We process operator contact and configuration data on sovereign, non-US infrastructure.
Last updated: 2026-07-26
This policy covers personal data processed by MetaGrator in the course of providing the catalog API, engagement engine, and supporting services to platform and operator customers. It does not cover personal data of end-players, which is processed by our customers under their own privacy policies.
Operator-customer contact data (name, email, role, company), technical metadata required to operate the API (request logs, error logs, performance metrics), commercial data (contract terms, revenue-share calculations, transaction reconciliation), and integration metadata (which endpoints are called, from which IPs, with what payloads, for security and debugging purposes only).
All personal data is processed on sovereign, non-US infrastructure, with no US-parented entity in the processing chain. The processing jurisdiction is disclosed to your DPO, and any transfer happens only with explicit customer consent and a documented legal basis.
Contract performance for operational data, legitimate interest for security and fraud-prevention logging, consent for marketing communications. Detailed Article 6 mapping available on request to dpo@mgrator.com.
Operational logs: 90 days. Commercial records: 10 years (regulatory requirement). Customer contact data: until contract end plus 12 months. Marketing data: until unsubscribe.
Access, rectification, erasure, restriction, portability, and objection, as defined under the GDPR. Submit requests to dpo@mgrator.com and we respond within 30 days.
Sovereign, non-US hosting; sovereign transactional email; and sovereign customer messaging. The full subprocessor list with jurisdiction and DPA references is published at /legal/subprocessors and updated within 30 days of any change.
Data Protection Officer: dpo@mgrator.com. Lead supervisory authority disclosed to your DPO on request.