Compliance centre
Everything the platform will refuse to do, and why. If you are trying to work out who is responsible for what before a contract meeting, this is the page to bring.
- Markets in the rule set164
- Rule changes, 12 months37
- Notice before enforcement11 days median
Who is responsible for what
Ours
- Holding the network connection and the contract behind it
- Filing and maintaining sender registrations in your entity name
- Keeping the rule set current for every market on your account
- Stopping anything a local rule would not permit, and naming the rule that stopped it
- Storing consent, message and delivery records in your chosen region
Yours
- Holding a current operating licence in every market you send into
- Collecting consent lawfully and keeping the evidence you point us at
- The content of the message, the offer in it and the terms behind the offer
- Telling us when a licence, entity name or trading style changes
- Deciding what happens to contacts whose consent cannot be evidenced
Flowora Media Ltd supplies messaging infrastructure. We do not operate a gaming site, accept wagers or hold player funds, and nothing on this site is directed at the public.
The rule set, market by market
Six of the entries, in the shape the platform stores them. Every send is evaluated against the row for its destination market before it leaves.
- Basis
- Explicit opt-in, ePrivacy Art. 13
- Sender
- Alphanumeric, pre-registered
- Quiet hours
- 21:00 to 08:00 local
Responsible-play wording required in the body of every marketing message.
- Basis
- Express consent, CASL
- Sender
- Long code or short code
- Quiet hours
- 21:00 to 09:00 local
Sender must identify the licensed entity, not the brand alone, in the first message.
- Basis
- Explicit opt-in, marketing act
- Sender
- Alphanumeric, pre-registered
- Quiet hours
- 20:00 to 09:00 local
Bonus terms may not be abbreviated below a stated minimum in the message body.
- Basis
- Explicit opt-in, GDPR Art. 6
- Sender
- Alphanumeric, registered per brand
- Quiet hours
- 22:00 to 08:00 local
A registered brand name must match the operating licence exactly, not the trading style.
- Basis
- Opt-in, POPIA s.69
- Sender
- Alphanumeric or short code
- Quiet hours
- 20:00 to 08:00 local
Opt-out must be free to the recipient and honoured inside the same working day.
- Basis
- Prior consent, personal data law
- Sender
- Alphanumeric, per-network
- Quiet hours
- 21:00 to 07:00 local
Registration is per network rather than per market, so one refusal does not block the rest.
The remaining 158 entries are in the account console, filterable by region and by rule.
What changed recently
Each revision is dated and kept. Where a change would start refusing something you already send, the affected templates and identities appear in your account while the old rule still applies.
2026-08-14
Portugal
Brand name must match the licence exactly
Two networks began refusing registrations filed under a trading style rather than the licensed brand. Existing identities were unaffected; new filings now validate the name against the licence on file before submission.
2026-07-02
Ontario
The licensed entity has to be named up front
The first message of any sequence must name the licensed entity, not the brand alone. Templates flagged by the check were listed in each affected account eleven days before enforcement began.
2026-05-21
South Africa
Opt-out must be free to the recipient
Premium-rated opt-out paths are no longer accepted. Inbound handling moved to a zero-rated number on every South African route, with no change required on your side.
2026-03-09
Sweden
Quiet hours widened by one hour
The evening window now opens at 21:00 rather than 22:00 local. Held messages release at 08:00 as before, and nothing in flight was dropped when the change took effect.
Audits, attestations and what we can hand you
ISO 27001 certificate
Current scope and statement of applicability, available under a mutual non-disclosure agreement.
SOC 2 Type II report
Issued annually. The most recent covers the twelve months to March and is shared on request.
Penetration test summary
Twice yearly, by an external firm. We share the summary and the remediation state, not the raw findings.
Processor agreement
Our standard data processing terms, including the sub-processor list and the transfer mechanisms behind each one.
Send us the question your legal team asked
The awkward ones are the useful ones. If we cannot answer it we will say so rather than send you a policy document that does not.