EU, UK and Swiss Data Protection

Version 4.0. | Effective date: 2 November 2026

This Data Processing Addendum, including its Annexes (the Addendum), forms part of and is subject to the GameAnalytics Terms and Conditions, including their Part A (General Terms) and Part B (Product Terms), or the applicable written master services or subscription agreement between the Customer and GameAnalytics Limited, together with any Order Form (together, the Agreement). It records the terms on which GameAnalytics processes Personal Data on behalf of the Customer in connection with the Services and applies to every Product, whether used as a Free Feature or under a Subscription.

GameAnalytics Limited is a company registered in England and Wales under number 09214168, a wholly owned subsidiary of GameAnalytics ApS (Denmark, CVR 34043221). GameAnalytics Limited is the contracting entity under the Agreement. GameAnalytics ApS operates the Services and the information security management system that supports them. References to GameAnalytics, we, us or our mean GameAnalytics Limited and, where it acts as a member of the processing group, GameAnalytics ApS.

1. Definitions and interpretation

1.1 Capitalised terms used but not defined in this Addendum have the meaning given in the Agreement. The following definitions apply.

  • Applicable Data Protection Law means all laws and regulations relating to the processing of Personal Data and privacy that apply to a party, including, as applicable: (a) Regulation (EU) 2016/679 (the EU GDPR); (b) the EU GDPR as retained in United Kingdom law by the European Union (Withdrawal) Act 2018 (the UK GDPR) together with the Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection; (d) Regulation (EU) 2022/2065 and Regulation (EU) 2024/1689 (the EU AI Act) to the extent applicable to the Services; and (e) the ePrivacy rules and the United States state privacy laws referred to in Annex 4, in each case as amended or replaced.
  • Controller, Processor, Data Subject, Personal Data, Special Category Personal Data, processing, personal data breach have the meaning given in the EU GDPR, and cognate terms are construed accordingly. Where the UK GDPR or a United States state privacy law applies, the equivalent terms under that law apply (for example business, service provider, consumer and sensitive personal information).
  • Customer-Enabled Integration means any feature by which the Customer directs Customer Personal Data to a destination or tool of the Customer's own choosing, including Data Export, the self-hosted Metrics API Model Context Protocol server, any artificial intelligence client or tool connected by the Customer to the Services, Game Data Sharing and Game Transfer.
  • Customer Personal Data means Personal Data contained in the End User Data and any other Personal Data that GameAnalytics processes on behalf of the Customer as Processor under the Agreement, as described in Annex 1. It excludes Personal Data that GameAnalytics processes as Controller under clause 2.2, and excludes MarketIQ content and Ad Insights API data, which are compiled by GameAnalytics and its data partners and are not processed on the Customer's behalf.
  • End User means an individual who plays, installs or interacts with a game or application operated by the Customer and from which the GameAnalytics software development kit or collection API transmits event data.
  • End User Data means the event and device data transmitted to the Services from the Customer's games, as further described in Annex 1.
  • Restricted Transfer means a transfer of Customer Personal Data to, or access from, a country or territory not benefiting from an adequacy decision under Applicable Data Protection Law.
  • Standard Contractual Clauses or SCCs means (a) for transfers subject to the EU GDPR, the clauses annexed to Commission Implementing Decision (EU) 2021/914; (b) for transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner (the UK Addendum) or the International Data Transfer Agreement (the IDTA); and (c) for transfers subject to Swiss law, the EU SCCs as adapted by the Swiss Federal Data Protection and Information Commissioner.
  • Sub-processor means any third party engaged by GameAnalytics to process Customer Personal Data in the performance of the Services. A provider engaged by GameAnalytics solely to support processing that GameAnalytics carries out as Controller under clause 2.2, such as identity, authentication, logging, billing, support or website tooling, is not a Sub-processor and is described in the Privacy Notice.

