
WISHGATE LTD ("Data Controller")
Contact: privacy@wishgate.io
Last reviewed: July 1, 2026
This document describes how Wishgate complies with the EU General Data Protection Regulation (GDPR) and related data protection laws.
WISHGATE LTD, a company incorporated in Bulgaria (UIC 208871609) with its registered office at ul. Stefan Peshev 76, fl. 1, 5400 Sevlievo, Gabrovo Province, Bulgaria, is the Data Controller for personal data processed through the platform. If you have questions about how your data is handled, contact us at privacy@wishgate.io.
| Processing Activity | Lawful Basis | Notes |
|---|---|---|
| Account registration and authentication | Performance of contract (Art. 6(1)(b)) | Necessary to provide the service |
| Organization profile and game listings | Performance of contract (Art. 6(1)(b)) | Core service functionality |
| Partnership management, chat, audit logs | Performance of contract (Art. 6(1)(b)) | |
| Social platform data fetching (YouTube, Twitch, TikTok) | Legitimate interest (Art. 6(1)(f)) + Contract | Creator initiates linking; necessary for platform matching |
| Payment processing via Stripe | Performance of contract (Art. 6(1)(b)) | |
| In-app notifications | Legitimate interest (Art. 6(1)(f)) | Essential platform communication |
| Email digest notifications | Consent (Art. 6(1)(a)) | User-configurable; opt-out available in Settings |
| Legal record keeping (payment records, audit logs) | Legal obligation (Art. 6(1)(c)) | 7-year retention for financial records |
| Platform abuse prevention | Legitimate interest (Art. 6(1)(f)) |
Under GDPR, you have the following rights. To exercise them, email privacy@wishgate.io with subject "GDPR Request — [Right Type]". We respond within 30 days.
You may request a copy of all personal data we hold about you. We will provide it in a commonly used electronic format (JSON or CSV).
You may correct inaccurate personal data at any time via your account settings or by contacting us.
You may request deletion of your personal data. We will comply unless retention is required by:
Deleted account data is anonymized within 30 days. Data referenced in partnerships (audit log, messages) may be retained in anonymized form.
You may request your data in a machine-readable format (JSON). This covers: account data, organization data, partnership history, and social platform data we store.
You may object to processing based on legitimate interest. We will stop unless we have compelling legitimate grounds.
You may request restriction of processing in specific circumstances (e.g., while we verify a rectification request).
Where processing is based on consent (email digests), you may withdraw consent at any time in your notification settings.
| Data Category | Retention Period | Basis |
|---|---|---|
| Active user account data | While account is active | Contract |
| Deleted account — personal identifiers | Anonymized within 30 days | Erasure right |
| Partnership messages | 3 years after partnership ends | Legitimate interest (dispute resolution) |
| Partnership audit log | 3 years | Legitimate interest |
| Payment records (Stripe) | 7 years | Legal obligation (accounting law) |
| Steam key assignment records | 3 years | Legitimate interest |
| Server/access logs | 30 days | Legitimate interest (security) |
| Social platform OAuth tokens | Retained (encrypted) while the platform is connected; deleted on disconnect or account closure | Performance of contract |
We transfer data to the following countries outside the EEA:
| Recipient | Country | Transfer Mechanism | Purpose |
|---|---|---|---|
| Stripe, Inc. | USA | EU-US Data Privacy Framework / SCCs | Payment processing |
| Google LLC (YouTube) | USA | EU-US Data Privacy Framework / SCCs | YouTube API data fetch |
| Twitch Interactive / Amazon | USA | EU-US Data Privacy Framework / SCCs | Twitch API data fetch |
| TikTok (varies) | USA / Singapore | SCCs | TikTok API data fetch |
Standard Contractual Clauses (Commission Implementing Decision 2021/914) are used where the EU-US Data Privacy Framework does not apply.
We only collect data that is necessary for the platform to function:
The full set of measures is documented in §7 of the Privacy Policy.
In the event of a personal data breach that risks harm to affected individuals, we will:
Wishgate does not make solely automated decisions that produce legal or similarly significant effects on individuals. The match score algorithm is informational only and does not affect partnership approval decisions (which require manual studio/creator action).
If you believe your data protection rights have been violated, you may lodge a complaint with:
A directory of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
Wishgate does not target users under 16. If we become aware of data collected from a child under 16, we will delete it immediately and notify the relevant authority if required.