This Data Processing Agreement (“DPA”) is concluded pursuant to Art. 28 GDPR between
the Customer as named in the main contract (the “Controller”),
and
Johannes Tornow, Visage Esports (Einzelunternehmen), Sophie-Charlotten-Str. 84, 14059 Berlin, Germany (the “Processor”).
It supplements the Terms of Service between the parties (the “Main Contract”). In the event of a conflict, this DPA prevails with regard to the processing of personal data.
1. Subject Matter, Duration, and Purpose
1.1. The Processor processes personal data on behalf of the Controller exclusively for the purpose of providing the Service described in the Main Contract — a Software-as-a-Service platform for the analysis of Dota 2 match data.
1.2. This DPA applies for the term of the Main Contract. It ends automatically when the Main Contract ends, subject to the obligations in Section 10, which survive.
1.3. This DPA does not cover personal data that the Processor processes as a controller in its own right. In particular, the processing of publicly available match and player data described in the Processor’s Privacy Policy is carried out by the Processor as controller and is not subject to this DPA.
2. Nature of Processing and Categories of Data
2.1. The type of personal data processed, the categories of data subjects, and the nature and purpose of processing are set out in Annex 1.
2.2. Processing takes place exclusively within the European Union or the European Economic Area, unless otherwise permitted under Section 7 (Sub-processors) and safeguarded in accordance with Chapter V GDPR. Any relocation of processing to a third country requires the conditions of Art. 44 et seq. GDPR to be met.
3. Instructions of the Controller
3.1. The Processor processes personal data only on documented instructions from the Controller, unless required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
3.2. The Controller’s initial instructions are set out in this DPA and the Main Contract. Individual instructions may be issued in text form (e.g., by email) to contact@visage.gg. Verbal instructions must be confirmed in text form without undue delay.
3.3. The Processor shall inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions. The Processor is entitled to suspend the execution of such an instruction until it is confirmed or amended by the Controller.
3.4. If an instruction goes beyond the scope of services agreed in the Main Contract and causes additional expense, the Processor may claim reasonable remuneration after informing the Controller in advance.
4. Obligations of the Processor
4.1. Confidentiality. The Processor shall ensure that all persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Where the Processor acts personally, the Processor is bound by this obligation directly.
4.2. Security of processing. The Processor shall implement the technical and organisational measures set out in Annex 2 pursuant to Art. 32 GDPR. The Processor may modify these measures, provided the agreed level of protection is not reduced. Material changes shall be documented.
4.3. Assistance with data subject rights. Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures in fulfilling the Controller’s obligation to respond to requests for exercising data subject rights under Chapter III GDPR. If a data subject contacts the Processor directly regarding data processed on behalf of the Controller, the Processor shall forward the request to the Controller without undue delay and shall not respond independently.
4.4. Assistance with the Controller’s obligations. The Processor shall assist the Controller in ensuring compliance with the obligations under Art. 32 to 36 GDPR (security of processing, personal data breaches, data protection impact assessments, prior consultation), taking into account the nature of processing and the information available to the Processor.
4.5. Personal data breaches. The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Controller. The notification shall contain the information available to the Processor pursuant to Art. 33(3) GDPR. The Processor shall take appropriate remedial measures without undue delay and shall document the incident.
4.6. Records of processing. The Processor maintains a record of all categories of processing activities carried out on behalf of the Controller pursuant to Art. 30(2) GDPR.
4.7. Data protection officer. The Processor is not required to appoint a data protection officer. The contact point for data protection matters is contact@visage.gg.
5. Obligations of the Controller
5.1. The Controller is responsible for assessing the lawfulness of the processing and for safeguarding the rights of data subjects. In particular, the Controller warrants that it has a valid legal basis for transferring personal data to the Processor and for having it processed.
5.2. Where the Controller uploads or makes accessible personal data of its own players, employees, or other individuals within the Service, the Controller is responsible for informing those individuals in accordance with Art. 13 and 14 GDPR.
5.3. The Controller shall inform the Processor without undue delay if it discovers errors or irregularities in the Processor’s handling of personal data.
6. Rights of Audit
6.1. The Controller has the right to satisfy itself of the Processor’s compliance with this DPA, in particular the implementation of the technical and organisational measures.
6.2. The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. As a rule, evidence shall be provided by means of self-disclosure, current certifications or audit reports of the sub-processors used, or comparable documentation.