1.2 A reference to a statute or statutory provision is a reference to it as amended, extended or re-enacted. The Annexes form part of this Addendum. In the event of conflict, the order of precedence is: the SCCs (where engaged), then this Addendum, then the remainder of the Agreement, in each case solely on data protection matters.

2. Roles of the parties and scope

2.1 The parties acknowledge that, in respect of the End User Data processed through the Services, the Customer acts as Controller and GameAnalytics acts as Processor. The Customer determines the purposes and means of the processing of End User Data and is responsible for establishing a lawful basis for that processing and for providing all notices and, where required, obtaining all consents from End Users, including any consent required for the storage of or access to information on an End User's device and for the use of advertising identifiers.

2.2 GameAnalytics processes certain Personal Data as an independent Controller for its own business purposes, including: account creation and administration; authentication and identity management for dashboard, API and Model Context Protocol access, including OAuth grants and tokens; issuance and management of Credentials; billing; security monitoring and access logging, including server-side logs of API, Model Context Protocol and Ad Insights API requests; service improvement in aggregate and non-identifying form; and direct communications with the Customer's authorised users. That processing is governed by the GameAnalytics Privacy Notice and not by this Addendum.

2.3 Where the Customer uses a Customer-Enabled Integration, the allocation of roles set out in clause 9 applies.

2.4 Where the Customer uses Game Data Sharing to receive data from another GameAnalytics customer, GameAnalytics processes the shared data as Processor of the sharing customer up to the point of sharing and as Processor of the Customer thereafter, and each customer is responsible for its own lawful basis.

2.5 This Addendum applies to processing that is subject to Applicable Data Protection Law. It does not extend or vary the scope of processing beyond what is described in Annex 1.

3. GameAnalytics obligations as Processor

3.1 Documented instructions. GameAnalytics processes Customer Personal Data only on the documented instructions of the Customer, including the instructions set out in the Agreement, this Addendum and the Customer's configuration of the Services, unless required to process by law to which GameAnalytics is subject, in which case GameAnalytics informs the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest. The Customer's configuration of the Services, including the events and fields it chooses to transmit, the Products and features it enables, the users it authorises and the destinations it selects, constitutes documented instructions.

3.2 Instruction outside scope. GameAnalytics informs the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, without any obligation to conduct a legal review of the adequacy of the Customer's instructions.

3.3 Confidentiality. GameAnalytics ensures that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and process the data only on instruction.

3.4 Security. GameAnalytics implements and maintains the technical and organisational measures set out in Annex 3, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects. GameAnalytics ApS maintains certification of its information security management system to ISO/IEC 27001:2022, covering the Services and their supporting infrastructure on Amazon Web Services and Google Cloud, and GameAnalytics undergoes an annual SOC 2 Type II examination and holds the kidSAFE COPPA certification and has been awarded the ePrivacy seal, which is currently under periodic reassessment, relevant to the Services. GameAnalytics may change the measures in Annex 3 provided that the change does not materially reduce the level of security.

3.5 Assistance. Taking into account the nature of the processing and the information available to it, GameAnalytics assists the Customer by appropriate technical and organisational measures, insofar as reasonably possible, with the Customer's obligations to respond to Data Subject requests under clause 4, and with the Customer's obligations relating to security, personal data breach notification, data protection impact assessments and prior consultation under Articles 32 to 36 of the EU GDPR and equivalent provisions. GameAnalytics may charge a reasonable fee for assistance that goes beyond the self-service functionality of the Services and the information published on its trust portal, and clause 4 applies to assistance with Data Subject requests.

3.6 Records. GameAnalytics maintains a record of processing activities carried out on behalf of the Customer as required by Article 30(2) of the EU GDPR and makes it available to the Customer on reasonable request.

4. Data Subject requests

4.1 GameAnalytics promptly notifies the Customer if it receives a request from a Data Subject to exercise rights of access, rectification, erasure, restriction, portability or objection, or any equivalent right under a United States state privacy law, in each case in respect of Customer Personal Data, and does not respond to that request itself except on the documented instruction of the Customer or as required by law. GameAnalytics may inform the Data Subject that the request should be addressed to the Customer as Controller.

