Skip to content

Note: Studio commissions are accepted selectively right now — our focus is on the hosting lines.

All legal documents

Legal

Data Processing Agreement (DPA)

Last updated: 10 August 2026

This Data Processing Agreement (hereinafter "DPA") specifies the data protection obligations of the parties in connection with the hosting, server, e-mail, gameserver and related services commissioned by the customer. It applies to the extent that the customer, in the course of using these services, has personal data of third parties (e.g. its own users, customers or employees) processed on the provider''s infrastructure.

§ 1 Subject matter, roles

(1) The customer is the data controller (Art. 4 (7) GDPR). The processor (Art. 4 (8) GDPR) is Nobody Workz – Michael Gloe & Lukas Eberle GbR.

(2) The processor processes personal data exclusively on behalf of and in accordance with the documented instructions of the controller, unless a legal obligation requires otherwise. The controller remains responsible for the lawfulness of the processing and for safeguarding data subject rights.

§ 2 Nature, purpose, duration, categories of data and data subjects

(1) Nature and purpose: storage, provisioning and technical operation of the services booked by the controller (hosting of websites/databases, e-mail, gameservers, associated backups and logs) and support.

(2) Duration: for the duration of the main contract for the booked services.

(3) Categories of data (determined by the controller): in particular inventory and communication data, content data of applications stored by the controller, usage and connection data; depending on the controller''s use, further data categories may apply.

(4) Categories of data subjects (determined by the controller): e.g. users, customers, prospects, employees or communication partners of the controller.

§ 3 Right to issue instructions

(1) The processor processes the data only within the scope of the controller''s instructions. The contract documents and the configurations selected in the portal constitute the initial instruction. Further instructions are given in text form.

(2) If the processor considers an instruction unlawful, it shall notify the controller without delay; it may suspend execution until confirmation or amendment.

§ 4 Technical and organisational measures (TOM)

(1) The processor implements the technical and organisational measures required by Art. 32 GDPR and maintains them for the duration of the contract. These include in particular:

  • Confidentiality: physical access controls to data centres via infrastructure partners (Tier-III data centres, entry security), access controls (individual accounts, strong authentication, 2FA, passkeys), authorisation controls (role-based permissions, need-to-know, audit trail), separation controls (multi-tenant/data separation).
  • Integrity: transport encryption (TLS), protection against unauthorised modification, insert-only audit log of security-relevant events, input controls.
  • Availability and resilience: DDoS protection, 24/7 monitoring, redundant sites (DE/NL), backup concepts in accordance with the relevant service, recoverability.
  • Procedures for regular review, assessment and evaluation: patch/update processes, incident handling, regular review of measures, ad-hoc pen testing.

(2) Measures within the controller''s sphere of responsibility (e.g. security of applications operated by the controller, configuration, passwords, own backups) are the controller''s responsibility.

§ 5 Sub-processors

(1) The controller grants general authorisation for the use of the sub-processors named below. The list is maintained on an ongoing basis; the current version is available via the privacy policy or on request.

EU sub-processors (no third country):

ProviderLocationFunctionLegal basis
24fire GmbHGermanyVirtualised server infrastructure (VPS, dedicated, gameserver hosts) in NTT Frankfurt 1 (DE) and SkyLink Eygelshoven (NL)Art. 28 GDPR
INWX (InterNetworX Ltd. & Co. KG)GermanyDomain registrar (DENIC/ICANN)Art. 28 GDPR
Plesk International GmbHSwitzerland/EUWeb hosting control panelArt. 28 GDPR
Plesk mail server (self-operated on a 24fire server)GermanyE-mail platform (Postfix/Dovecot/Roundcube: IMAP/SMTP/webmail, DKIM/SPF/DMARC)Art. 28 GDPR
Pelican Panel (self-operated on a 24fire VM)GermanyGameserver management panel (Wings, SFTP, live console)Art. 28 GDPR

Third-country or mixed sub-processors (with safeguard pursuant to Art. 44 et seqq. GDPR):

ProviderLocationFunctionSafeguard
Cloudflare, Inc. (also Cloudflare Germany GmbH)USA / GermanyDDoS protection, CDN, bot/abuse protection (Turnstile), DNSEU-U.S. Data Privacy Framework (certified) + EU Standard Contractual Clauses
Discord, Inc.USACommunity server, OAuth login (optional), bot integration (ticket mirror, embeds)EU-U.S. Data Privacy Framework
Sentry (Functional Software, Inc.)USA / EU regionError tracking (optional, eu.sentry.io)EU hosting of telemetry, EU-U.S. Data Privacy Framework + SCC
Supabase, Inc.USA / EU region eu-west-1 (Ireland)Platform database (customers, orders, tickets, documents)EU hosting of content data, EU-U.S. Data Privacy Framework + SCC
Google Ireland Ltd. (group: Google LLC)Ireland / USAReach measurement (Google Analytics 4, only with consent)EU-U.S. Data Privacy Framework + SCC

Independent controllers (not sub-processors):

ProviderLocationFunction
Stripe Payments Europe, Ltd.Ireland (group: USA)Card payments, wallet, subscriptions
PayPal (Europe) S.à r.l. et Cie, S.C.A.LuxembourgPayPal payments
Tebex LimitedUnited KingdomTebex webstore (sale of digital studio assets); UK adequacy decision

Payment service providers and the Tebex webstore act as independent controllers for their own payment and sales processing and are not sub-processors; their privacy notices apply in addition.

(2) The processor commits all sub-processors to a data protection level adequate to this DPA (Art. 28 (4) GDPR). The processor notifies the controller in text form or by updating this list of intended changes (addition/replacement); the controller may object for substantive data protection reasons.

§ 6 Third-country transfer

Processing outside the EU/EEA shall take place only where the requirements of Art. 44 et seqq. GDPR are met, in particular on the basis of an adequacy decision (e.g. EU-U.S. Data Privacy Framework for certified U.S. providers, UK adequacy decision) or appropriate safeguards (EU Standard Contractual Clauses with supplementary technical and organisational measures).

§ 7 Support obligations

The processor supports the controller, within reason and against reimbursement of any additional effort, in fulfilling the data subjects'' rights (Art. 12–23), the obligations to report data breaches (Art. 33, 34), the data protection impact assessment (Art. 35) and the prior consultation (Art. 36).

§ 8 Notification of personal data breaches

The processor notifies the controller of personal data breaches affecting the processed data without undue delay (generally within 72 hours) after becoming aware of them and provides the information needed for the controller to fulfil its obligations.

§ 9 Audit and verification rights

The processor provides the controller with the information required to demonstrate compliance and enables reasonable reviews, which the controller may request with reasonable prior notice and without unreasonable disruption to operations; primarily by way of information, documentation or evidence. Existing certifications or audit reports of sub-processors will be made available on request, where available.

§ 10 Deletion and return

Upon completion of the processing, the processor shall delete or return the personal data at the controller''s choice, unless a legal retention obligation applies. Where legal retention obligations apply, access to the affected data is restricted to what is legally required.

§ 11 Conclusion, precedence

(1) This DPA applies to the hosted processing of customer content and becomes part of the contract upon booking a corresponding service. On request, the provider will provide a separately signed version.

(2) In case of conflict between this DPA and other agreements, the provisions of this DPA shall prevail in matters of data protection.