This Data Processing Agreement ("DPA") forms part of the Games For Crowds Terms of Service, or another written agreement between the parties, governing the Customer's use of Games For Crowds (the "Agreement").
This DPA applies where Loquiz OÜ, incorporated in Estonia, European Union, operating Games For Crowds ("GFC," "Processor," "we," "us," or "our"), processes Customer Personal Data on behalf of a customer, game creator, school, business, event host, or other organisation using Games For Crowds ("Customer," "Controller," "you," or "your").
This DPA is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and equivalent data protection laws where applicable.
1. Definitions
For this DPA:
- Agreement means the Games For Crowds Terms of Service or other written agreement governing Customer's use of the Platform.
- Applicable Data Protection Laws means GDPR, the Estonian Personal Data Protection Act, the ePrivacy Directive and applicable national implementing laws, and any other privacy or data protection laws that apply to the processing of Customer Personal Data.
- Customer Personal Data means personal data that Customer provides to GFC, or that is collected through Customer's games, where GFC processes that data on behalf of Customer as processor.
- Data Subject means an identified or identifiable natural person to whom Customer Personal Data relates.
- Platform means gamesforcrowds.com, g4c.app, and related Games For Crowds services.
- Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.
- Subprocessor means another processor engaged by GFC to process Customer Personal Data.
The terms "controller," "processor," "personal data," "processing," and "supervisory authority" have the meanings given to them under GDPR.
2. Roles of the Parties
2.1 Customer as Controller
Customer is the controller of Customer Personal Data. Customer determines what personal data is collected through Customer's games, why it is collected, how long it is needed, and whether the collection is appropriate for the event, audience, jurisdiction, and game context.
Customer is responsible for:
- having a lawful basis for collecting and processing Customer Personal Data;
- giving players, participants, parents, guardians, employees, students, or other Data Subjects any privacy notices required by law;
- obtaining any required consents, including for minors, photos, videos, location-based gameplay, and AI-assisted features;
- ensuring that game content and questions do not request unnecessary, sensitive, unlawful, or inappropriate personal data;
- responding to Data Subject requests where Customer is responsible for the underlying data;
- complying with any sector-specific rules that apply to Customer, such as school, employment, child privacy, event, or public-sector obligations.
2.2 GFC as Processor
GFC acts as processor for Customer Personal Data when it hosts, stores, transmits, displays, analyses, or otherwise processes game-specific player data on Customer's behalf to provide the Platform.
GFC acts as an independent controller for personal data it processes for its own account administration, billing, security, website analytics, marketing, legal compliance, and platform operation purposes, as described in the Games For Crowds Privacy Policy.
3. Subject Matter and Duration
The subject matter, duration, nature, and purpose of the processing are described in Annex 1.
This DPA remains in effect for as long as GFC processes Customer Personal Data on behalf of Customer. It terminates automatically when the Agreement ends and GFC has deleted or returned Customer Personal Data as described in this DPA, unless Applicable Data Protection Laws require continued retention.
4. Customer Instructions
GFC will process Customer Personal Data only:
- to provide, secure, maintain, support, and improve the Platform;
- as documented in the Agreement, this DPA, the Privacy Policy, and Customer's configuration of the Platform;
- as otherwise instructed by Customer in writing;
- as required by Applicable Data Protection Laws.
If GFC believes an instruction infringes Applicable Data Protection Laws, GFC will inform Customer unless legally prohibited from doing so. GFC is not required to follow instructions that would require it to violate law, compromise platform security, or materially change the Platform outside the Agreement.
5. Confidentiality
GFC will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations, whether by contract, employment obligation, or statutory duty.
GFC will restrict access to Customer Personal Data to personnel and Subprocessors who need access to provide, secure, support, or maintain the Platform.
6. Security Measures
GFC will implement appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Current measures are described in Annex 2.
Customer acknowledges that security measures may evolve over time, provided that GFC does not materially reduce the overall level of protection for Customer Personal Data.
