Data processing agreement
This agreement under article 28 of the GDPR and of the UK GDPR applies between you, as the controller of the data of the players of your servers, and 1up-servers, as your processor. It is part of the terms of service, so you accept it when you accept the terms; businesses may ask for a signed copy at soporte@1up-servers.com.
This text has not been reviewed by a professional yet
Draft written by the team. The owner of the service is not incorporated yet, so its identity details are marked as pending, and the document is waiting for the review of a legal adviser before it has contractual value.
1. Subject, duration and data
We host your game servers for as long as the contract lasts. The data concerned are those of the players who join your servers: nicknames, game or Steam ids, IP addresses, connection times and in-game chat. We do not process special categories of data on purpose.
2. Instructions
We process the data only to provide the service and according to your documented instructions, which are these terms and the settings you choose in the panel. We tell you if an instruction appears to break the law.
3. Confidentiality and security
Only staff bound by confidentiality access the data, and only when needed. We apply the security measures described in the privacy policy, including encryption in transit, isolation of each server and access logging.
4. Sub-processors
You authorise the sub-processors on the sub-processors page. We give you notice of any change at least 30 days in advance so you can object, and we bind each sub-processor to the same obligations.
5. Assistance
We help you answer the requests of players exercising their rights, and with security, impact assessments and prior consultations, taking into account the information available to us.
6. Personal data breaches
We notify you without undue delay, and within 48 hours of becoming aware where possible, of any breach affecting the data of your servers, with the information you need to meet your own obligations.
7. Return and deletion
When the contract ends you can download your server files. We then delete the data, including backups, after the retention periods in the privacy policy, unless the law requires us to keep it.
8. Audits and transfers
We make available the information needed to show compliance and allow reasonable audits with prior notice. Transfers outside the EEA rely on the safeguards listed on the sub-processors page, including the standard contractual clauses where applicable.