Data Processing Agreement
Last updated: 13 August 2026
1. Scope and parties
This agreement applies where you operate a game server using our anti-cheat plugin. In that case the plugin records data about players who are not our customers, and under Art. 4 GDPR you are the controller of that data and Tamiroz is the processor. It forms part of, and is governed by, our Terms of Service, and takes effect when you first activate an anti-cheat plan.
For everything else (your own account, your purchases, your sessions), Tamiroz is the controller, and our Privacy Policy applies instead.
2. Subject matter and duration
- Subject matter: receiving, storing and displaying anti-cheat detections reported by the plugin running on your game server.
- Nature and purpose: detecting cheating on your server and making those detections visible to you in your dashboard, so that you can decide what action to take.
- Types of personal data: in-game nickname, SteamID and IP address of the player a detection relates to, together with the reason and time of the detection.
- Categories of data subjects: players who connect to your game server.
- Duration: for as long as you hold an active anti-cheat plan for that server, plus the deletion described in §7.
3. Our obligations
- Documented instructions: we process this data only to provide the service described in §2, and on your documented instructions, which for normal operation are the settings you choose in your dashboard and this agreement itself. We do not use it for our own purposes, and we do not sell it.
- Confidentiality: access is limited to the people who need it to operate the platform, and they are bound by an obligation of confidentiality.
- Security: see §4.
- Assistance: see §5 and §6.
4. Security measures (Art. 32)
- All traffic between your server, your browser and the platform is encrypted in transit.
- Your data is isolated per server, and every request for it is authorised against the server's ownership before it is served.
- The API token your game server uses is generated by us, shown to you once, and stored only as a keyed fingerprint: it cannot be recovered from our database, only regenerated.
- The plugin interface is rate-limited per server so a compromised or misbehaving server cannot flood or degrade the service for others.
- Data is stored on infrastructure in the European Union with regular backups to a separate location.
5. Sub-processors
You give us general authorisation to engage sub-processors for this data. The current sub-processor is:
- Hetzner (hosting, database and object storage): European Union.
The other providers listed in our Privacy Policy do not receive anti-cheat data. We will inform you of any intended change to this list in advance, and you may object to a change on reasonable data-protection grounds; if we cannot resolve the objection you may terminate the affected plan. We remain responsible to you for any sub-processor's performance.
6. Assistance and breach notification
- Data subject requests: if a player contacts us about data held for your server, we will not answer on your behalf; we will refer them to you and help you respond. Your dashboard lets you view and delete detections for your server directly, which is normally all that is needed.
- Personal data breach: we will notify you without undue delay after becoming aware of a breach affecting this data, with the information you need to meet your own obligations under Art. 33.
- Impact assessments: we will provide the information reasonably needed for a data protection impact assessment or prior consultation, taking into account the nature of the processing and what is available to us.
7. Deletion at the end of processing
When the last anti-cheat plan for a server ends, the anti-cheat detections and settings held for that server are deleted automatically, and no copy is retained. Deleting the server from your dashboard has the same effect. You can also delete detections yourself at any time while the plan is active. This is how the platform behaves by default; it is not a promise that requires you to make a request.
8. Information and audits
On request we will make available the information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits carried out by you or an auditor you appoint. Audits are limited to what is necessary, must be scheduled with reasonable notice, and must not compromise the security or confidentiality of other customers' data.
Questions about this agreement: support@tamiroz.com.