7. Subprocessors
Customer authorises GFC to use the Subprocessors listed in Annex 3 and to add or replace Subprocessors as needed to provide the Platform.
GFC will ensure that each Subprocessor is bound by written data protection obligations that are no less protective, in substance, than those in this DPA, to the extent applicable to the services provided by that Subprocessor.
GFC will maintain an up-to-date list of Subprocessors in this DPA or another location made available to Customer. Customer may object to a new Subprocessor on reasonable data protection grounds by contacting [email protected] within 30 days after notice or publication of the change. If the parties cannot resolve the objection, Customer may stop using the affected services and terminate the affected part of the Agreement.
8. International Data Transfers
GFC is established in Estonia, European Union. Some Subprocessors may process Customer Personal Data outside the European Economic Area.
Where Customer Personal Data is transferred outside the EEA, GFC will use appropriate safeguards under Chapter V of the GDPR, such as:
- an adequacy decision by the European Commission;
- the EU-US Data Privacy Framework where the recipient is certified and the framework applies;
- the European Commission's Standard Contractual Clauses;
- another lawful transfer mechanism permitted by Applicable Data Protection Laws.
Where Standard Contractual Clauses are required for a transfer of Customer Personal Data, the parties agree that the applicable clauses are incorporated by reference to the extent necessary. The parties will complete any required supplementary information reasonably needed to give effect to those clauses.
9. Data Subject Requests
Taking into account the nature of the processing, GFC will provide reasonable assistance to Customer, where technically feasible, to help Customer respond to Data Subject requests to access, correct, delete, restrict, object to, or port Customer Personal Data.
If GFC receives a request directly from a Data Subject relating to Customer Personal Data, GFC may direct the Data Subject to Customer unless required by law to respond directly.
Customer remains responsible for verifying the identity of the Data Subject and deciding how to respond to the request.
10. Assistance With Compliance
Taking into account the nature of processing and the information available to GFC, GFC will provide reasonable assistance to Customer with Customer's obligations under Articles 32 to 36 of the GDPR, including security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, where applicable.
GFC may charge reasonable fees for assistance that goes beyond standard support, unless the assistance is required because of GFC's breach of this DPA.
11. Security Incident Notification
GFC will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.
The notice will include information reasonably available to GFC, such as:
- the nature of the Security Incident;
- the categories and approximate number of affected Data Subjects and records, where known;
- likely consequences, where known;
- measures taken or proposed to address the Security Incident.
GFC's notification of a Security Incident is not an acknowledgement of fault or liability.
Customer is responsible for determining whether it must notify Data Subjects, supervisory authorities, customers, schools, parents, guardians, or other third parties, except where GFC has a direct legal obligation to notify.
12. Return and Deletion
Upon termination of the Agreement, Customer may request deletion or return of Customer Personal Data where available through the Platform or by contacting [email protected].
GFC will delete or anonymise Customer Personal Data within a reasonable period after termination or deletion request, unless retention is required by law, needed for security, fraud prevention, dispute resolution, accounting, backup integrity, or otherwise permitted by Applicable Data Protection Laws.
Photos and videos captured during gameplay are automatically deleted 30 days after capture, including copies sent to AI processors for processing, as described in the Privacy Policy.
Account data may be retained for 30-90 days after account deletion to allow account recovery and operational deletion cycles. Payment records and billing history may be retained for 5-7 years for tax, legal, and financial compliance.
13. Audits and Information
GFC will make available information reasonably necessary to demonstrate compliance with this DPA.
Customer may request audit information by contacting [email protected]. GFC may satisfy audit requests by providing security documentation, policies, summaries, third-party certifications, Subprocessor information, or written responses.
On-site audits are permitted only where legally required and only after reasonable notice, during normal business hours, under confidentiality obligations, and in a manner that does not compromise the security, confidentiality, availability, or privacy of GFC systems or other customers' data.
14. Customer Responsibilities for Games
Because Customer controls game content and gameplay configuration, Customer must not use the Platform to collect personal data that is unnecessary, excessive, unlawful, or inappropriate for the game context.
