Working draft. This document has not yet been reviewed by a lawyer. Bracketed placeholders are unfilled. Do not rely on it until this banner is removed.
Data Processing Addendum
Version 2026-08-26. Part of the Terms of Service, for Communities whose Members' data is subject to data-protection law (GDPR/UK GDPR and similar).
1. Roles and scope
For Community data (Terms, Section 9) the Community is the controller and [OPERATOR_NAME — the person or future entity operating the Service] is the processor. Subject matter: operating the Service. Duration: while the Community exists plus the deletion window. Nature and purpose: hosting, displaying and acting on game-server administration data at the Community's direction. Data subjects: the Community's players and staff. Categories: player names and platform identifiers, IP addresses, chat and event logs, moderation records, linked Discord identifiers, supporter names/emails/identifiers from the Community's payment providers.
2. Processor obligations
We process Community data only on the Community's documented instructions (using the Service IS the instruction), ensure persons processing it are bound to confidentiality, apply the technical measures described in the Privacy Policy (Section 6), assist the Community — taking into account the nature of processing — with data-subject requests and with its own security and notification obligations, and delete Community data on termination as described in the Privacy Policy (Section 4), unless law requires retention.
3. Subprocessors
The Community authorises the subprocessors listed in the Privacy Policy (Section 5). We will update that list before adding one; continued use after the update is acceptance. Subprocessors are bound by terms no less protective than this DPA.
4. Personal data breach
We will notify the affected Community without undue delay after becoming aware of a personal data breach affecting its Community data, with the information reasonably available to us.
5. Audit and transfers
This DPA and the Privacy Policy constitute the information made available to demonstrate compliance; we will additionally answer reasonable written questions no more than once a year. [TRANSFERS — fill in where the server physically runs and, if EEA/UK Members' data is processed outside those areas, incorporate the applicable Standard Contractual Clauses.]
6. Liability
Liability under this DPA is subject to the limitations in the Terms (Sections 12–13) to the maximum extent permitted by the applicable data-protection law.