4.2 GameAnalytics provides the Customer with self-service functionality, where included in the Customer's Subscription, and reasonable assistance to enable the Customer to respond to such requests. The Customer acknowledges that End User Data is keyed to pseudonymous identifiers and that the Customer must supply the relevant identifier of each Data Subject concerned to enable location of the data. Where the Customer's Subscription includes functionality allowing the Customer to locate, access or delete the End User Data of an individual Data Subject, the Customer uses that functionality first.

4.3 Assistance beyond self-service functionality is provided on the Customer's written instruction sent to privacy@gameanalytics.com, identifying each Data Subject by the relevant identifier, and is limited to the End User Data of the Data Subjects so identified that GameAnalytics holds at the date of the instruction. GameAnalytics provides it in a machine-readable format, separately for each Data Subject. Such assistance is free of charge for up to ten Data Subjects per Customer per calendar month. Assistance for additional Data Subjects is charged at the administrative fee per Data Subject published on the Pricing Page or, where none is published, at a reasonable fee notified to the Customer before the assistance is provided.

4.4 An instruction covering more than fifty Data Subjects in any calendar month, or which in substance concerns all or a significant part of the End Users of a Game, is a request for the export of End User Data and not assistance under clause 4.3. GameAnalytics fulfils such a request through the export functionality of PipelineIQ at the Fees published on the Pricing Page or stated in an Order Form, and informs the Customer before any Fees apply. No Fees apply under clauses 4.3 and 4.4 where the request results from a breach of this Addendum by GameAnalytics.

4.5 On receipt of an instruction under clause 4.3, GameAnalytics extracts the End User Data of the identified Data Subjects without undue delay, provided the instruction is received while that data is still held under the retention periods in Annex 1. A Data Subject request does not otherwise extend those retention periods, and GameAnalytics does not restore or retain data beyond those periods by reason of such a request.

4.6 Each instruction under clause 4.3 confirms that it corresponds to a request actually received by the Customer from the Data Subject concerned. On request, the Customer informs GameAnalytics of the number and dates of the requests received, without disclosing their content. Section 10.2 of the Agreement applies to the use of assistance under this clause for any other purpose.

5. Personal data breach

5.1 GameAnalytics notifies the Customer without undue delay, and in any event within seventy-two hours, after becoming aware of a personal data breach affecting Customer Personal Data. Notification is given to the email address of the Customer's Account administrator or, where designated, the security contact on the Order Form. The notification describes, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it, and may be provided in phases as information becomes available. The GameAnalytics contact for data protection matters is the Director Legal & Compliance, at privacy@gameanalytics.com.

5.2 GameAnalytics takes reasonable steps to contain and remediate the breach and cooperates with the Customer in the Customer's fulfilment of its own notification obligations. A notification under this clause is not an acknowledgement of fault or liability. A security event that does not result in unauthorised access to, or loss, alteration or disclosure of, Customer Personal Data, including an unsuccessful attempt or a remediated vulnerability, is not a personal data breach for the purposes of this clause.

5.3 Where a breach affects Personal Data that GameAnalytics processes as Controller under clause 2.2, GameAnalytics handles notification to the individuals concerned and to supervisory authorities itself, and informs the Customer where the Customer's authorised users are affected.

6. Sub-processors

6.1 General authorisation. The Customer grants GameAnalytics general authorisation to engage Sub-processors, subject to this clause. The Sub-processors engaged as at the effective date are set out in Annex 2 and in the current list published on the GameAnalytics website or trust portal.

6.2 Flow-down. GameAnalytics imposes on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this Addendum, in particular sufficient guarantees to implement appropriate technical and organisational measures. GameAnalytics remains liable to the Customer for the performance of each Sub-processor's obligations.

