VenAdmin VenAdmin
Legal

Privacy Policy

What data VenAdmin processes, why, on what legal basis, who it is shared with, how long it is kept and how to exercise your rights.

Last updated: 2026-09-04

This policy explains how personal data is handled on venadmin.com and in the VenAdmin application. It draws a line between two very different situations: data about the people who use our services, where we decide on the processing, and data our customers record about their own players, where they decide and we carry it out.

1. Who processes your data

Data controller
SILICON DIGITAL SARL
Registered office
Angle Bd Abdelmoumen et Rue Soumaya, Résidence Shehrazade 3, 4ᵉ étage, n° 20, Palmiers, Casablanca, Maroc
Privacy contact
[email protected]
Trade register
580075

Any question about this policy or about exercising your rights can be sent to [email protected]. We reply within one month at the latest.

2. Scope and our two roles

VenAdmin is software sold to professionals who run gaming venues. That creates two distinct regimes, which should not be confused:

We are the data controller
for data about site visitors, people who contact us, and account holders and their users (managers, cashiers, technicians). We decide why and how that data is processed. That is the subject of this policy.
We are a processor
for the data our customers record in the Service about their own players: identity, phone number, prepaid time balance, spending history, loyalty points. The venue decides what it collects and why; we host it and process it on the venue's instructions.
If you are a player at a venue running VenAdmin and want to access or delete your data, contact the venue: it is the data controller. We assist it, but we do not act without its instruction.

This policy does not cover third-party sites we may link to, which have their own practices.

3. Data we collect

CategoryExamplesSource
Identity and contactName, email address, phone number, venue name, countryProvided by you (sign-up, contact form)
Account and accessLogin, hashed password, role and permissions, PIN hashes, sign-in datesCreated while using the Service
Subscription and billingPlan, status, billing dates, subscription and transaction identifiers, billing countryPassed on by Paddle
Service usageAudit logs of sensitive actions, timestamps, the venue concernedGenerated automatically
Technical dataIP address, browser type, language, anti-abuse security signalsCollected automatically on connection
Support exchangesThe content of your messages and our repliesProvided by you

We collect no special-category data (health, opinions, origin, biometrics) and never ask for any. No card details pass through or are stored on our servers: payment is handled by Paddle.

4. Purposes and legal bases

PurposeData involvedLegal basis
Create and manage your account, provide the ServiceIdentity, account and access, usagePerformance of the contract
Manage subscriptions, billing and refundsIdentity, subscription and billingPerformance of the contract and legal obligation (accounting)
Send service emails (address verification, password reset, billing notices)Identity, accountPerformance of the contract
Answer contact, demo or support requestsIdentity, support exchangesPre-contractual steps and legitimate interest
Keep the platform secure, prevent fraud and abuseTechnical data, audit logsLegitimate interest in protecting the service and its users
Improve the Service and fix defectsAggregated technical logsLegitimate interest
Send you commercial information about VenAdminIdentity, contactConsent, withdrawable at any time
Meet our legal obligations and respond to authoritiesAs required by the requestLegal obligation

Where processing rests on our legitimate interest, we have checked that it does not disproportionately affect your rights. You may object at any time (see « Your rights »).

5. Cookies and analytics

venadmin.com uses no analytics cookies, no advertising cookies and no third-party trackers. We load no Google Analytics, no social network pixel and no profiling tool.

Only strictly necessary cookies are used, which do not require consent:

  • a language preference cookie, remembering whether you read the site in French, English or Arabic;
  • in the application, a session cookie that keeps you signed in and a token protecting against forged requests.

You can delete these cookies from your browser; the language preference will be forgotten and the application session will end.

6. Retention periods

DataPeriodStarting point
Account and venue dataFor the term of the agreementAccount creation
Data after termination30 days (export possible), then deletionEnd of the agreement
BackupsUp to 30 further days, depending on the rotation cycleDeletion from live systems
Invoicing records10 years, accounting and tax obligationInvoice issue
Audit logs12 monthsThe action being recorded
Technical and security logs12 months maximumRecording
Contact requests with no follow-up3 yearsLast exchange
Proof of marketing consent3 years after withdrawal or last contactConsent being given

Player data recorded by a venue is kept for as long as that venue decides, and at the latest until its account is deleted, under the rules above.

