Legal information
Data processing agreement
This English version is a translation provided for convenience. In case of discrepancy, the French version prevails.
This data processing agreement (the “Agreement”) is entered into between:
- the customer subscribing to the SuperMDT service for an organization, acting as controller (the “Controller”);
- [TO COMPLETE: company name, legal form, registered office, registration], publisher of SuperMDT, acting as processor (the “Processor”).
It is annexed to and forms an integral part of the terms of sale (the “Terms of Sale”). It is accepted at subscription and also applies during the free trial. In case of conflict between the Agreement and the Terms of Sale regarding data protection, the Agreement prevails. The terms “personal data”, “processing”, “controller”, “processor” and “personal data breach” have the meaning given by Regulation (EU) 2016/679 (the “GDPR”).
1. Purpose
The Agreement sets out the conditions under which the Processor processes, on behalf of the Controller, the personal data needed to provide the SuperMDT service (the “Service”), in accordance with article 28 GDPR.
2. Description of the processing
- Nature and purpose: hosting, storage, organization, consultation, provision and deletion of the organization’s data, in order to provide the Service: intranet and mobile data terminal (MDT) for the fictional public services of a roleplay game server, connection with the game server and with Discord.
- Duration: the term of the contract, then the read-only period (14 days) and archiving period (90 days) provided in the Terms of Sale, until the data is deleted.
- Data subjects: the organization’s members; the players of the Controller’s game server whose data is sent by the bridge; any real person whose data would be entered by the Controller or its members, despite the prohibition in the Terms of Use.
- Categories of data:
- members’ Discord identity (ID, username, display name, avatar);
- members’ organizational data (service, rank, badge number, assignments, duty sessions, absences, sanctions, fictional pay, notes);
- players’ game identifiers (FiveM identifiers, Rockstar license, character ID) and their characters’ data;
- in-game positions, held in memory for the live map and never stored in the database;
- audit log (author, action, item, date and time);
- roleplay content (profiles, records, reports, files, photos, documents), which concerns fictional characters.
- Sensitive data: the Service is not intended to process the special categories of data under article 9 GDPR or data relating to criminal convictions of real people. The Service’s medical files and criminal records exclusively concern fictional characters. The Controller shall not enter real data in them.
3. Processor obligations
The Processor undertakes to:
- process the data only on documented instructions from the Controller, including with regard to transfers outside the European Union. Instructions consist of the Agreement, the Terms of Sale and the configuration of the Service made by the Controller and its authorized members. If the Processor considers that an instruction infringes data protection law, it immediately informs the Controller;
- ensure the confidentiality of the data and that persons authorized to process it are bound by confidentiality;
- implement the security measures described in annex 2, and update them to maintain at least an equivalent level of security;
- respect the conditions for engaging other processors set out in section 5;
- assist the Controller, through appropriate technical and organizational measures and insofar as possible, in responding to data subjects’ requests (access, rectification, erasure, restriction, portability, objection). For this purpose the Service provides tools to view, edit, archive, purge and export data. If a data subject contacts the Processor directly, it forwards the request to the Controller without responding itself, unless instructed otherwise;
- assist the Controller in ensuring compliance with its obligations regarding security, breach notification, impact assessments and prior consultation, taking into account the nature of the processing and the information available to it;
- at the end of the contract, delete or return the data in accordance with section 7;
- make available to the Controller the information necessary to demonstrate compliance with its obligations and allow audits under section 8;
- keep a record of the categories of processing activities carried out on behalf of the Controller (article 30.2 GDPR).
4. Controller obligations
The Controller:
- provides the Processor with the necessary data and instructions, and ensures that the processing it decides on is lawful (legal basis, information of data subjects, in particular its members and its server’s players);
- sets the retention periods for its organization’s data and uses the Service’s tools (archiving, purge, record expungement, export) to apply them;
- configures its members’ permissions and ensures compliance with the Terms of Use, in particular the prohibition on entering real data in game content;
- responds to data subjects’ requests, with the Processor’s assistance.
5. Sub-processors
5.1. The Controller gives the Processor general authorization to engage the sub-processors listed in annex 1.
5.2. The Processor informs the Controller of any intended addition or replacement, by notification in the Service or by message, at least thirty (30) days in advance. The Controller may object on reasonable data protection grounds within that period. Failing agreement, it may terminate the contract free of charge before the change takes effect, and the paid share of the unperformed period is refunded.
