VYKIX VYKIX · Legal

Data Processing Agreement

PrivacyTermsCookiesDPAImpressum

Document version DPA-2026-08-13

Last Updated: August 13, 2026

1. Parties and Scope

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and LIMITBRAVITY - LDA, trading as VYKIX, Rua Das Costeiras 103, 4835-421 Guimarães, Portugal, VAT PT517675110 (“Processor”), for a game server, VPS, bare-metal server, web hosting, or other service on which the Controller processes personal data.

This DPA applies only where VYKIX processes personal data on behalf of the Controller. VYKIX is separately a controller for its own accounts, billing, tax, fraud, network security, abuse prevention, support administration, and legal records, as explained in the Privacy Policy. Payment providers, domain registrars and registries, and optional Rust partner services are not VYKIX subprocessors merely because the customer chooses their independent service.

The DPA becomes binding when the customer accepts the Terms and submits an Order that involves processor services. It satisfies Article 28(3) GDPR; it does not purport to execute international-transfer Standard Contractual Clauses without the modules, options, annexes, parties, and signatures required for that transfer.

2. Processing Details

Subject matterHosting, storage, transmission, backup where enabled, technical support, security, deletion, and other infrastructure operations needed to supply the ordered service.
DurationThe service term plus the deletion and backup-rotation periods in Section 10, unless law requires longer preservation.
Nature and purposeAutomated storage, compute, transmission and security; and limited authorized access where the Controller requests support or access is necessary to respond to a security incident.
Data subjectsThe Controller's users, players, visitors, customers, employees, contractors, contacts, or other persons whose data the Controller places in or transmits through the service.
Data categoriesWhatever ordinary personal data the Controller chooses to host, which may include identifiers, contact data, account records, IP addresses, logs, gameplay data, communications, and application/database content.
Location of processingThe location selected in the accepted Order: Frankfurt, Amsterdam, Chicago, or New York. Support and administration may be performed from Portugal.
Special dataThe service is not designed for large-scale special-category or criminal-offence data. The Controller must not upload such data unless the Order expressly supports it and both parties have documented the necessary safeguards and instructions.

3. Controller Obligations and Instructions

The Controller determines the purposes and means of its hosted processing and is responsible for a lawful basis, transparent notices, data-subject rights, data minimization, retention settings, application security, user permissions, and lawful configuration of plugins or partner services.

The Terms, accepted Order, service configuration, support requests, and lawful instructions sent through the client area or agreed support channel are the Controller's documented instructions. VYKIX will process personal data only on those instructions, including for transfers, unless Union or Member State law requires otherwise. Where legally permitted, VYKIX will inform the Controller before required processing.

VYKIX will promptly inform the Controller if, in its opinion, an instruction infringes applicable data-protection law. VYKIX may pause the affected instruction while the parties clarify it; this does not require VYKIX to provide legal advice or independently audit all customer processing.

4. Confidentiality and Personnel

VYKIX limits access to persons who need it to operate, secure, or support the service. Employees and authorized contractors with relevant access are bound by contractual or statutory confidentiality obligations and receive access appropriate to their role. Contractor NDAs do not replace VYKIX's responsibility to control and review access.

5. Security

Taking account of the state of the art, implementation cost, nature and risks of the processing, VYKIX implements the measures in Annex II. The Controller remains responsible for controls under its administration, including operating-system and application configuration, user accounts, credentials, software updates on self-managed services, encryption choices, and its own backups unless an Order expressly includes a managed feature.

VYKIX may update security measures to address risk or improve protection, provided the overall level of protection is not materially reduced. No security measure can eliminate all risk.