Customer must not use the Platform to collect:
- government identity numbers, payment card numbers, bank details, passwords, or authentication secrets;
- medical, health, biometric, genetic, or highly sensitive information unless Customer has a lawful basis and GFC has agreed in writing;
- information from children without any legally required parental, guardian, school, or institutional authorisation;
- precise location data unless it is necessary for the game and properly disclosed to participants;
- photos or videos without any consent or notice required by law.
Customer is responsible for reviewing AI-assisted game features before use and for ensuring that prompts, photos, and other inputs submitted to AI features are lawful, appropriate, and not unnecessarily sensitive.
15. Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless Applicable Data Protection Laws require otherwise.
Nothing in this DPA limits liability that cannot legally be limited.
16. Order of Precedence
If there is a conflict between this DPA and the Agreement, this DPA controls with respect to the processing of Customer Personal Data.
If Standard Contractual Clauses apply and conflict with this DPA or the Agreement, the Standard Contractual Clauses control for the relevant restricted transfer.
17. Contact
Questions, DPA requests, Subprocessor objections, and privacy-related notices may be sent to:
Email: [email protected]
Legal entity: Loquiz OÜ, incorporated in Estonia, European Union
Website: gamesforcrowds.com
Annex 1: Processing Details
A. Subject Matter
GFC processes Customer Personal Data to provide the Games For Crowds Platform, including game hosting, gameplay sessions, game configuration, player participation, media handling, AI-assisted features, analytics available to Customer, support, security, and account administration related to Customer's use of the Platform.
B. Duration
For the term of the Agreement and thereafter as necessary for deletion, backup cycles, legal compliance, dispute resolution, security, fraud prevention, and accounting.
C. Nature and Purpose of Processing
GFC may collect, receive, host, store, transmit, display, organise, retrieve, analyse, generate, transform, delete, and otherwise process Customer Personal Data to:
- host and operate Customer's games;
- allow players to join and participate in games;
- record gameplay progress, scores, choices, completion status, and session information;
- provide game creator dashboards, statistics, and exports where available;
- process photos, videos, prompts, text, or other inputs submitted through game features;
- provide AI-assisted text, quiz, photo analysis, and photo manipulation features where enabled;
- provide customer support and troubleshooting;
- protect the Platform against abuse, fraud, unauthorised access, and security threats;
- comply with legal obligations.
D. Categories of Data Subjects
- Game Creators and their authorised team members
- Game players and participants
- Event attendees
- Students, pupils, or children participating in games, where Customer lawfully uses GFC in those settings
- Customer staff, contractors, or representatives
- Individuals whose information is entered into a game by Customer or players
E. Categories of Customer Personal Data
Depending on Customer's configuration and player choices, Customer Personal Data may include:
- names, nicknames, pseudonyms, or player identifiers;
- gameplay responses, scores, choices, progress, completion time, and session data;
- photos, videos, and media submitted or captured during gameplay;
- device location where a location-based game feature is enabled and the player grants permission;
- prompts, topics, text, image inputs, and outputs associated with AI-assisted features;
- IP address, browser, device, and technical log data;
- game creator account contact details and team member information where processed on Customer's behalf;
- other information that Customer or players choose to submit through a game.
Customer must not intentionally submit special category data or highly sensitive data unless Customer has a lawful basis and GFC has agreed in writing.
F. Special Category Data
The Platform is not designed for intentional collection of special category data under Article 9 GDPR. However, photos, videos, free-text answers, prompts, or game content may incidentally reveal sensitive information. Customer is responsible for configuring games to avoid unnecessary or unlawful collection of such data.
G. Processing Location
Primary processing is performed in the European Union or through GFC's infrastructure and service providers. Subprocessors may process data in other locations subject to the safeguards described in this DPA.
