Privacy Policy
What data VenAdmin processes, why, on what legal basis, who it is shared with, how long it is kept and how to exercise your rights.
Last updated: 2026-09-04
This policy explains how personal data is handled on venadmin.com and in the VenAdmin application. It draws a line between two very different situations: data about the people who use our services, where we decide on the processing, and data our customers record about their own players, where they decide and we carry it out.
1. Who processes your data
- Data controller
- SILICON DIGITAL SARL
- Registered office
- Angle Bd Abdelmoumen et Rue Soumaya, Résidence Shehrazade 3, 4ᵉ étage, n° 20, Palmiers, Casablanca, Maroc
- Privacy contact
- [email protected]
- Trade register
- 580075
Any question about this policy or about exercising your rights can be sent to [email protected]. We reply within one month at the latest.
2. Scope and our two roles
VenAdmin is software sold to professionals who run gaming venues. That creates two distinct regimes, which should not be confused:
- We are the data controller
- for data about site visitors, people who contact us, and account holders and their users (managers, cashiers, technicians). We decide why and how that data is processed. That is the subject of this policy.
- We are a processor
- for the data our customers record in the Service about their own players: identity, phone number, prepaid time balance, spending history, loyalty points. The venue decides what it collects and why; we host it and process it on the venue's instructions.
This policy does not cover third-party sites we may link to, which have their own practices.
3. Data we collect
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, email address, phone number, venue name, country | Provided by you (sign-up, contact form) |
| Account and access | Login, hashed password, role and permissions, PIN hashes, sign-in dates | Created while using the Service |
| Subscription and billing | Plan, status, billing dates, subscription and transaction identifiers, billing country | Passed on by Paddle |
| Service usage | Audit logs of sensitive actions, timestamps, the venue concerned | Generated automatically |
| Technical data | IP address, browser type, language, anti-abuse security signals | Collected automatically on connection |
| Support exchanges | The content of your messages and our replies | Provided by you |
We collect no special-category data (health, opinions, origin, biometrics) and never ask for any. No card details pass through or are stored on our servers: payment is handled by Paddle.
4. Purposes and legal bases
| Purpose | Data involved | Legal basis |
|---|---|---|
| Create and manage your account, provide the Service | Identity, account and access, usage | Performance of the contract |
| Manage subscriptions, billing and refunds | Identity, subscription and billing | Performance of the contract and legal obligation (accounting) |
| Send service emails (address verification, password reset, billing notices) | Identity, account | Performance of the contract |
| Answer contact, demo or support requests | Identity, support exchanges | Pre-contractual steps and legitimate interest |
| Keep the platform secure, prevent fraud and abuse | Technical data, audit logs | Legitimate interest in protecting the service and its users |
| Improve the Service and fix defects | Aggregated technical logs | Legitimate interest |
| Send you commercial information about VenAdmin | Identity, contact | Consent, withdrawable at any time |
| Meet our legal obligations and respond to authorities | As required by the request | Legal obligation |
Where processing rests on our legitimate interest, we have checked that it does not disproportionately affect your rights. You may object at any time (see « Your rights »).
6. Retention periods
| Data | Period | Starting point |
|---|---|---|
| Account and venue data | For the term of the agreement | Account creation |
| Data after termination | 30 days (export possible), then deletion | End of the agreement |
| Backups | Up to 30 further days, depending on the rotation cycle | Deletion from live systems |
| Invoicing records | 10 years, accounting and tax obligation | Invoice issue |
| Audit logs | 12 months | The action being recorded |
| Technical and security logs | 12 months maximum | Recording |
| Contact requests with no follow-up | 3 years | Last exchange |
| Proof of marketing consent | 3 years after withdrawal or last contact | Consent being given |
Player data recorded by a venue is kept for as long as that venue decides, and at the latest until its account is deleted, under the rules above.
