This Device Intelligence Processing Notice was last updated on 04 August, 2026
This Device Intelligence Processing Notice (“Notice”) is provided by GB Group PLC (“GBG”) to its Customers to assist them in developing comprehensive and transparent disclosures for consumers. Its purpose is to clarify how personal data are processed and to support compliance with transparency, privacy, and regulatory requirements under applicable U.S. law.
The Device Intelligence Module on the GBG GO Platform provides authentication, security, and risk assessment capabilities that Customers may deploy either as a standalone service or as part of an orchestrated workflow in support of the Customer’s identity verification and fraud prevention use cases, including consumer login and authentication events.
To deliver these capabilities, the Service implements a Web SDK to collect device data, behavioral information, location details, and signals related to malware or session integrity (security), as further described in the Categories of Personal Data Processed section below.
The processing of personal data by the Device Intelligence Service is governed by the Customer’s configuration settings, implementation choices, consumer permissions, and the data provided or made available through use of the Web SDK.
GBG processes personal data through the Device Intelligence Service in the role of a service provider under the California Consumer Privacy Act (CCPA), and as a processor under the comprehensive consumer privacy laws of other U.S. states, including but not limited to Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, Iowa, Indiana, Tennessee, Montana, New Hampshire, New Jersey, Minnesota, and Maryland (collectively, “US Privacy Laws”). The Customer is the business under the CCPA and the controller under other U.S. Privacy Laws with respect to personal data processed through the Service.
Where the Customer is a financial institution, regulated entity, or other Customer whose processing of personal data through the Service is subject to sectoral or regulatory frameworks outside the scope of U.S. Privacy Laws, including without limitation the Gramm-Leach-Bliley Act (GLBA) where applicable, and analogous frameworks, GBG acts as a service provider to the Customer, processing personal data solely on the Customer’s behalf, under the Customer’s direction. Reference in this Notice to “service provider” or “processor” obligations apply consistently to GBG’s processing under such frameworks, to the extent consistent with applicable law.
In each of these roles, GBG processes personal data only on behalf of the Customer, pursuant to the Customer’s documented instructions as set forth in the applicable agreement terms, and for the limited business purposes identified in this Notice. Specifically, GBG:
The Device Intelligence Service processes several categories of personal data, each relevant to the purposes of the Service. The following table outlines these categories, provides a description, and lists representative examples to assist Customers in evaluating their compliance and transparency needs. The exact data collected and processed is determined by the Customer’s configuration choices enabled by the Service, the Customer’s implementation, and the notice, consent, and consumer permissions obtained by the Customer from consumers in accordance with applicable law and the Customer Obligations section below.
|
Category of Personal Data |
Description |
Examples of Data Collected |
Source |
|
Behavioral Data |
Information about how a user interacts with a webpage, application, or session |
Mouse movements, pointer activity, keystroke timing, focus or blur events, clipboard events, touch interactions, and device motion or orientation signals. |
Consumer device, browser, app, SDK, or Customer implementation |
|
Device Data |
Information about the user’s device, browser, and technical environment |
Hardware and browser attributes, device type, operating system, language, platform, screen settings, browser settings, installed fonts or plugins, time zone, media device signals, and similar device or browser characteristics. |
Consumer device, browser, app, SDK, or Customer implementation |
|
Network Data |
Information about the network connection used during the session |
IP address and related connection information. |
Consumer device, browser, network connection, SDK, or Customer implementation |
|
Transactional Data |
Information about when and how an interaction, session, or transaction occurred |
Event timestamps, session events, transaction events, and workflow-related event information. |
Customer implementation, GBG Go Platform, SDK, or service workflow |
|
Location Data |
Information about the user’s geographic location during the session or transaction, where enabled or permitted |
Latitude, longitude, location accuracy, and related location signals |
Consumer device, browser, app, SDK, user permission settings, or Customer implementation |
|
Diagnostic and Performance Data |
Technical information about how the SDK or service performs during the session. |
Page load timing, SDK performance information, latency, error information, and similar diagnostic data. |
SDK, browser, app, GBG systems, or Customer implementation |
|
Malware Data |
Information used to assess whether the device, browser, or session environment may be compromised, automated, or manipulated |
Malware indicators, suspicious URLs, bot or automation indicators, tampering signals, and similar device integrity information. |
Consumer device, browser, app, SDK, or Customer implementation |
|
Derived Risk Signals and Scores |
Signals and scores returned to the Customer to support the Customer’s identity verification, fraud prevention, and risk assessment workflows. The Customer determines the use, weighting, thresholds, and downstream decisioning logic applied to these signals. |
Device risk signals, session risk indicators, behavioral anomaly indicators, malware risk flags, location mismatch indicators, and other fraud or security risk signals. |
Derived by the Service from data collected at the Customer’s direction, configured according to the Customer’s implementation choices, and returned to the Customer for the Customer’s use. |
GBG processes personal data through the Device Intelligence Service for the specific purposes described below, in accordance with Customer’s documented instructions, the applicable agreement, and applicable U.S. law.
