Security and data protection at ULTIDO
Every statement carries its status. You see what we can evidence today, what is planned with a date, and what is still missing.
As of 2 October 2026
How to read this page
- Verified
- Evidence on file, with a review date.6 items
- Planned
- Committed, with a date.9 items
- Missing
- Known gap.10 items
- Not applicable
- Does not apply, with a reason.0 items
1Overview
ULTIDO GmbH runs a game-based web app for visitors of theme parks, stadiums and zoos. For the parks, we process guest data as a processor under Art. 28 GDPR.
2Contracts and data protection
- 2.1Data protection contact
For data protection questions, contact privacy@ultido.com.
Missing - 2.2Data Processing Agreement
On request, under a non-disclosure agreement
Planned by 31 October 2026 - 2.3Technical and organisational measures
On request, under a non-disclosure agreement
Planned by 31 October 2026 - 2.4Record of processing activities (Art. 30(2))
On request, under a non-disclosure agreement
Planned by 30 November 2026 - 2.5Data subject request process
On request, under a non-disclosure agreement
Planned by 30 November 2026 - 2.6Retention and deletion schedule
On request, under a non-disclosure agreement
Planned by 30 November 2026 - 2.7Non-disclosure agreement
Version 0.1.0Draft
Planned by 30 November 2026 - 2.8Trust Center privacy notice
Version 0.1.0Draft
Planned by 30 November 2026
3Subprocessors
6 subprocessors process data on behalf of the parks. 4 of them are based in or process data in the US.
Vercel Inc.
MissingHosting, serverless functions and frontend delivery, including aggregated web telemetry (Vercel Analytics)
- Place of processing
- Germany (fra1)
- Transfer
- Data Privacy Framework and Standard Contractual Clauses
Clerk Inc.
MissingAuthentication and identity, and triggering of all profile emails
- Place of processing
- United States
- Transfer
- Data Privacy Framework and Standard Contractual Clauses
Twilio Inc.via Clerk Inc.
MissingTechnical delivery of the profile and reward emails triggered by Clerk
- Place of processing
- United States
- Transfer
- EU-US Data Privacy Framework
Supabase Inc.
MissingDatabase, backend and object storage for image output
- Place of processing
- Germany (eu-central-1)
- Transfer
- Standard Contractual Clauses
Google LLC
MissingAI image stylisation (inference)
- Place of processing
- Not yet evidenced
- Transfer
- Not yet evidenced
Papoo Software & Media GmbH
MissingConsent management for cookies (§ 25 TDDDG)
- Place of processing
- Germany
- Transfer
- None (EU)
Next review of the register: 15 January 2027
4Artificial intelligence
- 4.1AI Act transparency
Version 3.2.0, effective 25 September 2026Draft
Planned
5Security and controls
- 5.1Verified
The park app's server functions run in Frankfurt am Main (Vercel region fra1).
Read the regions of the current production deployment from the Vercel API.
- 5.2Verified
The park app's database and file storage are in the EU (Supabase, eu-central-1, Frankfurt am Main).
Read the project region from the Supabase management API.
- 5.3Verified
Row level security is enabled on every table of the application database.
Catalogue query on pg_tables: all 20 tables in the public schema have RLS enabled.
- 5.4Verified
Images uploaded by or generated for guests are stored in a non-public bucket.
Catalogue query on storage.buckets: the guest media bucket is not public.
- 5.5Verified
The park app is only reachable encrypted: TLS 1.3, HTTP to HTTPS redirect and HSTS for two years.
Checked the TLS handshake and response headers of the production domain live.
- 5.6Verified
Preview deployments are protected by Vercel Authentication.
Read the project's protection setting from the Vercel API; shareable links and protection exceptions are not covered by this check.
- 5.7Missing
The park app sends security headers (content security policy, framing protection, nosniff).
- 5.8Missing
The application database is backed up and can be restored to a point in time.
- 5.9Missing
Administrative access to hosting, database and source code is protected by multi-factor authentication.
- 5.10Personal data breach response
On request, under a non-disclosure agreement
Planned by 30 November 2026
6Contact
- Data protection
- privacy@ultido.com
- Report a vulnerability
- security@ultido.com
- Access to documents
- trust@ultido.com