Spectatr.ai

Legal

Platform Security Policy

The technical and organisational measures Spectatr.ai applies to safeguard customer data, video assets, user accounts and platform infrastructure across PULSE, AXIS, BRAND GAUGE and JORDY.

Last Updated: 19 May 2026

1. Purpose and Scope

This Security Policy describes the technical and organisational measures Spectatr.ai (operated by Fanbuff Technology India Private Limited, "Spectatr.ai", "we", "our") applies to safeguard customer data, video assets, user accounts and platform infrastructure across our products PULSE (AI Highlights), AXIS (Media Management), BRAND GAUGE (Sponsor Analytics) and JORDY (AI Sports Agent).

This Policy applies to all customer-facing environments, all employees and contractors who access Spectatr.ai systems, and all data processed through the platform, including live and recorded video feeds, generated highlights, metadata, sponsor analytics outputs and user account information.

2. Data Classification

Spectatr.ai classifies the data it processes into the following categories:

  • Customer Content: live feeds, recorded video, generated highlights, metadata, sponsor analytics outputs. Owned by the Customer; processed by Spectatr.ai on the Customer's behalf.
  • Account Data: usernames, hashed credentials, role assignments, organisation membership, access logs.
  • Contact Data: names, business email addresses, phone numbers submitted via demo or contact forms.
  • Operational Data: server logs, system telemetry, aggregated usage metrics.

Customer Content remains the property of the Customer at all times. Spectatr.ai does not sell, rent or share Customer Content with any third party other than infrastructure sub-processors strictly required to deliver the service.

3. Infrastructure and Hosting

Cloud Hosting

The platform is hosted on enterprise-grade cloud infrastructure. Physical security, environmental controls and hardware redundancy at the data centre layer are operated by the underlying cloud provider.

Environment Separation

Production, staging and development environments are logically separated. Production access is restricted to a defined set of authorised personnel.

Backups

Account data and metadata are backed up on a regular schedule. Customer Content is retained for the term of the engagement and deleted on written request following contract termination, subject to any retention obligations agreed in the underlying Master Service Agreement.

4. Encryption

In Transit

All connections between the Customer, the Spectatr.ai platform and our infrastructure are encrypted using TLS. The portal enforces HTTPS; HTTP requests are redirected.

At Rest

Stored video assets, highlights, metadata and database contents are encrypted at rest using the encryption standards of the underlying cloud infrastructure.

Credentials

User passwords are never stored in plaintext. They are hashed using industry-standard password hashing techniques.

5. Access Control and Authentication

User Access

Access to the Customer portal is governed by per-organisation accounts. Each Customer manages their own users; role-based access control determines what each user can view, edit, download or distribute. Spectatr.ai does not access Customer accounts other than for support purposes explicitly requested by the Customer.

Authentication

The portal supports password-based authentication. Customers are responsible for the strength and confidentiality of their credentials and for managing the lifecycle of their own users.

Internal Access

Access by Spectatr.ai personnel to production systems is restricted to a small, named set of engineering and operations staff under the principle of least privilege. Access is removed promptly on role change or departure.

Logging

Authentication and administrative actions on the platform are logged. Logs concerning a Customer's own organisation are available on written request.

6. Personnel

  • All Spectatr.ai personnel are bound by confidentiality obligations as a condition of engagement.
  • Personnel are required to follow internal security and acceptable-use practices when accessing Spectatr.ai systems.

7. Sub-processors

Spectatr.ai engages a limited number of sub-processors strictly to deliver the service. Each is bound by a written agreement containing confidentiality obligations. Current categories of sub-processor are:

  • Cloud infrastructure providers (compute, storage, networking).
  • Email and notification delivery providers.
  • Customer support and CRM tooling.
  • Analytics tooling for aggregated, non-personal usage metrics.

A current list of named sub-processors is available to Customers on written request.

8. Incident Response

Spectatr.ai maintains an internal process for identifying, containing and resolving security incidents. In the event of a confirmed security incident affecting Customer data, Spectatr.ai will notify the affected Customer without undue delay, including the nature of the incident, the data categories affected, the steps taken in response, and a point of contact for further information.

9. Data Retention and Deletion

  • Customer Content is retained for the term of the engagement and deleted following written request after contract termination, unless a longer retention period is agreed in writing.
  • Account Data is retained for the term of the engagement and for a reasonable period thereafter for audit purposes, then deleted.
  • Customer-initiated data export is available throughout the engagement in the formats supported by the platform.

10. Customer Responsibilities

The security of the platform is a shared responsibility. Customers are expected to:

  • Keep portal credentials confidential and not share login details across multiple users.
  • Promptly remove access for users who no longer require it.
  • Notify Spectatr.ai immediately at the contact below if a credential is suspected to be compromised.
  • Ensure that any feeds or content delivered to the platform are owned by the Customer or that the Customer holds the necessary rights to process them.

11. Policy Review

This Policy is reviewed periodically and updated as required to reflect changes in the platform and applicable law. The current version is available on request.

12. Contact

Security-related questions and incident reports may be directed to:

Spectatr.ai (Fanbuff Technology India Private Limited)

Last updated: 19 May 2026 — Spectatr.AI