Skip to content
Legal

Privacy notice

How we handle personal data on this website, where our role as processor for our customers' data begins, and the rights you have. This page is general information and not legal advice.

About this notice

1.1 This notice explains how GAME CHANGER 360 LTD handles personal data in connection with new.gamechanger360.co.uk (the "website"). It covers the enquiry form, the newsletter, the Integrity Readiness Check and the technical data created when you visit a page.

1.2 It is written to meet the transparency requirements of Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where this notice refers to an Article, that is an Article of the UK GDPR.

1.3 It does not cover the personal data that our customers place into 360 Academy, 360 Report, 360 Sentinel or 360 Intelligence. Our role there is different, and section 3 explains why that distinction matters more than anything else in this notice.

1.4 This notice is general information about how we handle personal data. It is not legal advice, and it does not form part of any contract between us.

Who we are and how to contact us

2.1 The controller of the personal data described in sections 4 to 7 is GAME CHANGER 360 LTD, a private company limited by shares incorporated in England and Wales with company number 15064064. Our registered office is Tennyson House, Cambridge Business Park, Cambridge, CB4 0WZ, United Kingdom. We trade as GAMECHANGER360.

2.2 For any question about this notice, or to exercise a right described in section 17, write to privacy@gamechanger360.co.uk or to the Data Protection Lead at our registered office.

2.3 [TO CONFIRM: whether a data protection officer has been appointed under Article 37 UK GDPR and, if so, their name and contact details.] If no data protection officer is appointed, requests are handled by the director responsible for data protection.

When we are a controller and when we are a processor

3.1 We act in two clearly separated capacities, and the capacity determines who you should approach about your data.

3.2 We are the controller for personal data you give us through this website: your enquiry, your newsletter subscription, your Integrity Readiness Check submission and the technical data our hosting provider records when a page is served. We decide why and how that data is used, and this notice governs it.

3.3 We are a processor for the personal data that an organisation places into our products. Federations, leagues, clubs, regulators, universities and player associations deploy 360 Academy, 360 Report, 360 Sentinel and 360 Intelligence, and decide what goes into them, why, who may see it and how long it is kept. That organisation is the controller. We process it only on its documented instructions, under a written data processing agreement that meets Article 28.

3.4 So if you are a learner in an academy, a reporter using a whistleblowing channel, a person named in a case file, or a member of staff whose material has been indexed, the controller is the organisation that operates that channel, not us. Its privacy notice applies, and a rights request should go to it. If you approach us instead, we will not act on your data ourselves. We will tell you who the controller is where we are permitted to, and we will pass the request to it.

3.5 We do not use customer data from the products for our own purposes. We do not use it to train publicly available models, and we do not combine it with data from other customers.

Website enquiries and briefing requests

4.1 When you use the enquiry form we process:

  • your first and last name
  • your work email address
  • your organisation and, if you give it, your role
  • the stakeholder group you select and the reason for the enquiry
  • the content of your message
  • whether you asked to receive the newsletter as well

4.2 We use it to read your enquiry, to reply, to arrange a briefing or demonstration if that is what you asked for, and to keep a record of the exchange. Submissions are delivered to our mailbox by email. This website has no customer database behind it, so an enquiry lives in email and in our own business records rather than in a store on the site.

4.3 The lawful bases are Article 6(1)(f), our legitimate interests in responding to a business enquiry and pursuing a commercial relationship, and, where you have asked us to take steps towards a contract, Article 6(1)(b). Section 8 summarises our balancing test. Where a customer relationship follows, Article 6(1)(b) covers the personal data we need to perform that contract, and Article 6(1)(c) covers data we must keep to comply with a legal obligation such as our accounting records.

4.4 The form asks you to confirm that you have read this notice. That confirmation is not the lawful basis for the processing, and withdrawing it would not remove our ability to answer you. Your right to object under Article 21 is set out in section 17.

4.5 Retention: correspondence relating to an enquiry that does not lead to a commercial relationship is kept for [TO CONFIRM: retention period for enquiry correspondence, for example 24 months from last contact] and then deleted. Where a commercial relationship follows, records are kept for the life of the relationship and then for as long as we need them to meet our legal, accounting and limitation-period obligations.

4.6 Giving us this data is voluntary, but we cannot answer an enquiry without a name, an email address and a message.

4.7 Please do not use this form to raise an integrity concern, and please do not attach evidence to it. It is an ordinary business mailbox and it gives you none of the protection that 360 Report is built to provide.

