Data processing agreement

Last updated: 6 October 2026

This data processing agreement ("DPA") is part of our terms of service. It applies whenever we process personal data of players on behalf of a customer, as required by Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). The customer accepts it by creating an account. Customers who need a signed copy can request one at [privacy contact email, can be the same as email]. If the English and Slovenian versions differ, the Slovenian version prevails.

1. Parties and roles

The customer (the company that publishes games) is the controller. [Company legal name, e.g. Playable Marketing d.o.o.], [Street and number, postcode city, Slovenia] ("we") is the processor. Where these terms conflict with the terms of service on data protection, this DPA prevails.

2. Subject, duration, nature and purpose

  • Subject: hosting and running the customer's published games and measuring their performance.
  • Duration: for as long as the customer uses the service, plus the deletion period in section 9.
  • Nature: collection, storage, aggregation, display and deletion through the service.
  • Purpose: only to provide the service to the customer.

3. Data subjects and categories of data

  • Data subjects: people who play the customer's games ("players").
  • Data: game events with time and score; a random session ID; leaderboard nicknames and scores (only if the player joins a leaderboard); for prize wheels and score rewards a random device ID, the prize or score and the coupon code assigned; if the customer turns on the contact form, the email and (if asked) name and phone the player enters, with the consent text and time.
  • No special categories of data. Camera images in camera mode are processed only on the player's device and never reach us. Apart from the contact form, we don't store players' names, emails or IP addresses with the data above.

4. Our obligations

  • We process the data only on the customer's documented instructions — this DPA, the terms and the settings the customer chooses in the service — including for transfers to third countries, unless EU or Member State law requires otherwise (in which case we inform the customer first, unless the law forbids it).
  • We tell the customer if we believe an instruction infringes data protection law.
  • Everyone authorised to process the data is bound by confidentiality.
  • We take the technical and organisational measures in Annex 1 (Art. 32 GDPR).
  • We help the customer, as far as possible, to answer data subject requests and to meet its obligations under Articles 32–36 GDPR (security, breach notification, impact assessments). Customers can delete leaderboard entries in Analytics and delete whole campaigns with their data at any time.
  • We make available the information needed to show compliance with Article 28 GDPR (see section 10).

5. Customer obligations

  • The customer is responsible for the lawfulness of the processing, for informing players (for example by adding its privacy policy link to each campaign, shown under the game), and for any consent its promotions need.
  • The customer won't use games to collect special categories of data or to target children under 16 without the consent required by law.
  • The customer writes the consent text of its contact forms and is responsible for it. If the customer sets up a webhook, we send each new contact to the address it chooses, on its instruction; the receiving system is the customer's responsibility.

6. Sub-processors

The customer gives general authorisation to use the sub-processors below. We impose the same data protection obligations on them by contract. We will announce intended changes on this page and by email to account owners at least 30 days in advance; the customer may object on reasonable grounds and, if we can't resolve the objection, end the contract before the change takes effect. We remain responsible for our sub-processors.

Sub-processorServiceLocationPlayer data?
Supabase Inc.Database, login, file storageEU data centreYes
Vercel Inc.Hosting and content deliveryServer code in Frankfurt (EU); global delivery networkYes (in transit)
Anthropic PBCAI concept generation from campaign briefsUSANo
Stripe Payments Europe Ltd.Payments and invoicingIrelandNo

7. International transfers

Player data is stored in the EU. Where a sub-processor may access personal data from a third country, the transfer is based on an adequacy decision (including the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses, with supplementary measures where needed.

8. Personal data breaches

We notify the customer without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting its data, with the information the customer needs to meet its own obligations under Articles 33 and 34 GDPR.

9. Deletion at the end

When the customer deletes a campaign or its account, we delete the related personal data; copies in backups are removed when those backups expire under our hosting provider's schedule. This does not apply where the law requires us to keep data. Before deleting, the customer can download its data under Settings → Your data. Independently, player data is deleted automatically 25 months after it was collected.

10. Audits

On request we provide the information needed to demonstrate compliance with this DPA. The customer, or an independent auditor bound by confidentiality, may audit us once a year with 30 days' notice and at its own cost, or at any time after a breach or if a supervisory authority requires it.

11. Liability and law

Liability follows the terms of service, except where the GDPR provides otherwise. This DPA is governed by the law of Slovenia.

Annex 1 — Technical and organisational measures

  • Encryption: all traffic over HTTPS (TLS); databases and backups encrypted at rest.
  • Isolation: every query runs with the user's own rights; row-level security separates workspaces in the database.
  • Access control: passwords stored only as salted hashes; production access limited to authorised staff with two-factor authentication; no shared admin keys in the application.
  • Data minimisation: pseudonymous random IDs instead of personal identifiers; no IP addresses stored with player data; camera images never leave the player's device.
  • Retention: automatic deletion of player data after 25 months and of other records as set out in our privacy policy.
  • Abuse protection: rate limits and server-side validation on all public endpoints.
  • Availability: managed hosting with daily backups.
  • Hardening: security headers, protection against clickjacking on account pages, dependency updates.