7. Recipients and processors
We sell no data and disclose none to third parties for commercial purposes. The only recipients are our technical providers, bound by contract and allowed to process data solely for the service concerned:
| Provider | Role | Data involved |
|---|---|---|
| Paddle.com Market Ltd | Sale of subscriptions as merchant of record, payment, invoicing, taxes | Identity, contact, subscription and billing |
| Resend | Transactional email delivery (verification, reset, notifications) | Email address, message content |
| Cloudflare | Content delivery, protection against attacks and automated traffic | Technical connection data |
| OVH SAS (OVHcloud) | Hosting of the application, database and backups (France) | All Service data |
| Media storage | Hosting of uploaded images (logos, product pictures) | Files uploaded by the customer |
Data may also be shared with our professional advisers (lawyer, accountant) bound by professional secrecy, or with an administrative or judicial authority where the law requires it. If the business were sold, data would transfer to the buyer under the same commitments, and you would be informed beforehand.
8. International transfers
Some of our providers are established outside Morocco, notably in the European Union, the United Kingdom and the United States. Your data may therefore be transferred to those countries.
These transfers are covered by appropriate safeguards: European Commission standard contractual clauses, contractual security and confidentiality commitments and, where applicable, recognised certification mechanisms. For processing subject to Moroccan law 09-08, transfers are carried out in accordance with the requirements of the CNDP, the Moroccan data protection authority.
A copy of the safeguards in place can be requested at [email protected].
9. Security
We implement technical and organisational measures proportionate to the risk, including:
- strict data isolation between venues, enforced by the database itself and not only by application code;
- encryption of communications in transit (HTTPS);
- passwords and PIN codes stored as irreversible hashes, never in clear text;
- role and permission management, with minimal access by default;
- audit logging of sensitive actions (payments, deletions, permission changes);
- regular backups and monitoring of administrator access;
- production system access limited to the people who need it.
No system is infallible. In the event of a data breach likely to create a risk for the people concerned, we notify the competent authority and, where the risk is high, the individuals and the customer venue concerned, within the timeframes set by regulation.
10. Your rights
Subject to the conditions set by the applicable regulation, you have the right to:
- access the data we hold about you and obtain a copy;
- have inaccurate or incomplete data corrected;
- request erasure of your data, except where we must keep it;
- request restriction of processing you contest;
- receive your data in a structured, machine-readable format and have it transferred;
- object to processing based on our legitimate interest, and to any marketing;
- withdraw your consent at any time, without affecting the lawfulness of processing carried out beforehand;
- give instructions about what happens to your data after your death.
These rights are exercised at [email protected]. We may ask for proof of identity in case of reasonable doubt. We reply within one month, extendable by two months for complex requests, in which case you are informed.
A reminder: for data a venue records about its players, the request must go to the venue. If it reaches us directly, we forward it without delay and assist the venue in handling it.
11. Deleting your account
Account deletion is requested from within the Service or by email to [email protected]. We confirm the request before carrying it out, because it cannot be undone.
After confirmation, data remains exportable for 30 days and is then deleted from live systems. It subsequently disappears from backups as they rotate. Only data we are legally required to keep remains, principally invoicing records.
12. Minors
The Service is aimed at professionals. We do not create accounts for minors and do not knowingly collect their data through our own forms.
A venue may record minor players. As data controller, it is then for the venue to obtain the required parental authorisations and to comply with the rules applicable to admitting minors to its premises.
13. Changes to this policy
This policy may be updated to reflect changes to the Service, to our providers or to regulation. The last-updated date is shown at the top of the page.
Any material change, in particular a new purpose or a new processor, is brought to your attention by email or within the Service before it takes effect.
14. Contact
- Personal data and rights requests
- [email protected]
- Support
- [email protected]
- Postal address
- SILICON DIGITAL SARL — Angle Bd Abdelmoumen et Rue Soumaya, Résidence Shehrazade 3, 4ᵉ étage, n° 20, Palmiers, Casablanca, Maroc