Annex 2: Technical and Organisational Measures
GFC maintains technical and organisational measures designed to protect Customer Personal Data, including:
A. Access Control
- Google Sign-In / OAuth-based authentication for account access
- Session tokens with limited lifetime
- Role- or permission-based access where supported by the Platform
- Access limited to authorised personnel and service providers with a need to know
B. Transmission Security
- HTTPS encryption for data transmitted to and from the Platform
- Secure payment processing handled by Stripe; GFC does not collect or store credit card numbers
C. Infrastructure Security
- Hosting through professional cloud infrastructure providers
- Cloudflare bot protection and traffic filtering
- Server-side logging for security, troubleshooting, and abuse prevention
- Regular platform maintenance and security updates as reasonably appropriate
D. Data Minimisation and Retention
- Players can participate without creating accounts
- Players may use pseudonyms or nicknames
- Photos and videos are automatically deleted 30 days after capture
- Account data deletion and retention periods as described in the Privacy Policy
- Payment and billing records retained only as needed for tax, legal, and financial compliance
E. Confidentiality and Personnel Controls
- Personnel access limited according to operational need
- Confidentiality obligations for personnel with access to personal data
- Internal handling practices designed to reduce unnecessary access to Customer Personal Data
F. Resilience and Recovery
- Infrastructure and backup practices designed to support service continuity and recovery
- Incident response processes for suspected or confirmed Security Incidents
G. Subprocessor Management
- Use of reputable third-party providers for hosting, payments, authentication, analytics, newsletter forms, security, and AI-assisted features
- Written data protection terms with Subprocessors where available and applicable
- Transfer safeguards for international processing where required
Annex 3: Subprocessors
GFC uses the following Subprocessors or third-party service providers to provide, secure, maintain, and support the Platform. The exact use of each provider may depend on Customer's configuration and the features used.
| Subprocessor | Purpose | Data Processed | Location / Transfer Notes |
|---|---|---|---|
| DigitalOcean | Hosting and infrastructure | Server logs, hosted game data, account and gameplay data as needed to operate the Platform | May process in the EEA or other regions; DPA and transfer safeguards available |
| Cloudflare | Security, bot protection, traffic filtering, CDN/infrastructure support | IP address, device/browser data, traffic metadata, security logs | May process outside the EEA; relies on applicable transfer safeguards |
| Google Sign-In, Google Analytics, Google Tag Manager, Google Gemini | Authentication data, analytics data where consented, photos submitted to Gemini-enabled AI features | May process outside the EEA; Google privacy and business data protection terms apply | |
| Stripe | Payment processing | Billing contact details, transaction confirmations, payment metadata; GFC does not store credit card numbers | May process outside the EEA; Stripe DPA and transfer safeguards apply |
| MailerLite | Newsletter forms and mailing list management | Newsletter sign-up details, email address, form interaction data, unsubscribe data | May process outside the EEA; MailerLite DPA and transfer safeguards apply |
| OpenAI | AI text and quiz generation | Prompts, topics, text inputs, generated outputs submitted to AI text features | May process outside the EEA; OpenAI data processing terms and transfer safeguards apply |
GFC may update this list from time to time. Customer may request current Subprocessor information by contacting [email protected].
Annex 4: Standard Contractual Clauses
Where the Standard Contractual Clauses are required for a restricted transfer of Customer Personal Data, the following terms apply unless the parties agree otherwise in writing:
- Module: Controller-to-Processor, where Customer is the controller and GFC is the processor.
- Docking Clause: Included.
- Subprocessor Authorisation: General authorisation, subject to the Subprocessor notice and objection process in this DPA.
- Governing Law: Estonian law, where permitted by the Standard Contractual Clauses.
- Supervisory Authority: Estonian Data Protection Inspectorate, where applicable.
- Processing Details: Annex 1 of this DPA.
- Technical and Organisational Measures: Annex 2 of this DPA.
- Subprocessors: Annex 3 of this DPA.
If a different SCC module is required by law because of the parties' roles or locations, the parties will apply the module that most closely reflects the actual transfer and processing relationship.