The Integrity Brief newsletter

5.1 If you subscribe to The Integrity Brief we process your email address, the page you subscribed from and, where you subscribed through the enquiry form, your name. We use it to send the briefing and to manage your subscription.

5.2 The lawful basis is your consent under Article 6(1)(a), and we rely on your consent under regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 to send the briefing to you by email. Subscribing is a positive act you take yourself, and it is never bundled with anything else: on the enquiry form and in the Readiness Check the newsletter is a separate, unticked box.

5.3 You can withdraw consent at any time, and it is as easy to withdraw as it was to give. Use the unsubscribe link in any issue or email us. Withdrawal does not affect the lawfulness of anything sent before it.

5.4 We do not embed a tracking pixel in the briefing to measure whether you opened it, and we do not rewrite the links in it to measure whether you clicked. Our sending platform is capable of both, and we have not turned either on. If we ever do, we will update this notice first, because reading a tracking pixel is storage on your device within the meaning of regulation 6 of the Privacy and Electronic Communications Regulations and would need your consent. [TO CONFIRM: that open and click tracking are disabled at the Resend account level, and a note in the launch checklist to keep them disabled.]

5.5 Retention: we keep your subscription until you unsubscribe. After that we keep a suppression record of your address so that we can honour your choice and not add you back by accident. We keep that suppression record for as long as we send the briefing at all.

The Integrity Readiness Check

6.1 The Readiness Check is an indicative self-assessment about an organisation's integrity arrangements. It runs in two separate steps, and the first one asks for nothing that identifies you.

6.2 Step one: you describe the organisation (its type, sport, jurisdiction, scale, betting-market exposure and whether it has had integrity cases), the function you work in, your answers to eight questions, and anything you choose to type into three optional free-text boxes. The assessment is then run and the report is returned to your browser. Nothing from step one is stored on our servers or emailed to us, and the response is served with a no-store cache directive. It is transmitted in that step to the AI service that drafts the narrative, and section 9 explains that in full. Your progress is held in your browser's session storage so that a reload does not lose your work; section 3 of our cookie policy describes that.

6.3 Step two, which only happens if you ask for it: you give your name, your work email address, your organisation and, optionally, your job title. We re-run the assessment from your answers on the server, generate a PDF report and email it to you. We also send ourselves a copy, including the organisation profile and anything you typed into the free-text boxes, so that we can follow up on an informed basis.

6.4 The lawful basis for producing and sending the report you asked for is Article 6(1)(b), steps taken at your request before entering into a contract. The lawful basis for the internal copy and for the single follow-up contact described at the point of submission is Article 6(1)(f), our legitimate interests in developing a commercial conversation with an organisation that has asked to be assessed. Section 8 summarises our balancing test. If you tick the newsletter box as well, section 5 applies to that.

6.5 Please keep the free-text boxes at the level of your organisation's arrangements. Do not name individuals, do not describe an open case or an allegation, and do not include health, criminal-offence or other sensitive details. We do not need them, we do not want them in an ordinary mailbox, and section 9 explains that what you type is also sent to an AI model to draft the narrative.

6.6 Retention: the report and the covering emails sit in our mailbox and are kept for [TO CONFIRM: retention period for Readiness Check submissions and reports, for example 24 months from delivery]. Where we hold anonymous aggregate results for research, they contain no personal data and no organisation name, and are not covered by this notice.

6.7 The result is not an audit, a certification or a statement that any organisation does or does not comply with any law. Clause 4 of our terms of use sets out what it is and what it is not.

Technical, security and analytics data

7.1 When you request a page, our hosting provider processes your IP address, the request headers your browser sends, the page requested and the time of the request, so that it can deliver the page and defend the service against attack and abuse. That is a normal part of serving a website and it happens whether or not you fill in a form.

7.2 Our form endpoints apply a short-lived rate limit keyed to your IP address, held in the memory of the serving instance for sixty seconds, to stop bursts of automated submissions. Each form also carries a hidden field that people never see and automated scripts tend to fill in. Neither creates a profile of you.

7.3 We use Vercel Web Analytics and Vercel Speed Insights to measure aggregate traffic and page performance. Neither sets a cookie, and neither is used to follow you across other websites. Our cookie policy describes them, and section 4 of it explains what we do not do.

7.4 The lawful basis for all of this is Article 6(1)(f), our legitimate interests in keeping the website available, secure and usable, and in understanding in aggregate which pages are read.

7.5 Retention: request and security logs are retained by our hosting provider for [TO CONFIRM: request and security log retention period on our current Vercel plan]. Rate-limit counters are discarded within a minute. Analytics data is aggregate and is not held against an identifiable person.

