Personal identifiers are removed from all retained backups

Tips, bracket picks, and scoring contributions are retained in anonymised form so that historical leaderboards and round results remain accurate. The original participant cannot be re-identified once the PII scrub is complete.

Banter Board posts are free text the participant wrote, so they are treated as personal data rather than kept as history. When an erasure runs, the text, GIF and mentions of the participant’s posts are removed and the posts leave the board. A post that still appears in a moderation view shows its author as “Former member”. Closing an account without requesting erasure keeps the display name on its posts.

Hub admins can configure additional privacy controls beyond GDPR’s baseline:

  • Email visibility: hide participant emails from group leaderboards and exports
  • Display name policy: require real names, allow nicknames, or allow pseudonyms
  • Data export restrictions: limit which admin roles can export participant data
  • Retention overrides: configure custom retention periods for analytics, audit logs, and inactive participant data (Enterprise)

Configure from Admin → Settings → Security → Privacy.

Was this page helpful?

Raise a ticket about this page

Comments