Skip to content

Data Processing Agreement

Last updated: 2026-01-01

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between ForgeVector Software Limited ("Processor") and the customer ("Controller"). It sets out the terms on which ForgeVector Software Limited processes personal data on behalf of the Controller in connection with the ReplayCore platform.

This DPA is supplemental to the Terms of Service. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail in relation to the processing of personal data.

2. Definitions

"Controller" means the customer who determines the purposes and means of the processing of personal data.

"Processor" means ForgeVector Software Limited, which processes personal data on behalf of the Controller.

"Personal Data", "Processing", "Data Subject", "Supervisory Authority", and "Special Categories of Personal Data" have the meanings given in Applicable Data Protection Law.

"Applicable Data Protection Law" means the UK GDPR and the Data Protection Act 2018, and any other applicable data protection legislation, as amended from time to time.

3. Subject Matter and Duration

The subject matter of processing is the operation of the ReplayCore replay recording, storage, and playback platform as described in the Terms of Service.

Processing shall commence on the effective date of the Terms of Service and shall continue for the duration of the subscription, unless terminated earlier in accordance with the Terms of Service.

4. Nature and Purpose of Processing

The Processor shall process personal data solely for the purposes of providing the services described in the Terms of Service, including: recording and storing Minecraft player activity on the Controller's server; making recordings available for playback through the Controller's panel account; providing support and maintenance services; and complying with legal obligations.

The Processor shall not process personal data for any other purpose without the prior written consent of the Controller.

5. Types of Personal Data and Categories of Data Subjects

The personal data processed may include: Minecraft player usernames and UUIDs; in-game player positions, actions, and chat messages recorded during gameplay sessions; IP addresses associated with connection events; and panel account information (name, email address) of users authorised by the Controller.

The categories of data subjects are: players of the Controller's Minecraft server whose activity is recorded; and administrative users of the Controller's ReplayCore panel account.

6. Obligations of the Controller

The Controller warrants that it has a valid lawful basis under Applicable Data Protection Law for instructing the Processor to process personal data, and that all instructions given to the Processor are lawful.

The Controller is responsible for ensuring that data subjects are informed of the processing of their personal data through an appropriate privacy notice, in accordance with Applicable Data Protection Law.

The Controller shall notify the Processor promptly of any instruction that, in the Controller's reasonable opinion, would infringe Applicable Data Protection Law.

7. Obligations of the Processor

The Processor shall: process personal data only on the documented instructions of the Controller; ensure that persons authorised to process the personal data are subject to appropriate confidentiality obligations; implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk; assist the Controller in complying with its obligations under Applicable Data Protection Law; and delete or return all personal data to the Controller on termination of the services.

The Processor shall inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.

8. Sub-processors

The Controller provides general authorisation for the Processor to engage sub-processors. The Processor shall maintain a current list of sub-processors and shall notify the Controller of any intended changes (additions or replacements) by updating the sub-processor list at replaycore.com/en/legal/dpa, giving the Controller at least 30 days' prior notice.

The Processor only shares personal data with responsible third-party providers acting on its behalf. Current sub-processors include: Cloudflare, Inc. (CDN, DDoS mitigation, Workers compute, and object storage; stores data in the region closest to the user automatically); OVH Cloud (dedicated infrastructure and database hosting; data-centre locations currently in London, United Kingdom and Beauharnois, Canada); Stripe, Inc. (payment processing); Resend, Inc. (transactional email).

The Processor imposes data protection obligations on all sub-processors equivalent to those set out in this DPA, and advises the Controller to review each provider's own privacy policy.

9. International Transfers

The Processor runs on OVH Cloud and Cloudflare infrastructure, with OVH data-centre locations currently in London (United Kingdom) and Beauharnois (Canada), and stores replay files in Cloudflare object storage, where Cloudflare stores data in the region closest to the user automatically; the panel is served through Cloudflare's global network. Where personal data is transferred to a country outside the UK or EEA, the Processor shall ensure that appropriate safeguards are in place, including standard contractual clauses approved by the UK Information Commissioner's Office where required.

10. Security

The Processor shall implement and maintain appropriate technical and organisational security measures, including: encryption of personal data at rest and in transit; access controls limiting processing to authorised personnel; regular security testing and vulnerability management; and incident detection and response procedures. The Processor follows security best practices recommended in the UK and by the ICO and Cloudflare, and conducts regular security audits.

The Processor shall notify the Controller without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting the Controller's data.

11. Data Subject Rights

The Processor shall, to the extent technically feasible and taking into account the nature of processing, assist the Controller in fulfilling its obligations to respond to data subject rights requests under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection.

Requests from data subjects received directly by the Processor shall be forwarded to the Controller promptly.

12. Data Protection Impact Assessments

The Processor shall provide reasonable assistance to the Controller in carrying out data protection impact assessments and in consulting with Supervisory Authorities where required.

13. Deletion and Return

On termination of the services, the Processor shall, at the Controller's election, delete or return all personal data and delete existing copies, unless applicable law requires retention of the personal data. The Processor shall certify deletion in writing on request.

Replay data may be downloaded by the Controller at any time via the panel during the subscription period. Following termination, data is retained for 30 days to allow for recovery of inadvertent cancellations, after which it is permanently deleted.

14. Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice (not less than 30 days) and execution of a suitable confidentiality agreement.

Where the Processor undergoes third-party security audits (such as SOC 2 or ISO 27001 assessments), it shall share summaries of audit reports with the Controller on request.

15. Governing Law

This DPA is governed by the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction to settle any disputes arising out of or in connection with this DPA.

For questions about this DPA or to request a countersigned copy, contact admin@forgevector.co.uk.