HomeLegal
Data Processing Addendum
The Article 28 GDPR processor terms that apply when Clubhouse AC processes personal data on behalf of a server administrator acting as controller (typically, the forensic snapshot a player produces when redeeming a PIN).
- Last updated
- September 16, 2026
- sections
- 17
Auto-accepted on subscription per §17
On this page
- 01Parties, Scope and Order of Precedence
- 02Definitions
- 03Subject Matter, Duration, Nature and Purpose
- 04Categories of Data and Data Subjects
- 05Controller Obligations
- 06Processor Obligations (Art. 28(3))
- 07Sub-processors
- 08Data Subject Rights Assistance
- 09Security Measures (Art. 32)
- 10Personal Data Breach Notification (Art. 33)
- 11DPIA + Prior Consultation Assistance (Art. 35-36)
- 12International Transfers
- 13Audit and Inspection Rights
- 14Return or Deletion on Termination
- 15Liability
- 16Governing Law
- 17Acceptance
Parties, Scope and Order of Precedence
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the operator of Clubhouse AC ("Processor") and the subscriber ("Controller", typically the server administrator). It applies whenever the Processor processes Personal Data on the Controller's behalf in connection with the Service, and gives effect to Article 28 GDPR, the equivalent Article 28 UK GDPR and any other applicable data-protection law that requires a written processor agreement.
Order of precedence.
If there is a conflict between this DPA and the main Terms of Service on a matter of Personal Data processing, this DPA prevails. If there is a conflict between this DPA and any Standard Contractual Clauses executed between the parties, the Standard Contractual Clauses prevail.
Definitions
Capitalised terms have the meaning given in the GDPR unless otherwise defined. In particular:
- GDPR means Regulation (EU) 2016/679 and, where applicable, the UK GDPR as retained in UK law by the Data Protection Act 2018.
- Personal Data, Processing, Controller, Processor, Data Subject, Personal Data Breach, Sub-processor and Supervisory Authority have the meanings given in Article 4 GDPR.
- Service means the Clubhouse AC scanner application, dashboard, workbench, PIN issuance system and related APIs described in the Terms of Service.
- Standard Contractual Clauses (SCCs) means the Standard Contractual Clauses for the transfer of personal data to third countries approved by the European Commission's Implementing Decision (EU) 2021/914 and, where relevant, the UK IDTA/Addendum issued by the ICO.
Subject Matter, Duration, Nature and Purpose
Subject matter.
Processing of Personal Data collected by the Clubhouse AC scanner when a Data Subject (a player) voluntarily redeems a PIN issued by the Controller.
Duration.
For as long as the Controller's subscription is active, plus any retention period required to fulfil a Data Subject rights request, resolve a dispute or comply with a legal obligation.
Nature of processing.
Collection (by the scanner running on the Data Subject's device with their consent), transmission (over an encrypted, session-bound channel), storage (in the Processor's infrastructure), analysis (against curated detection rulesets), presentation (to the Controller through the dashboard) and eventual deletion or anonymisation.
Purpose.
To produce a forensic scan report the Controller uses to identify the presence of cheat, bypass and tampering artefacts on the Data Subject's device, and to enforce the Controller's community rules.
Categories of Data and Data Subjects
Categories of Personal Data.
The categories enumerated in Section 03 of the Terms of Service and Section 03 of the Privacy Policy. In summary: OS metadata, hardware identifiers, running processes, loaded modules, installed programs, execution artefacts (Amcache / Prefetch / ShimCache / BAM / PcaSvc), file system metadata, registry artefacts, event log excerpts, DNS cache, network adapters, active and recent connections, IP addresses, and screenshots of the Data Subject's display at scan time.
Data Subjects.
Players who voluntarily redeem a PIN issued by the Controller and complete a scan.
Special categories.
The Service is not designed to process Article 9 special-category data. The Controller shall not, and shall use reasonable efforts to ensure Data Subjects shall not, submit special-category data through the Service without the Processor's prior written agreement.
Controller Obligations
- Ensure it has a valid lawful basis under Article 6 GDPR (and, where applicable, an Article 9 exemption) for the processing carried out through the Service.
- Inform Data Subjects, in advance of issuing a PIN, of the categories of data the scanner collects (see Terms §05) and their rights, so that redeeming a PIN constitutes informed and freely-given consent.
- Only issue PINs for legitimate anti-cheat verification purposes described in the Acceptable Use Policy.
- Respond to Data Subject requests directed to the Controller in the first instance, with the Processor's assistance under §08 below.
- Refrain from instructing the Processor to carry out any processing that would violate applicable data-protection law.
Processor Obligations (Art. 28(3))
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, including with regard to transfers to a third country or international organisation, unless required by Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28(3)(a)).
- Ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b)).
- Take all measures required pursuant to Article 32 as described in §09 below.
- Respect the conditions in §07 for engaging Sub-processors.
- Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising Data Subject rights (see §08).
