Data Processing Agreement (DPA) under Art. 28 GDPR between you as the operator of your DayZ server ("Controller") and Deacon Härschel as the provider of Brigarde Killfeed ("Processor"). It supplements the terms of service and applies automatically upon their acceptance.
This agreement governs the processing of personal data that arises from the use of Brigarde Killfeed on behalf of the Controller. It applies for the duration of use of the Service and ends automatically when that use ends.
The data processed is the data that results from the server logs (ADM files) of the DayZ server operated by the Controller (see privacy policy item 6), for the purpose of providing the kill feed, statistics, map display, and related features of the Service.
The data processed includes player identifiers/gamertags, in-game positions, kill and hit events, connection times, and possibly chat content of players on the Controller's server.
The Processor processes the data exclusively according to the Controller's settings configured via the dashboard (e.g. chosen feed channels, enabled features) and any further documented instructions.
The Processor takes appropriate technical and organisational measures under Art. 32 GDPR (including restricting access to each server's own data, encrypted transmission, session security) and binds any personnel involved to confidentiality.
The Processor uses PebbleHost (hosting) as a sub-processor. The use of further sub-processors will be announced to the Controller in advance; if the Controller does not object within 14 days, this is deemed consent.
The Processor assists the Controller, as far as technically possible, in fulfilling data subject rights (Art. 12-23 GDPR) and in notifications under Art. 33/34 GDPR, and will inform the Controller without undue delay of any personal data breach that becomes known to it and affects the Controller's data.
After use of the Service ends, data associated with the Controller's server will be deleted or returned upon the Controller's request, unless a statutory retention obligation applies (see privacy policy item 16 on retention after disconnecting).
The Controller may satisfy itself, to a reasonable extent, that this agreement is being complied with, in particular by reviewing the dashboard's diagnostics page; an on-site audit is not envisaged given the size of the operation, but can be discussed on request.
The liability provisions of the terms of service apply in addition.