Every major claim, with the evidence behind it.
Enterprise reviews follow the same script: who is the controller, what is contracted, how is the data protected, does the platform actually perform, and what happens when something goes wrong. Here are our answers, in one place, stated plainly for your procurement, security and legal teams.
Platform · IP · Validation · Security · Compliance · Operations
The answers a review usually starts with
Eleven lines. Every one of them is set out in full, with its evidence, further down this page.
| Item | Where we stand |
|---|---|
| ISO/IEC 27001 | Certification audit scheduled for spring 2027. No certificate yet. Security |
| SOC 2 | Not held. |
| Hosting and separation | Servers in the European Union. Own logically separated data set per campaign; own database where the design or local law calls for it. |
| Data processing agreement | Art. 28 GDPR, signed before any data flows. Roles and contracts |
| Technical and organisational measures | An annex to that agreement, covering the control areas listed below. |
| Subprocessors | Named in the agreement, engaged only with your prior consent, bound by terms at least as protective as ours. |
| International transfers | Standard contractual clauses, Module 2, with the UK addendum and separate country annexes for markets such as Switzerland and Turkey. |
| Breach notification | Typically within 24 hours of becoming aware, or reasonably suspecting. |
| Data subject requests | Passed to you within typically five business days, with our assistance in answering them. |
| Deletion or return | At your choice, typically within 90 days of the end of processing, with written certification. |
| Uptime and SLA | Measured availability and a defined escalation path, not a published figure we cannot stand behind. Measured values under NDA. A contractual SLA, where an engagement requires one, is named and priced into scope. |
How it is built, deployed and connected
One engine behind every campaign
How FIBRE® is engineered: the services, data flows and components every mechanic runs on. See the architecture →
Three ways in
FIBRE-built pages, embedded modules or API access from your own stack. Your systems stay the fixed point. Integration & API →
Built for launch day
The platform is load-tested for TV-spot traffic spikes and operated for high availability, because a campaign that is down during its own advertising is a compliance problem and a brand problem at once.
Uptime & SLA
We report measured availability and operate a defined escalation path. We do not publish an uptime figure we cannot stand behind. Measured figures are shared under NDA. Where an engagement requires a contractual availability SLA, it is named and priced into the scope before you commit.
Who controls the platform, and what backs that up
Platform control is a procurement question, not a marketing one. These are the claims and the evidence behind them.
PCS controls the platform and its roadmap
Promo Consulting Solutions GmbH controls the source-code repository and decides what is built next. Evidence: repository control and documented development governance.
PCS holds the rights it needs
The exclusive contractual rights required to operate, modify and further develop the source code. Evidence: the development agreements and their exclusive usage-rights provisions.
No dependency on one external licensor
Continued development does not rest with a third-party platform provider. Evidence: the chain of rights and the development arrangements inside the Alliance.
Shown on request
A summary of the rights position, or confirmation of it, is available during procurement under NDA.
What the numbers actually mean
95.5% decided automatically
Measured on a 5,000-receipt benchmark: the share resolved end to end without a person. The remaining 4.5% were flagged as uncertain and decided by trained reviewers before payout, not rejected. Methodology and error rates (false positives, false negatives) are available under NDA.
1,000+ receipt formats, 20+ languages
Validation trained on the formats and retail chains that matter in each of the 41 markets. Receipt validation →
Auditable draws, seven-layer fraud screening
Winner selection is documented and reproducible, meeting the evidence standards regulators expect. Every entry passes FIBRE Shield™, our seven-layer fraud stack, before any payout: IP address checks, behavioural analysis, layout analysis, document analysis, detection of computer-based editing, textual analysis and online fraud detection.
Every entry passes seven independent screening layers before a single reward is paid. Fraudulent, duplicate and invalid submissions are filtered out at no cost to you.
What each layer checks
1 · IP address checks. Flags entries from suspicious, masked or clustered addresses.
2 · Behavioural analysis. Spots unnatural patterns in speed, timing and repetition.
3 · Layout analysis. Checks the receipt structure against genuine retailer formats.
4 · Document analysis. Examines the file itself for signs of manipulation, including capture metadata (EXIF): when and how the photo was taken.
5 · Computer-based editing. Detects digital edits and re-saved or generated images.
6 · Textual analysis. Reads the text on the receipt and checks retailer wording, line items, totals and tax lines for consistency.
7 · Online fraud detection. Cross-references known fraud signals across entries, including image fingerprints that catch the same receipt template re-used across accounts.
What protects the data, in the terms your security team uses
The full technical and organisational measures form an annex to the data processing agreement. These are the control areas they cover.
Hosted in the EU, separated per campaign
Participant data is processed and stored on servers in the European Union. Every campaign runs in its own logically separated data set; where the campaign design or local law calls for it, a market runs in its own database. Data leaves the campaign environment on one route only: as a structured, consented export to the brand — into its own CRM, or to the agency the brand names. Where that export feeds audience matching on an advertising platform, the identifiers can be hashed before they leave. Nothing goes anywhere the brand has not designated.
In transit and at rest
Campaign and participant data is encrypted in transmission and in storage, including on mobile devices used in operations.
Named accounts, least privilege, logging
Individual user accounts with strong authentication, access limited to those who need it for a defined purpose, with auditing, logging and change control on any system that can reach personal data.
Firewalling, patching, malware protection
Hardware firewalling with maintained rule sets, security and firmware patching on a defined cadence, and commercial-grade malware protection kept current.
