Data Processing Addendum

Last updated 1 August 2026.

1. Scope and parties

This Data Processing Addendum (“DPA”) forms part of the Forgeport Terms of Service between Forgeport and an Organization. It applies when the Organization is the controller of personal data relating to its Portal community and Forgeport processes that data on the Organization’s behalf. Terms such as controller, processor, personal data, processing, and data subject have the meanings given by applicable data-protection law, including the GDPR where it applies.

Forgeport remains an independent controller for the processing identified as such in our Privacy Policy, including platform authentication and security, fraud prevention, our payment-processor records, and legal compliance. This DPA does not change those independent purposes.

2. Processing details

  • Subject matter and purpose: hosting and operating the Organization’s Portal, Player accounts, wallet, commerce, engagement, support, and game-server connection.
  • Duration: for the Organization’s use of Forgeport and afterward only for deletion, return, backup rotation, dispute evidence, or a legal retention duty.
  • Nature: collecting, recording, organizing, storing, retrieving, displaying, transmitting, securing, restricting, anonymizing, and deleting data to provide the Service.
  • Data subjects: Players, prospective Players, linked game users, and people who contact or interact with the Organization through a Portal.
  • Data: Player account identifiers and contact details; authentication and security data; IP address, device and session data; Game Account identifiers and links; wallet, payment, order, reward, spin and delivery records; profile or Portal content; and support communications.

Forgeport is not designed for special-category data, government identifiers, full payment-card data, or children’s data. The Organization must not instruct Forgeport to collect such data through free-text content or configuration fields.

3. Instructions and responsibilities

Forgeport will process covered data only on the Organization’s documented instructions, including the Terms, this DPA, and the Organization’s ordinary use and configuration of the Service, unless applicable law requires otherwise. If legally permitted, we will tell the Organization before carrying out a legally required instruction. We will inform the Organization if we reasonably believe an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve it.

The Organization is responsible for the lawfulness, fairness, and accuracy of its instructions; its privacy notice and lawful bases; responding as controller to its community; obtaining any necessary permissions; configuring staff access appropriately; and not collecting more data than it needs.

4. Confidentiality and security

Forgeport limits access to covered data to people who need it to operate or support the Service and who are bound by confidentiality. We maintain proportionate technical and organizational measures, including access controls, tenant scoping, encrypted transport, hashed passwords and tokens, audit and immutable financial records, rate limits, least-privilege production access, encrypted off-platform backups, incident response, and tested recovery procedures. No service can promise absolute security; the measures may evolve while maintaining an appropriate level of protection for the risk.

5. Subprocessors

The Organization gives general authorization for Forgeport to use subprocessors needed to provide the Service. The current subprocessors and their functions are identified in the Privacy Policy. Forgeport will impose, in substance, the same data-protection obligations on each subprocessor for the processing it performs and remains responsible for its processor obligations that it delegates.

We will announce a material new subprocessor through an updated policy or in-product notice. An Organization may object on reasonable data-protection grounds by contacting us promptly. We will try to provide a reasonable alternative; if none is reasonably available, either party may end the affected Service without penalty for future periods.

6. International transfers

Where covered data is transferred from the EEA, UK, or another restricted jurisdiction, Forgeport will use a lawful transfer mechanism described in the Privacy Policy. If the EU Standard Contractual Clauses, UK addendum, or an equivalent instrument is required for a transfer between the Organization and Forgeport, the parties will enter the applicable instrument on request; the processing details in Section 2 and security measures in Section 4 will supply the corresponding annex information.

7. Assistance and incidents

Taking account of the nature of the processing and the information available to us, Forgeport will reasonably assist the Organization with data-subject requests, security and breach duties, data protection impact assessments, and regulator consultations. We will notify the Organization without undue delay after becoming aware of a personal-data breach affecting covered data and provide available information reasonably needed for the Organization’s response. The Organization remains responsible for deciding whether and how to notify data subjects or an authority.

8. Return, deletion, and retention

During the Service, the Organization may access and export data through the available product tools or by contacting us. At the end of the Service and at the Organization’s choice, Forgeport will return an available export and then delete or anonymize covered data, or delete/anonymize it without a prior return, after the documented restoration period, unless law requires retention. Data may remain in encrypted disaster-recovery backups until those backups rotate out and will not be restored for ordinary use. Independent-controller records remain subject to the Privacy Policy and applicable retention duties.

9. Information and audits

Forgeport will provide information reasonably necessary to demonstrate compliance with this DPA. An Organization may request an audit no more than once per year, unless a regulator or confirmed incident reasonably requires another. The parties will first use current policies, security documentation, certifications, and written answers. Any further audit must be proportionate, protect other customers and confidential systems, avoid production disruption, and be paid for by the Organization unless it identifies a material breach by Forgeport.

10. Priority and contact

If this DPA conflicts with the Terms on the processing of covered personal data, this DPA controls. The liability provisions in the Terms apply to this DPA to the extent permitted by applicable law. Questions or requests under this DPA: contact@forgeport.net.