Data Processing Addendum
Effective 29 September 2026
This Data Processing Addendum ("DPA") forms part of the Publisher Terms between GreenMind Media Inc. ("GreenMind", "we", "us" or "our") and the Studio. It applies whenever we process personal data on the Studio's behalf in providing GreenMind Publishing (the "Service"). Words defined in the Publisher Terms have the same meaning here.
"Data Protection Law" means every law on the protection of personal information that applies to that processing, including, where they apply, the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, Canada's Personal Information Protection and Electronic Documents Act and its provincial equivalents, and the privacy laws of the United States and its states. "Controller", "processor", "personal data", "data subject", "processing" and "personal data breach" have the meanings Data Protection Law gives them.
1. Roles
The Studio is the controller of Player Data, and GreenMind is its processor. Where the Studio itself processes Player Data for another controller, such as a publisher, the Studio is a processor and GreenMind is its sub-processor, and the Studio is responsible for having that controller's authority for this DPA.
Where US state privacy laws apply, we act as the Studio's service provider or processor. We do not sell or share Player Data, retain, use or disclose it for any purpose other than providing the Service, or combine it with personal information we hold for other purposes, except as those laws permit a service provider to.
This DPA does not cover the information GreenMind holds as a controller in its own right: the Studio's Members' GreenMind accounts, the record of who accepted the agreements, and our own security and service logs. Those are covered by GreenMind's Privacy Policy. Where a Player also holds a GreenMind account of their own, that account is covered by the Privacy Policy too.
2. Subject matter, nature, purpose and duration
We process Player Data to provide the Service to the Studio: storing it, signing Players in, running lobbies, delivering config and flags to the Studio's games, and showing it to the Studio's Members in the console. We process it for as long as the Studio uses the Service, and then until it is deleted under clause 13.
3. Our obligations
- We process Player Data only on the Studio's documented instructions, including with regard to transfers outside the country where it was collected, unless the law requires otherwise, in which case we will tell the Studio first where the law allows. The Publisher Terms, this DPA, and the Studio's use of the console and the platform API are the Studio's instructions.
- We will tell the Studio if we believe an instruction breaks Data Protection Law.
- Everyone we authorise to process Player Data is bound to keep it confidential.
- We apply the security measures in clause 7.
- We help the Studio, taking into account the nature of the processing and the information available to us, to meet its own obligations under Data Protection Law: answering data subject requests (clause 9), security, breach notification (clause 10), and data protection impact assessments and consultations with a supervisory authority (clause 11).
4. Data subjects
- The Studio's Players.
- The Studio's own staff and anyone else, where the Studio or its Players put their details into the Service, for example in a support request, a report or a blog post.
5. Categories of personal data
- Player identifiers: the identifier the Studio's server gives for a Player, an Epic Online Services product user id where the Studio signs Players in with Epic Online Services, the Player's id in the Service, and any online-subsystem id the Studio's game sends with a lobby seat.
- Names: display names, and the names Players are seated under in lobbies.
- Activity records: when a Player was first and last signed in, and lobby and match records: who was seated, who was host and ready, the game mode, map, status and outcome, and when.
- Content: config values, feature flags, tours, blog posts and support requests and reports, to the extent they contain personal data.
The Studio decides what goes into these fields. The Service is not designed to hold special categories of personal data, payment card numbers, government identifiers or passwords, and the Studio must not send them.
6. The Studio's obligations
The Studio is responsible for the lawfulness of the Player Data it sends to the Service and of its instructions to us: for having a lawful basis, for giving its Players the notices Data Protection Law requires (including that a service provider processes their data), and for obtaining any consent required, including a parent's where the law asks for one.
7. Security
We take technical and organisational measures appropriate to the risk of the processing. They include:
- encryption of data in transit to and from the Service, and at rest;
- access limited by role: in the console, each Member can reach only the Org, projects and Environments their role allows; within GreenMind, only staff who need it to run the Service can reach Player Data;
- each Environment's data kept apart, so that a Credential for one Environment can reach no other;
- server keys and invitation links stored only as hashes, and player access tokens that expire after one hour;
- database backups with point-in-time recovery, so that data can be restored after a fault, overwritten within seven days.