Our legitimate interests, and how we balance them

8.1 Where we rely on Article 6(1)(f) we are required to balance our interest against your rights. This is a summary of that assessment, which we keep in full and will provide on request.

8.2 The purpose: to respond to business enquiries, to develop commercial relationships with the organisations we sell to, and to keep the website secure and functioning. Those are legitimate business purposes and we cannot operate without them.

8.3 Necessity: the processing is limited to what the purpose needs. We ask for business contact details and nothing about your private life. We do not buy contact data, we do not enrich what you give us from other sources, we do not build behavioural profiles and we do not sell or share anything for advertising.

8.4 The balance: the people who contact us do so themselves, in a professional capacity, and expect a reply. The data is ordinary business contact information given voluntarily for that exact purpose, and its use is described plainly at the point of collection and in this notice. The intrusion is low and there is no realistic prospect of harm or surprise. Where the interest is security and availability, the processing is technical, short-lived and in every visitor's interest.

8.5 Your control: you can object at any time under Article 21, and to direct marketing you can object absolutely. If you object to a follow-up contact we will stop, and we will keep the minimum record needed to remember that you asked us to.

8.6 We conclude that our interests are not overridden by your interests, rights and freedoms in respect of the processing described in sections 4, 6 and 7. If you disagree, tell us and we will look at it again.

AI processing and automated decision-making

9.1 We are direct about this because the Readiness Check involves a model, and because you are entitled to know what it does and does not decide.

9.2 The assessment itself is not done by a model. Your eight answers are scored in our own code against a fixed rule set. The score, the band and the three priorities you see are produced by that code and are the same every time for the same answers.

9.3 A large language model is then used to write the narrative around the finished analysis: the executive summary, a note connecting what you typed to what the answers show, a sentence on each priority, and a three-item watch list. The model is reached through Vercel AI Gateway and is currently an Anthropic model. It is given the organisation profile, your eight answers, the score, the band, the priorities our code has already selected, the regulatory items our code has already selected, and whatever you typed into the free-text boxes. It is instructed to use no fact outside that material, and its output must fit a fixed schema. It is not given your name, your email address or your organisation's name. If the model is unavailable, slow or returns something that fails validation, the report is completed from our own written narrative instead.

9.4 The narrative pass is not used to evaluate you, and nothing in the Readiness Check makes a decision about a person. The output is an indicative assessment of an organisation's arrangements. It produces no decision about any individual, and so no decision based solely on automated processing within the meaning of Article 22 is taken about you. We do not carry out profiling of visitors to this website.

9.5 What you type into the free-text boxes is transmitted to the gateway and to the model provider. That is the reason for the warning in clause 6.5. [TO CONFIRM: the AI Gateway and model provider terms that apply to our account, including whether inputs are excluded from provider retention and from model training, so that this clause can state it as fact.]

9.6 The model used is configurable, so the provider named in clause 9.3 may change. When it does we will update this notice and the record of processors before the change goes live.

9.7 Our products use AI in ways this notice does not cover, because there we act as a processor. Where 360 Intelligence indexes a customer's own material, or 360 Sentinel scores a signal, the customer decides what is processed and its own notice applies. Those arrangements, including any human review a customer requires before action is taken on a case, are set out in the agreement with that customer.

Who we disclose personal data to

10.1 We do not sell personal data, we do not share it with advertisers or data brokers, and we do not disclose it for anyone else's marketing. We use a small number of processors, each engaged under terms that meet Article 28:

  • Vercel Inc., United States: hosting, content delivery, request and security logging, the cookie-less analytics described in clause 7.3, and the AI Gateway described in clause 9.3.
  • The model provider reached through that gateway, currently Anthropic: generation of the narrative sections of a Readiness Report, as described in section 9.
  • Resend, Inc., United States: delivery of transactional email (enquiry confirmations and Readiness Reports) and of The Integrity Brief, including management of the subscriber list.

10.2 We also disclose personal data to our professional advisers, to our accountants and auditors, and to a purchaser or successor if we sell or reorganise the business, in each case under a duty of confidence.

10.3 We disclose personal data where we are required to by law, or where it is necessary to establish, exercise or defend legal claims. Where we receive a request from a public authority we check that it is lawful and properly made, and we disclose no more than the request requires. Section 14 explains the position for material held in the reporting product.

10.4 We will tell you if we add a processor that handles personal data collected through this website, by updating this section before the change takes effect. Our customers receive notice of changes to product sub-processors through their agreement, not through this notice.

