1. Introduction and Relationship to the Terms
In short — this DPA governs how we handle the personal data your community puts into the Service, and it forms part of our Terms of Service.
This Data Processing Addendum (the "DPA") forms part of, and is incorporated into, the Terms of Service (the "Terms") between Jack Ryan Brolly, trading as OpsCentre ("we", "us", "our", or "OpsCentre"), and a Community Director (the "Customer", "you", or "your"). It applies where, in operating a community on the Service, you provide personal data that we process on your behalf.
This DPA records the terms on which we process such personal data as your processor, as required by Article 28 of the UK GDPR. It applies in addition to, and does not reduce, the data protection commitments in our Privacy Policy. Capitalised terms not defined here have the meanings given in the Terms.
By subscribing to and using the Service as a Community Director, you agree to this DPA, which takes effect on that basis without the need for a separate signature. Where this DPA conflicts with the rest of the Terms on the subject of data processing, this DPA prevails.
2. Definitions
In short — the key data protection terms used in this DPA.
| Term | Meaning |
|---|---|
| Customer Personal Data | Personal data contained in the Content that we process on your behalf in providing the Service to your community. |
| Controller / Processor / Data Subject / Personal Data / Processing | Have the meanings given in the UK GDPR. |
| UK GDPR | The retained EU law version of the General Data Protection Regulation as it forms part of the law of the United Kingdom, together with the Data Protection Act 2018. |
| Sub-processor | A third party engaged by us to process Customer Personal Data in connection with the Service. |
| Data Protection Law | All laws applicable to the processing of personal data under this DPA, including the UK GDPR and, where applicable, the EU GDPR. |
3. Roles of the Parties
In short — you are the controller of your community's data; we are your processor.
In relation to Customer Personal Data, you are the data controller and we are your data processor. You determine the purposes and means of the processing; we process Customer Personal Data on your behalf in accordance with this DPA.
You are responsible for ensuring that you have a lawful basis to process the Customer Personal Data, that you have provided any privacy information required to the relevant data subjects, and that your instructions to us comply with Data Protection Law. You acknowledge that the Service is intended for fictional, in-character roleplay records, and that our Acceptable Use Policy requires that real personal data about real, identifiable people is not entered into community records. Where you or your Authorised Users nonetheless enter such data, you remain the controller responsible for it.
The subject-matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex 1.
4. Our Processing of Customer Personal Data
In short — we only process your data to run the Service and on your instructions — not for our own purposes.
We will process Customer Personal Data only on your documented instructions, including with regard to transfers, unless required to do otherwise by law (in which case we will, where legally permitted, inform you of that requirement before processing).
Your documented instructions are set out in this DPA, the Terms, and your configuration and use of the Service. The provision of the Service, and any processing initiated by you or your Authorised Users in using the Service, constitute instructions to process Customer Personal Data. We will inform you if, in our opinion, an instruction infringes Data Protection Law, though we are not obliged to carry out a legal review of your instructions.
We will not sell Customer Personal Data, and we will not process it for our own independent purposes.
5. Confidentiality
In short — anyone who handles your data on our side is bound to keep it confidential.
We will ensure that any person authorised to process Customer Personal Data is subject to an appropriate duty of confidentiality, whether a contractual or statutory duty, and that access is limited to those who need it to provide the Service.
6. Security of Processing
In short — we apply appropriate technical and organisational measures to protect your data, described in Annex 2.
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, we will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. A description of these measures is set out in Annex 2.
You acknowledge that the measures in Annex 2 are appropriate for the Service and the nature of the data it is designed to hold, and that we may update them from time to time provided that the updated measures do not materially reduce the overall level of security.
7. Sub-processors
In short — you give us general permission to use trusted providers (listed in Annex 3); we'll tell you before adding new ones, and we remain responsible for them.
You provide general authorisation for us to engage sub-processors to process Customer Personal Data in connection with the Service. This authorisation is given by you when you subscribe to the Service and accept the Terms. Our current sub-processors are listed in Annex 3.
We will impose on each sub-processor data protection obligations that are materially the same as those set out in this DPA, and we remain fully responsible to you for the performance of each sub-processor's obligations.
Where we intend to add or replace a sub-processor, we will update the list in Annex 3 and give you reasonable notice through the Service or by other means. If you have a reasonable objection to a new sub-processor on data protection grounds, you may raise it with us, and we will work with you in good faith to address it; if we cannot, you may, as your sole remedy, terminate your Subscription in respect of the affected processing in accordance with the Terms.
8. International Transfers
In short — if your data is processed outside the UK, we make sure appropriate safeguards are in place.
Some of our sub-processors may process Customer Personal Data outside the United Kingdom. Where we transfer Customer Personal Data outside the United Kingdom, we will ensure that the transfer is subject to appropriate safeguards as required by Data Protection Law, such as a recognised adequacy decision or an approved transfer mechanism (for example, the UK International Data Transfer Agreement or the UK Addendum to the European Commission's Standard Contractual Clauses).
9. Assisting You with Data Subject Requests
In short — if someone exercises their data rights against you, we'll help you respond.
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, to fulfil your obligation to respond to requests from data subjects exercising their rights under Data Protection Law (such as access, rectification, erasure, restriction, portability, and objection).
Where a data subject makes such a request directly to us in respect of Customer Personal Data, we will, where lawful to do so, advise the data subject to contact you and/or inform you of the request, rather than responding to it ourselves, since you are the controller.
