Data Processing Agreement

Last updated: 3 August 2026. This DPA forms part of the Asobi Cloud Terms of Service and applies automatically when you use Asobi Cloud. You (the customer) are the controller of your players' personal data; the processor is Widgrens IT AB, org.nr 559241-2752, Melongatan 15, 754 49 Uppsala, Sweden. VAT no. SE559241275201. If you need a countersigned copy, email dpa@asobi.dev.

Scope and duration

We process player personal data solely to run your game backend, for as long as your subscription lasts plus the wind-down period below. Categories:

  • Player accounts, sessions, and identifiers.
  • Match state, chat, voting, and presence data.
  • Wallet / inventory / IAP receipt metadata (not payment card data - IAP is via platform stores; no card data touches Asobi).
  • Aggregated telemetry we need to run the service.

Your own account and billing data is not covered here: for it we (and Paddle, as merchant of record) act as independent controllers - see the privacy policy.

Instructions

We process player data only on your documented instructions - operating the service as configured by you is the standing instruction - and we tell you if an instruction looks unlawful. Personnel with access are bound by confidentiality.

Sub-processors

You authorise the sub-processors below. Any addition will be notified in advance with an objection window.

  • Hetzner Online (Germany) - compute and S3-compatible object storage; our database runs on this compute (self-managed, no third-party database service).
  • Equivalent EU provider (Germany, Finland) - fallback compute region if required for capacity.
  • Apple / Google (US) - only for in-app purchase receipt validation at the platforms that run your game. This is a lawful necessity for validating purchases; no player PII leaves the EU through this path beyond what Apple/Google already hold for their own billing.

Location

All regular processing in the EU. Primary region: Hetzner, Germany. Backups remain in the EU.

Security

  • TLS 1.2+ in transit.
  • At-rest encryption for Postgres and object storage.
  • Role-based access for operators; all access logged.
  • Erlang/OTP process isolation - one crashed match cannot read another match's state.
  • Personal data is kept out of operational logs by design; log streams have bounded retention.
  • Breach notification: without undue delay and within 72 hours of discovery, per GDPR Art. 33.

Assistance and audits

We assist you with data-subject requests (export and erasure of a player's data on your instruction) and with your GDPR Art. 32-36 obligations. We make available the information needed to demonstrate compliance and allow audits, normally satisfied by documentation; on-site audits are by arrangement, at your cost, no more than annually unless a breach occurred.

Data export and deletion

  • Player-level export and erasure on request (forwarded from controller to processor).
  • Account-level: at end of contract, data is returned in a portable format and deleted within 30 days.

Liability

Each party is liable towards data subjects as allocated by Article 82 GDPR: we are liable for damage caused by processing only where we have not complied with GDPR obligations specifically directed to processors, or where we have acted outside or contrary to your lawful documented instructions. Between the parties, the liability provisions of the Cloud Terms of Service apply to this DPA, except that neither party's liability is limited towards data subjects where the GDPR does not permit it.

Standard Contractual Clauses

Where any transfer to a non-adequate country would occur (currently limited to IAP receipt validation, which is initiated by the platforms themselves), we rely on the EU Commission's SCCs per Decision 2021/914.