
Privacy notice
Last updated 9 October 2026
This notice explains what personal data A Bit Slotty! collects through abitslotty.com, including the client area and the team area, why we collect it, how long we keep it and the rights you have.
Who we are
A Bit Slotty! is a videoslot game studio. We are the controller of the personal data described here. Contact us about privacy at legal@abitslotty.com.
If you visit the website without signing in
- We record the page you viewed, when, the site you came from (its address only), any campaign tags in the link, your approximate location (country, region and city, worked out from your IP address when you visit) and your type of device, browser and operating system.
- To count unique visitors we create an anonymous code from your IP address, browser and a secret that changes every day. It can't be used to identify you or to follow you from one day to the next. We don't store your IP address.
- We don't use cookies or similar technology for this, and we don't use third-party tracking or advertising tools.
If you have an account
Accounts are by invitation only, for our clients (operators and distributors), our team and our partners.
- Your details: name, email address, your role, your company (for client accounts), and a profile picture if you add one. Your password is stored only in scrambled (hashed) form by our sign-in provider. If you use two-factor authentication we keep the settings it needs.
- Sign-in records: when you sign in or out, failed sign-in attempts, password resets and invitation acceptance, with your IP address, approximate location and device.
- What you do in the app: pages you view in the client and team areas, files you download, searches, and pages you create or change. Visits you make to the public website while signed in are linked to your account.
- Content you create in the team area (pages, files) and the history of its changes.
- Records of administrative actions (such as invitations, role changes and access changes) in an audit log.
Why we use it, and our legal basis
- To provide the website, the client area and the team area, and to manage accounts: to perform our agreements with you or your organisation, and our legitimate interest in running our business.
- To keep accounts and data secure (sign-in records, two-factor authentication, audit records): our legitimate interest in security, and legal obligations where they apply.
- To understand how our website and client area are used, and to serve our clients better (for example, which games and documents a client has looked at): our legitimate interest. You can object at any time (see Your rights).
- To send emails you need, such as invitations, password resets and security notices.
Cookies
We only use cookies that are needed for the site to work: they keep you signed in, and remember a preview choice for some staff. We don't use analytics, advertising or tracking cookies, so we don't ask for cookie consent.
Who we share it with
We use these service providers, who process data only on our instructions:
- Supabase: database, sign-in and file storage (hosted in London).
- Vercel: website hosting (servers in London).
- Resend: sending emails.
- Sentry: error reports, so we can fix problems (stored in the EU, Frankfurt).
Where a provider handles data outside the UK or EEA, we rely on appropriate safeguards such as standard contractual clauses. We don't sell personal data.
How long we keep it
- Website visit records and in-app activity: 13 months, after which only daily totals that identify no one are kept.
- Account details: while your account exists. Closed accounts are kept switched off so that records stay consistent, unless you ask us to anonymise them.
- Audit records of administrative actions: kept indefinitely as a security and legal record.
- Archived team pages: deleted permanently 30 days after being archived.
Your rights
You can ask us for a copy of your personal data, to correct it, to erase it (we do this by anonymising your account, which removes your name, email and location details while keeping records that identify no one), to restrict or object to how we use it, and to receive it in a portable format. Contact us at the address above; we'll reply within one month. You can also complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (AEPD, aepd.es), or to the data protection authority where you live or work.
Security
Data is encrypted in transit; access is controlled by role and checked by the database itself; staff with wider access must use two-factor authentication; files are private and shared only through short-lived links; and administrative actions are logged.
Changes
We'll update this notice if what we do changes, and show the date at the top. See also our Terms of Use.