When Customer uses the Device Intelligence Service, GBG processes personal data to provide device intelligence, authentication, security, fraud prevention, and risk assessment capabilities in support of the Customer’s identity verification and fraud prevention workflows.
GBG may process personal data for the following purposes:
|
Purpose |
Description |
|
Service Delivery |
To provide, operate, and make available the Device Intelligence Service through the GBG Go Platform, including associated APIs, SDKs, web flows, dashboards, and service components. |
|
Authentication, Device Recognition, and Risk Assessment |
To authenticate consumers and recognize devices, assess device consistency, evaluate session integrity, and generate device, session, behavioral, location, malware, or other risk signals returned to the Customer. |
|
Fraud Prevention and Security |
To detect, prevent, and investigate fraud, abuse, automated bot activity, malware, device tampering, suspicious behavior, account takeover, and other security or integrity risks affecting the Customer. |
|
Legal and Compliance |
To comply with applicable law, legal process, regulatory inquiries, court orders, and lawful requests from public authorities, and to establish, exercise, or defend legal claims as permitted under applicable law. |
Definition of Sensitive Data
Depending on the Customer’s configuration, implementation, consumer permissions, and the applicable law, certain types of personal data processed through the Device Intelligence Service may be classified as “Sensitive Personal Information” under the California Consumer Privacy Act (CCPA) or as “Sensitive Data” according to other U.S. Privacy Laws.
Customer Obligations Regarding Sensitive Data
Prior to enabling, submitting, or otherwise making Sensitive Data available to GBG through the Service, Customers are responsible for determining and fulfilling their obligations under applicable laws. These obligations may include, where required:
Customer Obligations Regarding Notice and Consent at Collection
Because the Device Intelligence Service collects device, behavioral, location, and malware related signals directly from the consumer’s device or browser at the Customer’s direction and through the Customer’s deployment of the Web SDK, the Customer is solely responsible for providing all required notices and obtaining all required consents or other authorizations from consumers at or before the point of collection. The Customer’s obligations may include, where required under applicable law:
GBG does not interact directly with consumers and does not provide notice at collection in its own name. The Customer’s notice and consent obligations are independent of, and in addition to, the Customer's obligations regarding Sensitive Data described above.
The list of approved Subprocessors can be reviewed in the Data Processing Agreement.
