Last updated: 3 August 2026. This DPA forms part of the Asobi Cloud Terms of Service and applies automatically when you use Asobi Cloud. You (the customer) are the controller of your players' personal data; the processor is Widgrens IT AB, org.nr 559241-2752, Melongatan 15, 754 49 Uppsala, Sweden. VAT no. SE559241275201. If you need a countersigned copy, email dpa@asobi.dev.
We process player personal data solely to run your game backend, for as long as your subscription lasts plus the wind-down period below. Categories:
Your own account and billing data is not covered here: for it we (and Paddle, as merchant of record) act as independent controllers - see the privacy policy.
We process player data only on your documented instructions - operating the service as configured by you is the standing instruction - and we tell you if an instruction looks unlawful. Personnel with access are bound by confidentiality.
You authorise the sub-processors below. Any addition will be notified in advance with an objection window.
All regular processing in the EU. Primary region: Hetzner, Germany. Backups remain in the EU.
We assist you with data-subject requests (export and erasure of a player's data on your instruction) and with your GDPR Art. 32-36 obligations. We make available the information needed to demonstrate compliance and allow audits, normally satisfied by documentation; on-site audits are by arrangement, at your cost, no more than annually unless a breach occurred.
Each party is liable towards data subjects as allocated by Article 82 GDPR: we are liable for damage caused by processing only where we have not complied with GDPR obligations specifically directed to processors, or where we have acted outside or contrary to your lawful documented instructions. Between the parties, the liability provisions of the Cloud Terms of Service apply to this DPA, except that neither party's liability is limited towards data subjects where the GDPR does not permit it.
Where any transfer to a non-adequate country would occur (currently limited to IAP receipt validation, which is initiated by the platforms themselves), we rely on the EU Commission's SCCs per Decision 2021/914.