6. Subprocessors

The Controller gives general written authorization for the subprocessors below and for replacements notified under this Section. A provider is a subprocessor only to the extent it processes Controller Personal Data for VYKIX:

ProviderLocationProcessing
Cloudflare, Inc.United States / global networkProxied traffic delivery, web security, and DDoS mitigation where enabled for the ordered service.
Global Secure Layer (applicable contracting entity in VYKIX's supplier record)Routing locations applicable to the protected serviceNetwork routing and DDoS mitigation where selected. VYKIX will provide the exact contracting entity and relevant safeguard to the Controller on request.
Eranium B.V.Netherlands / applicable network locationsNetwork routing and DDoS mitigation where selected.
Postmark (ActiveCampaign, LLC)United StatesTransmission of email sent through a VYKIX support or notification channel, including text and quoted excerpts that the Controller or its authorized user places in that message. No connection to hosted systems.
Anthropic PBC (Claude), Google LLC (Gemini), or OpenAI, L.L.C. The provider and contracting entity in use are recorded in VYKIX's supplier register and supplied on request.United States, or the processing region recorded in the supplier registerLimited to text, quoted log excerpts, and attachments that the Controller or its authorized user itself submits through a VYKIX support channel (live chat or a Level 1 ticket), and that an authorized staff member submits to obtain assistance in preparing a reply. No connection to hosted systems, customer files, WHMCS, billing, or payment data. The account tier, model-training setting, and retention setting in use are recorded in the supplier register and supplied on request.

VYKIX may operate mitigation itself or switch traffic between already-authorized providers according to service location, capacity, or threat. Not every provider receives every customer's traffic. VYKIX will impose data-protection obligations on each subprocessor that are no less protective, in substance, than the obligations applicable to the relevant processing under this DPA, and remains responsible for its subprocessor's performance as required by Article 28.

VYKIX will give at least 30 days' notice, by email to the account address, before a new subprocessor begins to process Controller Personal Data, where practicable before processing begins. The Controller may object during that period on reasonable data-protection grounds. The parties will try in good faith to resolve the concern; if no reasonable alternative exists, either party may terminate the affected service without penalty for the unused prepaid period.

NorthC (European locations) and SBA Edge (West Chicago) supply colocation facilities for VYKIX-owned hardware: building, power, cooling, and network cross-connects. On the confirmed operating model neither has routine logical access to hosted disks, so neither is listed as a data subprocessor. Payment providers, registrars, and WHMCS software licensing are not authorized by this list to access hosted Controller content. VYKIX staff may use Anthropic, Google, or OpenAI only for controller-side live chat and Level 1 (basic first-line) support under the Privacy Policy. VYKIX staff may not use those tools to connect to hosted systems or to extract Controller content from a Service. Where the Controller or its authorized user itself includes hosted content in a support message, that inclusion is the Controller's instruction to process that content for the purpose of answering the request, within the limits of the entries above. Any wider processing of hosted Controller Personal Data by an AI provider on the Controller's behalf would require prior authorization as a subprocessor under this Section.

7. Assistance

Taking account of the nature of processing and information available to it, VYKIX will reasonably assist the Controller with data-subject requests, security, breach assessment, data-protection impact assessments, and prior consultation obligations under Articles 32–36 GDPR. The Controller should first use available service controls. Additional work outside normal support may be charged at a reasonable disclosed rate unless the assistance is required because VYKIX breached this DPA.

8. Personal-Data Breaches

VYKIX will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller Personal Data. As information becomes available, the notice will describe the known nature of the breach, affected data and data subjects where reasonably identifiable, likely consequences, measures taken or proposed, and a contact point. VYKIX may provide information in phases and will take reasonable steps to contain and remediate the breach.

Notification is not an admission of fault. The Controller is responsible for any notification to its supervisory authority or data subjects, with VYKIX's reasonable assistance.

9. International Transfers

VYKIX supplies capacity in Frankfurt, Amsterdam, Chicago and New York. Where the Controller selects a United States location, hosted Controller Personal Data is stored and processed by VYKIX itself, on VYKIX-owned hardware, in that location; the selection recorded in the accepted Order is the Controller's documented instruction under Section 3, including as to the place of processing. The colocation providers for each region are identified in this Section, and VYKIX will confirm the operator and its access model for a specific selected location on request.

VYKIX is established in Portugal. A customer's disclosure to VYKIX in Portugal does not require EU international-transfer SCCs merely because that customer is also established in the EEA. UK law currently recognizes the EEA under its applicable adequacy framework for relevant transfers.

