GBG Device Intelligence Processing Notice 

This Device Intelligence Processing Notice was last updated on 04 August, 2026

Purpose of This Notice

This Device Intelligence Processing Notice (“Notice”) is provided by GB Group PLC (“GBG”) to its Customers to assist them in developing comprehensive and transparent disclosures for consumers. Its purpose is to clarify how personal data are processed and to support compliance with transparency, privacy, and regulatory requirements under applicable U.S. law.

Scope of Data Processing

The Device Intelligence Module on the GBG GO Platform provides authentication, security, and risk assessment capabilities that Customers may deploy either as a standalone service or as part of an orchestrated workflow in support of the Customer’s identity verification and fraud prevention use cases, including consumer login and authentication events.

To deliver these capabilities, the Service implements a Web SDK to collect device data, behavioral information, location details, and signals related to malware or session integrity (security), as further described in the Categories of Personal Data Processed section below.

The processing of personal data by the Device Intelligence Service is governed by the Customer’s configuration settings, implementation choices, consumer permissions, and the data provided or made available through use of the Web SDK.

Role of GBG

GBG processes personal data through the Device Intelligence Service in the role of a service provider under the California Consumer Privacy Act (CCPA), and as a processor under the comprehensive consumer privacy laws of other U.S. states, including but not limited to Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, Iowa, Indiana, Tennessee, Montana, New Hampshire, New Jersey, Minnesota, and Maryland (collectively, “US Privacy Laws”). The Customer is the business under the CCPA and the controller under other U.S. Privacy Laws with respect to personal data processed through the Service.

Where the Customer is a financial institution, regulated entity, or other Customer whose processing of personal data through the Service is subject to sectoral or regulatory frameworks outside the scope of U.S. Privacy Laws, including without limitation the Gramm-Leach-Bliley Act (GLBA) where applicable, and analogous frameworks, GBG acts as a service provider to the Customer, processing personal data solely on the Customer’s behalf, under the Customer’s direction. Reference in this Notice to “service provider” or “processor” obligations apply consistently to GBG’s processing under such frameworks, to the extent consistent with applicable law.

In each of these roles, GBG processes personal data only on behalf of the Customer, pursuant to the Customer’s documented instructions as set forth in the applicable agreement terms, and for the limited business purposes identified in this Notice. Specifically, GBG:

  • does not sell personal data, as that term is defined under U.S. Privacy Laws;
  • does not share personal data for cross-context behavioral advertising, as that term is defined under the CCPA;
  • does not retain, use, or disclose personal data outside the direct business relationship with the Customer or for any purpose other than the business purposes specified in the applicable agreement and DPA, including this Notice;
  • does not combine personal data received from or on behalf of the Customer with personal data received from or on behalf of any other person, except as expressly permitted by the CCPA and its implementing regulations § 7050(a)(4) (including for the purposes of preventing and protecting against malicious, deceptive, fraudulent, or illegal activity);
  • process personal data in a manner consistent with the purpose limitation, data minimization, and proportionality requirements of applicable U.S. Privacy Laws; and
  • provides reasonable assistance to the Customer in responding to verified consumer rights requests, in accordance with the DPA.

Categories of Personal Data Processed

The Device Intelligence Service processes several categories of personal data, each relevant to the purposes of the Service. The following table outlines these categories, provides a description, and lists representative examples to assist Customers in evaluating their compliance and transparency needs. The exact data collected and processed is determined by the Customer’s configuration choices enabled by the Service, the Customer’s implementation, and the notice, consent, and consumer permissions obtained by the Customer from consumers in accordance with applicable law and the Customer Obligations section below.

 

Category of Personal Data

Description

Examples of Data Collected

Source

Behavioral Data

Information about how a user interacts with a webpage, application, or session

Mouse movements, pointer activity, keystroke timing, focus or blur events, clipboard events, touch interactions, and device motion or orientation signals.

Consumer device, browser, app, SDK, or Customer implementation

Device Data

Information about the user’s device, browser, and technical environment

Hardware and browser attributes, device type, operating system, language, platform, screen settings, browser settings, installed fonts or plugins, time zone, media device signals, and similar device or browser characteristics.

Consumer device, browser, app, SDK, or Customer implementation

Network Data

Information about the network connection used during the session

IP address and related connection information.

Consumer device, browser, network connection, SDK, or Customer implementation

Transactional Data

Information about when and how an interaction, session, or transaction occurred

Event timestamps, session events, transaction events, and workflow-related event information.

Customer implementation, GBG Go Platform, SDK, or service workflow

Location Data

Information about the user’s geographic location during the session or transaction, where enabled or permitted

Latitude, longitude, location accuracy, and related location signals

Consumer device, browser, app, SDK, user permission settings, or Customer implementation

Diagnostic and Performance Data

Technical information about how the SDK or service performs during the session.

Page load timing, SDK performance information, latency, error information, and similar diagnostic data.

