Analyse Games logoAnalyseGames
Pricing
Sign inGet started
Legal

Data Processing Addendum

The Article 28 GDPR terms for the player data your games send us, where you are controller and we are processor.

Last updated September 15, 2026

On this page
  1. 1. Definitions
  2. 2. Roles
  3. 3. Your instructions
  4. 4. Confidentiality
  5. 5. Security
  6. 6. Subprocessors
  7. 7. International transfers
  8. 8. Helping you with data subject requests
  9. 9. Personal data breaches
  10. 10. Other help we give you
  11. 11. Retention while the Service runs
  12. 12. Deleting or returning data at the end
  13. 13. Audits and information
  14. 14. Liability and precedence
  15. Annex I: Details of the processing
  16. Annex II: Technical and organisational measures

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Customer", "you") and Breukers Willem Albertus E.E., trading as VertCode Development, which provides Analyse Games ("Analyse Games", "we"). It applies to the personal data we process on your behalf when your games, servers, stores and integrations send data to Analyse Games, and it meets the requirements of Article 28(3) of the EU General Data Protection Regulation (GDPR).

It takes effect automatically when you accept the Terms, with no signature needed. If you need a countersigned copy for your records, write to [email protected].

1. Definitions

Words defined in the GDPR, such as "controller", "processor", "personal data", "processing", "data subject", "personal data breach" and "supervisory authority", have the same meaning here. In addition:

  • Customer Personal Data means personal data in Customer Data (as defined in the Terms) that we process on your behalf, mainly player data.
  • Subprocessor means another processor we engage to process Customer Personal Data.
  • Data Protection Law means the GDPR, Greek Law 4624/2019 and any other data protection law of the EU or its member states that applies to the processing.
  • SCCs means the standard contractual clauses for international transfers adopted by the European Commission in Implementing Decision (EU) 2021/914.

2. Roles

  • You are the controller of Customer Personal Data, or a processor acting for another controller (for example a studio you work for). We are your processor, or your subprocessor in that case.
  • You decide which games send data, which events and properties they include, which integrations are connected and who on your team can see what. You are responsible for the lawfulness of the processing, for having a legal basis, and for giving your players the information Articles 13 and 14 GDPR require.
  • For the personal data of your own team members that we need to run your account, we are a separate controller, as described in our Privacy Policy.

3. Your instructions

  • We process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless EU or member state law requires otherwise. In that case we tell you before processing, unless that law forbids it on important grounds of public interest.
  • Your instructions are: these Terms and this DPA; your configuration of the Service (games, SDKs, integrations, retention settings, team access, alerts, MCP connections); and any further written instructions you give us that are consistent with the Terms.
  • We tell you straight away if we believe an instruction infringes Data Protection Law.

4. Confidentiality

Everyone at Analyse Games and at our Subprocessors who can access Customer Personal Data is bound by a contractual or statutory duty of confidentiality, and only accesses it as needed to provide, secure and support the Service.

5. Security

We implement the technical and organisational measures in Annex II to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. We may update these measures as technology develops, as long as the overall level of security is not reduced.

6. Subprocessors

  • You give us general written authorisation to engage Subprocessors. The current list is on our Subprocessors page, which forms part of this DPA.
  • We inform you of any intended addition or replacement of a Subprocessor at least 30 days in advance, by email to account owners and by updating the Subprocessors page.
  • You can object on reasonable data protection grounds within those 30 days. We will then discuss it with you in good faith. If we can't resolve the objection, you can end the affected part of the Service before the change applies, and we refund any prepaid fees for the time after it ends.
  • We impose on each Subprocessor, by written contract, data protection obligations that are the same as, or at least as protective as, those in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. We remain fully responsible to you for our Subprocessors' performance.

7. International transfers

  • We store and process Customer Personal Data in the European Union.
  • We only transfer Customer Personal Data to a country outside the European Economic Area, or allow access from one, where a valid transfer mechanism under Chapter V GDPR applies: an adequacy decision (including the EU-US Data Privacy Framework for certified recipients), or the SCCs, Module 3 (processor to processor), entered into with the Subprocessor, together with a transfer impact assessment and supplementary measures where needed.
  • If you are established outside the EEA, the transfer of Customer Personal Data from us back to you is covered by the SCCs, Module 4 (processor to controller), which are incorporated by reference, to the extent the GDPR applies to that transfer. For those SCCs: clause 7 (docking) applies; clause 17 is governed by Greek law; clause 18 designates the courts of Athens, Greece; and the Annexes are completed with the information in Annex I and II of this DPA.