Controlled facilities
Physical security and access control at the data centres and facilities where campaign data is processed.
Backups, recovery site, tested plan
A disaster recovery plan covering system backup, technology replacement and an alternate recovery site. The plan is maintained and periodically tested rather than filed away.
Vulnerability assessments at least annually
Vulnerability assessments are carried out at least once a year, more often where a client or a regulator requires it, and summary findings are shared with the client on request.
Stored where the contract says
Personal data is stored only in the contractually agreed geography and is not accessed from outside it, other than where strictly necessary for support and under the same protections.
No plain-text browsing
Measures are in place designed to prevent personal data from being readable in plain text for support or maintenance purposes, by our staff or by subcontractors.
Confidentiality, training, inventories
Everyone with access is bound by confidentiality and trained on handling personal data, including how to handle access requests from public authorities. We maintain an inventory of the systems that process personal data and of who is authorised to access them.
Within a defined, short window
On becoming aware of, or reasonably suspecting, a personal data breach, the agreement provides for breach notification within a defined, short window, typically 24 hours, with enough detail to meet the client's own reporting obligations, followed up as more becomes known. That is well inside the statutory window a controller has.
Passed on promptly
The agreement provides for participant requests to reach the client within a short defined period, typically five business days, with our assistance in answering them.
Notified, reviewed, challenged where appropriate
Requests for disclosure from public authorities are notified to the client where legally permitted, reviewed for lawfulness, and challenged where there are reasonable grounds to consider them unlawful.
Deleted or returned on a defined timeline
At the client's choice, the agreement provides for secure erasure or return within a defined period, typically 90 days of the end of processing, with written certification that it has been done.
Documentation, inspections, cooperation
Clients can request the information needed to demonstrate compliance and audit the systems and premises where their data is processed. Findings are remediated on notice.
ISO/IEC 27001: certification audit scheduled for spring 2027
We are implementing an information security management system aligned with ISO/IEC 27001, with the certification audit scheduled for spring 2027. The certificate goes on this page when we hold it, and not a day before. The platform itself runs on infrastructure certified to ISO/IEC 27001:2022 and covered by a SOC 2 Type 2 attestation for security, confidentiality and availability. That is our provider’s certificate, not ours; evidence is available on request.
Public liability and professional indemnity cover in place
Promo Consulting Solutions GmbH carries public liability insurance (Betriebshaftpflicht) and professional indemnity insurance (Vermögensschadenhaftpflicht). A current certificate naming the insured entity, the sums insured and the territorial scope is provided on request, before contract.
Register extract and credit report on request
A current extract from the commercial register (Amtsgericht Hanau, HRB 99379) and a Creditreform credit report are provided on request, so your supplier assessment does not stall on paperwork. The extract shows 2016: that is when Promo Consulting Solutions GmbH took over the business and the Competence Alliance was formed. Consumer promotions have run since 2010, before that through a predecessor entity that has since been consolidated and is no longer used.
No lock-in, no minimum term
Term and notice are agreed per campaign. We do not require a framework commitment, a minimum term or a minimum spend.
WCAG 2.1 AA as the working standard
Consumer-facing campaign pages are built to WCAG 2.1 AA: keyboard operation, colour contrast, labelled form fields and alternative text. We hold no third-party accessibility audit and do not imply one.
You are the controller. We are the processor.
The brand decides purpose and means; we process on documented instructions. Where we act as controller — the contact data of your project team, or a cashback promotion we run in our own name — we say so in the contract rather than leaving it open.
Art. 28 GDPR, signed before any data flows
Our standard agreement covers processing purposes, data categories, retention, technical and organisational measures, subprocessors and audit rights. Your legal team reviews it before onboarding, not after launch.
Standard contractual clauses and country annexes
Module 2 controller-to-processor clauses are part of the agreement, with the UK addendum where UK data is involved and separate country annexes for markets such as Switzerland and Turkey that apply their own regimes.
Named, vetted, contractually bound
Subprocessors are listed in the agreement and engaged only with your prior consent. Each one is assessed before engagement and bound by terms at least as protective as ours. We remain responsible to the client for their engagement, on the terms set out in our agreement.
The legal framework behind 41 markets
Rules in 41 markets
Which mechanics are allowed where, which permits are required, and how the rules differ. Rules by market →
How compliance scales
Terms, permits, taxes and winner obligations, organised per market. Independent licensed attorneys advise; Competence Alliance coordinates. Legal compliance →
The operating record
The numbers, stated as estimates
468 campaigns, ~12M consumers, ~€3M distributed to consumers as cashback and digital vouchers. See the numbers →
Frequently asked questions
What is the Trust Center for?
It lists the major claims made on this site together with the evidence behind each one: benchmarks, documents and processes. Nothing has to be taken on trust alone.
Which documents are available on request?
The data processing agreement, the technical and organisational measures, the incident process and the validation benchmark. They are shared on request, under NDA where a brand requires it.
How is the 95.5 per cent figure measured, and what does it mean?
It comes from a documented benchmark of 5,000 receipts and describes the share decided automatically, not an accuracy rate. The remaining 4.5% are flagged as uncertain by the trust score and decided by a person before any payout. No submission is rejected because the system was unsure. Methodology and error rates, including false positives and negatives, are available under NDA.
Send us your security questionnaire.
We would rather answer it before the campaign than during it. Data processing agreement, measures annex and subprocessor list are available on request. Company master data, contract, liability and insurance are on the supplier pack.