10. Personal Data Breaches and Assistance
In short — if there's a breach affecting your data, we'll tell you promptly and help you meet your obligations.
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide you with sufficient information to allow you to meet any obligations to report the breach to a supervisory authority or to notify affected data subjects.
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to you with: the security of processing; the notification of personal data breaches; the carrying out of data protection impact assessments; and prior consultation with a supervisory authority, in each case as required by Data Protection Law.
11. Return and Deletion of Data
In short — when your community ends, we delete your data by default — you can ask for an export first.
On termination or expiry of your Subscription, or otherwise on the ending of the provision of the Service to your community, we will delete the Customer Personal Data we hold on your behalf, save to the extent that we are required to retain a copy by law.
Before deletion, you may request that we provide you with an export of the Customer Personal Data in a commonly used format, provided that you make the request within the period notified by us or otherwise within a reasonable period around the ending of the Service. Exports are prepared by us on request; the Service does not currently include a self-service export facility, and we will use reasonable efforts to provide the export within a reasonable period of your request. After that period, the data will be deleted in the ordinary course.
Deletion may be subject to a short operational delay, and copies may persist temporarily in routine backups, which are cycled and overwritten in the ordinary course. We will not actively process such residual copies and will ensure they are deleted in accordance with our backup cycle. This Section is to be read together with the retention provisions of our Privacy Policy and the Terms.
12. Audit and Information
In short — we'll give you the information you reasonably need to show this DPA is being met.
We will make available to you the information reasonably necessary to demonstrate compliance with our obligations under this DPA and Article 28 of the UK GDPR, and will allow for and contribute to reasonable audits, including inspections, conducted by you or an auditor mandated by you.
To respect the confidentiality, security, and integrity of the Service and of other customers' data, any audit will be subject to reasonable prior notice, will be conducted during normal business hours, will not unreasonably disrupt the Service, and may, where appropriate, be satisfied by our provision of relevant documentation and responses to reasonable information requests. As a small provider, our primary means of demonstrating compliance is the provision of information and documentation.
13. General
In short — the housekeeping: this DPA runs with the Terms, follows the same governing law, and may be updated.
This DPA takes effect when you first subscribe to the Service as a Community Director and continues for as long as we process Customer Personal Data on your behalf. It is governed by the laws of England and Wales and is subject to the same jurisdiction provisions as the Terms.
We may update this DPA from time to time to reflect changes in the Service, our practices, or the law, in the same manner as we update the Terms. Where the rest of the Terms and this DPA conflict on the subject of data processing, this DPA prevails. In all other respects, the Terms continue to apply.
Annex 1 — Details of Processing
In short — a summary of what data we process for you, why, and about whom.
| Field | Details |
|---|---|
| Subject-matter | The provision of the OpsCentre Community Management System to the Customer's community. |
| Duration | For the duration of the Customer's Subscription and until deletion of the Customer Personal Data in accordance with Section 11. |
| Nature and purpose | Hosting, storage, organisation, retrieval, and management of community records and related information, in order to provide the Service and its modules. |
| Types of personal data | Personal data that the Customer and its Authorised Users choose to enter into the Service. The Service is intended for fictional, in-character roleplay records; the Customer must not enter real personal data about real, identifiable people. Account-level data of Authorised Users is handled by us as controller under our Privacy Policy. |
| Categories of data subjects | The Customer's Authorised Users, and the fictional characters and roleplay personas represented within the community's records. |
Annex 2 — Technical and Organisational Security Measures
In short — the measures we apply to protect your data, described by what they achieve.
We implement appropriate technical and organisational measures to protect Customer Personal Data, including the following. These measures are described by their effect; the specific technologies used to achieve them may change over time, provided the overall level of security is not materially reduced.
- Tenant isolation — Logical separation and isolation of each community's data from that of other communities, so that one community cannot access another's records.
- Access controls — Role-based and permission-based access controls that limit access to data to authorised users and personnel, on a need-to-know basis.
- Audit logging — Logging of access to, and changes of, records within the Service, supporting accountability and the detection of unauthorised activity.
- Encryption in transit — Use of encrypted connections to protect data transmitted between users and the Service.
- Reputable infrastructure — Use of established, reputable infrastructure and service providers with their own recognised security practices.
- Authentication — Authentication of users via a third-party identity provider, so that account passwords are not held by us.
- Confidentiality — Obligations of confidentiality on personnel with access to data, and restriction of access to those who require it to provide the Service.
- Breach management — Procedures to identify, manage, and where required report personal data breaches.
Annex 3 — Sub-processors
In short — the trusted providers we use to deliver the Service.
We engage the following sub-processors to process Customer Personal Data in connection with the Service. We will update this list and notify the Customer before adding or replacing a sub-processor, in accordance with Section 7.
| Sub-processor | Purpose |
|---|---|
| Stripe | Payment processing for Subscriptions (not yet engaged; will apply from the launch of paid Subscriptions). |
| Discord | User authentication and sign-in. |
| Railway | Hosting and database infrastructure for the Service. |
| Cloudflare | Content delivery, performance, and security protection. |
| Resend | Transactional email delivery (service and notice emails). |
| Microsoft | Business email and communications used in operating the Service. |
To be viewed in conjunction with https://www.opscentre.uk/legal/privacy
End of Data Protection Addendum