We review these measures from time to time and may change them, provided the overall level of protection is not reduced. No service can promise perfect security, and the Studio remains responsible for the security of its own games, servers and Credentials.
8. Sub-processors
The Studio authorises us to use sub-processors to provide the Service. Today we use one: Amazon Web Services, which hosts our servers, database and backups in the United States. An up-to-date list is available on request.
Signing Players in with Epic Online Services does not make Epic a sub-processor: we check a Player's Epic token against the public keys Epic publishes, and send Epic no Player Data. The Studio's own use of Epic Online Services is governed by its agreement with Epic.
Before we add or replace a sub-processor, we will tell the Studio's admins by email or in the console. The Studio may object on reasonable data protection grounds within 30 days. If we cannot address the objection, the Studio may end the Publisher Terms.
We bind each sub-processor to data protection obligations no less protective than those in this DPA, and remain responsible to the Studio for its performance of them.
9. Requests from players
If a Player contacts us directly about a Studio's game, we will not answer the request ourselves, except to tell them to contact the Studio, and we will pass it to the Studio without undue delay.
The Studio can answer many requests itself: the console finds a Player by display name, by Player id, or by the identifier the Studio's server gave, and shows what the Service holds about their identity; the platform API reads a Player, corrects their display name, and deletes a Player. Exporting what the Service holds about a Player is not yet available in the console or the API. Until it is, the Studio sends the request to the address in clause 16, naming the Player's id and Environment, and we carry it out without undue delay and in any case within 14 days.
10. Personal data breaches
We will notify the Studio without undue delay after becoming aware of a personal data breach affecting Player Data. We will give the Studio the information it reasonably needs to meet its own obligations, as it becomes available: what happened, the categories and approximate number of Players and records concerned, the likely consequences, and what we have done or propose to do about it. We will take reasonable steps to contain the breach and reduce its effects.
Notifying the Studio of a breach is not an admission of fault or liability.
11. Impact assessments and consultations
On request, we will give the Studio reasonable information about the Service to help it carry out a data protection impact assessment, or consult a supervisory authority, where Data Protection Law requires it to.
12. International transfers
GreenMind is in Canada and hosts the Service in the United States, so Player Data is processed in both. Where Data Protection Law restricts the transfer of personal data outside the place it came from, we rely on a transfer mechanism that law recognises: for data from the European Union and the United Kingdom, Canada's adequacy status, and our sub-processors' standard contractual clauses or their certification under the EU-U.S. Data Privacy Framework and its UK extension. Where a further mechanism or additional terms are required for a transfer, we will work with the Studio in good faith to put them in place.
13. Deletion and return at the end of the Service
When the Publisher Terms end, the Studio may ask us, within 30 days, for a copy of its Player Data in a common machine-readable format. After those 30 days, we delete the Studio's Player Data from the Service within a further 30 days, and it is gone from our backups within seven days after that, unless the law requires us to keep it.
14. Information and audits
On the Studio's written request, we will provide the information reasonably necessary to demonstrate that we meet our obligations under this DPA, such as written answers to a security questionnaire. The Studio may ask no more than once a year, except after a personal data breach or where a supervisory authority requires it.
Where Data Protection Law gives the Studio a right to an audit that this information does not satisfy, the audit is carried out by the Studio or an independent auditor bound to confidentiality, on reasonable notice, during business hours, without access to other studios' data, and at the Studio's cost.
15. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Publisher Terms, except where Data Protection Law does not allow them. Nothing in this DPA limits a right that Data Protection Law gives a data subject.
Where this DPA and the Publisher Terms conflict, this DPA governs the processing of Player Data. This DPA lasts for as long as we process Player Data for the Studio, and may be revised as the Publisher Terms describe.
16. Contact us
Questions about this DPA, requests about Player Data, and breach or security reports go to our privacy officer:
GreenMind Media Inc.
greenmindmediagroup@gmail.com