6.3 Changes. GameAnalytics gives the Customer at least fourteen days prior notice of the addition or replacement of a Sub-processor by updating the published list and by notice through the platform or by email to the Customer's Account administrator. The Customer may object on reasonable data protection grounds within fourteen days of the notice. If the parties cannot resolve the objection within a further fourteen days, the Customer may terminate the affected Product or feature, as its sole and exclusive remedy, on written notice, and any prepaid Fees for the unused remainder of the Subscription Term for that Product are refunded pro rata.

6.4 Emergency replacement. Where a Sub-processor must be replaced urgently for security or continuity reasons, GameAnalytics may do so before the notice period expires and informs the Customer without undue delay; the objection right in clause 6.3 applies from that notice.

6.5 Providers supporting processing that GameAnalytics carries out as Controller under clause 2.2 are not Sub-processors, are not subject to the notice and objection mechanism in this clause, and are listed in the Privacy Notice.

7. International transfers

7.1 GameAnalytics does not carry out a Restricted Transfer of Customer Personal Data except where an appropriate transfer mechanism is in place. Where the recipient is certified under the EU-US Data Privacy Framework, the UK Extension to the EU-US Data Privacy Framework or the Swiss-US Data Privacy Framework, and the transfer falls within the scope of that certification, the parties rely on that framework.

7.2 Where a Data Privacy Framework does not apply, the parties enter into the Standard Contractual Clauses, which are incorporated by reference and completed as set out in Annex 4. For transfers subject to the EU GDPR, module two (Controller to Processor) applies; for onward transfers to Sub-processors, module three (Processor to Processor) applies. For transfers subject to the UK GDPR, the UK Addendum applies to the EU SCCs. For transfers subject to Swiss law, the EU SCCs apply as adapted by the Swiss authority. Acceptance of the Agreement constitutes execution of the SCCs by both parties.

7.3 GameAnalytics makes available to the Customer, on reasonable request, information relevant to the transfer, including a transfer impact assessment, and adopts supplementary measures where necessary to ensure a level of protection essentially equivalent to that guaranteed within the European Economic Area and the United Kingdom.

7.4 Hosting locations. Customer Personal Data is hosted in the regions stated in Annex 2. Support, maintenance and security operations may involve remote access from the locations of GameAnalytics personnel and Sub-processors as described in Annex 2, under the transfer mechanisms in this clause.

8. AI-powered features

8.1 AI Agent. Where the Customer uses the in-tool AI Agent, GameAnalytics processes the Customer's GameAnalytics data through a managed large language model provided by a Sub-processor listed in Annex 2, currently Amazon Web Services (Amazon Bedrock). Customer Personal Data processed through the AI Agent is not used to train, fine-tune or improve any foundation model, and is not retained by the model provider beyond the transient processing necessary to generate a response. GameAnalytics designs prompts to use aggregated or pseudonymous data where the feature permits. AI Agent sessions are logged and traced through an observability Sub-processor listed in Annex 2, solely to operate, debug and assure the quality of the feature. Any change of model provider is a Sub-processor change under clause 6.

8.2 Transparency. The AI Agent is a limited-risk artificial intelligence system for the purposes of the EU AI Act. Its outputs are generated by automated means, may contain errors, and are provided for informational purposes. The AI Agent does not carry out automated decision-making producing legal or similarly significant effects on Data Subjects.

8.3 Documentation Helper. The GameAnalytics Documentation Helper is a separate, publicly available assistant hosted by OpenAI. It operates on GameAnalytics product documentation only and does not process Customer Personal Data. The Customer's use of the Documentation Helper is governed by the terms of the hosting provider and not by this Addendum.

8.4 GameAnalytics-hosted Model Context Protocol services. Where GameAnalytics makes available a GameAnalytics-hosted Model Context Protocol server, GameAnalytics processes Customer Personal Data returned through that server as Processor under this Addendum. As at the effective date the hosted server returns aggregated metrics only and does not return End User level data; GameAnalytics will notify the Customer under clause 6.3 before any End User level data is made available through the hosted server. Authentication, authorisation and request logging for the hosted server are carried out by GameAnalytics as Controller under clause 2.2, and the artificial intelligence client connected by the Customer is a Customer-Enabled Integration under clause 9.

