Privacy policy

We handle two very different kinds of personal data: the account data of the operators who buy from us, and the recipient data those operators instruct us to message. This policy explains where the line sits and what we do on either side of it.

Last updated 14 August 2026

Who we are

SMSPro Communications Ltd (trading as SMSPro) is a business-to-business messaging provider registered in Gibraltar under company number 118472, with its registered office at Suite 4, Watergardens Block 6, Waterport Road, Gibraltar GX11 1AA. We supply campaign delivery, carrier routing, segmentation and attribution services to licensed online gaming operators. We do not operate a casino or sportsbook, we do not accept wagers, we do not hold player funds, and we do not sell any product or service to players.

This policy covers the website at smspro.agency and the commercial relationship behind it. The SMSPro messaging platform itself is a separate authenticated application governed by the data processing agreement signed with each client. For privacy questions of any kind, write to hello@smspro.agency.

The controller and processor split

Almost every argument about a messaging provider starts with confusion over who is responsible for what. We state it plainly.

Where we are the controller

We are the data controller for the personal data of the people we do business with: the commercial, technical and compliance contacts at an operator, prospects who ask us for a demo or a quote, and visitors to this website. We decide why and how that data is used, and the rights described further down apply to us directly.

Where we are the processor

We are the data processor for recipient data: the mobile numbers, player identifiers, behavioural events, segment membership and delivery outcomes that a client loads into or generates on the platform. The client is the controller. The client decides who is on the list, what the message says, when it goes out and on what legal basis. We act only on the client's documented instructions, given through the platform, the API or a written change request.

We never build a marketing list of our own from client data, never message a recipient in our own name, and never make one client's recipient data available to another. Fully anonymised route performance statistics, which contain no personal data, are the only thing that crosses between accounts.

Data we process as controller

  • Business contact data: name, job title, employer, work email, work phone number and the country you operate from, collected when you contact us, request a demo or are named as a contact on an account.
  • Account and contract data: signatories, billing contacts, purchase order references, invoicing details and the correspondence attached to the relationship.
  • Onboarding and licence data:the gaming licence numbers, regulator references, corporate ownership information and beneficial owner checks we run before a carrier bind is provisioned in a client's name.
  • Platform access data: usernames, hashed credentials, multi-factor enrolment, IP address at sign-in and an audit log of administrative actions taken inside the platform.
  • Website data: pages viewed, referring source, approximate country from a truncated IP address, and anything you type into a form on this site. See our cookie policy for exactly what is set in your browser.

We do not collect special category data, and we ask that you do not put it into a form field or an email to us. Nothing on this site is directed at anyone under eighteen.

Why we process it, and our lawful basis

  • Contract (Article 6(1)(b)): provisioning accounts, routing and delivering traffic, producing reporting, raising invoices and providing support to a client.
  • Legitimate interests (Article 6(1)(f)): business-to-business marketing to operators, securing the platform against abuse and fraud, keeping route performance records, and bringing or defending legal claims. Our balancing assessment is available on request.
  • Legal obligation (Article 6(1)(c)): accounting and tax records, sanctions and beneficial ownership screening, sender identity registration filed with carriers and regulators, and responding to lawful requests from a competent authority.
  • Consent (Article 6(1)(a)): optional analytics cookies on this website, and nothing else. You can withdraw it at any time without affecting anything you have already received from us.

We do not make decisions about you by automated means that produce a legal or similarly significant effect. Routing decisions inside the platform are automated, but they select a carrier path, not an outcome about a person.

Recipient data and our Article 28 terms

Every client signs a data processing agreement before the first message is sent. It forms part of the contract described in our terms of service, and in the language of Article 28 of the UK and EU GDPR it commits us to the following.

  • We process recipient data only on the client's documented instructions, including on transfers, and we tell the client if we believe an instruction breaches data protection law.
  • Everyone with access to recipient data is bound by a written duty of confidentiality and is granted access on a least-privilege basis, reviewed on a rolling schedule.
  • We apply the technical and organisational measures required by Article 32, described under security below, and we keep them under review as the platform changes.
  • We engage sub-processors only under written terms no less protective than our own, and we remain fully liable to the client for their performance.
  • We assist the client with data subject requests, with data protection impact assessments and with prior consultation, using the export and suppression tooling built into the platform.
  • We notify the client of a personal data breach affecting their recipient data as required by Article 33(2), with the detail the client needs to meet its own obligations.
  • At the end of the contract we delete or return recipient data at the client's election, subject only to retention we are legally required to apply.
  • We make available the information needed to demonstrate compliance and submit to audits and inspections by the client or an auditor it mandates, on reasonable notice and under confidentiality.

The consent ledger

A marketing message to a handset is only lawful where the recipient has a valid legal basis attached to them, and the burden of proving that sits with the operator. The consent ledger is how we make it provable rather than assumed.

For every number on a client file the ledger holds the source of the opt-in, the exact wording shown at the point of collection, the timestamp, the channel and the form or platform it came from, plus the full history of every change to that record: opt-outs, re-opt-ins, suppression from a self-exclusion or cooling-off flag, and cadence caps applied. Ledger entries are append-only. A record can be superseded but never silently edited or removed.

