Privacy Policy
iGacquire Privacy & Cookie Policy
Version 1.1 | Effective Date: October 15, 2025 | Last Updated: October 15, 2025
1. Introduction
iGacquire OÜ operates a B2B marketplace for the iGaming industry, facilitating introductions and transactions involving iGaming businesses and assets. This Policy explains how we collect, use, disclose, and protect personal data in compliance with the GDPR and other applicable privacy laws.
2. Data Controller
iGacquire OÜ
Registry code: 17328489
Registered address: Harju maakond, Tallinn, Põhja-Tallinna linnaosa, Tööstuse tn 75-71, 10416, Estonia
Email: privacy@igacquire.com
Data Protection Officer: dpo@igacquire.com (if appointed)
3. Information We Collect
3.1 Account and Registration Data
- Full name, business email, phone number
- Company name, registration details, jurisdiction
- Professional role and sector information
- Login credentials stored securely
3.2 KYC and Verification Data
- Government ID and proof of address
- Corporate documents and beneficial ownership
- Sanctions and AML screening results
3.3 Transaction and Deal Data
- Listings, descriptions, financial highlights, supporting documents
- Due diligence materials and audit trails
- Messages and calls through the platform
- Contract metadata and execution status
- Escrow settlement metadata
- Payment status information from providers. Card and account details are handled by providers and not stored by iGacquire.
3.4 Technical and Usage Data
- IP address, device identifiers, browser type, operating system
- Pages viewed, navigation paths, interactions and session duration
- Cookies and similar technologies as described in Section 11
3.5 Communications Data
- Support tickets and email correspondence
- Feedback, surveys, testimonials subject to your approval
- Clickwrap acceptances and electronic signatures
4. How We Use Personal Data
4.1 Legal Bases
- Contract performance to provide the marketplace, process introductions, and enable transactions
- Legal obligation for AML and KYC, tax and accounting, regulatory requests
- Legitimate interests in fraud prevention, security, fee enforcement, product improvement, and maintaining an audit trail of introductions and acceptances
- Consent for marketing communications and optional analytics or marketing cookies
4.2 Specific Purposes
- Account creation, authentication, and role management
- NDA gating and controlled access to confidential materials
- Transaction facilitation including escrow coordination and status confirmation
- Compliance screening, sanctions checks, and record keeping
- Security monitoring, incident response, and abuse prevention
- Analytics to improve features and performance
- Marketing with consent and preference management
5. Data Sharing and Disclosure
5.1 Categories of Recipients
- Counterparties Buyers and Sellers involved in a specific deal as necessary to progress a transaction
- Escrow and compliance providers acting as independent controllers for KYC and settlement:
- Shieldpay Ltd, United Kingdom, for fiat escrow and payments
- LEXR AG, Switzerland, for crypto escrow and settlement
- Identity and e-signature providers such as DocuSign or equivalent
- Hosting and infrastructure such as AWS or Google Cloud
- Analytics providers such as Google Analytics 4 with IP anonymization enabled
- Professional advisors lawyers, accountants, and auditors under confidentiality
- Supervisory and law enforcement authorities where legally required
5.2 Fee Enforcement and Debt Collection
Where fees remain unpaid, we may share necessary data with licensed international debt recovery agents and law firms for the establishment, exercise, or defense of legal claims. This processing relies on our legitimate interests and legal claims. Data may include identity and contact details, account and usage records, accepted legal terms, and invoices or payment status.
5.3 Arbitration and Courts
In case of disputes, data may be shared with the Arbitration Court of the Estonian Chamber of Commerce and Industry in Tallinn and the Harju County Court in Tallinn, Estonia, as well as appointed arbitrators, experts, and court officers.
5.4 No Sale of Personal Data
We do not sell personal data. We do not use personal data for behavioral advertising without your consent.
6. International Data Transfers
When transferring personal data outside the EEA, the United Kingdom, or Switzerland, we implement appropriate safeguards such as EU Standard Contractual Clauses, the UK IDTA or Addendum, and Swiss-approved clauses, together with transfer risk assessments and technical measures. Transfers to the United Kingdom and Switzerland may rely on adequacy decisions where applicable.
7. Data Retention
- Account data for the life of the account and up to 1 year after closure
- Transaction records 7 years for accounting and regulatory requirements
- KYC data 5 years after the end of the relationship or as required by law
- Audit trails for the period necessary to evidence introductions and fee calculations and for the duration of related claims
- Technical logs up to 12 months, unless needed for security investigations
- Marketing preferences until consent is withdrawn
Where legal claims are reasonably anticipated or ongoing, we may retain relevant data until resolution.
8. Your Rights
8.1 EU and EEA Residents
- Access, rectification, erasure, restriction
- Portability for data you provided to us
- Objection to processing based on legitimate interests and to direct marketing
- Withdraw consent without affecting prior processing
- Complain to a supervisory authority
8.2 California Residents
- Know what personal information is collected and disclosed
- Request deletion subject to exceptions
- Opt out of sale or sharing of personal information
- Non-discrimination for exercising rights
- Correct inaccurate information
- Limit use of sensitive personal information where applicable
8.3 Exercising Rights
Email privacy@igacquire.com with the subject line indicating your request. We may need to verify your identity and will respond within applicable deadlines.
9. Security
- TLS encryption in transit and industry-standard encryption at rest
- Role-based access controls and multi-factor authentication for staff
- Logging, monitoring, and intrusion detection
- Regular security reviews and penetration tests
- Employee privacy and security training
- Breach notification procedures compliant with GDPR
10. Children
The platform is for business users aged 18 and over. We do not knowingly collect data from minors. If we learn we have such data, we will delete it.
11. Cookies and Similar Technologies
11.1 Types of Cookies
- Essential required for authentication, security, and core features
- Analytics GA4 to understand usage and improve the platform with IP anonymization
- Functional to remember settings such as language
- Marketing only with consent
11.2 Managing Cookies
- Use our cookie banner to grant or withdraw consent by category
- Use browser settings to block or delete cookies
- Opt-out tools such as the GA opt-out add-on
Disabling essential cookies may limit functionality.
12. Automated Decision Making and Profiling
We may use automated systems for fraud detection, risk scoring, and matchmaking suggestions. You can request human review of decisions that produce legal or similarly significant effects and you may object to profiling based on legitimate interests.
13. Third-Party Links
Links to third-party sites are provided for convenience. Their privacy practices are their own. Review their policies before providing data.
14. Business Transitions
If iGacquire undergoes a merger, acquisition, or asset sale, personal data may be transferred to the acquirer in accordance with this Policy. We will notify you in advance where required.
15. Updates to this Policy
We may update this Policy to reflect legal changes or new features. Material changes will be announced by email or a prominent in-product notice at least 14 days before they take effect. The updated Policy will display a new effective date.
16. Supervisory Authorities
- Lead authority Estonian Data Protection Inspectorate
- Your local data protection authority within the EEA
- California residents may contact the California Attorney General
17. Contact
iGacquire OÜ Privacy Team
Email: privacy@igacquire.com
DPO: dpo@igacquire.com
Address: Harju maakond, Tallinn, Põhja-Tallinna linnaosa, Tööstuse tn 75-71, 10416, Estonia
18. Consent and Acknowledgment
By using iGacquire, you acknowledge that you have read and understood this Policy. If you do not agree, please discontinue use of the platform.
© 2025 iGacquire OÜ. This Policy is governed by Estonian law and applicable EU regulations.