Skip to content
All plans

Cloud

VPS Hosting Soon
Discord Bot Hosting Soon
Support

Legal

Data Processing Agreement

Last updated August 2026

If your server holds information about the people who play on it, this agreement is the paperwork for it. It forms part of the Terms & Conditions and applies automatically to every customer — there is nothing to sign, nothing to request and no enterprise plan to be on. If you need a countersigned copy for your own records, email dpo@ghostnode.gg and we will send one.

It is written to meet Article 28 of the UK GDPR and the EU GDPR, and to work as the equivalent arrangement under the other regimes named at the end.

Which of us is which

You are the controller. You decide what your server collects about your players and why — the character table, the ban list, the connection logs, whatever your scripts record. Nobody at GhostNode chose any of that.

We are your processor. We hold it because we host the machine, and we act on your instructions.

Separately, we are a controller in our own right for your account data — your name, your email, your invoices. That is governed by the Privacy Policy, not by this agreement. The two do not overlap: this document is only about the data on your server.

What we process, and why

Subject matter Hosting and operating the game server you bought, and the panel you manage it with.
Duration For as long as your server exists, plus the short grace period after termination.
Nature and purpose Storage, hosting, backup, and the operations you perform through the panel — viewing, editing, exporting and deleting.
Types of personal data Whatever your server stores. Typically in-game identifiers and character records, account identifiers from the game platform, IP addresses, connection times, chat and action logs, ban and moderation records.
Categories of data subject The players on your server, and anyone you give panel access to.
Special category data None expected. If you configure your server to collect it, that is your decision and your responsibility to justify.

What we undertake

  1. To process only on your instructions. Your use of the panel is your instruction. We will not process your players' data for our own purposes, and we will not sell it or use it to train anything. If we are ever required by law to process it otherwise, we will tell you first unless the law forbids us from doing so.
  2. To keep it confidential. Everyone with access is bound by confidentiality obligations, and access is limited to people who need it to do their job.
  3. To secure it with appropriate technical and organisational measures — set out under Security measures below.
  4. To engage sub-processors only as set out below, under written terms no less protective than these, and to remain liable to you for what they do.
  5. To help you answer your players. The panel already gives you the tools to find, export, correct and delete a player's records yourself, which is faster than asking us. Where it does not reach, we will help within a reasonable time.
  6. To help you with your own obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account what we know and what you know.
  7. To tell you about a breach without undue delay after becoming aware of one affecting your data, with what we know, what we are doing and who to ask. Notification is not an admission that either of us did anything wrong.
  8. To delete or return it at the end, as below.
  9. To make available what you need to show compliance, and to allow audits as described below.

What you undertake

You are responsible for the lawfulness of what you collect. In practice that means:

  • Having a lawful basis for collecting what your server collects, and telling your players what you collect and why. A line in your Discord rules or a privacy notice on your community site is usually enough; nothing is not.
  • Answering your players when they ask for their data or ask you to delete it. We have no relationship with them. If one writes to us we will point them at you and pass the request on, rather than acting on it ourselves.
  • Not instructing us to do something that would put either of us in breach of data protection law.
  • Keeping your own account secure, and giving sub-users only the permissions they actually need. Most incidents involving a customer's data begin with a shared password.
  • Not collecting more than you need. A roleplay server does not need a permanent record of every message ever sent, and the more you keep the more you have to answer for.

Sub-processors

You give us general authorisation to engage sub-processors. The current list, with what each does and where it is, is at Sub-processors and is kept current rather than restated here where it would go stale.

We will give at least 30 days' notice before adding or replacing one, by email to the address on your account. If you have a reasonable objection on data protection grounds, tell us within those 30 days and we will work with you to find a solution; if we cannot, you may terminate the affected service and take a pro-rata refund of the unused period.

International transfers

Your server sits in the region you chose, and its data stays there in the ordinary course. Where personal data is transferred out of the UK or the EEA — because you chose a region outside them, or because a sub-processor is elsewhere — we rely on the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses, on the Clauses themselves, or on an adequacy decision covering the destination.