The ledger is exportable in full by the client at any time, which turns a regulator question or a recipient complaint into a lookup rather than an investigation. We hold the ledger as processor: it belongs to the client, and we use it only to enforce suppression, block non-compliant traffic and answer the client's own audit requests. Where a campaign is loaded against numbers with no demonstrable basis in the ledger, we suspend it.

Who we share data with

We disclose personal data only where there is a reason to, and only to the categories below. We do not sell personal data, we do not share it for anyone else's marketing, and we do not operate a data brokerage of any kind.

  • Mobile network operators and messaging aggregators in the destination market, which receive the recipient number and the message content because that is what delivering an SMS consists of.
  • Sub-processors engaged to run parts of the platform, listed below.
  • Professional advisers such as auditors, accountants and lawyers, bound by professional confidentiality.
  • Regulators, carriers and law enforcement where we are legally required to respond, or where a carrier requires sender identity and traffic records to keep a route open.
  • An acquirer in the event of a merger, restructuring or sale of the business, under confidentiality and with this policy continuing to apply.

Sub-processors

We keep the list short on purpose. The current categories are cloud infrastructure hosted in the European Union, transactional email for platform notifications, a support ticketing system, an error and performance monitoring service, and the regional carrier aggregators used in the small number of markets where a direct bind is not available.

The full named list, with each sub-processor role and processing location, is maintained as an annex to the data processing agreement and issued to every client. We give clients notice of any addition or replacement in advance and a window to object on reasonable data protection grounds. If an objection cannot be resolved, the client may terminate the affected service without penalty.

International transfers

The platform and its primary data stores sit in the European Union, and EU recipient data stays inside the EU as a matter of configuration rather than of policy. Gibraltar is recognised by the United Kingdom for the purposes of UK data protection law, and transfers between Gibraltar and the European Economic Area are handled under Chapter V of the GDPR.

Delivering a message to a handset in a market outside the EEA necessarily involves sending the number and the message content to a carrier in that market. Where that happens, and for any sub-processor located outside the EEA or the UK, we rely on an adequacy decision where one exists and otherwise on the European Commission Standard Contractual Clauses, or the UK International Data Transfer Addendum, supported by a transfer risk assessment and additional safeguards including encryption in transit and strict data minimisation. A copy of the clauses in place for a given route is available to clients on request.

How long we keep things

  • Message content and recipient numbers: retained for the period set by the client in its account, with a platform default of thirteen months, after which content is deleted and only anonymised delivery statistics remain.
  • Delivery receipts and routing metadata: twenty-four months, because carriers and regulators can query the provenance of a message long after it landed.
  • Consent ledger entries: the life of the client account and six years after the last relevant campaign, since the ledger is the evidence that the campaign was lawful.
  • Suppression and opt-out records: kept indefinitely. Deleting an opt-out would allow the number to be messaged again, which is the opposite of what the recipient asked for.
  • Client account, contract and licence records: the life of the contract plus six years, for tax, audit and limitation purposes.
  • Prospect and enquiry data: twenty-four months from the last meaningful contact, then deleted.
  • Website analytics: fourteen months, in aggregated form.

Security

Data is encrypted in transit with TLS and at rest with AES-256. Access to production systems requires single sign-on with hardware-backed multi-factor authentication and is granted by role, with administrative actions written to an append-only audit log. Environments are segregated, secrets are held in a managed vault, backups are encrypted and restore-tested, and changes reach production through peer review and automated checks. We run an ISO 27001 certified information security management system, penetration testing on an annual cycle and a documented incident response process rehearsed against realistic scenarios.

Your rights

Where we are the controller you have the right to ask for access to your personal data, to have inaccurate data corrected, to have data erased, to have processing restricted, to receive your data in a portable format, to object to processing based on legitimate interests, and to withdraw consent where consent is the basis. Exercising any of these rights is free and will not disadvantage you commercially.

Write to hello@smspro.agency or to SMSPro Communications Ltd, Suite 4, Watergardens Block 6, Waterport Road, Gibraltar GX11 1AA. We may need to verify your identity before acting, and we will explain if a statutory exemption applies to any part of a request.

If you received a marketing message, we are the processor rather than the controller, and the operator whose brand is on the message holds your data and your rights request. Reply STOP to the message to be suppressed across every campaign that sender runs on our platform, and see our abuse policy for how to have the sender identified and your request routed to the right controller. We pass every such request on, and we enforce the suppression on our side either way.

Complaints

If you are unhappy with how we have handled your data, tell us first so we can put it right. You also have the right to complain to a supervisory authority: the Gibraltar Regulatory Authority in Gibraltar, the Information Commissioner's Office in the United Kingdom, or the data protection authority in the EU member state where you live or work.

Cookies

This website sets a small number of essential cookies and, with your permission, analytics cookies. What is set, why, and how to switch it off is covered in the cookie policy.

Changes to this policy

We update this policy when the platform, our sub-processors or the law change. The date at the top of the page always reflects the current version. Where a change materially affects clients we notify the account contacts directly and, where the data processing agreement requires it, agree the change in writing before it takes effect. Superseded versions are retained and can be requested.

Questions about this policy? Write to hello@smspro.agency or post to SMSPro Communications Ltd, Suite 4, Watergardens Block 6, Waterport Road, Gibraltar GX11 1AA.