Legal
Data Processing Agreement (DPA)
Last updated: 10 August 2026
This Data Processing Agreement (hereinafter "DPA") specifies the data protection obligations of the parties in connection with the hosting, server, e-mail, gameserver and related services commissioned by the customer. It applies to the extent that the customer, in the course of using these services, has personal data of third parties (e.g. its own users, customers or employees) processed on the provider''s infrastructure.
§ 1 Subject matter, roles
(1) The customer is the data controller (Art. 4 (7) GDPR). The processor (Art. 4 (8) GDPR) is Nobody Workz – Michael Gloe & Lukas Eberle GbR.
(2) The processor processes personal data exclusively on behalf of and in accordance with the documented instructions of the controller, unless a legal obligation requires otherwise. The controller remains responsible for the lawfulness of the processing and for safeguarding data subject rights.
§ 2 Nature, purpose, duration, categories of data and data subjects
(1) Nature and purpose: storage, provisioning and technical operation of the services booked by the controller (hosting of websites/databases, e-mail, gameservers, associated backups and logs) and support.
(2) Duration: for the duration of the main contract for the booked services.
(3) Categories of data (determined by the controller): in particular inventory and communication data, content data of applications stored by the controller, usage and connection data; depending on the controller''s use, further data categories may apply.
(4) Categories of data subjects (determined by the controller): e.g. users, customers, prospects, employees or communication partners of the controller.
§ 3 Right to issue instructions
(1) The processor processes the data only within the scope of the controller''s instructions. The contract documents and the configurations selected in the portal constitute the initial instruction. Further instructions are given in text form.
(2) If the processor considers an instruction unlawful, it shall notify the controller without delay; it may suspend execution until confirmation or amendment.
§ 4 Technical and organisational measures (TOM)
(1) The processor implements the technical and organisational measures required by Art. 32 GDPR and maintains them for the duration of the contract. These include in particular:
- Confidentiality: physical access controls to data centres via infrastructure partners (Tier-III data centres, entry security), access controls (individual accounts, strong authentication, 2FA, passkeys), authorisation controls (role-based permissions, need-to-know, audit trail), separation controls (multi-tenant/data separation).
- Integrity: transport encryption (TLS), protection against unauthorised modification, insert-only audit log of security-relevant events, input controls.
- Availability and resilience: DDoS protection, 24/7 monitoring, redundant sites (DE/NL), backup concepts in accordance with the relevant service, recoverability.
- Procedures for regular review, assessment and evaluation: patch/update processes, incident handling, regular review of measures, ad-hoc pen testing.
(2) Measures within the controller''s sphere of responsibility (e.g. security of applications operated by the controller, configuration, passwords, own backups) are the controller''s responsibility.
§ 5 Sub-processors
(1) The controller grants general authorisation for the use of the sub-processors named below. The list is maintained on an ongoing basis; the current version is available via the privacy policy or on request.
EU sub-processors (no third country):
| Provider | Location | Function | Legal basis |
|---|---|---|---|
| 24fire GmbH | Germany | Virtualised server infrastructure (VPS, dedicated, gameserver hosts) in NTT Frankfurt 1 (DE) and SkyLink Eygelshoven (NL) | Art. 28 GDPR |
| INWX (InterNetworX Ltd. & Co. KG) | Germany | Domain registrar (DENIC/ICANN) | Art. 28 GDPR |
| Plesk International GmbH | Switzerland/EU | Web hosting control panel | Art. 28 GDPR |
| Plesk mail server (self-operated on a 24fire server) | Germany | E-mail platform (Postfix/Dovecot/Roundcube: IMAP/SMTP/webmail, DKIM/SPF/DMARC) | Art. 28 GDPR |
| Pelican Panel (self-operated on a 24fire VM) | Germany | Gameserver management panel (Wings, SFTP, live console) | Art. 28 GDPR |
Third-country or mixed sub-processors (with safeguard pursuant to Art. 44 et seqq. GDPR):
| Provider | Location | Function | Safeguard |
|---|---|---|---|
| Cloudflare, Inc. (also Cloudflare Germany GmbH) | USA / Germany | DDoS protection, CDN, bot/abuse protection (Turnstile), DNS | EU-U.S. Data Privacy Framework (certified) + EU Standard Contractual Clauses |
| Discord, Inc. | USA | Community server, OAuth login (optional), bot integration (ticket mirror, embeds) | EU-U.S. Data Privacy Framework |
| Sentry (Functional Software, Inc.) | USA / EU region | Error tracking (optional, eu.sentry.io) | EU hosting of telemetry, EU-U.S. Data Privacy Framework + SCC |
| Supabase, Inc. | USA / EU region eu-west-1 (Ireland) | Platform database (customers, orders, tickets, documents) | EU hosting of content data, EU-U.S. Data Privacy Framework + SCC |
| Google Ireland Ltd. (group: Google LLC) | Ireland / USA | Reach measurement (Google Analytics 4, only with consent) | EU-U.S. Data Privacy Framework + SCC |
Independent controllers (not sub-processors):
| Provider | Location | Function |
|---|---|---|
| Stripe Payments Europe, Ltd. | Ireland (group: USA) | Card payments, wallet, subscriptions |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Luxembourg | PayPal payments |
| Tebex Limited | United Kingdom | Tebex webstore (sale of digital studio assets); UK adequacy decision |
Payment service providers and the Tebex webstore act as independent controllers for their own payment and sales processing and are not sub-processors; their privacy notices apply in addition.
(2) The processor commits all sub-processors to a data protection level adequate to this DPA (Art. 28 (4) GDPR). The processor notifies the controller in text form or by updating this list of intended changes (addition/replacement); the controller may object for substantive data protection reasons.
§ 6 Third-country transfer
Processing outside the EU/EEA shall take place only where the requirements of Art. 44 et seqq. GDPR are met, in particular on the basis of an adequacy decision (e.g. EU-U.S. Data Privacy Framework for certified U.S. providers, UK adequacy decision) or appropriate safeguards (EU Standard Contractual Clauses with supplementary technical and organisational measures).
§ 7 Support obligations
The processor supports the controller, within reason and against reimbursement of any additional effort, in fulfilling the data subjects'' rights (Art. 12–23), the obligations to report data breaches (Art. 33, 34), the data protection impact assessment (Art. 35) and the prior consultation (Art. 36).
§ 8 Notification of personal data breaches
The processor notifies the controller of personal data breaches affecting the processed data without undue delay (generally within 72 hours) after becoming aware of them and provides the information needed for the controller to fulfil its obligations.
§ 9 Audit and verification rights
The processor provides the controller with the information required to demonstrate compliance and enables reasonable reviews, which the controller may request with reasonable prior notice and without unreasonable disruption to operations; primarily by way of information, documentation or evidence. Existing certifications or audit reports of sub-processors will be made available on request, where available.
§ 10 Deletion and return
Upon completion of the processing, the processor shall delete or return the personal data at the controller''s choice, unless a legal retention obligation applies. Where legal retention obligations apply, access to the affected data is restricted to what is legally required.
§ 11 Conclusion, precedence
(1) This DPA applies to the hosted processing of customer content and becomes part of the contract upon booking a corresponding service. On request, the provider will provide a separately signed version.
(2) In case of conflict between this DPA and other agreements, the provisions of this DPA shall prevail in matters of data protection.