- Assist the Controller in ensuring compliance with Articles 32-36 (security, breach notification, DPIA, prior consultation) taking into account the nature of processing and the information available to the Processor.
- At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage (see §14).
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (see §13).
Sub-processors
The Controller grants a general written authorisation for the Processor to engage the sub-processors identified in the Privacy Policy Section 05 (currently including Vercel, Neon, Supabase, Cloudflare, Stripe, Resend, Discord and IP-geolocation lookup). The Processor shall inform the Controller of any intended addition or replacement of sub-processors with reasonable advance notice through the dashboard, the Discord support server or by email, giving the Controller the opportunity to object on reasonable data-protection grounds. If the Controller objects, the Processor may (at its option) either refrain from engaging the proposed sub-processor for the Controller's data or terminate the affected part of the Service and refund any prepaid unused portion.
The Processor shall impose the same data-protection obligations on its sub-processors, by contract or other binding instrument, and remains fully liable to the Controller for the performance of any sub-processor's obligations.
Data Subject Rights Assistance
The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests to exercise Data Subject rights under Articles 15-22 GDPR. Where a Data Subject sends a rights request directly to the Processor about a Controller's scan, the Processor shall promptly forward the request to the Controller and provide the Controller with the tooling needed to fulfil it (export, redaction, deletion of a specific scan report from the dashboard).
Security Measures (Art. 32)
The Processor implements the technical and organisational measures described in the Privacy Policy Section 08, including TLS 1.2+ in transit, salted-iterated password hashes, access-controlled and audit-logged databases, 2FA on every authenticated action, session-bound scanner uploads, and the sub-processor allowlist enforced by production configuration. The Processor may update these measures over time to reflect evolving best practice, provided the overall level of protection is not reduced.
Personal Data Breach Notification (Art. 33)
The Processor shall notify the Controller of any Personal Data Breach affecting the Controller's Personal Data without undue delay after becoming aware of it, and in any event within 72 hours where feasible, providing at least the categories and approximate number of Data Subjects and records concerned, the likely consequences of the breach, the measures taken or proposed to address it, and a contact point for further information. The Processor shall reasonably assist the Controller in fulfilling any resulting notification obligations to a Supervisory Authority (Art. 33) or to affected Data Subjects (Art. 34).
DPIA + Prior Consultation Assistance (Art. 35-36)
Where processing is likely to result in a high risk to the rights and freedoms of natural persons, the Processor shall provide reasonable information and assistance to enable the Controller to carry out a Data Protection Impact Assessment (Art. 35) and, where required, to consult its Supervisory Authority prior to processing (Art. 36).
International Transfers
To the extent Processing under this DPA involves the transfer of Personal Data outside the EEA, the UK or another jurisdiction requiring a transfer safeguard, the parties shall rely on an adequate safeguard recognised under Chapter V GDPR (or the equivalent UK-GDPR provision), including the Standard Contractual Clauses (Modules 2 and/or 3, as applicable) with the docking clause and Clause 7(1) of the SCCs deemed accepted. Where the transfer is to a country covered by an adequacy decision or by a certification (such as the EU-US Data Privacy Framework), that basis may be relied upon in lieu.
Audit and Inspection Rights
The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR. The Controller may audit the Processor's compliance no more than once per twelve-month period (except where a Supervisory Authority requires more frequent audits, or after a confirmed Personal Data Breach affecting the Controller's data), on at least 30 days' written notice, at the Controller's cost, during normal business hours, subject to the Processor's reasonable confidentiality and security requirements. Where the Processor holds an independent third-party security certification or SOC-style audit report covering the Service, the Controller shall accept those reports in lieu of an on-site inspection where they reasonably address the audit's scope.
Return or Deletion on Termination
On termination or expiry of the Controller's subscription, the Processor shall, at the Controller's written choice, either return all Personal Data processed on the Controller's behalf or irreversibly delete it (and delete existing copies), within 90 days of termination. Where Union or Member State law requires the Processor to retain a copy of Personal Data (for example for tax or accounting compliance), the Processor shall retain that copy only for the period required, subject to the confidentiality and security obligations of this DPA.
Liability
Liability for breaches of this DPA is subject to the limitation and exclusion provisions of the Terms of Service, save that nothing in this DPA excludes or limits liability that cannot be excluded or limited under applicable law, including for damages caused by a party's wilful misconduct or gross negligence, or for the payment of administrative fines imposed by a Supervisory Authority under Article 83 GDPR to the extent such fine is directly attributable to that party's breach.
Governing Law
This DPA is governed by the same law as the underlying Terms of Service, save that the SCCs (where incorporated) are governed by the law they nominate, and any statutory data-protection right of a Data Subject shall be governed by the law of the Data Subject's habitual residence to the extent that law is more protective than the governing law above.
Acceptance
This DPA is automatically accepted by the Controller on activation of a Clubhouse AC subscription and on continued use of the Service, and forms an integral part of the Terms of Service. A countersigned PDF copy is available on request from support@clubhouseac.com for enterprise buyers or for compliance records.