6.3. Where the evidence under Section 6.2 is insufficient in an individual case, the Controller may carry out a further inspection, or have one carried out by an independent auditor bound to confidentiality and not in competition with the Processor. Such inspections are conducted remotely — for example by written questionnaire, document review, or video conference — unless the specific cause of the inspection cannot be assessed by those means. The Processor operates no premises of its own; on-site inspections at a private residence are excluded, and inspections of the data centres used are subject to the arrangements of the respective sub-processor. Inspections shall be announced with reasonable notice of at least 30 days, shall take place during normal business hours, shall be limited to what is necessary for the specific cause, and shall not unreasonably disrupt business operations. As a rule, one inspection per calendar year is appropriate; further inspections require a specific cause. The Controller bears its own costs and shall reimburse the Processor’s reasonable expenses for inspections going beyond Section 6.2.
7. Sub-processors
7.1. The Controller grants the Processor general authorisation to engage sub-processors. The sub-processors currently engaged are listed in Annex 3, and the Controller approves them upon conclusion of this DPA.
7.2. The Processor maintains a current list of sub-processors at the address notified to the Controller. The Processor shall inform the Controller of any intended addition or replacement of a sub-processor at least 14 days in advance. Information may be provided by updating that list, provided the Controller has the option to subscribe to notifications of changes, or by text form (e.g., email) to the contact address given by the Controller. The Controller may object to the change on reasonable data protection grounds within 14 days of being informed. If the parties cannot reach agreement, the Controller may terminate the Main Contract with effect from the date on which the change takes effect; fees paid for periods after that date shall be refunded on a pro-rata basis.
7.3. Replacing a sub-processor with another provider of the same category of service listed in Annex 3 does not require separate approval, provided the level of data protection is not reduced and the location of processing does not change from within the EEA to a third country. The Processor shall document such changes and reflect them in the sub-processor list.
7.4. The Processor shall impose on each sub-processor data protection obligations that are substantially equivalent to those set out in this DPA, and remains fully liable to the Controller for the performance of the sub-processor’s obligations.
7.5. Services that the Processor obtains from third parties as ancillary services to support the performance of the contract — such as telecommunications services, postal services, maintenance, or user support — are not sub-processing within the meaning of this Section. The Processor shall nevertheless conclude appropriate agreements to safeguard the protection of personal data where such services may involve access to personal data.
8. Third-Country Transfers
8.1. Where a sub-processor listed in Annex 3 is established outside the European Economic Area, the transfer is safeguarded by the Standard Contractual Clauses adopted by the European Commission pursuant to Art. 46(2)(c) GDPR, together with any supplementary measures required following an assessment of the circumstances of the transfer.
8.2. The Processor shall provide the Controller with evidence of these safeguards on request.
9. Liability
9.1. Liability between the parties is governed by Art. 82 GDPR and by the liability provisions of the Main Contract.
9.2. The limitations of liability in the Main Contract do not apply to claims of data subjects under Art. 82 GDPR. Recourse between the parties following such claims is governed by Art. 82(5) GDPR.
10. Deletion and Return of Data
10.1. After the end of the provision of services relating to processing, the Processor shall, at the choice of the Controller, delete or return all personal data processed on behalf of the Controller, and delete existing copies, unless Union or Member State law requires storage of the personal data.
10.2. The Controller shall communicate its choice within 30 days after the end of the Main Contract. If the Controller does not do so, the Processor shall delete the data. Deletion shall take place no later than 90 days after the end of the Main Contract. Backups are deleted in accordance with the regular backup rotation cycle.
10.3. Documentation which serves as evidence of orderly and proper data processing shall be retained by the Processor beyond the end of the contract in accordance with the respective retention periods.
11. Final Provisions
11.1. Conclusion in electronic form. This DPA is published by the Processor and is incorporated into the Main Contract by reference. It is concluded in electronic form pursuant to Art. 28(9) GDPR and comes into effect when the Controller accepts the Main Contract; no separate signature is required. The Processor records the version accepted and the time of acceptance, and shall provide the Controller with a copy of the accepted version on request.
11.2. Versions. The Processor may publish updated versions of this DPA. The version accepted by the Controller continues to apply to that Controller until a new version is agreed; changes to Annex 3 are governed by Section 7.2. The date of the version in force is stated at the top of this document.
11.3. Amendments and supplements to this DPA require text form. This also applies to any waiver of this requirement.
11.4. This DPA is governed by the law of the Federal Republic of Germany.
11.5. Should individual provisions of this DPA be or become invalid, this shall not affect the validity of the remaining provisions.
