Skip to content

Draft. This page has not been approved yet and is not legally binding.

ULTIDO

Security and data protection at ULTIDO

Every statement carries its status. You see what we can evidence today, what is planned with a date, and what is still missing.

As of 2 October 2026

How to read this page

Verified
Evidence on file, with a review date.6 items
Planned
Committed, with a date.9 items
Missing
Known gap.10 items
Not applicable
Does not apply, with a reason.0 items

1Overview

ULTIDO GmbH runs a game-based web app for visitors of theme parks, stadiums and zoos. For the parks, we process guest data as a processor under Art. 28 GDPR.

3Subprocessors

6 subprocessors process data on behalf of the parks. 4 of them are based in or process data in the US.

  • Vercel Inc.

    Missing

    Hosting, serverless functions and frontend delivery, including aggregated web telemetry (Vercel Analytics)

    Place of processing
    Germany (fra1)
    Transfer
    Data Privacy Framework and Standard Contractual Clauses
  • Clerk Inc.

    Missing

    Authentication and identity, and triggering of all profile emails

    Place of processing
    United States
    Transfer
    Data Privacy Framework and Standard Contractual Clauses
  • Twilio Inc.via Clerk Inc.

    Missing

    Technical delivery of the profile and reward emails triggered by Clerk

    Place of processing
    United States
    Transfer
    EU-US Data Privacy Framework
  • Supabase Inc.

    Missing

    Database, backend and object storage for image output

    Place of processing
    Germany (eu-central-1)
    Transfer
    Standard Contractual Clauses
  • Google LLC

    Missing

    AI image stylisation (inference)

    Place of processing
    Not yet evidenced
    Transfer
    Not yet evidenced
  • Papoo Software & Media GmbH

    Missing

    Consent management for cookies (§ 25 TDDDG)

    Place of processing
    Germany
    Transfer
    None (EU)

Next review of the register: 15 January 2027

4Artificial intelligence

  1. 4.1
    AI Act transparency

    Version 3.2.0, effective 25 September 2026Draft

    Planned

5Security and controls

  1. 5.1

    The park app's server functions run in Frankfurt am Main (Vercel region fra1).

    Read the regions of the current production deployment from the Vercel API.

    Verified
  2. 5.2

    The park app's database and file storage are in the EU (Supabase, eu-central-1, Frankfurt am Main).

    Read the project region from the Supabase management API.

    Verified
  3. 5.3

    Row level security is enabled on every table of the application database.

    Catalogue query on pg_tables: all 20 tables in the public schema have RLS enabled.

    Verified
  4. 5.4

    Images uploaded by or generated for guests are stored in a non-public bucket.

    Catalogue query on storage.buckets: the guest media bucket is not public.

    Verified
  5. 5.5

    The park app is only reachable encrypted: TLS 1.3, HTTP to HTTPS redirect and HSTS for two years.

    Checked the TLS handshake and response headers of the production domain live.

    Verified
  6. 5.6

    Preview deployments are protected by Vercel Authentication.

    Read the project's protection setting from the Vercel API; shareable links and protection exceptions are not covered by this check.

    Verified
  7. 5.7

    The park app sends security headers (content security policy, framing protection, nosniff).

    Missing
  8. 5.8

    The application database is backed up and can be restored to a point in time.

    Missing
  9. 5.9

    Administrative access to hosting, database and source code is protected by multi-factor authentication.

    Missing

System status

  1. 5.10
    Personal data breach response

    On request, under a non-disclosure agreement

    Planned by 30 November 2026

6Contact

Data protection
privacy@ultido.com
Report a vulnerability
security@ultido.com
Access to documents
trust@ultido.com