SDK, browser, app, GBG systems, or Customer implementation

Malware Data

Information used to assess whether the device, browser, or session environment may be compromised, automated, or manipulated

Malware indicators, suspicious URLs, bot or automation indicators, tampering signals, and similar device integrity information.

Consumer device, browser, app, SDK, or Customer implementation

Derived Risk Signals and Scores

Signals and scores returned to the Customer to support the Customer’s identity verification, fraud prevention, and risk assessment workflows. The Customer determines the use, weighting, thresholds, and downstream decisioning logic applied to these signals.

Device risk signals, session risk indicators, behavioral anomaly indicators, malware risk flags, location mismatch indicators, and other fraud or security risk signals.

Derived by the Service from data collected at the Customer’s direction, configured according to the Customer’s implementation choices, and returned to the Customer for the Customer’s use.

Purposes of Processing

GBG processes personal data through the Device Intelligence Service for the specific purposes described below, in accordance with Customer’s documented instructions, the applicable agreement, and applicable U.S. law.

When Customer uses the Device Intelligence Service, GBG processes personal data to provide device intelligence, authentication, security, fraud prevention, and risk assessment capabilities in support of the Customer’s identity verification and fraud prevention workflows.

GBG may process personal data for the following purposes:

 

Purpose

Description

Service Delivery

To provide, operate, and make available the Device Intelligence Service through the GBG Go Platform, including associated APIs, SDKs, web flows, dashboards, and service components.

Authentication, Device Recognition, and Risk Assessment

To authenticate consumers and recognize devices, assess device consistency, evaluate session integrity, and generate device, session, behavioral, location, malware, or other risk signals returned to the Customer.

Fraud Prevention and Security

To detect, prevent, and investigate fraud, abuse, automated bot activity, malware, device tampering, suspicious behavior, account takeover, and other security or integrity risks affecting the Customer.

Legal and Compliance

To comply with applicable law, legal process, regulatory inquiries, court orders, and lawful requests from public authorities, and to establish, exercise, or defend legal claims as permitted under applicable law.

Sensitive Data

Definition of Sensitive Data

Depending on the Customer’s configuration, implementation, consumer permissions, and the applicable law, certain types of personal data processed through the Device Intelligence Service may be classified as “Sensitive Personal Information” under the California Consumer Privacy Act (CCPA) or as “Sensitive Data” according to other U.S. Privacy Laws.

Customer Obligations Regarding Sensitive Data

Prior to enabling, submitting, or otherwise making Sensitive Data available to GBG through the Service, Customers are responsible for determining and fulfilling their obligations under applicable laws. These obligations may include, where required:

  • Providing consumers with appropriate notice that describes the collection, use, and disclosure of Sensitive Data
  • Obtaining any required consent or authorization from consumers
  • Maintaining and publishing any applicable privacy notice or notice at the time of collection
  • Maintaining records of consent or authorization where required
  • Ensuring that the use of the Service is consistent with the Customer’s legal obligations and consumer-facing disclosures

Customer Obligations Regarding Notice and Consent at Collection

Because the Device Intelligence Service collects device, behavioral, location, and malware related signals directly from the consumer’s device or browser at the Customer’s direction and through the Customer’s deployment of the Web SDK, the Customer is solely responsible for providing all required notices and obtaining all required consents or other authorizations from consumers at or before the point of collection. The Customer’s obligations may include, where required under applicable law:

  • Providing notice at or before the point of collection of the categories of personal data collected through the Service, the purposes of collection, retention periods, and consumer rights, in a manner that satisfies Customer’s transparency obligations under U.S. Privacy Laws;
  • Implementing a cookie banner, consent management platform, or equivalent preference mechanism that distinguishes, where required, between strictly necessary or fraud prevention technologies and other categories of technology trackers subject to opt-in or opt-out requirements;
  • Honoring opt-outs: Customer is solely responsible for implementing and honoring all consumer choice signals (e.g., opt-outs, sensitive data limitations, etc.) and ensuring that no Personal Data is collected, disclosed, or processed through the Service in a manner inconsistent with such signals or Applicable Privacy Laws. Customer shall configure and use the Service, and any related websites, applications, integrations, or consent-management tools, accordingly.
  • Where the Customer collects or makes available precise geolocation, behavioral biometrics, or other sensitive personal data through the Service, obtaining any opt-in consent, providing any disclosure, and satisfying the additional notice and rights obligations applicable to sensitive personal data under U.S. Privacy Laws and any applicable state biometric privacy laws;
  • Maintaining records of the notices provided and the consents or authorizations obtained; and
  • Ensuring that the Customer’s use of the Service is consistent with the Customer’s consumer-facing privacy notice and any applicable industry, sectoral, or regulatory disclosure requirements.

GBG does not interact directly with consumers and does not provide notice at collection in its own name. The Customer’s notice and consent obligations are independent of, and in addition to, the Customer's obligations regarding Sensitive Data described above.

Subprocessors

The list of approved Subprocessors can be reviewed in the Data Processing Agreement.

