Studio Data Processing Terms
Last updated: July 30, 2026
These Data Processing Terms ("DPT") apply when a game we build for you under our Studio Services Terms collects personal data from your attendees, players or customers. They form part of that agreement.
They exist because a booth game that captures an email address is processing personal data, and the law requires the two of us to write down who is responsible for what. This document is that record. It is drafted to satisfy Article 28 of the UK and EU GDPR, and to work alongside US state privacy laws including the CCPA as amended.
1. Who is who
You are the controller. You decide that the data is collected, why, and what happens to it afterwards. The attendee list is yours.
We are the processor. We collect and hold the data only to run the game and hand the results to you. We do not decide what the data is for, we do not use it for our own purposes, and we do not sell or share it.
Under the CCPA we act as your service provider. We do not "sell" or "share" personal information as those terms are defined, and we do not use it for cross-context behavioural advertising.
2. What gets processed
| Categories of data subject | Your event attendees, visitors and players |
| Categories of personal data | Typically an email address and a display name or handle, plus a game score and timestamp. Whatever else your quote specifies, and nothing more. |
| Special category data | None. Our games are not designed to collect health, biometric, racial, political, religious, genetic, sexual-orientation or trade-union data, and you must not configure them to. |
| Children's data | None. Our games are not designed for and must not be directed at children under 13, or under 16 where local law sets that threshold. |
| Nature of processing | Collection through the game interface, storage, generating a leaderboard, and export to you |
| Purpose | Operating the game and delivering the collected data to you. Nothing else. |
| Duration | The hosting term stated in your quote, then deletion under section 7 |
If your project needs to collect anything beyond the above, it has to be agreed in writing in advance, and we may decline.
3. Our obligations
We will process personal data only on your documented instructions, which means the game as configured in your accepted quote plus anything you later ask for in writing. If we believe an instruction breaks data protection law, we will tell you and may pause that processing.
We will not use attendee personal data to train models, to build our own marketing lists, to enrich our own records, or for any purpose of our own.
We will keep processing confidential, and make sure anyone who touches the data is bound by confidentiality and has been told what the rules are. We will limit access to the people who actually need it to deliver your project.
We will help you, at your cost where the effort is significant, to respond to data subject requests, to complete a data protection impact assessment, and to deal with a regulator.
4. Your obligations
You are responsible for having a lawful basis for the collection, and for telling attendees what is happening. In practice that means the game must show, at or before the point of collection, who is collecting the data, what it will be used for, and a link to your privacy notice. We will build that into the game, but the wording and the legal basis are yours.
If you are running a prize draw or contest, the rules, eligibility, and any registration your jurisdiction requires are yours too.
You must not use the game to collect special category data, children's data, or anything outside section 2.
5. Security
We apply security measures appropriate to the risk, including: encryption in transit using current TLS; encryption at rest for stored data; access control on a least-privilege basis with individual credentials and multi-factor authentication on administrative access; logically separated storage per project; logging of administrative access; and deletion routines as described below.
We will not pretend to hold certifications we do not have. If your procurement process requires a specific standard, audit report or insurance position, ask before you accept a quote and we will tell you plainly what we can and cannot evidence.
6. Sub-processors
We use a small number of infrastructure providers to host and deliver the game. At the date above these are:
| Sub-processor | Role | Location |
|---|---|---|
| Cloudflare, Inc. | Application hosting, edge delivery, database and object storage | Global edge, primary storage in the United States |
| Stripe, Inc. | Payment processing for your fee only. Never attendee data. | United States |
You authorise these sub-processors. We will give you at least 30 days' notice before adding or replacing one that touches attendee data, and if you reasonably object on data protection grounds you may terminate the affected part of the project and receive a refund for work not performed. We remain responsible for our sub-processors' performance.
7. Retention and deletion
We keep attendee personal data for the hosting term in your quote, so that the leaderboard works during and after your event.
We delete it on the earliest of: your written request, which we action within 30 days; 30 days after the end of the hosting term; or termination of the project.
You can export the data at any time during the hosting term. Please do export it, because deletion is deletion. Backups containing the data age out within 35 days of deletion, after which no copy remains.
If the law requires us to keep something, we will tell you what and why.
8. International transfers
Our infrastructure is primarily in the United States and delivered through a global edge network, so personal data may be transferred outside the UK and EEA.
Where we transfer personal data out of the UK or EEA, we rely on the European Commission's Standard Contractual Clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum, which are incorporated into these terms by reference. Where those clauses require a choice, the governing law is Ireland for the EU SCCs and England and Wales for the UK Addendum, and the data exporter is you.
If you need the clauses as a separate signed document, ask us and we will provide them.
9. Personal data breach
If we become aware of a personal data breach affecting your attendee data, we will notify you without undue delay and in any event within 48 hours, by email to the contact on your project, with what we know at the time: what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it.
We will keep you updated as we learn more, and we will help you meet your own notification obligations to regulators and data subjects. We will not notify your regulator or your attendees on your behalf unless you ask us to in writing.
10. Audit
On reasonable written notice, and no more than once a year unless a breach or a regulator prompts it, we will provide the information you reasonably need to confirm we are meeting these terms. Where a questionnaire or document will do the job, we will start there rather than an on-site audit.
11. Return and end of processing
At the end of the project we will, at your choice, return the attendee data to you in a common machine-readable format, or delete it. If you do not tell us which within 30 days of the hosting term ending, we delete it.
12. Precedence and changes
If these terms conflict with the Studio Services Terms or our general Privacy Policy on the processing of attendee personal data, these terms control.
If you and we sign a separate data processing agreement, that signed agreement controls.
We may update these terms to reflect changes in law or our sub-processors, with the notice in section 6 where sub-processors are involved. The version in force when you accepted your quote governs your project.
Contact
Data protection and privacy: [email protected] Security questions and questionnaires: [email protected] Legal: [email protected]