8.5 Labs, early access and beta features. Features made available under Labs (including AI Labs), as early access or as beta features process Customer Personal Data on the same terms as this Addendum unless the enrolment terms for the feature state otherwise.

9. Customer-Enabled Integrations and boundary of responsibility

9.1 Certain features allow the Customer to direct Customer Personal Data to a destination or tool of the Customer's own choosing. These include, without limitation: Data Export to the Customer's AWS or Google Cloud storage; the self-hosted, open-source Metrics API Model Context Protocol server operated by the Customer; the connection of GameAnalytics data, including through the GameAnalytics-hosted Model Context Protocol server or any application programming interface, to third-party artificial intelligence clients, models, agents and other tools selected by the Customer; Game Data Sharing; and Game Transfer.

9.2 Boundary of responsibility. GameAnalytics acts as Processor only up to the point at which Customer Personal Data is delivered to, or accessed by, the Customer-controlled destination or tool. From that point, GameAnalytics has no control over and accepts no responsibility for the onward processing of that data. The Customer is the Controller in respect of all such onward processing and is solely responsible for the lawfulness, security and governance of that processing, including the selection and configuration of any third-party tool, any retention of data in that tool's history or storage after the Customer's access to the Services or the relevant Credential ends, and any transfer arising from it.

9.3 Delegated access. Where the Customer authorises a tool to access the Services on behalf of an authorised user, GameAnalytics validates that user's permissions on each request and rejects requests from users whose access has been removed. Revocation of the authorisation withdraws the tool's ability to make further requests and does not retrieve data already delivered.

9.4 GameAnalytics gives no representation or warranty regarding any third-party tool, model or client to which the Customer connects Customer Personal Data, and the Customer's use of any such tool is at the Customer's own risk and subject to that third party's terms.

10. Children's data

10.1 The Services are not directed to children and GameAnalytics does not knowingly collect Personal Data from children without the required consent. Where the Customer operates a game that is directed to children or is likely to be accessed by children, the Customer is responsible for configuring the Services so that persistent identifiers and related data are used solely to support the internal operations of the Customer's game, and for disabling any collection or use of advertising identifiers or behavioural profiling that is not permitted for such games, including the use of user-level features under SegmentIQ for purposes other than internal operations.

10.2 GameAnalytics processes persistent identifiers collected from child-directed games only to support internal operations as instructed by the Customer, and not to contact a child, to serve targeted advertising to a child, or to build a profile of a child for any other purpose. This clause reflects GameAnalytics obligations under the United States Children's Online Privacy Protection Act and its implementing rule, the United Kingdom Age Appropriate Design Code, and applicable European guidance on the processing of children's data. The Customer remains responsible for age assurance, for its own compliance with those regimes, and for determining whether its game is child-directed.

10.3 GameAnalytics does not make End User Data from games configured as child-directed available through AI-powered features or Customer-Enabled Integrations except in aggregated form, unless the Customer expressly instructs otherwise and confirms that the instruction is compatible with the regimes referred to in clause 10.2.

11. Audit and demonstration of compliance

11.1 GameAnalytics makes available to the Customer the information reasonably necessary to demonstrate compliance with this Addendum, including its current ISO/IEC 27001 certificate and SOC 2 Type II report, which the Customer may access through the GameAnalytics trust portal or on request, subject to confidentiality.

