Privacy Policy
Last updated: 4 August 2026
GTL MédiaInvest Sàrl ("we", "us") operates gsipoker.com (the "Site"). This policy explains what personal data we collect, why, on what legal basis, how long we keep it, and what rights you have.
We are subject to the Swiss Federal Act on Data Protection (nLPD/FADP) and, where it applies, to the EU General Data Protection Regulation (GDPR).
1. Controller and contact
GTL MédiaInvest Sàrl Route de Trélex 10, 1266 Duillier, Switzerland UID: CHE-221.695.578
For any question or request concerning your personal data: contact@gsipoker.com
We have not appointed a Data Protection Officer, as we are not required to do so. All requests are handled directly at the address above.
2. What we collect, and why
2.1 Early access sign-up
When you submit the sign-up form, we collect:
- your email address
- the audience category you select (Player, Organizer, or Media & Press)
- the date and time of your submission and of your confirmation
Purpose: to notify you when the index opens, and to send occasional launch-related announcements. Legal basis: your consent (GDPR art. 6(1)(a); nLPD art. 31). Confirmation uses double opt-in: no message is sent until you confirm via the link we email you.
2.2 User accounts
If you create an account, we process:
- your email address
- your display name, where you provide one
- authentication data (a hashed password, or an identifier supplied by Google or Discord if you sign in through them)
- your session records
- your credit balance and the ledger of credit movements on your account
- the display currency associated with your account
Purpose: to operate the account, authenticate you, and deliver the features you unlock. Legal basis: performance of a contract (GDPR art. 6(1)(b); nLPD art. 31).
2.3 Purchases
If you buy credits or a subscription, payment is processed by Stripe. We never receive, see or store your card number. We retain the transaction reference, the amount, the currency, the date, and the resulting credit movement.
Purpose: to deliver what you paid for, and to meet our accounting obligations. Legal basis: performance of a contract, and legal obligation (GDPR art. 6(1)(b) and (c); Swiss Code of Obligations art. 958f).
2.4 Organiser claims
If you claim an organiser page, we process the identity and contact details you submit in support of the claim, together with the decision taken on it.
Purpose: to verify that you are entitled to control the page. Legal basis: performance of a contract, and our legitimate interest in preventing impersonation (GDPR art. 6(1)(b) and (f)).
2.5 Technical logs
Our servers record technical events, including IP addresses, in order to operate the service and to detect abuse.
Legal basis: our legitimate interest in the security and stability of the Site (GDPR art. 6(1)(f)).
2.6 What we do not do
We do not use analytics, advertising, tracking pixels or third-party behavioural cookies. We do not profile you. We do not sell, rent or trade personal data, and we never will.
3. Cookies
The Site uses strictly necessary cookies only. It uses no analytics, no advertising, no tracking pixels and no third-party behavioural cookies.
Because these cookies are strictly necessary to provide a service you have requested, no consent banner is required.
Our Cookie Notice lists each cookie, what it does and how long it lasts. That page is the authoritative description; this policy does not duplicate it.
You can delete cookies at any time through your browser; doing so will sign you out.
4. Who we share data with
We use the following processors and third-party services. Each acts on our instructions or under its own controller responsibility as described below.
| Service | Role | Location |
|---|---|---|
| Infomaniak Network SA | Hosting and database | Switzerland |
| Infomaniak Swiss Backup | Encrypted backups | Switzerland |
| Stripe, Inc. / Stripe Payments Europe | Payment processing | EU / USA |
| Brevo (Sendinblue SAS) | Transactional and announcement email | EU (France) |
| Anthropic PBC | Automated reading of tournament documents | USA |
| Google LLC | Optional sign-in, if you choose it | USA |
| Discord Inc. | Optional sign-in, if you choose it | USA |
Google and Discord. If you sign in through one of these providers, they inform us of your email address and an account identifier. They act as independent controllers for the sign-in itself, under their own privacy policies. You are never required to use them: email sign-in is always available.
Anthropic. We use this service to read tournament structure documents automatically. In most cases these are documents published by organisers, containing no personal data. However, if you upload a photograph or a scanned PDF to our testing tool, the image is transmitted to Anthropic in order to be read. Spreadsheets, CSV files and PDFs containing a text layer are processed on our own servers and are never transmitted. Do not upload documents containing personal data to the testing tool.
Transfers to the United States (Stripe, Anthropic, Google, Discord) are covered by the European Commission's Standard Contractual Clauses and by the corresponding Swiss recognition. We do not share personal data with any other party, except where we are legally required to do so.
5. How long we keep data
| Data | Retention |
|---|---|
| Sign-up email addresses | Until you unsubscribe, or until you ask us to delete them |
| Account data | For the life of the account |
| Account data after deletion | Deleted immediately, except as below |
| Transaction and accounting records | 10 years (Swiss Code of Obligations art. 958f) |
| Credit ledger entries | 10 years, as accounting records |
| Organiser claim records | For as long as the claim stands, then as a record of the decision; deleted or anonymised when the account is deleted |
| Technical logs | Retained for as long as they remain useful for security and stability, and reviewed periodically |
Every mailing we send carries a one-click unsubscribe link.
6. Your rights
Under the nLPD and, where applicable, the GDPR, you may:
- access the personal data we hold about you
- rectify data that is inaccurate or incomplete
- erase your data ("right to be forgotten"), subject to the retention periods we are legally required to observe
- restrict or object to certain processing
- receive your data in a portable, machine-readable format
- withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal
To exercise any of these rights, write to contact@gsipoker.com. We will respond within 30 days. We may ask you to confirm your identity before acting on a request concerning an account.
If you believe we have not handled your data lawfully, you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC, Feldeggweg 1, 3003 Bern) or, if you are in the EU, with your national supervisory authority.
7. Security
Data is hosted in Switzerland. Traffic is encrypted in transit (TLS). Passwords are stored hashed and are never readable by us. Access to production systems is restricted to the Managing Director. Card data never reaches our servers.
No system is immune. If a breach occurs that is likely to result in a high risk to your rights, we will notify you and the competent authority as required by law.
8. Children
The Site is not intended for persons under 18. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, write to contact@gsipoker.com and we will delete it.
9. Changes
We may update this policy. The date at the top indicates the current version. If a change materially affects your rights, we will notify registered users by email before it takes effect.