Data Processing Agreement

Last updated: August 2026 · Forms part of the PlayProbe Terms of Service

Back to Home ←

This Data Processing Agreement ("DPA") is entered into between you (the "Controller") and Jakub Gabčo, trading as Drages Studio, Lidická 700/19, 602 00 Brno-Veveří, Czechia, IČO 06831109 (the "Processor", "we"). It applies automatically when you use PlayProbe to collect data from testers or players, and satisfies Article 28(3) of the GDPR. No signature is required; if your organisation needs a countersigned copy, email [email protected].

1. Roles and Scope

When you run a playtest or integrate the PlayProbe Unity SDK into your game, you determine why and how your testers' and players' personal data is processed. You are therefore the controller and we are your processor for that data.

We remain an independent controller for our own account data — your name, email, login records, and billing information — which is covered by our Privacy Policy rather than by this DPA.

2. Subject Matter and Duration

The subject matter is the provision of the PlayProbe playtesting platform. The nature and purpose of the processing is to collect, store, analyse, and present playtest feedback and gameplay telemetry on your behalf. Processing lasts for as long as your account is active, plus the retention periods in section 11.

3. Data and Data Subjects

Categories of data subjects: your playtesters and the players of games you have integrated the SDK into.

CategoryExamples
Feedback dataSurvey answers, ratings, free-text comments, answer tags
Gameplay telemetrySession duration, frame-rate metrics, in-game position data, custom events, crash reports
Technical dataPlatform (e.g. Windows, Android), session identifiers, and — with Instant Feedback — a hardware snapshot: OS and version, CPU and GPU model, RAM and video memory, device type and hardware model
MediaScreen recordings and Instant Feedback screenshots, where enabled and consented to
Account dataTester email address and display name, where the tester has a PlayProbe account

PlayProbe is not designed for special categories of data under Article 9. You must not use it to collect health, biometric, political, religious, or similar sensitive data.

4. Processing on Instructions

We process personal data only on your documented instructions, which are given through your configuration and use of the platform and through this DPA. We do not use your testers' or players' personal data for our own purposes, do not sell it, and do not use it to train machine learning models. If we believe an instruction breaches data protection law, we will tell you and may suspend that instruction. Where we are required by EU or Member State law to process data otherwise, we will inform you first unless that law forbids it.

5. Confidentiality

Everyone we authorise to process personal data is bound by an obligation of confidentiality and is granted access only to the extent needed to provide or support the service.

6. Security Measures

We apply the following technical and organisational measures under Article 32:

  • Encryption of data in transit (TLS) and at rest.
  • Row-level security in the database, so each account can reach only its own records.
  • Private storage buckets; recordings and screenshots are reachable only via short-lived signed URLs.
  • Access to production systems restricted to the operator and protected by multi-factor authentication.
  • Automated backups, with restore procedures maintained by our hosting provider.
  • Automatic deletion of recordings and screenshots after 30 days, enforced by a scheduled job.
  • Error monitoring and alerting so incidents are detected quickly.

7. Sub-processors

You give general authorisation for us to engage the sub-processors listed below. We have a written agreement with each imposing data protection obligations equivalent to those in this DPA, and we remain fully liable for their performance.

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageUnited Kingdom (London)
SentryError monitoringEuropean Union (Germany)
ResendTransactional email to testersEU / USA

We will give you at least 30 days' notice by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds within that period, you may terminate your subscription and receive a pro-rata refund for the unused term.

8. Data Subject Rights

The platform lets you access, correct, export, and delete your testers' data directly, which will usually be enough to answer a request. If a tester or player contacts us directly about data you control, we will not respond substantively but will forward the request to you without undue delay. Taking into account the nature of the processing, we will provide reasonable assistance with requests you cannot fulfil through the platform, and with your obligations under Articles 32 to 36 including data protection impact assessments.

9. Personal Data Breaches

We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting data we process for you. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Notifying your supervisory authority and affected individuals remains your responsibility as controller.

10. International Transfers

Primary storage is in the United Kingdom, which benefits from a European Commission adequacy decision. Where a sub-processor processes data in the United States, transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses together with supplementary measures such as encryption in transit and at rest.

11. Deletion and Return

You can export or delete your data at any time from within the platform. Screen recordings and Instant Feedback screenshots are deleted automatically 30 days after capture. On termination of your account, we delete personal data processed on your behalf within 30 days, unless we are required by law to keep it. On request before deletion, we will return the data in a machine-readable format.

12. Audits

On reasonable written request, and no more than once a year unless a regulator requires otherwise, we will make available the information necessary to demonstrate compliance with Article 28 and will contribute to audits conducted by you or an independent auditor you appoint. We may satisfy this by providing our own and our sub-processors' documentation and certifications. Audits must be scheduled with reasonable notice, must not unreasonably disrupt the service, and are subject to confidentiality.

13. Your Obligations

As controller, you are responsible for:

  • Having a valid lawful basis for the data you collect through PlayProbe.
  • Telling your testers and players what you collect and that PlayProbe processes it on your behalf, including naming PlayProbe in your own privacy policy if you ship the Unity SDK.
  • Obtaining any consent your jurisdiction requires before enabling the SDK or screen recording.
  • Not collecting special-category data or data from children below the applicable age of consent.
  • Responding to data subject requests relating to data you control.

14. Liability and Changes

Liability under this DPA is subject to the limitations in the Terms of Service, except where GDPR requires otherwise. If this DPA conflicts with the Terms on a data protection matter, this DPA prevails. We will give notice of material changes to this DPA by email at least 30 days before they take effect.

Contact

For data protection questions or a countersigned copy of this DPA, contact[email protected].