1. Scope
This DPA governs processing of personal data in connection with Persistly where the customer is controller and Northshore Labs LTDprocesses personal data on the customer's behalf.
2. Roles
The customer is the Data Controller. Northshore Labs LTD is the Data Processor for customer personal data processed through the hosted service.
3. Processing details
Processor will process data only on instructions from Controller, ensure confidentiality, and implement appropriate security measures.
The subject matter is hosted save persistence and sync for games. The duration is the term of the customer's use of Persistly plus deletion, backup, and legal retention periods. The purpose is to provide, secure, troubleshoot, and support the Service.
Data subjects may include customer operators and game players. Personal data may include account identifiers, authentication identifiers, project data, save IDs, player ref IDs, save metadata, save state if it contains personal data, IP addresses, logs, support messages, and billing metadata.
Where Auth Bridge is enabled, personal data may also include external identity provider names, issuer and subject identifiers, derived account-link metadata, email or display hints provided by the configured provider, token claim metadata needed to verify sign-in, and audit records of authentication exchanges. Persistly processes provider tokens for verification and does not intentionally retain raw provider tokens after the exchange.
Controller must not submit special category data, sensitive personal data, payment card data, passwords, government IDs, health data, administrative secrets, or children's personal data unless explicitly agreed in writing and supported by appropriate legal controls.
Controller is responsible for deciding what player identifiers and save payload fields are sent to Persistly, for minimizing personal data in save payloads, and for avoiding secrets or regulated data inside client-controlled game state.
4. Subprocessors
Processor may engage subprocessors for payments, authentication, hosting, observability, email, and security operations. See the Subprocessors page for the current list.
5. Security
Processor implements technical and organizational measures designed to protect personal data, including access controls, least-privilege operational access, encrypted transport, hosted database controls, logging, backup controls, and incident review.
6. Data subject rights
Processor will assist Controller in fulfilling access, deletion, and correction requests where required by applicable law.
7. Data breach
Processor will notify Controller without undue delay after becoming aware of a breach.
8. Return or deletion
Upon termination, data will be deleted or returned to Controller where required and technically feasible. Residual copies may remain in backups, logs, and accounting records for limited periods before deletion under normal retention cycles.
Export, deletion, and restore-history retention may depend on the active plan, account status, technical availability, legal retention obligations, and the distinction between active save state, retained history snapshots, logs, backups, and billing records.
9. International transfers
Data may be transferred internationally with appropriate safeguards, including use of the subprocessors listed on the Subprocessors page with contractual commitments and transfer mechanisms where required.
10. Audits and information
Processor will provide reasonable information needed to demonstrate compliance with this DPA. Audits must be reasonable, documented, limited to relevant systems and controls, and avoid creating security, confidentiality, or service availability risks.
11. Liability and governing law
Liability is governed by the Terms of Service. Bulgaria and EU law apply.
12. Contact
Data processing questions can be sent to legal@persistly.app.