8. Helping you with data subject requests

  • Taking into account the nature of the processing, we help you with appropriate technical and organisational measures to respond to requests from players and other data subjects exercising their rights under Chapter III GDPR.
  • You can look up a player, and export their data where your Plan includes exports, in the dashboard. To erase all data about a player, write to [email protected] with the game and the player identifier. We delete that player's records from every table that holds a player identifier within 14 days and confirm when done. Aggregated counts that cannot identify the player (for example, how many unique players were online on a day) are kept.
  • If a data subject contacts us directly about Customer Personal Data, we pass the request to you without undue delay and don't respond ourselves, except to tell them we have done so.

9. Personal data breaches

  • We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
  • The notice goes to the account owners' email addresses and describes, as far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we can't provide all of this at once, we provide it in phases without undue delay.
  • We take reasonable steps to contain and investigate the breach, and help you meet your obligations under Articles 33 and 34 GDPR.

10. Other help we give you

We give you reasonable help, taking into account the nature of the processing and the information available to us, with data protection impact assessments and prior consultations with supervisory authorities (Articles 35 and 36 GDPR). The information on this page, the Subprocessors page and our Security page will usually be sufficient.

11. Retention while the Service runs

Unless you delete data sooner, Customer Personal Data is kept in the Service as follows:

DataDefault retention
Raw events (joins, leaves, custom events and properties)400 days from the event
Session records13 months
Daily aggregates per player and per game25 months
Players online per minute90 days
Player profiles, purchases, subscriptions and experiment assignmentsWhile the game exists in your account

How much history the dashboard shows depends on your Plan. Data outside that window is kept for the periods above, not deleted, unless you delete it.

12. Deleting or returning data at the end

  • When you delete a game, or when the Service ends for your account, you can first export Customer Personal Data as described in section 19 of the Terms.
  • After the end of the Service, and after any data retrieval period under section 19 of the Terms, we delete all Customer Personal Data, including copies, within 30 days, and from backups within 90 further days, unless EU or member state law requires us to keep it. We confirm deletion in writing on request.
  • Where you delete an individual game, its Customer Personal Data is deleted within 30 days.

13. Audits and information

  • We make available to you all information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the Subprocessors page, our Security page and, on request, our records of processing for your account and any relevant certifications or audit reports of our Subprocessors.
  • If that information is not enough, or a supervisory authority requires it, you may audit our compliance, including by inspection, once per year (or more often after a personal data breach), with at least 30 days' written notice, during business hours, without unreasonable disruption and under confidentiality. You can appoint an independent auditor who is not our competitor. Each party bears its own costs, unless the audit reveals a material breach of this DPA by us.

14. Liability and precedence

  • Each party's liability under this DPA is governed by the liability section of the Terms, except where Article 82 GDPR does not allow such a limitation towards data subjects.
  • If this DPA conflicts with the Terms, this DPA prevails for anything relating to the processing of personal data. If the SCCs apply and conflict with this DPA, the SCCs prevail.
  • This DPA stays in effect as long as we process Customer Personal Data for you. It is governed by Greek law, and the courts of Athens have jurisdiction, subject to the rights of data subjects and supervisory authorities.

Annex I: Details of the processing

Subject matter and duration. Providing the Analyse Games analytics Service to you, for the duration of the Terms and the deletion period in section 12.

Nature of the processing. Collection through SDKs, plugins, modules and store webhooks; storage; aggregation and analysis; attribution of players to campaigns, links and creator codes; assignment of players to experiment variants; display in dashboards and exports; answering questions through Ask Analyse and the MCP server; sending alerts and digests you configure; deletion.

Purposes. To give you analytics about players, sessions, retention, revenue, acquisition, campaigns and experiments for your games, as configured by you.

Categories of data subjects.

  • Players of your games, servers, networks and experiences.
  • Buyers in stores you connect (such as Tebex or PayNow), where purchases are linked to a player.
  • Creators or partners whose creator codes or tracking links you record.

