Last updated 2026-09-27

Data processing agreement

This agreement sets out how DealCraft processes personal data on behalf of a business that uses it. It forms part of the Master service agreement and applies automatically to every business account.


Scope and applicable law

This Data processing agreement (“DPA”) applies whenever DealCraft processes personal data on behalf of the Customer while providing the Service. It is written to meet Article 28 of the EU General Data Protection Regulation (“GDPR”), the UK GDPR where it applies, and the Law of Georgia on Personal Data Protection.

Terms such as controller, processor, processing, data subject and personal data breach have the meanings given in those laws. Capitalised terms not defined here have the meanings in the Master service agreement.

Roles

For player data collected through the Customer's Games, the Customer is the controller and DealCraft is the processor.

For the Customer's own account and billing data, and for player accounts that players create with DealCraft directly, DealCraft is an independent controller, as described in the Privacy notice. Dodo Payments processes payment data as an independent controller in its role as merchant of record.

Processing only on instructions

DealCraft processes personal data only on the Customer's documented instructions. The settings the Customer chooses in the Service, this DPA and the Master service agreement are those instructions. DealCraft will inform the Customer if it believes an instruction breaks the law, and will not process personal data for any other purpose unless the law requires it.

Details of the processing

Data subjects: players of the Customer's Games and, where used, the Customer's counter staff.

Categories of data: email addresses a Game asks for, reward codes and their status, play records (result, time, language, country derived from the network, device type, browser and operating system), a device cookie identifier, a hash of a browser fingerprint and a keyed hash of a shortened network address. DealCraft does not store raw IP addresses and does not process special categories of data.

Purpose: running the Customer's Games, enforcing their limits, preventing abuse, issuing and checking Rewards, and reporting results to the Customer.

Duration: for as long as the Customer uses the Service, and afterwards as set out under Deletion.

Confidentiality of personnel

DealCraft ensures that anyone authorised to process personal data is bound by confidentiality and processes it only as needed for the Service.

Security measures

DealCraft maintains appropriate technical and organisational measures, including: encryption of data in transit with TLS; hashing of passwords with scrypt and of API secrets with SHA-256; encryption of stored signing secrets with AES-256-GCM; storing network addresses only as keyed hashes; isolation of every customer's data at the database layer; rate limits against abuse; daily backups; and access to production restricted to the operator. The Security page describes these measures in more detail.

Subprocessors

The Customer authorises DealCraft to use the subprocessors listed below. DealCraft imposes data protection obligations on each of them that are no less protective than this DPA and remains responsible for their performance.

DealCraft will announce a new subprocessor by email at least 14 days before it starts processing Customer personal data. If the Customer objects on reasonable data protection grounds and the parties cannot agree a solution, the Customer may terminate the affected Service without penalty.

International transfers

Customer personal data is hosted on Oracle Cloud in the United Arab Emirates. Email is delivered through Resend in the United States, and Google is involved only when a player chooses to sign in with Google.

Where a transfer requires safeguards under the GDPR, the UK GDPR or the Law of Georgia on Personal Data Protection, DealCraft relies on the European Commission's standard contractual clauses or another mechanism those laws recognise. The Customer may ask for a copy of the relevant safeguards.

Helping the Customer

DealCraft will forward to the Customer, within five business days, any request it receives from a data subject about the Customer's data, and will help the Customer respond to requests to access, correct, delete, restrict or port data.

DealCraft will provide reasonable information and help for the Customer's data protection impact assessments and consultations with supervisory authorities.

Personal data breaches

DealCraft will notify the Customer without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting Customer personal data. The notice will describe, as far as is known, the nature of the breach, the data and people affected, the likely consequences and the measures taken or proposed.

DealCraft will take reasonable steps to contain the breach and will support the Customer in meeting its own obligations to notify authorities and data subjects.

Deletion and return

When the Service ends, the Customer can ask for an export of its data for 30 days. DealCraft then deletes Customer personal data within a further 30 days, unless the law requires it to be kept. Copies in backups are overwritten within 30 days of deletion from the live database.

Information and audits

DealCraft will make available the information needed to demonstrate compliance with this DPA and will answer reasonable security questionnaires. Where that is not enough, the Customer may carry out an audit, at its own cost, once a year, with at least 30 days' written notice, during business hours and without access to other customers' data.

Liability

Each party's liability under this DPA is subject to the limitations in the Master service agreement, except where the law does not allow such a limit.

Order of precedence

If this DPA conflicts with the Master service agreement or the Terms of service on the processing of personal data, this DPA prevails. Where standard contractual clauses apply, they prevail over this DPA.

Subprocessors

Every company that processes personal data for DealCraft, what it does and where.

CompanyWhat it doesData it handlesLocation
Oracle CloudHosting of the application, the database and the backupsAll data the service storesUnited Arab Emirates
ResendDelivery of emails such as confirmations and claim codesEmail address and message contentUnited States
GoogleSign-in with Google, only when a user chooses itName, email address and profile pictureUnited States
Dodo PaymentsPayments and subscriptions, as merchant of record (independent controller)Business billing details and payment dataSeveral countries, as set out in the Dodo Payments privacy policy