5.3. The Processor imposes on each sub-processor, by contract, data protection obligations at least equivalent to those of the Agreement. It remains fully liable to the Controller for their performance.
6. Personal data breaches
The Processor notifies the Controller of any personal data breach affecting it without undue delay, and no later than [TO COMPLETE: deadline, for example 48 hours] after becoming aware of it, by message to the organization’s owner. The notification contains, insofar as they are known, the information required by article 33.3 GDPR (nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, measures taken or proposed, point of contact), supplemented as it becomes available. It is for the Controller to notify, where applicable, the supervisory authority and data subjects; the Processor assists it.
7. End of contract: return and deletion
7.1. Throughout the contract, then during the read-only and archiving periods, the Controller can obtain a full, free export of its data in a structured, commonly used format (JSON, CSV).
7.2. At the end of the contract, the data becomes read-only for 14 days, is archived for 90 days, then is permanently deleted, with backup copies erased as they rotate within a maximum of [TO COMPLETE: backup rotation period]. The Controller may request early deletion in writing. The Processor confirms deletion on request.
7.3. The Processor keeps no copy, except where required by law; data so kept remains protected by the Agreement.
8. Audits
On written request, the Processor makes available to the Controller the documentation demonstrating compliance with the Agreement (description of security measures, list of sub-processors, their certifications). If this documentation is insufficient, the Controller may have an audit carried out, at its own expense, no more than once a year except in case of a proven breach, by an independent auditor bound by confidentiality, with thirty (30) days’ notice, without disrupting the Service or affecting other customers’ data.
9. Transfers outside the European Union
The Controller’s data is hosted in France. Where a sub-processor is established or accesses data outside the European Economic Area, the transfer is covered by an adequacy decision (in particular the EU–US Data Privacy Framework for certified companies) or by the European Commission’s standard contractual clauses, supplemented where necessary by additional measures.
10. Liability and term
Each party is liable for damage caused by a breach of its obligations under the GDPR, under article 82 GDPR and the Terms of Sale. The Agreement takes effect when the organization is created and remains in force as long as the Processor processes data on behalf of the Controller.
Annex 1: sub-processors
| Sub-processor | Processing | Location | Safeguards |
|---|---|---|---|
| OVH SAS, 2 rue Kellermann, 59100 Roubaix, France | Hosting (virtual private server) of the application, database and backups | France | European Union |
| Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, United States | Object storage of photos and files (Cloudflare R2), once in service | [TO COMPLETE: storage region] | [TO COMPLETE: DPF / standard contractual clauses] |
| Discord Inc., 444 De Haro Street, Suite 200, San Francisco, CA 94107, United States | Member sign-in; sending messages and roles managed by the organization’s bot, when the Controller enables the Discord integration | United States | [TO COMPLETE: DPF / standard contractual clauses] |
Stripe processes the customer’s billing data on behalf of the Publisher (which is the controller for it) and does not access the organization’s data; it is therefore not on this list.
Annex 2: technical and organizational measures
- Encryption in transit: all exchanges with the Service and the bridge use HTTPS (TLS).
- Encryption at rest: [TO COMPLETE: server disk and backup encryption]
- Customer isolation: every record carries its organization’s identifier; every read and write goes through centralized access checks that verify membership of the organization; every server function is covered by an automated test proving that another organization cannot access it.
- Authentication: sign-in through Discord (OAuth2, “identify” scope), with no password stored by the Service; time-limited session tokens; bridge key specific to each organization, revocable.
- Access control: fine-grained permissions per service and rank, defined by the Controller; Publisher staff access limited to what is strictly necessary (support, security) and logged.
- Traceability: audit log of sensitive actions, available to the Controller.
- Integrity and availability: soft deletion (archives and restoration), purge reserved for the owner; backups [TO COMPLETE: frequency, retention, location, restore testing].
- Minimization: in-game positions held in memory and never stored; minimal Discord scope; Discord sending logs and read notifications automatically purged after 30 days.
- Application security: server-side validation of all input, rate limits and caps on data sent by the game, regular security updates.
- Organization: [TO COMPLETE: authorized staff, confidentiality undertakings, incident management procedure]