11.2 Where the reports and certifications referred to above are not sufficient to demonstrate compliance, GameAnalytics allows for and contributes to an audit, including an inspection, conducted by the Customer or an independent auditor mandated by the Customer, subject to reasonable prior written notice of at least thirty days, no more than once in any twelve-month period except where required by a supervisory authority or following a personal data breach affecting the Customer, during business hours, subject to confidentiality, and in a manner that does not disrupt GameAnalytics operations or compromise the security of other customers' data. The Customer bears its own costs and the reasonable costs of GameAnalytics in supporting the audit. As GameAnalytics operates remotely and on third-party cloud infrastructure, an inspection is conducted by remote interview and review of documentation and system evidence, and access to cloud provider facilities is governed by the provider's own audit programme.

12. Return and deletion

12.1 On termination or expiry of the Agreement, or of the Subscription or Product to which the data relates, and at the choice of the Customer, GameAnalytics deletes or returns Customer Personal Data processed on behalf of the Customer, and deletes existing copies, unless retention is required by law. The Customer may export its data using the functionality of the Services before termination. Return under this clause is fulfilled by making that functionality available until the effective date of termination, in the form and to the extent included in the Customer's Subscription at that date. Any extraction, format or delivery beyond that functionality is a separately chargeable service, and clause 4.4 applies to it. Deletion from production systems is completed within thirty days of termination. Deleted records are purged from the point-in-time recovery archive within a further five days. Where the Customer deletes a Game or an Organization through the platform, deletion of the related Customer Personal Data follows the same periods.

12.2 GameAnalytics may retain Customer Personal Data in aggregated or de-identified form that does not permit identification of a Data Subject, and may retain records to the extent required to establish, exercise or defend legal claims or to comply with a legal obligation. Retention periods applicable to the Services are described in Annex 1.

13. Liability

13.1 Each party's liability arising out of or related to this Addendum, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to the liability of a party means the single aggregate liability of that party under the Agreement, every Order Form and this Addendum together.

13.2 Nothing in this Addendum limits either party's liability to a Data Subject under the third-party beneficiary provisions of the Standard Contractual Clauses, or limits any liability that cannot be limited under Applicable Data Protection Law.

14. General

14.1 Governing law. This Addendum is governed by the laws of England and Wales, and disputes are resolved as set out in the Agreement, except that where the Standard Contractual Clauses require a specified governing law and forum, the SCCs are governed by the law of Denmark and disputes under them are subject to the courts of Denmark for transfers subject to the EU GDPR.

14.2 Term. This Addendum takes effect on the effective date and continues for as long as GameAnalytics processes Customer Personal Data under the Agreement. It supersedes any previous data processing addendum between the parties in respect of the Services from its effective date, subject to the transition rule for signed Order Forms in the Agreement.

14.3 Variation. GameAnalytics may update this Addendum on notice where required to reflect a change in Applicable Data Protection Law, a change in Sub-processors or transfer mechanisms, or a change in the Services, provided that no update materially reduces the protection afforded to Customer Personal Data.

14.4 Order of precedence within transfers. Where there is any conflict between this Addendum and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

Annex 1. Description of processing

Subject matter and duration. The provision of the GameAnalytics analytics, live operations, data pipeline and artificial intelligence Services to the Customer, for the duration of the Agreement and any period of retention described below.

Nature and purpose of processing. Collection, storage, structuring, aggregation, analysis and display of game event data to enable the Customer to measure and improve the performance of its games, including analytics (AnalyticsIQ), segmentation, experimentation and live configuration (SegmentIQ), data pipelines, warehousing, export and programmatic access (PipelineIQ), and the AI-powered features described in clause 8. MarketIQ and the Ad Insights API operate on market and creative intelligence compiled by GameAnalytics and do not process Customer Personal Data, save for the account and request data that GameAnalytics processes as Controller.

Categories of Data Subject. End Users of the Customer's games, and the Customer's own authorised personnel who access the Services (whose account data is processed by GameAnalytics as Controller).