7. Recipients and processors

We sell no data and disclose none to third parties for commercial purposes. The only recipients are our technical providers, bound by contract and allowed to process data solely for the service concerned:

ProviderRoleData involved
Paddle.com Market LtdSale of subscriptions as merchant of record, payment, invoicing, taxesIdentity, contact, subscription and billing
ResendTransactional email delivery (verification, reset, notifications)Email address, message content
CloudflareContent delivery, protection against attacks and automated trafficTechnical connection data
OVH SAS (OVHcloud)Hosting of the application, database and backups (France)All Service data
Media storageHosting of uploaded images (logos, product pictures)Files uploaded by the customer

Data may also be shared with our professional advisers (lawyer, accountant) bound by professional secrecy, or with an administrative or judicial authority where the law requires it. If the business were sold, data would transfer to the buyer under the same commitments, and you would be informed beforehand.

8. International transfers

Some of our providers are established outside Morocco, notably in the European Union, the United Kingdom and the United States. Your data may therefore be transferred to those countries.

These transfers are covered by appropriate safeguards: European Commission standard contractual clauses, contractual security and confidentiality commitments and, where applicable, recognised certification mechanisms. For processing subject to Moroccan law 09-08, transfers are carried out in accordance with the requirements of the CNDP, the Moroccan data protection authority.

A copy of the safeguards in place can be requested at [email protected].

9. Security

We implement technical and organisational measures proportionate to the risk, including:

  • strict data isolation between venues, enforced by the database itself and not only by application code;
  • encryption of communications in transit (HTTPS);
  • passwords and PIN codes stored as irreversible hashes, never in clear text;
  • role and permission management, with minimal access by default;
  • audit logging of sensitive actions (payments, deletions, permission changes);
  • regular backups and monitoring of administrator access;
  • production system access limited to the people who need it.

No system is infallible. In the event of a data breach likely to create a risk for the people concerned, we notify the competent authority and, where the risk is high, the individuals and the customer venue concerned, within the timeframes set by regulation.

10. Your rights

Subject to the conditions set by the applicable regulation, you have the right to:

  • access the data we hold about you and obtain a copy;
  • have inaccurate or incomplete data corrected;
  • request erasure of your data, except where we must keep it;
  • request restriction of processing you contest;
  • receive your data in a structured, machine-readable format and have it transferred;
  • object to processing based on our legitimate interest, and to any marketing;
  • withdraw your consent at any time, without affecting the lawfulness of processing carried out beforehand;
  • give instructions about what happens to your data after your death.

These rights are exercised at [email protected]. We may ask for proof of identity in case of reasonable doubt. We reply within one month, extendable by two months for complex requests, in which case you are informed.

If you believe your rights are not being respected, you may complain to the CNDP in Morocco, or to the supervisory authority of your country of residence if you are in the European Union.

A reminder: for data a venue records about its players, the request must go to the venue. If it reaches us directly, we forward it without delay and assist the venue in handling it.

11. Deleting your account

Account deletion is requested from within the Service or by email to [email protected]. We confirm the request before carrying it out, because it cannot be undone.

After confirmation, data remains exportable for 30 days and is then deleted from live systems. It subsequently disappears from backups as they rotate. Only data we are legally required to keep remains, principally invoicing records.

12. Minors

The Service is aimed at professionals. We do not create accounts for minors and do not knowingly collect their data through our own forms.

A venue may record minor players. As data controller, it is then for the venue to obtain the required parental authorisations and to comply with the rules applicable to admitting minors to its premises.

13. Changes to this policy

This policy may be updated to reflect changes to the Service, to our providers or to regulation. The last-updated date is shown at the top of the page.

Any material change, in particular a new purpose or a new processor, is brought to your attention by email or within the Service before it takes effect.

This policy is written in French and translated into English. In case of any discrepancy between the versions, the French version prevails.

14. Contact

Personal data and rights requests
[email protected]
Postal address
SILICON DIGITAL SARL — Angle Bd Abdelmoumen et Rue Soumaya, Résidence Shehrazade 3, 4ᵉ étage, n° 20, Palmiers, Casablanca, Maroc