Data Processing Agreement
Last updated: August 2026 · Forms part of the PlayProbe Terms of Service
Back to Home ←This Data Processing Agreement ("DPA") is entered into between you (the "Controller") and Jakub Gabčo, trading as Drages Studio, Lidická 700/19, 602 00 Brno-Veveří, Czechia, IČO 06831109 (the "Processor", "we"). It applies automatically when you use PlayProbe to collect data from testers or players, and satisfies Article 28(3) of the GDPR. No signature is required; if your organisation needs a countersigned copy, email [email protected].
1. Roles and Scope
When you run a playtest or integrate the PlayProbe Unity SDK into your game, you determine why and how your testers' and players' personal data is processed. You are therefore the controller and we are your processor for that data.
We remain an independent controller for our own account data — your name, email, login records, and billing information — which is covered by our Privacy Policy rather than by this DPA.
2. Subject Matter and Duration
The subject matter is the provision of the PlayProbe playtesting platform. The nature and purpose of the processing is to collect, store, analyse, and present playtest feedback and gameplay telemetry on your behalf. Processing lasts for as long as your account is active, plus the retention periods in section 11.
3. Data and Data Subjects
Categories of data subjects: your playtesters and the players of games you have integrated the SDK into.
| Category | Examples |
|---|---|
| Feedback data | Survey answers, ratings, free-text comments, answer tags |
| Gameplay telemetry | Session duration, frame-rate metrics, in-game position data, custom events, crash reports |
| Technical data | Platform (e.g. Windows, Android), session identifiers, and — with Instant Feedback — a hardware snapshot: OS and version, CPU and GPU model, RAM and video memory, device type and hardware model |
| Media | Screen recordings and Instant Feedback screenshots, where enabled and consented to |
| Account data | Tester email address and display name, where the tester has a PlayProbe account |
PlayProbe is not designed for special categories of data under Article 9. You must not use it to collect health, biometric, political, religious, or similar sensitive data.
4. Processing on Instructions
We process personal data only on your documented instructions, which are given through your configuration and use of the platform and through this DPA. We do not use your testers' or players' personal data for our own purposes, do not sell it, and do not use it to train machine learning models. If we believe an instruction breaches data protection law, we will tell you and may suspend that instruction. Where we are required by EU or Member State law to process data otherwise, we will inform you first unless that law forbids it.
5. Confidentiality
Everyone we authorise to process personal data is bound by an obligation of confidentiality and is granted access only to the extent needed to provide or support the service.
6. Security Measures
We apply the following technical and organisational measures under Article 32:
- Encryption of data in transit (TLS) and at rest.
- Row-level security in the database, so each account can reach only its own records.
- Private storage buckets; recordings and screenshots are reachable only via short-lived signed URLs.
- Access to production systems restricted to the operator and protected by multi-factor authentication.
- Automated backups, with restore procedures maintained by our hosting provider.
- Automatic deletion of recordings and screenshots after 30 days, enforced by a scheduled job.
- Error monitoring and alerting so incidents are detected quickly.
7. Sub-processors
You give general authorisation for us to engage the sub-processors listed below. We have a written agreement with each imposing data protection obligations equivalent to those in this DPA, and we remain fully liable for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | United Kingdom (London) |
| Sentry | Error monitoring | European Union (Germany) |
| Resend | Transactional email to testers | EU / USA |
We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds within that period, you may terminate your subscription and receive a pro-rata refund for the unused term.
8. Data Subject Rights
The platform lets you access, correct, export, and delete your testers' data directly, which will usually be enough to answer a request. If a tester or player contacts us directly about data you control, we will not respond substantively but will forward the request to you without undue delay. Taking into account the nature of the processing, we will provide reasonable assistance with requests you cannot fulfil through the platform, and with your obligations under Articles 32 to 36 including data protection impact assessments.
9. Personal Data Breaches
We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting data we process for you. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Notifying your supervisory authority and affected individuals remains your responsibility as controller.
10. International Transfers
Primary storage is in the United Kingdom, which benefits from a European Commission adequacy decision. Where a sub-processor processes data in the United States, transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses together with supplementary measures such as encryption in transit and at rest.
11. Deletion and Return
You can export or delete your data at any time from within the platform. Screen recordings and Instant Feedback screenshots are deleted automatically 30 days after capture. On termination of your account, we delete personal data processed on your behalf within 30 days, unless we are required by law to keep it. On request before deletion, we will return the data in a machine-readable format.
12. Audits
On reasonable written request, and no more than once a year unless a regulator requires otherwise, we will make available the information necessary to demonstrate compliance with Article 28 and will contribute to audits conducted by you or an independent auditor you appoint. We may satisfy this by providing our own and our sub-processors' documentation and certifications. Audits must be scheduled with reasonable notice, must not unreasonably disrupt the service, and are subject to confidentiality.
13. Your Obligations
As controller, you are responsible for:
- Having a valid lawful basis for the data you collect through PlayProbe.
- Telling your testers and players what you collect and that PlayProbe processes it on your behalf, including naming PlayProbe in your own privacy policy if you ship the Unity SDK.
- Obtaining any consent your jurisdiction requires before enabling the SDK or screen recording.
- Not collecting special-category data or data from children below the applicable age of consent.
- Responding to data subject requests relating to data you control.
14. Liability and Changes
Liability under this DPA is subject to the limitations in the Terms of Service, except where GDPR requires otherwise. If this DPA conflicts with the Terms on a data protection matter, this DPA prevails. We will give notice of material changes to this DPA by email at least 30 days before they take effect.
Contact
For data protection questions or a countersigned copy of this DPA, contact[email protected].