Categories of Personal Data. The Services are designed to process pseudonymous behavioural and technical data rather than directly identifying data. Depending on the Customer's configuration, Customer Personal Data may include: device and vendor identifiers and, where enabled by the Customer, advertising identifiers; a limited-ad-tracking flag; a per-game pseudonymous player identifier and a device-level user identifier; approximate location (country, region and city) derived from the internet protocol address at the point of ingestion, after which the full address is not stored with the event and a truncated form is retained for a short period for security and abuse prevention; device, platform, operating system and build attributes; session and gameplay event data; in-app purchase and ad monetisation data; user acquisition and attribution metadata; and, where the Customer uses custom event fields or user-level features, the additional fields and per-player views the Customer configures. The Customer determines the custom event data it transmits and must not transmit Special Category Personal Data or directly identifying data through custom fields.

Special Category Personal Data. None is required by the Services. The Customer must not configure the Services to transmit Special Category Personal Data.

Product-specific processing. SegmentIQ Pro presents End User Data at the level of individual pseudonymous players for the Customer's internal analysis. PipelineIQ Data Warehouse loads player-level and aggregated End User Data into a Google BigQuery instance provisioned by GameAnalytics for the Customer. PipelineIQ Data Export writes raw End User Data to storage designated by the Customer, at which point clause 9 applies. The Metrics API, the Organization API and the GameAnalytics-hosted Model Context Protocol server return aggregated metrics and account configuration data. The AI Agent processes the Customer's GameAnalytics data transiently to answer questions.

Retention. GameAnalytics retains Customer Personal Data only for as long as necessary to provide the Services, subject to the following maximum periods: interactive query and dashboard access to detailed data is limited to a defined maximum look-back period of up to four years; raw event-level data is retained for up to twelve months for all Games, to support analytics, data pipeline and backfill features, and for a shorter period for Games configured as child-directed where the Documentation so states; player-level aggregated data is retained for up to one year; granular, non-aggregated event data made available through the Data Warehouse is retained for up to thirty days; truncated internet protocol addresses are retained for up to thirty days; AI Agent session logs and traces are retained for up to ninety days; daily aggregated checkpoint data is retained for up to one year; and aggregated key performance indicators that do not permit identification of a Data Subject may be retained on a rolling basis to provide historical trends. The periods above are maximum periods. GameAnalytics may apply shorter periods at any time, including for specific plans as stated in the Documentation, and does not commit to retain data for the full period.

Annex 2. Sub-processors

The following Sub-processors are engaged as at the effective date. GameAnalytics maintains an up-to-date list on its website or trust portal and notifies the Customer of changes in accordance with clause 6.

Sub-processors
Sub-processor Service provided Processing location
Amazon Web Services (Amazon Web Services EMEA SARL and Amazon Web Services, Inc.) Cloud infrastructure, storage, processing and hosting of the Services United States
Amazon Web Services (Amazon Bedrock) Managed large language model for the AI Agent United States
Google Cloud (Google Cloud EMEA Limited and Google LLC) Managed data warehouse (BigQuery) for PipelineIQ Data Warehouse United States
Imply Data, Inc. Managed real-time analytics database supporting queries and dashboards United States
SolarEngine User-level analysis engine for SegmentIQ. Applies to SegmentIQ only and is not used for any other Product Hong Kong (SegmentIQ only)
Langfuse GmbH Logging and tracing of AI Agent sessions (observability) European Union (Germany)
GameAnalytics ApS Group operation of the Services, engineering, administration and support Denmark (personnel work remotely from locations in the European Union and the United Kingdom)

The following providers support processing that GameAnalytics carries out as Controller and are therefore not Sub-processors under this Addendum: the identity provider used for dashboard, API and Model Context Protocol authentication; the log management provider holding access and request logs; the infrastructure provider operating the Ad Insights API request layer; the consent management, product analytics and support tooling used on the GameAnalytics website and platform; and the payment provider used for self-checkout. They are listed in the Privacy Notice.

Where the Customer elects to receive data through Data Export to its own AWS or Google Cloud storage, or connects an artificial intelligence client or other tool to the Services, the Customer's own provider is not a Sub-processor of GameAnalytics and the Customer contracts with that provider directly.

