FIBRE® Evidence Centre

Every major claim, with the evidence behind it.

Enterprise reviews follow the same script: who is the controller, what is contracted, how is the data protected, does the platform actually perform, and what happens when something goes wrong. Here are our answers, in one place, stated plainly for your procurement, security and legal teams.

Platform · Validation · Security · Compliance · Operations

Platform

How it is built, deployed and connected

Architecture

One engine behind every campaign

How FIBRE® is engineered: the services, data flows and components every mechanic runs on. See the architecture →

Deployment

Three ways in

FIBRE-built pages, embedded modules or API access from your own stack. Your systems stay the fixed point. Integration & API →

Availability

Built for launch day

The platform is load-tested for TV-spot traffic spikes and operated for high availability, because a campaign that is down during its own advertising is a compliance problem and a brand problem at once.

Availability

Uptime & SLA

Availability targets are agreed contractually per engagement. Current figures and SLA terms are available under NDA.

Validation

What the numbers actually mean

Benchmark

95.5% decided automatically

Measured on a 5,000-receipt benchmark: the share resolved end to end without a person. The remaining 4.5% were flagged as uncertain and decided by a reviewer before payout, Because uncertain cases are decided by a person before payout, the accuracy of the final decision is close to 100%. Methodology and error rates (false positives, false negatives) are available under NDA.

Coverage

1,000+ receipt formats, 20+ languages

Validation trained on the formats and retail chains that matter in each of the 41 markets. Receipt validation →

Campaign integrity

Auditable draws, seven-layer fraud screening

Winner selection is documented and reproducible, meeting the evidence standards regulators expect. Every entry passes FIBRE Shield™, our seven-layer fraud stack, before any payout: IP address checks, behavioural analysis, layout analysis, document analysis, detection of computer-based editing, and online fraud detection.

FIBRE Shield™

Every entry passes seven independent screening layers before a single reward is paid. Fraudulent, duplicate and invalid submissions are filtered out at no cost to you.

MULTI-LAYER FRAUD CHECK1IP ADDRESS CHECKS2BEHAVIOURALANALYSIS3LAYOUT ANALYSIS4DOCUMENT ANALYSIS5COMPUTER-BASEDEDITING6TEXTUAL ANALYSIS7ONLINE FRAUDDETECTION
What each layer checks

1 · IP address checks. Flags entries from suspicious, masked or clustered addresses.

2 · Behavioural analysis. Spots unnatural patterns in speed, timing and repetition.

3 · Layout analysis. Checks the receipt structure against genuine retailer formats.

4 · Document analysis. Examines the file itself for signs of manipulation, including capture metadata (EXIF): when and how the photo was taken.

5 · Computer-based editing. Detects digital edits and re-saved or generated images.

6 · Textual analysis. Reads the text on the receipt and checks retailer wording, line items, totals and tax lines for consistency.

7 · Online fraud detection. Cross-references known fraud signals across entries, including image fingerprints that catch the same receipt template re-used across accounts.

Technical and organisational measures

What protects the data, in the terms your security team uses

The full technical and organisational measures form an annex to the data processing agreement. These are the control areas they cover.

Data residency

Hosted in the EU, one database per market

Participant data is processed and stored on servers in the European Union, with a separate database per market as local law expects. Data leaves the campaign environment one way: as a structured, consented export into the brand's own CRM.

Encryption

In transit and at rest

Campaign and participant data is encrypted in transmission and in storage, including on mobile devices used in operations.

Access control

Named accounts, least privilege, logging

Individual user accounts with strong authentication, access limited to those who need it for a defined purpose, with auditing, logging and change control on any system that can reach personal data.

Network and endpoint

Firewalling, patching, malware protection

Hardware firewalling with maintained rule sets, security and firmware patching on a defined cadence, and commercial-grade malware protection kept current.

Physical security

Controlled facilities

Physical security and access control at the data centres and facilities where campaign data is processed.

Resilience

Backups, recovery site, tested plan

A disaster recovery plan covering system backup, technology replacement and an alternate recovery site. The plan is maintained and periodically tested rather than filed away.

Testing

Vulnerability assessments at least annually

Vulnerability assessments are carried out at least once a year, more often where a client or a regulator requires it, and summary findings are shared with the client on request.