Categories of personal data.

  • Player identifiers: platform ID (such as a Minecraft UUID or Roblox UserId), or an anonymous identifier your SDK generates.
  • Display name, as sent by your game.
  • Country, derived from the player's IP address at the time they join. The IP address is sent to our IP lookup Subprocessor to find the country and is not stored; it is held only as a one-way hash in memory for up to one hour to avoid repeat lookups.
  • Session data: join and leave times, playtime, server or instance and deployment, integration version.
  • Events and custom properties that your game sends, including values, items and tags.
  • Purchases and subscriptions from connected stores: transaction ID, item, quantity, amount, currency, coupon, status (completed, refunded, chargeback), subscription period and status, creator code.
  • Acquisition data: how the player arrived (hostname, tracking link, referral, campaign, creator code).
  • Experiment assignments and outcomes.
  • Segments and tags you apply to players in the Service.
  • Questions and answers in Ask Analyse and knowledge base pages, to the extent they contain player data.

Special categories of data. None. You must not send special categories of personal data, or data about criminal convictions, to the Service.

Frequency of transfer. Continuous, as your games send data.

Subprocessors. As listed on the Subprocessors page, for the processing described there.

Annex II: Technical and organisational measures

Encryption and secrets

  • All traffic between players' servers, browsers and our services uses TLS (HTTPS). Strict Transport Security is enabled on analyse.net.
  • Connections to our databases use TLS, over a private network between our servers.
  • Store credentials, webhook secrets, Discord webhook URLs and two-factor secrets are encrypted at rest with AES-256-GCM.
  • Passwords are hashed with Argon2. Session tokens, ingest keys, MCP tokens and OAuth codes are stored only as hashes.

Access control

  • Customer access is role-based (owner, admin, analyst, creator) and can be limited to specific games. Ingest keys only allow sending data for one game or studio.
  • Two-factor authentication with authenticator apps and passkeys, trusted-device limits, session listing and revocation.
  • MCP apps get read-only tools, limited to the games and tools the customer approves, and can be revoked at any time.
  • Staff access to production systems is limited to the founders, protected by SSH keys and two-factor authentication, and granted only as needed.

Separation

  • Every record carries the customer's game or studio identifier, and every query is scoped to what the requesting user or token may access.
  • Customer Data is never used to train AI models or to inform another customer's results.

Availability and resilience

  • Replicated database clusters. Backups every 6 hours, kept for 3 months in Hetzner object storage in the EU.
  • Ingest deduplication and retry, rate limiting and request size limits.

Monitoring and incident response

  • Structured logging of errors and security-relevant events, retained for 30 days.
  • A documented process for handling personal data breaches, including the notice commitment in section 9.

Secure development

  • Code review, dependency updates, input validation on every API, security headers on the web app.
  • A responsible disclosure policy for security researchers.

Data minimisation

  • IP addresses of players are not stored. Deletion of individual players on request, and automatic expiry of raw data under section 11.

Other legal pages

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Subprocessors
  • Refunds and Withdrawal
  • AI and Your Data
  • Security
  • Accessibility Statement
  • Imprint
Breukers Willem Albertus E.E.Valaoritou 1, TK 10671 Athens, Greece
GEMI
186520701000
VAT
802973201
Tax office
KEFODE Attikis
Product
FeaturesPricingDocsDownloadsChangelog
Legal
Terms of ServicePrivacy PolicyCookie PolicyRefund PolicyImprintAccessibility
Data protection
Processing AgreementSubprocessorsAI and your dataSecurityContact[email protected]
Tax, consumer rights and data protection

VATPrices exclude VAT. It is charged at your local rate on consumer sales in the EU. Reverse charge applies to VAT-registered businesses outside Greece.

Right of withdrawalConsumers in the EU can withdraw within 14 days of buying a plan. If you asked for it to start straight away, you only pay for the days you used.

Your dataWe are controller for your account and processor for the player data you send us. The Privacy Policy sets out your GDPR rights, our legal bases and retention periods; the DPA and Subprocessors list cover processing on your behalf.

Where and whoStored in the EU. Reach us at [email protected], or complain to the Hellenic Data Protection Authority.

© 2026 Breukers Willem Albertus E.E., trading as VertCode Development · Analyse GamesData stored in the EU