Transfers outside the United Kingdom

11.1 Some of the processors in section 10 are established in the United States and may process personal data there or in other countries. That means personal data collected through this website can be transferred outside the United Kingdom.

11.2 Where the UK Government has made adequacy regulations for the destination, we rely on those. For transfers to a recipient in the United States that is certified under the UK Extension to the EU-US Data Privacy Framework, we rely on that certification for the data the certification covers.

11.3 Otherwise we rely on Article 46 safeguards: either the International Data Transfer Agreement issued by the Information Commissioner, or the European Commission's standard contractual clauses together with the International Data Transfer Addendum to those clauses. Where a processor also transfers data onward, its contract must place the equivalent obligations on the recipient.

11.4 We carry out a transfer risk assessment before relying on an Article 46 safeguard, and we apply supplementary measures where the assessment calls for them, including encryption in transit and minimisation of what is sent.

11.5 You can ask us for a copy of the relevant transfer mechanism, and we will provide it with commercially confidential terms redacted.

11.6 For the products, hosting location and data residency are agreed with each customer in its own agreement and are not determined by this notice.

How long we keep personal data

12.1 We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires. The periods are stated with each activity above and summarised here:

  • Enquiry correspondence: clause 4.5.
  • Newsletter subscription and suppression records: clause 5.5.
  • Readiness Check submissions and reports: clause 6.6.
  • Request and security logs: clause 7.5.
  • Records we must keep by law, such as accounting records: for the period the relevant legislation requires.

12.2 Where a claim is reasonably in prospect we keep the material relevant to it until the claim and any appeal are resolved, and then apply the period above.

12.3 Retention in the products is configured by the customer in its agreement with us, and can differ by data type and by case type. We delete or return the data on exit as that agreement requires.

Special category and criminal offence data

13.1 We do not ask for special category data or criminal offence data through this website, and we ask you not to send any. The forms have no field for it. If it reaches us in free text or in a message, we do not use it and we delete it from our records unless we are obliged to keep it.

13.2 The products are a different matter, and we say so plainly. A whistleblowing and case management system will receive allegations, and those allegations can contain data revealing health, racial or ethnic origin, religious or philosophical beliefs, sexual orientation or sex life, and can contain data about criminal offences and alleged offences within the meaning of Article 10 and section 11(2) of the Data Protection Act 2018. Safeguarding material in an academy setting can do the same.

13.3 Where that happens the deploying organisation is the controller. It must identify its own condition for the processing: an Article 9(2) condition where one is needed, and a condition in Schedule 1 to the Data Protection Act 2018 where the UK GDPR requires one, such as paragraph 10 (preventing or detecting unlawful acts), paragraph 12 (regulatory requirements relating to unlawful acts and dishonesty) or paragraph 18 (safeguarding of children and of individuals at risk). Most of those conditions require the controller to have an appropriate policy document in place, and it is the controller's responsibility to have one.

13.4 Our responsibility as processor is to handle that material only as instructed and to protect it properly: role-based access, access enforced at the level of the individual record, two-factor authentication for administrators, encryption in transit and at rest, and an audit log of every action taken on a case. The Security and trust page describes the architecture, and the data processing agreement records the commitments.

Whistleblower and reporter confidentiality

14.1 This section matters more than its length suggests, so we have kept it separate.

14.2 360 Report is built so that a reporter does not have to identify themselves. There is no account and no sign-up. No name, email address or telephone number is required to submit a report, and the role, sport and organisation fields are optional. Follow-up works through a case reference and a secret access code rather than an identity, so an investigator can put a question back into a case and a reporter can answer it without anyone learning who they are.

14.3 The consequence is deliberate: in a genuinely anonymous case file there is usually no reporter identity for anyone to disclose, including us, including under legal compulsion. That is a stronger protection than a promise of confidentiality, because it does not depend on anyone keeping the promise.

14.4 Where a reporter chooses to identify themselves, or includes details that could identify them, that information sits in the case file under the deploying organisation's control. Any decision about disclosure is that organisation's to make under its own policy and the law of its jurisdiction, not ours. We do not attempt to identify or re-identify reporters, we do not use technical data to work out who filed a report, and we do not disclose case content to anyone outside the deploying organisation unless that organisation instructs us to or the law compels us.

14.5 A UK organisation using the channel will have its own obligations to workers who make protected disclosures under the Employment Rights Act 1996, as amended by the Public Interest Disclosure Act 1998, and organisations operating in the European Union will have obligations under their national implementation of the EU Whistleblower Directive. The product is configured to support those obligations. Meeting them remains the deploying organisation's duty.

