Legal

Data Processing Agreement

Last updated: August 25, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the Customer and adgamify, and applies whenever adgamify processes Player Data as a processor on the Customer's behalf.

Need a signed copy for your legal team?
This page is the current, always-up-to-date version of our DPA. If you need a countersigned PDF for procurement, request one and we'll send it over.
Request signed PDF

1. Definitions

“Player Data” means personal data submitted by Players through a Customer's published Game, as described in our Privacy Policy. “Controller,” “Processor,” “Sub-processor,” and “Data Subject” have the meanings given under applicable data protection law.

2. Roles of the parties

For Player Data, the Customer is the Controller and adgamify is the Processor. adgamify processes Player Data only on the Customer's documented instructions — which include the game configuration and fields the Customer sets up in the editor — and only for the purpose of providing the platform.

3. Duration

This DPA applies for as long as adgamify processes Player Data on the Customer's behalf, i.e. for the term of the Customer's subscription or Event Pass, and for any post-termination retention period described in our Privacy Policy.

4. adgamify's obligations

  • Process Player Data only on the Customer's instructions, except where required by law;
  • Ensure personnel who process Player Data are subject to confidentiality obligations;
  • Implement the technical and organizational security measures described in Section 6;
  • Engage Sub-processors only under the terms of Section 5;
  • Assist the Customer, to the extent reasonably possible, in responding to Data Subject requests and in meeting its own obligations regarding security, breach notification, and data protection assessments;
  • Notify the Customer without undue delay after becoming aware of a security incident affecting Player Data;
  • At the Customer's choice, delete or return Player Data at the end of the relationship, except where retention is required by law.

5. Sub-processors

The Customer authorizes adgamify to engage the following Sub-processors to help deliver the platform:

Sub-processorPurpose
ClerkAuthentication and account/session management
PayPalPayment processing (does not receive Player Data)
DigitalOceanApplication hosting and Postgres database infrastructure

We will provide reasonable advance notice, such as an update to this page, before adding or replacing a Sub-processor with access to Player Data, so Customers can object on reasonable grounds.

6. Security measures

  • Encryption of data in transit;
  • Access controls limiting who can reach production data, with authentication managed via Clerk;
  • Logical separation of each Customer's data within our Postgres database by workspace;
  • Routine review of access and dependencies as the platform evolves.

7. International transfers

Where Player Data is transferred outside the jurisdiction it was collected in, adgamify will rely on appropriate safeguards, such as standard contractual clauses, to the extent required by applicable law.

8. Audit rights

On reasonable written request, and no more than once per year absent a security incident or regulatory requirement, adgamify will provide the Customer with information reasonably necessary to demonstrate compliance with this DPA.

9. Liability and governing law

Liability under this DPA is governed by the limitation-of-liability terms in our Terms of Service. This DPA is governed by the laws of [GOVERNING LAW JURISDICTION — not yet finalized].

10. Contact

Questions about this DPA, or requests for a signed PDF copy, can be sent to privacy@adgamify.com or via /contact.