Last updated: 10 September 2026
LootLocker stores player accounts, save data and game state for studios and publishers. This page describes how we protect it.
The commitments below also form Exhibit B to our Data Processing Agreement, which is where they are contractually binding.
Where your data lives
Player and customer data is hosted and stored in the European Economic Area. Our primary infrastructure runs on Hetzner in Helsinki, Finland.
A small number of providers we use to operate the platform are established outside the EEA or process limited data outside it — content delivery, monitoring, email and our internal tooling. Each is named, with what it handles and where, on our sub-processor page. Transfers to countries without an adequacy decision are covered by the European Commission's Standard Contractual Clauses.
Technical and organisational measures
Access control. Access to customer and player data is limited to personnel and sub-processors who need it in order to provide the Service.
Encryption. Data is encrypted in transit and at rest. This includes backups.
Infrastructure. We host with established infrastructure providers, listed on our sub-processor page.
Confidentiality. Personnel with access to customer or player data are bound by confidentiality obligations.
Incident handling. We maintain processes for identifying and responding to security incidents affecting customer and player data. Where a personal data breach affects a customer's data, we notify that customer without undue delay, with enough information for them to meet their own reporting obligations.
Review. We review these measures periodically and adjust them as our infrastructure and the applicable risks develop.
These measures describe our current practice and may change over time, provided the overall level of security is not materially reduced.
Data retention and deletion
When a customer's agreement ends, they have a 30-day window to export their data. We delete it within 30 days of that window closing. Copies held in routine encrypted backups are removed in the ordinary course of our backup rotation and remain protected under our Data Processing Agreement until they are.
Reporting a vulnerability
We run a responsible disclosure programme. It sets out how to report an issue, what is in scope, what we consider ineligible, and our commitment not to pursue legal action against researchers who follow it.
Read the responsible disclosure programme
What we don't claim
We are not currently certified to ISO 27001 or SOC 2. We would rather say that plainly than imply otherwise. If your procurement process needs a completed security questionnaire, email security@lootlocker.com and we will fill one in.