Data location

Stored where the contract says

Personal data is stored only in the contractually agreed geography and is not accessed from outside it, other than where strictly necessary for support and under the same protections.

Support access

No plain-text browsing

Measures are in place designed to prevent personal data from being readable in plain text for support or maintenance purposes, by our staff or by subcontractors.

People

Confidentiality, training, inventories

Everyone with access is bound by confidentiality and trained on handling personal data, including how to handle access requests from public authorities. We maintain an inventory of the systems that process personal data and of who is authorised to access them.

When something happens
Incident notification

Within a defined, short window

On becoming aware of, or reasonably suspecting, a personal data breach, the agreement provides for breach notification within a defined, short window, typically 24 hours, with enough detail to meet the client's own reporting obligations, followed up as more becomes known. That is well inside the statutory window a controller has.

Data subject requests

Passed on promptly

The agreement provides for participant requests to reach the client within a short defined period, typically five business days, with our assistance in answering them.

Authority requests

Notified, reviewed, challenged where appropriate

Requests for disclosure from public authorities are notified to the client where legally permitted, reviewed for lawfulness, and challenged where there are reasonable grounds to consider them unlawful.

End of engagement

Deleted or returned on a defined timeline

At the client's choice, the agreement provides for secure erasure or return within a defined period, typically 90 days of the end of processing, with written certification that it has been done.

Audit

Documentation, inspections, cooperation

Clients can request the information needed to demonstrate compliance and audit the systems and premises where their data is processed. Findings are remediated on notice.

Certification

ISO/IEC 27001: in progress, stated honestly

We are implementing an information security management system aligned with ISO/IEC 27001, with certification as the stated goal. The certificate goes on this page when we hold it, and not a day before.

Roles and contracts
GDPR roles

You are the controller. We are the processor.

The brand decides purpose and means; we process on documented instructions. Where we act as controller, for example for the contact data of your project team, we say so in the contract rather than leaving it open.

Data processing agreement

Art. 28 GDPR, signed before any data flows

Our standard agreement covers processing purposes, data categories, retention, technical and organisational measures, subprocessors and audit rights. Your legal team reviews it before onboarding, not after launch.

International transfers

Standard contractual clauses and country annexes

Module 2 controller-to-processor clauses are part of the agreement, with the UK addendum where UK data is involved and separate country annexes for markets such as Switzerland and Türkiye that apply their own regimes.

Subprocessors

Named, vetted, contractually bound

Subprocessors are listed in the agreement and engaged only with your prior consent. Each one is assessed before engagement and bound by terms at least as protective as ours. We remain responsible to the client for their engagement, on the terms set out in our agreement.

Compliance, market by market

The legal framework behind 41 markets

Rules

Rules in 41 markets

Which mechanics are allowed where, which permits are required, and how the rules differ. Rules by market →

Coordination

How compliance scales

Terms, permits, taxes and winner obligations, organised per market. Independent licensed attorneys advise; Competence Alliance coordinates. Legal compliance →

Operations

The operating record

Results

The numbers, stated as estimates

468 campaigns, ~12M consumers, ~€3M cashback paid out. See the numbers →

Proof

Case studies

Mechanics, markets and outcomes from delivered campaigns. Case studies →

Reach

41 European markets

One operating model across the map. Market coverage →

Frequently asked questions

What is the Evidence Centre for?

It lists the major claims made on this site together with the evidence behind each one: benchmarks, documents and processes. Nothing has to be taken on trust alone.

Which documents are available on request?

The data processing agreement, the technical and organisational measures, the incident process and the validation benchmark. They are shared on request, under NDA where a brand requires it.

How is the 95.5 per cent figure measured, and what does it mean?

It comes from a documented benchmark of 5,000 receipts and describes the share decided automatically, not an accuracy rate. The remaining 4.5% are flagged as uncertain by the trust score and decided by a person before any payout. No submission is rejected because the system was unsure. Because uncertain cases are decided by a person before payout, the accuracy of the final decision is close to 100%.

Send us your security questionnaire.

We would rather answer it before the campaign than during it. Data processing agreement, measures annex and subprocessor list are available on request.

Start the review