Where the Clauses apply, they are incorporated into this agreement: you are the data exporter, we are the data importer, module two applies, and the parties, the specification above and the security measures below complete the annexes. Where you are yourself a processor for somebody else, module three applies instead.

Choosing a region is the strongest control you have here. If you need the data to stay in the UK or the EU, pick a region that is in it, and it will.

Security measures

These are the measures we apply, and they complete the annex the Clauses require:

  • Encryption in transit for all connections to the panel, the API and file transfer.
  • Each customer's server in its own isolated container, with its own credentials.
  • Database access using that customer's own credentials, scoped to their own database — never a shared privileged account.
  • Access control in the panel, per sub-user and per capability, checked on the server side.
  • Two-step sign in available on every account.
  • Secrets encrypted at rest, described rather than displayed, and stripped from logs.
  • An audit trail of every state change, attributed to the person who caused it and retained for 24 months.
  • Automated backups to separate infrastructure, and a snapshot taken before any destructive operation and kept 24 hours.
  • Staff access limited to what the role requires, logged, and reviewed.
  • Automated monitoring of machine health, with alerting on failure.

Audits

You may satisfy yourself that we are doing what this agreement says. In the first instance we will answer a written questionnaire, and provide the documentation and any third-party reports we hold. Where that genuinely does not answer your question, you may audit us — on 30 days' notice, no more than once a year unless a regulator or a breach requires otherwise, during working hours, without disrupting other customers, and subject to confidentiality. You bear the cost of an audit you request unless it finds a material breach, in which case we bear it.

Deletion and return

When your server is terminated we delete its data after the grace period described in the Terms & Conditions. You can export everything before then, and we would rather you did — there is no charge and the tools are already in the panel.

Backups age out on their normal cycle rather than being reached into and edited, which is standard practice and the reason a deletion request cannot be instant everywhere at once. Nothing recovered from a backup is put back into service after a deletion.

Liability

Each party's liability under this agreement is subject to the limits in the Terms & Conditions, and counts towards the same aggregate cap rather than sitting alongside it — except where the law does not permit those limits, in particular a data subject's own right to compensation, which neither of us can contract away.

You indemnify us against any claim, fine or proceeding brought by a data subject, a regulator or a third party that arises from your instructions, from data you had no lawful basis to collect, from a failure to give your players the information or the rights they were owed, or from your breach of this agreement. That indemnity applies in full to business customers and, for consumers, only to the extent consumer law permits.

Where we are both found liable for the same loss, each of us bears the share that reflects our own responsibility for it, and neither of us is liable for the other's share.

Other regimes

This agreement is also intended to satisfy the equivalent requirements elsewhere, and we will apply it as such:

  • California. We are a “service provider” under the CCPA as amended. We do not sell or share personal information, do not retain, use or disclose it except to provide the service, and will not combine it with data from other sources except as that law permits.
  • Australia. We handle the data in line with the Australian Privacy Principles and will assist you with the Notifiable Data Breaches scheme.
  • New Zealand. We act as your agent under the Privacy Act 2020, holding the data solely for you.
  • Singapore. We act as a data intermediary under the PDPA, processing only on your behalf.
  • Japan and South Korea. We act as a party entrusted with handling the data under the APPI and PIPA respectively, and process only within the scope you entrust.
  • India. We act as a data processor under the Digital Personal Data Protection Act 2023, on your behalf as data fiduciary.

Getting in touch

dpo@ghostnode.gg for anything under this agreement, including a signed copy, a completed security questionnaire, or a question about a specific sub-processor.


GhostNode Ltd is a company registered in England and Wales, company number 17414337. Registered office: 66 Paul Street, London, EC2A 4NA, United Kingdom. General enquiries support@ghostnode.gg; anything about personal data dpo@ghostnode.gg.

More policies

All policies