 

Company Name

Subcontractor

Supplier Site

Supplier Address

Purpose

Type of Customer information processed

Sub-processor of personal data

Processing Locations

AMAZON WEB SERVICES UK LIMITED

AWS

https://aws.amazon.com/

38 Avenue John F. Kennedy,

L-1855,

Luxembourg

Hosting

All client data as specified in the Statement of Work

Yes

Dependent on Callsign SaaS hosting location

New Relic

New Relic

https://newrelic.com

188 Spear Street,

Suite 1000, San Francisco, CA

94105

Platform and Application Monitoring

Network and Application diagnostic information including Device information and IP addresses

Yes

EU (Germany) with US available

Atlassian, Inc

Atlassian

https://www.atlassian.com

Level 6, 341 George Street,

Sydney, NSW

2000, Australia

Information Technology Tools

Access to any personal data optionally provided by a customer agent when reporting an issue with the Callsign service

Yes

Global (All Atlassian cloud across AWS regions)

Note: access to any personal data optionally provided by a customer agent when reporting an issue with the Callsign service.

Microsoft Corporation

Azure Sentinel - SIEM solution

 

45 Fremont Street,

8th Floor, San Francisco, CA

94105

Information Technology Tools

User IP addresses and User Agent Strings only

Yes

UK

Crowdstrike

Crowdstrike

https://www.crowdstrike.co.uk

150 Mathilda Place

Sunnyvale, CA

94068 United States

Endpoint security, threat intelligence, and cyberattack response service provider

User IP addresses and User Agent Strings only

Yes

US

MaxMind, Inc

Maxmind

https://www.maxmind.com

14 Spring Street,

3rd Floor, Waltham, MA

02451, US

IP Databases

N/A

No

N/A

Digital.ai Software Inc

Digital.ai Software (Arxan)

www.digital.ai

5717 Legacy Drive,

Suite 250, Plano, TX

75024

App Protection

N/A

No

N/A

ScientiaMobile

ScientiaMobile

https://www.scientiamobile.com

11180 Sunrise Valley Drive Suite

20191, USA 

75024

Databases

N/A

No

N/A

Smartbear

Stoplight

https://stoplight.io

1834 E Oltorf St. Ste

200 Austin, TX USA

78741

Documentation Portal

N/A

No

N/A

Dexguard

Guardsquare

https://www.guardsquare.com

/dexguard

Tervuursevest 362/1,

3000 Leuven, Belgium,

VAT-BE-0550.675

Information Technology Tools

N/A

No

N/A

Artifactory

JFrog Ltd

https://jfrog.com

275 Grays Inn Road,

WC1X 8QB,

London,UK

Information Technology Tools

N/A

No

N/A

Salesforce UK Ltd 

Tableau

https://www.tableau.com/

Floor 26 Salesforce Tower

110 Bishopsgate,

EC2N 4AY, London 

Data Analytic

All transactional data

Yes

EU

Salesforce UK Ltd 

Slack Technologies, LLC

https://slack.com/intl/en-gb/

Slack Technologies Limited

Salesforce Tower

60 R801

North Dock, Dublin

Ireland

Messaging Services

Customer Data

Yes

EU

Retention and Deletion  

Data Category 

Retention Period 

Deletion  

Notes 

Device Intelligence Data 

12 months  

Automatically deleted after the retention period expires. 

Customer may request or configure a shorter period where supported by the Service. 

 

Post-termination deletion. Upon termination or expiration of the applicable Customer agreement, GBG will delete personal data processed on behalf of Customer within 90 days, unless a longer retention period is required by applicable law, or otherwise permitted under the applicable agreement. Upon Customer's written request, GBG will provide written confirmation of deletion in accordance with the DPA.  

Deletion upon rights request. Where Customer submits a verified deletion request on behalf of a consumer, GBG will support Customer by deleting applicable personal data from production systems within a reasonable timeframe after receiving sufficient information from Customer to identify the relevant data, unless retention is required or permitted by applicable law or the applicable agreement. GBG will also direct applicable Subprocessors to delete the relevant personal data within a reasonable timeframe. GBG will confirm completion of the deletion request to Customer.  

Consumer Rights/Processor Assistance. Under applicable U.S. Privacy Laws, consumers may have rights regarding personal data processed about them. As a service provider/processor, GBG does not directly receive, verify, or respond to consumer rights requests unless expressly agreed in writing. Instead, GBG supports Customer in fulfilling applicable consumer rights obligations by providing the technical and operational assistance described below. Customer is responsible for receiving, verifying, and responding to consumer rights requests within legally mandated timeframes.  

Artificial Intelligence

AI and machine learning capabilities are used solely to deliver authentication and fraud prevention services for the specific customer and end client from which the data originates. Customer Personal Data is not used for general AI model training, retraining, product improvement, or the development of broader AI systems unless explicitly authorized by the customer and permitted under the applicable agreement and DPA. Any customer-specific model training performed to support service delivery is isolated to that customer environment and does not involve cross-customer data sharing or reuse. Technical and contractual controls are in place to ensure customer data is processed only in accordance with approved configurations and authorized purposes.