Annex 3. Technical and organisational measures

GameAnalytics ApS maintains an information security management system certified to ISO/IEC 27001:2022 (certificate 122160 issued by Prescient Security LLC, an IAS-accredited certification body), covering the Services and their infrastructure on Amazon Web Services and Google Cloud, and subject to annual surveillance audits. GameAnalytics undergoes an annual SOC 2 Type II examination. The measures include, without limitation:

  • Access control: role-based access, least-privilege provisioning, multi-factor authentication for administrative access, periodic access reviews, and validation of user permissions on each application programming interface and Model Context Protocol request.
  • Encryption: encryption of Customer Personal Data in transit using current transport-layer security, and encryption at rest for stored data.
  • Pseudonymisation and minimisation: the Services are designed around pseudonymous identifiers; full internet protocol addresses are not stored with event data; AI-powered features are designed to operate on aggregated or pseudonymous data where the feature permits.
  • Segregation: logical separation of customer data and environment segregation between development, testing and production.
  • Logging and monitoring: centralised logging of administrative, API and Model Context Protocol access, with retention periods stated in the Privacy Notice, and monitoring for anomalous activity.
  • Resilience: infrastructure redundancy, monitored availability, backup and a tested business continuity and disaster recovery capability.
  • Vulnerability management: monitoring, patching, dependency and vulnerability tracking, periodic penetration testing, and credential rotation following any suspected compromise.
  • Personnel: confidentiality obligations, security awareness training, and role-appropriate training on the handling of children's data for personnel with access to it.
  • Supplier management: security assessment, transfer impact assessment where relevant and contractual data-protection commitments for Sub-processors and other providers.
  • Incident response: a documented procedure for detecting, assessing, reporting and responding to personal data breaches, with external data protection support available.

Further details, including current certificates and reports, are available on the GameAnalytics trust portal at https://www.gameanalytics.com/trust/trust-report 

Annex 4. Transfer mechanisms and jurisdiction-specific terms

Standard Contractual Clauses (EU GDPR). For the purposes of the EU SCCs: the Customer is the data exporter and GameAnalytics is the data importer; module two applies to processing by GameAnalytics and module three applies to onward transfers to Sub-processors; the optional docking clause applies; the option for general written authorisation of Sub-processors applies, with the notice period set out in clause 6; the governing law and forum are those of Denmark; the description of processing is set out in Annex 1; the technical and organisational measures are set out in Annex 3; and the competent supervisory authority is the Danish Datatilsynet. GameAnalytics is not itself certified under the EU-US Data Privacy Framework; clause 7.1 applies to Sub-processors that are.

United Kingdom. For transfers subject to the UK GDPR, the UK Addendum to the EU SCCs applies. Tables 1 to 3 are completed by reference to the information in this Addendum and its Annexes; Table 4 indicates that neither party may end the UK Addendum as set out in its Section 19. The competent supervisory authority is the Information Commissioner's Office.

Switzerland. For transfers subject to Swiss law, the EU SCCs apply with the adaptations issued by the Swiss Federal Data Protection and Information Commissioner, including that references to the GDPR are understood as references to the Swiss Federal Act on Data Protection, and the competent authority is the Swiss Commissioner.

United States state privacy laws. Where the California Consumer Privacy Act as amended, or another United States state privacy law, applies to the Customer's use of the Services, GameAnalytics acts as a service provider or processor as defined by that law. GameAnalytics does not sell or share Customer Personal Data, does not retain, use or disclose it for any purpose other than performing the Services or as permitted by that law, and does not combine it with Personal Data from other sources except as permitted. The Customer may take reasonable steps to remediate unauthorised use, and GameAnalytics enables the Customer to respond to consumer rights requests. GameAnalytics notifies the Customer if it determines that it can no longer meet its obligations under the applicable law.

Mainland China. Where End User Data originates from Mainland China, the GameAnalytics Mainland China Addendum applies in addition to this Addendum.

‍

Upcoming Data Processing Addendum