Policy

Privacy Policy

Last updated: 26 August 2026

1. Who we are

1.1. Lumivant Technologies Limited ("Lumivant", "we", "us", "our") is a company incorporated in the Republic of Seychelles, with its registered office at F2-2A, Oceanic House, Providence Estate, Mahé, Seychelles.

1.2. We develop and supply business-to-business iGaming platform software to licensed operators. We do not operate gambling sites, we do not hold player accounts, and we do not hold player funds.

1.3. For any question about this policy or about how we handle personal data, contact contact@lumivanttech.com.

2. Scope — and our two different roles

2.1. This policy explains what we do with personal data for which we are the controller: visitors to www.lumivanttech.com, people who email us, and representatives of our business clients, suppliers and partners.

2.2. Separately, when a licensed operator runs its business on our platform, we process personal data about that operator's players on the operator's instructions. For that data the operator is the controller and we act only as its processor. That processing is governed by the data processing agreement between us and the operator, not by this policy. Players should read the privacy notice of the site they play on and address requests to that operator. Section 7 sets this out in more detail.

In short: this policy covers our own website and business contacts. If you are a player on a site built on Lumivant, the operator of that site — not Lumivant — is responsible for your data, and you should contact them.

3. Visitors to this website

3.1. This website is a static site. It sets no cookies. It runs no analytics, and carries no advertising, tracking pixels, session recording or social media trackers. There are no forms on the site — the only way to contact us through it is by email.

3.2. Our web server keeps standard access logs. Each entry records the IP address of the requesting device, the date and time of the request, the URL requested, the HTTP status code returned, the number of bytes served, the referring page (if your browser sends one), and your browser's user-agent string.

3.3. We use those logs only to operate and secure the site, to diagnose faults, and to identify abuse such as scanning or denial-of-service attempts. Where the EU General Data Protection Regulation ("GDPR") applies to this processing, our legal basis is our legitimate interests in running a secure and functioning website (Article 6(1)(f)).

3.4. Access logs are rotated daily and retained for approximately ten days, after which they are deleted.

3.5. Fonts. The site's typefaces are self-hosted: they are served from our own web server (lumivanttech.com) alongside the rest of the site. Pages on this site make no requests to third-party font services or to any other third party, so no data about your visit is disclosed to a font provider.

4. People who contact us

4.1. If you email contact@lumivanttech.com, complaints@lumivanttech.com or rg@lumivanttech.com, we receive your name, your email address, the organisation you write on behalf of, and whatever information you choose to include in your message and attachments.

4.2. We use it to answer you, to carry on commercial discussions, to investigate and resolve complaints, and to keep a record of what was agreed or reported.

4.3. Where the GDPR applies, our legal basis is our legitimate interests in responding to business enquiries and keeping proper records, the taking of steps at your request prior to entering a contract, or compliance with a legal obligation where the correspondence concerns a regulatory matter.

4.4. We keep correspondence for as long as the relationship or matter is live, and for a further period afterwards where we need it to evidence what was agreed or to meet a legal, regulatory or licensing requirement. After that it is deleted.

5. Clients, suppliers and partners

5.1. In the course of contracting with operators, game studios, payment providers and professional advisers, we hold the business contact details of the individuals who represent them, records of contracts and commercial terms, correspondence, and — where we are required to carry out due diligence on a corporate counterparty — identity and background information about its directors, officers and beneficial owners.

5.2. Where the GDPR applies, our legal bases are the performance of a contract, compliance with our legal and regulatory obligations, and our legitimate interests in managing and safeguarding our business relationships.

6. Who we disclose personal data to

6.1. Service providers who act on our behalf — for example hosting and infrastructure, email, and legal, audit and accounting advisers — under obligations of confidentiality and, where required, a written data processing agreement.

6.2. Regulators, licensing authorities, banks and payment partners, auditors and law enforcement, where we are legally required to disclose, where it is necessary to obtain or maintain a licence or banking relationship, or where it is necessary to investigate suspected fraud or financial crime.

6.3. A buyer or successor, if we sell or reorganise all or part of our business, subject to equivalent protection for the data.

6.4. We do not sell personal data, and we do not disclose it for third-party advertising or marketing.

7. Player personal data — where we act as a processor

7.1. Operators who license our platform use it to process personal data about their players. Depending on the modules the operator has taken, that can include registration and identity details, contact details, account and wallet records, deposits, withdrawals and other transactions, gameplay and bonus history, responsible-gaming settings and interventions, KYC, AML and risk records, and technical data such as device details, IP address and session logs.

7.2. For all of that data the operator is the controller. We process it only on the operator's documented instructions and for the purpose of providing and supporting the platform, and we do not use it for our own purposes.

7.3. We apply appropriate technical and organisational measures, keep client environments segregated, restrict internal access to what a role requires, maintain audit logging of administrative activity, and engage sub-processors only under written terms imposing equivalent obligations.

7.4. If you are a player and you want to exercise a right over your data, please contact the operator of the site you play on — they hold the relationship with you and are responsible for answering. If you contact us directly, we will refer you to the operator and, where appropriate, tell the operator that you have been in touch. We cannot act on a player's request without the operator's instruction.

8. International transfers

8.1. We are established in Seychelles and we use service providers in more than one country. Personal data we hold may therefore be processed outside the country in which you are located, including outside the European Economic Area.

8.2. Where the GDPR applies to a transfer, we rely on an appropriate transfer mechanism — in most cases the European Commission's standard contractual clauses — together with any additional safeguards needed in the circumstances of the transfer. You can ask us for information about the mechanism used for a particular transfer.

9. Security

9.1. We encrypt data in transit over public networks, control and review access on a least-privilege basis, log administrative activity, separate client environments from one another, and assess the security of the suppliers we rely on.

9.2. No system can be guaranteed secure. If a personal data breach occurs, we will act on it without undue delay and notify affected controllers, data subjects and supervisory authorities to the extent the applicable law requires.

10. Your rights

10.1. Where the GDPR or a comparable data protection law applies to our processing, you have the right to ask for access to your personal data and for a copy of it; to have inaccurate data corrected; to have data erased; to have processing restricted; to object to processing carried out on the basis of legitimate interests; to receive data you provided to us in a portable form; and to withdraw consent where our processing relies on consent. You also have the right to lodge a complaint with a supervisory authority.

10.2. To exercise a right, email contact@lumivanttech.com. We may need to verify your identity before we act, so that we do not disclose data to the wrong person. Where the GDPR applies we will respond within one month, and will tell you if we need longer because the request is complex.

10.3. If your request concerns your data as a player on a site built on our platform, clause 7.4 applies and you should approach the operator.

11. Children

11.1. This website is directed at businesses, not at children, and we do not knowingly collect personal data about children through it.

11.2. Access to gambling products is restricted to players who are of legal age in their jurisdiction, and at least 18. Age verification is the responsibility of the licensed operator, using the verification tooling our platform provides.

12. Changes to this policy

12.1. We may update this policy to reflect changes in our services, our suppliers or the law. The date at the top of this page shows when it was last changed, and where a change materially affects our clients we will tell them directly.

13. Contact

13.1. Lumivant Technologies Limited, F2-2A, Oceanic House, Providence Estate, Mahé, Seychelles — contact@lumivanttech.com.