Every major claim, with the evidence behind it.
Enterprise reviews follow the same script: who is the controller, what is contracted, how is the data protected, does the platform actually perform, and what happens when something goes wrong. Here are our answers, in one place, stated plainly for your procurement, security and legal teams.
Platform · Validation · Security · Compliance · Operations
How it is built, deployed and connected
One engine behind every campaign
How FIBRE® is engineered: the services, data flows and components every mechanic runs on. See the architecture →
Three ways in
FIBRE-built pages, embedded modules or API access from your own stack. Your systems stay the fixed point. Integration & API →
Built for launch day
The platform is load-tested for TV-spot traffic spikes and operated for high availability, because a campaign that is down during its own advertising is a compliance problem and a brand problem at once.
Uptime & SLA
Availability targets are agreed contractually per engagement. Current figures and SLA terms are available under NDA.
Accuracy you can interrogate
95.5% validation accuracy
Measured on a 5,000-receipt benchmark. Methodology and error rates (false positives, false negatives) are available under NDA.
1,000+ receipt formats, 20+ languages
Validation trained on the formats and retail chains that matter in each of the 41 markets. Receipt validation →
Auditable draws, seven-layer fraud screening
Winner selection is documented and reproducible, meeting the evidence standards regulators expect. Every entry passes FIBRE Shield™, our seven-layer fraud stack, before any payout: IP address checks, behavioural analysis, layout analysis, document analysis, detection of computer-based editing, and online fraud detection.
Every entry passes seven independent screening layers before a single reward is paid. Fraudulent, duplicate and invalid submissions are filtered out at no cost to you.
What each layer checks
1 · IP address checks. Flags entries from suspicious, masked or clustered addresses.
2 · Behavioural analysis. Spots unnatural patterns in speed, timing and repetition.
3 · Layout analysis. Checks the receipt structure against genuine retailer formats.
4 · Document analysis. Examines the file itself for signs of manipulation, including capture metadata (EXIF): when and how the photo was taken.
5 · Computer-based editing. Detects digital edits and re-saved or generated images.
6 · Textual analysis. Reads the text on the receipt and checks retailer wording, line items, totals and tax lines for consistency.
7 · Online fraud detection. Cross-references known fraud signals across entries, including image fingerprints that catch the same receipt template re-used across accounts.
What protects the data, in the terms your security team uses
The full technical and organisational measures form an annex to the data processing agreement. These are the control areas they cover.
Hosted in the EU, one database per market
Participant data is processed and stored on servers in the European Union, with a separate database per market as local law expects. Data leaves the campaign environment one way: as a structured, consented export into the brand's own CRM.
In transit and at rest
Campaign and participant data is encrypted in transmission and in storage, including on mobile devices used in operations.
Named accounts, least privilege, logging
Individual user accounts with strong authentication, access limited to those who need it for a defined purpose, with auditing, logging and change control on any system that can reach personal data.
Firewalling, patching, malware protection
Hardware firewalling with maintained rule sets, security and firmware patching on a defined cadence, and commercial-grade malware protection kept current.
Controlled facilities
Physical security and access control at the data centres and facilities where campaign data is processed.
Backups, recovery site, tested plan
A disaster recovery plan covering system backup, technology replacement and an alternate recovery site. The plan is maintained and periodically tested rather than filed away.
Vulnerability assessments at least annually
Vulnerability assessments are carried out at least once a year, more often where a client or a regulator requires it, and summary findings are shared with the client on request.
Stored where the contract says
Personal data is stored only in the contractually agreed geography and is not accessed from outside it, other than where strictly necessary for support and under the same protections.
No plain-text browsing
Measures are in place designed to prevent personal data from being readable in plain text for support or maintenance purposes, by our staff or by subcontractors.
Confidentiality, training, inventories
Everyone with access is bound by confidentiality and trained on handling personal data, including how to handle access requests from public authorities. We maintain an inventory of the systems that process personal data and of who is authorised to access them.
Within a defined, short window
On becoming aware of, or reasonably suspecting, a personal data breach, the agreement provides for breach notification within a defined, short window, typically 24 hours, with enough detail to meet the client's own reporting obligations, followed up as more becomes known. That is well inside the statutory window a controller has.
Passed on promptly
The agreement provides for participant requests to reach the client within a short defined period, typically five business days, with our assistance in answering them.
Notified, reviewed, challenged where appropriate
Requests for disclosure from public authorities are notified to the client where legally permitted, reviewed for lawfulness, and challenged where there are reasonable grounds to consider them unlawful.
Deleted or returned on a defined timeline
At the client's choice, the agreement provides for secure erasure or return within a defined period, typically 90 days of the end of processing, with written certification that it has been done.
Documentation, inspections, cooperation
Clients can request the information needed to demonstrate compliance and audit the systems and premises where their data is processed. Findings are remediated on notice.
ISO/IEC 27001: in progress, stated honestly
We are implementing an information security management system aligned with ISO/IEC 27001, with certification as the stated goal. The certificate goes on this page when we hold it, and not a day before.
You are the controller. We are the processor.
The brand decides purpose and means; we process on documented instructions. Where we act as controller, for example for the contact data of your project team, we say so in the contract rather than leaving it open.
Art. 28 GDPR, signed before any data flows
Our standard agreement covers processing purposes, data categories, retention, technical and organisational measures, subprocessors and audit rights. Your legal team reviews it before onboarding, not after launch.
Standard contractual clauses and country annexes
Module 2 controller-to-processor clauses are part of the agreement, with the UK addendum where UK data is involved and separate country annexes for markets such as Switzerland and Türkiye that apply their own regimes.
Named, vetted, contractually bound
Subprocessors are listed in the agreement and engaged only with your prior consent. Each one is assessed before engagement and bound by terms at least as protective as ours. We remain responsible to the client for their engagement, on the terms set out in our agreement.
The legal framework behind 41 markets
Rules in 41 markets
Which mechanics are allowed where, which permits are required, and how the rules differ. Rules by market →
How compliance scales
Terms, permits, taxes and winner obligations, organised per market. Independent licensed attorneys advise; Competence Alliance coordinates. Legal compliance →
The operating record
The numbers, stated as estimates
468 campaigns, ~12M consumers, ~€3M cashback paid out. See the numbers →
Frequently asked questions
What is the Evidence Centre for?
It lists the major claims made on this site together with the evidence behind each one: benchmarks, documents and processes. Nothing has to be taken on trust alone.
Which documents are available on request?
The data processing agreement, the technical and organisational measures, the incident process and the validation benchmark. They are shared on request, under NDA where a brand requires it.
How is the 95.5 per cent validation figure measured?
It comes from a documented benchmark of 5,000 receipts. The remainder is not rejected: those submissions go to human review before any decision is made.
Send us your security questionnaire.
We would rather answer it before the campaign than during it. Data processing agreement, measures annex and subprocessor list are available on request.
