Data Processing Agreement

Last updated 7 September 2026

This agreement is concluded automatically when you create a Rudder account and applies to every project on it — you do not need to sign anything separately. If your legal team needs a countersigned copy on paper, write to hello@rudder.build and we will provide one.

1. Parties and roles

You, the Rudder account holder, are the controller. [LEGAL ENTITY NAME], [REGISTERED ADDRESS], operating Rudder, is the processor. This agreement is Article 28 GDPR terms and forms part of the Terms of Service. Where the two conflict on data protection, this agreement wins.

2. Subject matter of the processing

Subject matter Operating a game backend on your behalf.
Duration For as long as your account exists, plus the retention periods below.
Nature and purpose Storing, retrieving, modifying and deleting player records so that your game can authenticate players and run its economy, progression and live operations.
Categories of data subject The players of your games, and the members of your project team.
Categories of personal data Player identifiers, nicknames, avatar URLs, region and language, login identities (provider and subject as supplied by your game), free-form profile data and storage blobs whose contents you determine, gameplay state (wallets, counters, resource rows created by installed modules, module logs), activity days, and an audit log of administrative actions.
Special categories None. You must not send special category data to Rudder.

3. Our obligations

  • We process personal data only on your documented instructions. Your use of the API and the dashboard is such an instruction. If the law compels us to process it otherwise, we tell you first unless that law forbids it.
  • We do not use your players' personal data for our own purposes. Specifically: not to train, fine-tune, evaluate or prompt any AI or machine-learning model; not for analytics of our own; not for advertising; and never for sale or disclosure to a third party outside this agreement.
  • Everyone with access is bound by confidentiality. Access is limited to the people who need it to run the service, and to support work you have asked us for.
  • We implement the technical and organisational measures in section 6 and keep them current.
  • We help you meet your own obligations: responding to data subject requests, carrying out data protection impact assessments, and consulting your supervisory authority, so far as is reasonable given the information we hold.
  • We make available the information you need to demonstrate our compliance, and allow audits by you or an auditor you appoint, at reasonable notice, at most once a year unless an incident or an authority requires more.

4. Sub-processors

You give general authorisation for the following sub-processors:

Sub-processorPurposeLocation
Hetzner Online GmbHApplication and database hostingGermany
ResendTransactional email to your team membersUnited States

Each is bound by data protection terms no less protective than these. Transfers to the United States rely on the EU-US Data Privacy Framework or on Standard Contractual Clauses. Player data is not sent to Resend; only your team's email addresses are.

We give at least 30 days' notice by email before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period; if we cannot resolve the objection, you may terminate the affected project without penalty.

5. International transfers

All player data is stored and processed inside the European Union, in Germany, for the database and the application. We do not move it elsewhere without telling you first and putting a lawful transfer mechanism in place.

6. Security measures

  • TLS for all traffic in transit; certificates issued and renewed automatically.
  • Encryption at rest of the database volumes.
  • Account passwords stored as bcrypt hashes; API tokens stored as hashes only, and shown once at creation.
  • Keys scoped per project and per environment, so a compromised staging key cannot reach production data.
  • Every administrative action on a player is written to an audit log with a before/after diff, retained for 90 days.
  • Least-privilege access to production, and separation of staging and production data.
  • Regular backups, restorable, held under the same protections as production.

7. Personal data breaches

If we become aware of a breach affecting your players' personal data, we notify you without undue delay and in any case within 72 hours, describing what happened, which categories and how many records are affected as far as we can tell, the likely consequences and what we are doing about it. Notifying your supervisory authority and your data subjects remains your call as controller.

8. Assistance with data subject requests

The API lets you fulfil most requests yourself and without involving us: read a player, export their data, and delete them. Deleting a player clears nickname, avatar and profile data and deletes their login identities and storage blobs outright. Where a request cannot be met through the API, we assist you at no charge.

If a player contacts us directly, we do not answer on your behalf. We forward the request to you without undue delay.

9. Deletion and return of data

  • Deleting your account permanently deletes every project where you are the only owner and all of that project's player data, immediately and irreversibly.
  • Deleting a project marks it deleted and stops serving it, but its player data is retained until you ask us to erase it. Write to us and we erase it within 30 days.
  • The administrative audit log is deleted automatically after 90 days; idempotency records after 24 hours.
  • Deleted data disappears from backups within 30 days, when the backup containing it expires.
  • Before deletion you may export your data through the API. On request we provide an export in a structured, commonly used, machine-readable format.

10. Your obligations

You warrant that you have a lawful basis for sending us the personal data you send, that you have told your players about it as the law requires, that you do not send special category data or data about children where you lack the required consent, and that your instructions to us do not breach data protection law.

11. Liability and term

Liability under this agreement is subject to the limits in the Terms of Service, except where data protection law does not allow it to be limited. This agreement lasts as long as we process personal data on your behalf and ends when that processing and the retention periods above have ended.

Questions or a countersigned copy: hello@rudder.build.