|
Company Name |
Subcontractor |
Supplier Site |
Supplier Address |
Purpose |
Type of Customer information processed |
Sub-processor of personal data |
Processing Locations |
|
AMAZON WEB SERVICES UK LIMITED |
AWS |
https://aws.amazon.com/ |
38 Avenue John F. Kennedy, L-1855, Luxembourg |
Hosting |
All client data as specified in the Statement of Work |
Yes |
Dependent on Callsign SaaS hosting location |
|
New Relic |
New Relic |
https://newrelic.com |
188 Spear Street, Suite 1000, San Francisco, CA 94105 |
Platform and Application Monitoring |
Network and Application diagnostic information including Device information and IP addresses |
Yes |
EU (Germany) with US available |
|
Atlassian, Inc |
Atlassian |
https://www.atlassian.com |
Level 6, 341 George Street, Sydney, NSW 2000, Australia |
Information Technology Tools |
Access to any personal data optionally provided by a customer agent when reporting an issue with the Callsign service |
Yes |
Global (All Atlassian cloud across AWS regions) Note: access to any personal data optionally provided by a customer agent when reporting an issue with the Callsign service. |
|
Microsoft Corporation |
Azure Sentinel - SIEM solution |
|
45 Fremont Street, 8th Floor, San Francisco, CA 94105 |
Information Technology Tools |
User IP addresses and User Agent Strings only |
Yes |
UK |
|
Crowdstrike |
Crowdstrike |
https://www.crowdstrike.co.uk |
150 Mathilda Place Sunnyvale, CA 94068 United States |
Endpoint security, threat intelligence, and cyberattack response service provider |
User IP addresses and User Agent Strings only |
Yes |
US |
|
MaxMind, Inc |
Maxmind |
https://www.maxmind.com |
14 Spring Street, 3rd Floor, Waltham, MA 02451, US |
IP Databases |
N/A |
No |
N/A |
|
Digital.ai Software Inc |
Digital.ai Software (Arxan) |
www.digital.ai |
5717 Legacy Drive, Suite 250, Plano, TX 75024 |
App Protection |
N/A |
No |
N/A |
|
ScientiaMobile |
ScientiaMobile |
https://www.scientiamobile.com |
11180 Sunrise Valley Drive Suite 20191, USA 75024 |
Databases |
N/A |
No |
N/A |
|
Smartbear |
Stoplight |
https://stoplight.io |
1834 E Oltorf St. Ste 200 Austin, TX USA 78741 |
Documentation Portal |
N/A |
No |
N/A |
|
Dexguard |
Guardsquare |
https://www.guardsquare.com |
Tervuursevest 362/1, 3000 Leuven, Belgium, VAT-BE-0550.675 |
Information Technology Tools |
N/A |
No |
N/A |
|
Artifactory |
JFrog Ltd |
https://jfrog.com |
275 Grays Inn Road, WC1X 8QB, London,UK |
Information Technology Tools |
N/A |
No |
N/A |
|
Salesforce UK Ltd |
Tableau |
https://www.tableau.com/ |
Floor 26 Salesforce Tower 110 Bishopsgate, EC2N 4AY, London |
Data Analytic |
All transactional data |
Yes |
EU |
|
Salesforce UK Ltd |
Slack Technologies, LLC |
https://slack.com/intl/en-gb/ |
Slack Technologies Limited
Salesforce Tower 60 R801 North Dock, Dublin Ireland |
Messaging Services |
Customer Data |
Yes |
EU |
|
Data Category |
Retention Period |
Deletion |
Notes |
|
Device Intelligence Data |
12 months |
Automatically deleted after the retention period expires. |
Customer may request or configure a shorter period where supported by the Service. |
Post-termination deletion. Upon termination or expiration of the applicable Customer agreement, GBG will delete personal data processed on behalf of Customer within 90 days, unless a longer retention period is required by applicable law, or otherwise permitted under the applicable agreement. Upon Customer's written request, GBG will provide written confirmation of deletion in accordance with the DPA.
Deletion upon rights request. Where Customer submits a verified deletion request on behalf of a consumer, GBG will support Customer by deleting applicable personal data from production systems within a reasonable timeframe after receiving sufficient information from Customer to identify the relevant data, unless retention is required or permitted by applicable law or the applicable agreement. GBG will also direct applicable Subprocessors to delete the relevant personal data within a reasonable timeframe. GBG will confirm completion of the deletion request to Customer.
Consumer Rights/Processor Assistance. Under applicable U.S. Privacy Laws, consumers may have rights regarding personal data processed about them. As a service provider/processor, GBG does not directly receive, verify, or respond to consumer rights requests unless expressly agreed in writing. Instead, GBG supports Customer in fulfilling applicable consumer rights obligations by providing the technical and operational assistance described below. Customer is responsible for receiving, verifying, and responding to consumer rights requests within legally mandated timeframes.
AI and machine learning capabilities are used solely to deliver authentication and fraud prevention services for the specific customer and end client from which the data originates. Customer Personal Data is not used for general AI model training, retraining, product improvement, or the development of broader AI systems unless explicitly authorized by the customer and permitted under the applicable agreement and DPA. Any customer-specific model training performed to support service delivery is isolated to that customer environment and does not involve cross-customer data sharing or reuse. Technical and contractual controls are in place to ensure customer data is processed only in accordance with approved configurations and authorized purposes.