For an onward restricted transfer by VYKIX to a non-EEA subprocessor, VYKIX will use an applicable adequacy decision or Data Privacy Framework certification, or enter the relevant completed 2021 EU SCC module and carry out any required transfer assessment and supplementary measures. For UK-restricted transfers, VYKIX will use the applicable adequacy regulation, UK IDTA, or UK Addendum.

The parties do not treat a generic SCC link as a signed agreement. Where SCCs are actually required between the Controller and VYKIX for a particular transfer, the parties will complete and execute the correct module, options and Annexes separately. VYKIX will provide information about an applicable onward-transfer safeguard on request, subject to proportionate confidentiality and security redactions.

10. Return, Deletion, and Backups

During an active service, the Controller may retrieve or delete data through the service tools. Before termination or the deletion timestamp, the Controller must export any data it wishes to retain. At the end of the service, VYKIX will, at the Controller's choice, delete or return hosted personal data, and will delete existing copies, unless Union or Member State law requires storage. A return request must reach VYKIX before the applicable deletion timestamp, while the data still exists; the parties will agree a reasonable format and delivery method. Where the Controller makes no choice, VYKIX deletes.

  • For overdue paid services, suspension begins 72 hours after the due timestamp and cancellation and deletion of active service data begin 168 hours after the due timestamp.
  • For a free trial, suspension occurs 48 hours after activation and active trial data is deleted seven days after suspension.
  • For a timely end-of-term cancellation, deletion begins when the paid term ends.

Residual disaster-recovery copies, if any, remain access-restricted and unavailable for ordinary service use until the relevant recovery set is overwritten or expires under VYKIX's actual operational rotation. Such copies are not restored except for disaster recovery, security, legal compliance, or dispute preservation. VYKIX will not state a fixed backup period until the live configuration has been verified. Any legally preserved copy is isolated and deleted when the preservation duty ends.

11. Information and Audits

VYKIX will make available information reasonably necessary to demonstrate compliance with Article 28 and this DPA. The Controller may request a written review first. If that is insufficient, the Controller may conduct or appoint an independent qualified auditor for an audit no more than once per year, unless a breach or supervisory authority reasonably requires more, with reasonable notice, during business hours, subject to confidentiality, security, and protection of other customers. The Controller bears its reasonable audit cost unless the audit identifies a material VYKIX breach.

12. Liability, Priority, and Contact

Liability is governed by the Terms and mandatory data-protection law. If this DPA conflicts with the Terms on processing Controller Personal Data, this DPA prevails. The remainder of the Terms, including governing law and mandatory consumer protections, continues to apply.

Where the Controller is a consumer within the meaning of applicable consumer law, the charging provision in Section 7 and the audit-cost provision in Section 11 do not apply to assistance or information that VYKIX is required to provide free of charge, and nothing in this DPA limits a right that mandatory consumer or data-protection law gives that Controller.

Data-protection contact: [email protected].

Annex I — Parties

Controller: the customer identified in the accepted Order. Role: controller of the hosted processing.

Processor: LIMITBRAVITY - LDA, trading as VYKIX, Rua Das Costeiras 103, 4835-421 Guimarães, Portugal, VAT PT517675110. Role: processor for hosted Controller Personal Data.

Annex II — Technical and Organizational Measures

  • Logical access limited by role and operational need; confidentiality obligations for authorized personnel and contractors.
  • Transport encryption for supported management and web interfaces.
  • Network filtering, firewalling, monitoring, and DDoS protection appropriate to the service; mitigation may be VYKIX-operated or supplied by an authorized provider.
  • VYKIX-owned server hardware in controlled colocation facilities; no routine facility-provider logical access to hosted disks.
  • Logging, patching, incident handling, and restoration procedures proportionate to the platform and risk.
  • Access-restricted disaster-recovery backups on VYKIX-controlled hardware where enabled, retained according to the operational rotation in force for the relevant platform.
  • Customer isolation appropriate to the service type; customer responsibility for security controls inside self-managed VPS and bare-metal environments.

← Back to vykix.com