Playable

Denmark · owned by Independent (Denmark) · playable.com · 33 vendors

Playable is a self-service gamification platform for marketers, enabling them to create interactive marketing campaigns at scale. The company's platform helps businesses engage audiences, capture zero-party data, and drive measurable results through gamified experiences. Playable was established in Denmark in 2017, initially as Leadfamly, and later rebranded to Playable in 2022.

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 33 sub-vendors.

Insights

Last updated 2026-09-13 · revision 16

33 direct vendors, 345 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Playable exhibits medium-high migration readiness. Key strengths include a cloud-native SaaS platform built on AWS, indicating a modern and flexible architecture. The platform's API-driven nature (REST API & Webhooks) and 50+ native integrations suggest a modular system that can adapt to new environments. A strong foundation of security and governance, evidenced by ISO 27001:2022 and ISAE 3000 Type 2 certifications, would support a secure migration process. The clear and strict EU data residency requirement (AWS Ireland) provides a defined scope for data location during migration. The diverse vendor base (62 services from 7 countries) suggests less reliance on a few critical vendors, potentially offering more flexibility. However, challenges exist: the presence of 'WordPress' in the internal tech stack could indicate legacy components that might complicate a full modernization. The 'Unknown' vendor lock-in risk is a significant concern, as high lock-in could severely impede migration flexibility and increase costs. Managing the complexity of 50+ integrations during a major migration could also be a substantial undertaking. Finally, ongoing regulatory assessments for NIS2 and the ePrivacy Directive could introduce new compliance requirements, potentially adding unforeseen scope and cost to a migration project.

Compliance

8 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

Playable is a cloud SaaS provider serving 650+ enterprise and global brand customers. SOC 2 (particularly Type II) is increasingly expected by enterprise customers — especially those headquartered in the US or UK — as a condition of vendor onboarding. While Playable holds ISO 27001:2022 certification and an ISAE 3000 GDPR report (which serve as European equivalents), SOC 2 is a US-centric framework from the AICPA and is not legally mandated. The risk is Medium because: (1) absence of SOC 2 may create friction in enterprise sales cycles with US-headquartered clients (e.g., Virgin Red's parent Virgin Group has US operations); (2) ISO 27001 and ISAE 3000 are strong substitutes accepted in EU/EEA markets; (3) no legal penalty for non-compliance, but commercial risk exists. Playable's existing certifications substantially address the Trust Service Criteria underlying SOC 2.

Evidence: https://playable.com/iso-gdpr-security/, https://content.playable.com/hubfs/E-guides/English/E-guides%20(PDF)/iso27001-2022-certificate-playable-2025.pdf

GDPR (source) — Compliant

Playable demonstrates a mature, well-documented GDPR compliance posture. They are headquartered in Denmark (EU), making GDPR universally applicable. Critically, they have obtained an independent ISAE 3000 Type 2 assurance report specifically covering GDPR compliance, published a comprehensive and legally detailed Data Processing Agreement (DPA v2.0, March 2026) aligned with Article 28(3) GDPR, restrict all data processing to EU/EEA (with limited UK access under adequacy decision), and have implemented a full suite of technical and organisational measures (TOMs). The risk level is Low because of the strong evidence of active, independently verified compliance rather than self-attestation alone. Residual risk exists around ongoing enforcement evolution (e.g., AI-related data processing, cookie consent), but the overall posture is strong.

Evidence: https://playable.com/iso-gdpr-security/, https://playable.com/playable-dpa-v2/, https://content.playable.com/hubfs/E-guides/English/E-guides%20(PDF)/report-isae-3000-gdpr-fsr-type-2-playable-2025.pdf, https://playable.com/privacy-policy-for-playable-aps/

Danish Marketing Practices Act — Assessment Required

As a Danish company providing marketing technology services, Playable is subject to the Danish Marketing Practices Act (Consolidated Act No. 426 of 3 May 2017, as amended). This Act governs fair marketing practices, including rules on competitions, prize draws, and promotional games — which are core use cases of Playable's platform. Risk is Low for Playable itself as a platform provider (rather than the brand running the campaign), as primary compliance obligations for specific marketing campaigns rest with the Data Controller (Playable's customers). However, Playable should ensure its platform facilitates compliant campaign structures.

Evidence: https://playable.com/playable-dpa-v2/, https://playable.com/terms-and-conditions-v2/, https://www.forbrugerombudsmanden.dk/en/

Financials

Three-year financials

Financial Resilience Score: 6/10

Playable ApS demonstrates several qualitative strengths that support financial resilience, though verified quantitative data was not available in the report. The company operates a SaaS/subscription revenue model, which typically provides recurring, high-margin, and predictable cash flows. Its diversified enterprise customer base spans multiple industries (FMCG, travel, retail, sports, loyalty) and geographies (Denmark, UK, Netherlands, Iceland, Middle East), reducing single-customer and geographic concentration risk. The company has established meaningful competitive moats through 40+ pre-built game types, ISO 27001:2022 certification, and G2 category leadership recognition in gamification (2025-2026). With 650+ brands as customers including Carlsberg, Virgin Red, Arla, and Icelandair, Playable has demonstrated enterprise credibility and switching costs. However, resilience is tempered by exposure to a niche martech category where marketing gamification represents discretionary spend vulnerable to budget cuts during downturns. Competition from broader martech suites (Braze, Klaviyo, Salesforce Marketing Cloud) and point competitors poses ongoing pressure. The 2022-2023 rebrand from Leadfamly to Playable likely absorbed capital, and prior venture funding suggests the company may be scaling with negative EBIT, though this cannot be confirmed without accessing the årsrapport filings.

Key strengths: Diversified enterprise customer base across multiple industries and geographies, SaaS/subscription recurring revenue model, 650+ brands using the platform including blue-chip customers (Carlsberg, Virgin Red, Arla, Icelandair), ISO 27001:2022 certification and GDPR compliance, G2 Leader / Momentum Leader recognition in Gamification category (2025-2026), International footprint across DK, UK, NL, Iceland, Middle East, Product moat with 40+ pre-built game types and integrations

Risk factors: Niche category exposure - marketing gamification is discretionary spend vulnerable to budget cuts, Competition from broader martech/CDP suites (Braze, Klaviyo, Salesforce Marketing Cloud), Competition from point competitors (Justuno, Drimify, Optimove), One-off rebrand costs from Leadfamly to Playable transition (2022-2023), Private-company opacity with limited financial transparency, Potential negative EBIT if scaling on venture capital, Single-product concentration - essentially one gamification SaaS platform

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report