Annex 1 — Details of the Processing
Categories of data subjects
- Authorized Users of the Controller (e.g., players, coaches, analysts, management, and other staff of the Controller’s organization)
- Individuals whose data the Controller enters into or uploads to the Service
Categories of personal data
- Account and contact data: name or handle, email address, hashed password, role within the organization
- Usage data: log-in timestamps, IP address, actions performed within the Service, session data
- Game-related data linked by the Controller to identified individuals: linked Dota 2 / Steam account identifiers, match and performance data, team and roster assignments
- Content created or uploaded by the Controller: notes, annotations, tags, scouting and analysis records, and uploaded match replay files together with the player and match information they contain
Nature and purpose of processing
Collection, recording, organisation, structuring, storage, retrieval, use, analysis (including AI-assisted analysis where the Controller uses such features), aggregation, disclosure to the Controller’s Authorized Users, restriction, erasure, and destruction — for the purpose of providing, operating, securing, and supporting the Service, and providing support to the Controller.
Special categories of personal data
The Service is not intended for the processing of special categories of personal data within the meaning of Art. 9 GDPR (including health data). The Controller shall not enter such data into the Service.
Duration of processing
For the term of the Main Contract, followed by the deletion periods set out in Section 10.
Annex 2 — Technical and Organisational Measures (Art. 32 GDPR)
Confidentiality
- Physical access control: Servers are operated in the data centres of the hosting provider (see Annex 3), which are secured against unauthorised physical access. The Processor has no on-site hardware access.
- System access control: Administrative access to production systems is limited to the Processor and uses key-based authentication; password-based remote login is disabled.
- Data access control: Within the Service, access is governed by a role and organization concept; Authorized Users can access only the data of their own organization. Administrative access to production data occurs only where necessary for operation, support, or troubleshooting.
- Separation control: Data of different customer organizations are logically separated and enforced at the application layer.
- Encryption: All connections use transport encryption (TLS). Passwords are stored only as salted hashes using a current key derivation function.
Integrity
- Data are transmitted exclusively over encrypted connections. Data carriers are not physically transported.
- Changes to production systems are made from version-controlled sources.
Availability
- Automated backups with a defined retention period.
- The website and API are served behind a provider offering upstream filtering and rate limiting (see Annex 3).
Procedures for review and evaluation
- Sub-processors are selected with due care and bound by agreements pursuant to Art. 28 GDPR.
- Privacy by default: only data required for the respective purpose are collected, and deletion periods are defined (Section 10).
- Personal data breaches are handled in accordance with Section 4.5.
The Processor is a sole proprietorship without dedicated security staff. The measures above are proportionate to the nature, scope, and purposes of the processing and to the risk involved, as required by Art. 32(1) GDPR. Additional measures can be agreed individually.
Annex 3 — Approved Sub-processors
| Sub-processor | Purpose | Location of processing | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH, Gunzenhausen, Germany | Hosting of the application, databases, and backups | Germany | Within the EU |
| Sendinblue GmbH (Brevo), Berlin, Germany | Transactional email (e.g., password resets, account notifications) | EU | Within the EU |
| Fastly, Inc., San Francisco, USA | Content delivery network and protection of the website | USA / global edge network | EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR |
| OpenAI, L.L.C., USA / OpenAI Ireland Ltd. | AI-assisted analysis features | USA, EU | EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR |
| xAI Corp., USA | AI-assisted analysis features | USA | EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR |
| Stripe Payments Europe, Ltd., Dublin, Ireland (incl. affiliates such as Stripe, Inc., USA) | Payment processing and subscription billing | EU, USA | EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR |
The categories of service listed above are: (a) hosting and infrastructure, (b) transactional email delivery, (c) content delivery and website protection, (d) AI-assisted analysis features, and (e) payment processing and invoicing. Section 7.3 applies to changes of provider within these categories.
Note on AI-assisted features (category d): Where the Controller uses AI-assisted features, the content submitted to those features may be transmitted to one of the model providers named above for the purpose of generating the requested output. The retention and further use of submitted content by the respective model provider are governed by that provider’s terms; the Processor selects the provider used for a given feature and will inform the Controller on request which provider is used and under which terms. The Controller should not submit personal data to these features beyond what is necessary for the intended analysis, and should not submit special categories of personal data within the meaning of Art. 9 GDPR.
If the Controller does not wish its data to be processed by one or more of the model providers named above, the parties may agree in text form to restrict use to a subset of them.
Note on payment processing (category e): Stripe is listed here for transparency. The data processed for payment purposes are the Controller’s own billing and contact data, in respect of which the Processor acts as controller rather than on the Controller’s behalf; to that extent Stripe is not a sub-processor within the meaning of Section 7. Stripe processes payment data in part as an independent controller for the purposes of executing payments, meeting its own regulatory obligations, and preventing fraud.