14.6 This website is not a reporting channel. If you need to raise an integrity concern, use the reporting service operated by the relevant organisation. Do not use our enquiry form.

Children and school-age participants

15.1 This website is aimed at professionals working in and around sport. It is not directed at children, and we do not intend to collect personal data about children through it. Please do not include details about a child in an enquiry or in the Readiness Check free-text boxes.

15.2 The products are used in settings where children and other school-age participants are present, including academies, youth pathways and university programmes. In those deployments the deploying organisation is the controller. It decides whether children use the service, on what basis, and how their data is handled, and where its service is likely to be accessed by children in the United Kingdom it must apply the Information Commissioner's Age Appropriate Design Code.

15.3 We support that as processor through access control, data minimisation in what the product asks for, configurable retention and the confidentiality measures in section 13. Where a deployment involves children, we expect the customer's data protection impact assessment to address it, and we will contribute to that assessment as Article 28(3)(f) requires.

Security

16.1 We take appropriate technical and organisational measures under Article 32, sized to the risk of what we hold.

16.2 For this website: everything is served over HTTPS, and form submissions travel over TLS. HTTP strict transport security, a strict referrer policy, frame denial and content-type protections are set at the edge. The site has no administrative login and no customer database, so there is no store on it to breach. Access to the mailbox that receives enquiries and Readiness Reports is limited to the people who need it, on managed accounts with multi-factor authentication.

16.3 For the products: the measures are described on the Security and trust page and committed to contractually. They include encryption in transit and at rest, access enforced at the level of the individual record, two-factor authentication for administrators, audit logging across layers and encrypted backups.

16.4 No system is beyond risk. If a personal data breach occurs we will assess it without delay, notify the Information Commissioner within 72 hours where Article 33 requires it, tell affected people where Article 34 requires it, and notify a customer without undue delay where the breach concerns data we process on its behalf.

16.5 If you believe you have found a vulnerability, please tell us before you tell anyone else. The Security and trust page explains how.

Your rights, and how to exercise them

17.1 In respect of the personal data for which we are the controller, you have the following rights. Some of them apply only in particular circumstances, and we will explain if one of those limits applies to your request.

  • Access (Article 15): to be told whether we hold personal data about you and to receive a copy of it, with the information this notice sets out.
  • Rectification (Article 16): to have inaccurate data corrected and incomplete data completed.
  • Erasure (Article 17): to have data deleted where we no longer need it, where you have withdrawn the consent it rested on, or where you have successfully objected.
  • Restriction (Article 18): to have us hold data without using it while a dispute about its accuracy or our grounds is resolved.
  • Portability (Article 20): to receive data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller, where we process it by automated means on the basis of consent or contract.
  • Objection (Article 21): to object to processing based on our legitimate interests, and to object to direct marketing at any time, which we will always honour.
  • Automated decisions (Article 22): not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect. As clause 9.4 explains, we take no such decision.
  • Withdrawal of consent (Article 7(3)): to withdraw consent at any time where consent is the basis, which applies to the newsletter.

17.2 To exercise any of these rights, email privacy@gamechanger360.co.uk or write to us at the registered office in clause 2.1. Tell us which right you are exercising and what you are looking for; a narrower request usually gets a better answer faster. There is no fee.

17.3 We may ask for information to satisfy ourselves of your identity before we act, because disclosing personal data to the wrong person is itself a breach. We will ask only for what we need.

17.4 We respond within one month of receiving your request. Where a request is complex, or where you have made a number of requests, we may extend that by up to two further months under Article 12(3), and if we do we will tell you within the first month and explain why.

17.5 If your request concerns data held in one of our products, section 3 applies: the deploying organisation is the controller, and your request should go to it. Tell us if you are not sure who that is and we will help you identify the right contact.

Complaints to the Information Commissioner's Office

18.1 If you are unhappy with how we have handled your personal data or your request, please tell us first. We would rather fix it, and we can usually do so faster than any other route.

18.2 You also have the right under Article 77 to complain to the Information Commissioner's Office, the United Kingdom's supervisory authority for data protection. You do not need to come to us first.

18.3 Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. Website: ico.org.uk.

18.4 You also have the right to an effective judicial remedy under Article 79.

Changes to this notice

19.1 We review this notice when our processing changes and at least once a year. The date shown with this page is the date of the current version.

19.2 Where a change materially affects how we use personal data for which we are the controller, we will say so on this page and, where the change requires it, contact the people affected before it takes effect.

19.3 We keep previous versions and will provide the version that applied on a given date on request.