Data Processing Agreement
Data Processing Agreement (DPA) pursuant to Art. 28 GDPR. This DPA forms an integral part of the Terms of Service (the "Agreement") entered into between hoaxeye (the "Processor") and the customer (the "Controller"). It governs the processing of personal data that the Processor performs on behalf of the Controller in the course of providing the Services.
This DPA is concluded in electronic form within the meaning of Art. 28 para. 9 GDPR at the moment the Controller activates an API key or completes checkout for a paid plan. hoaxeye logs that acceptance together with the version of this DPA in force at that time; the version history of this page is publicly version-controlled in our source repository and can be reconstructed on request. A countersigned bilateral copy can be requested at any time from [email protected].
1. Subject Matter and Duration
The Processor processes personal data on behalf of the Controller for the sole purpose of providing the Services as defined in the Agreement. This DPA remains in force for the duration of the Agreement and for any post-termination period during which the Processor still processes personal data on behalf of the Controller.
Scope (household exemption). This DPA applies where the Controller operates a FiveM server with public or semi-public access (invite links, listing on a server browser, public Discord, etc.). Where the Controller uses hoaxeye solely for a strictly private server accessible only to the Controller and their household or personal friends within the meaning of Art. 2 para. 2 lit. c GDPR, the Controller is not a controller within the meaning of Art. 4 no. 7 GDPR, and this DPA does not apply. As soon as the server admits persons outside that personal sphere, this DPA applies automatically.
2. Nature and Purpose of Processing
Anti-cheat intelligence, fraud and abuse detection, identity correlation, ban-evasion detection, verification, dashboard operation, analytics, and related operational security functions for the Controller's FiveM server(s) and related communities.
3. Types of Personal Data
- Online identifiers (FiveM license/identifiers, Steam ID, Discord ID, Rockstar ID, HWIDs, hashed identifiers)
- IP addresses, connection and network metadata, ASN and geolocation metadata
- Device and browser signals (fingerprint hashes, WebRTC candidates, timezone, language)
- Session and join events, moderation actions, risk scores, verdicts
- Verification-flow data (Discord OAuth handles, risk score, appeal metadata)
- Screenshots, recordings, or evidence data submitted by the Controller's integrations (where applicable)
- Free-text data entered by moderators (ban reasons, notes, appeal communications)
- Resource code excerpts from the Controller-controlled FiveM server, limited to short snippets needed to qualify a heuristic finding (no End-User personal data). For findings of the static signature-catalog family (
signature.*), no raw code excerpts are transmitted — only an opaque pattern identifier and a SHA-256 hash of the 80-character context window. - Server telemetry & operational metrics (aggregated trigger counts, resource inventory snapshots, framework class, exploit-risk score, join/heartbeat heatmaps)
- Network protection telemetry (where activated): connection metadata only — source IP, packet headers, timing signatures, handshake validity. No game content, voice or chat.
4. Categories of Data Subjects
- End-users of the Controller (players who connect to the Controller's server)
- The Controller's own administrators, moderators and staff (account-level users)
- Third parties who interact with the Services via the Controller's integrations (e.g. Discord guild members in the verify flow)
5. Obligations of the Processor
The Processor shall:
- process personal data only on documented instructions from the Controller (the Agreement, the dashboard configuration and this DPA constitute such instructions), including transfers to a third country or an international organisation, unless required to do so by Union or Member State law;
- ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- take all measures required pursuant to Art. 32 GDPR (see the TOM in Section 11);
- respect the conditions referred to in paragraphs 2 and 4 of Art. 28 GDPR for engaging sub-processors;
- taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising data subject rights;
- assist the Controller in ensuring compliance with the obligations pursuant to Art. 32 to 36 GDPR, taking into account the nature of processing and the information available to the Processor;
- at the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of the Services relating to processing, and delete existing copies, unless Union or Member State law requires storage of the personal data;
- make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (see Section 10).
The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
6. Sub-Processors
(1) The Controller grants the Processor general authorisation to engage sub-processors.
(2) Notification channel. The Processor shall inform the Controller of any intended addition or replacement of a sub-processor at least thirty (30) days in advance (a) by email to the contact address registered with the Controller's hoaxeye account and, in parallel, (b) through a dated entry on the Privacy Policy page and, where applicable, a dashboard notice.
(3) Objection. The Controller may object to a proposed sub-processor within that thirty (30) day period on reasonable data-protection grounds by email to [email protected]. If the Controller objects, the Processor may (i) address the concern (e.g. by additional safeguards), (ii) refrain from using the sub-processor, or (iii) if none of the above is reasonably possible, notify the Controller that the affected part of the Services can no longer be provided.
(4) Right of extraordinary termination. If the Processor cannot accommodate a reasoned objection, the Controller has a special right to terminate the affected Services in text form with effect from the date on which the new sub-processor would start processing. Prepaid fees for the unused portion of the current billing period will be refunded on a pro-rata basis.
(5) Current sub-processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting, database, infrastructure, encrypted EU backup storage | Germany (EU) |
| Cloudflare, Inc. | CDN, DDoS protection, Turnstile CAPTCHA, STUN | USA / global edge (SCCs / DPF) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing, subscription billing, transaction-level fraud prevention | Ireland (EU) / USA (SCCs / DPF) |
| Discord, Inc. | (i) OAuth identity verification for the optional player verify flow (only if enabled by the Controller); (ii) outbound bot notifications to operator-controlled Discord channels for audit, threat-pulse, leave-log and similar operational events; (iii) outbound webhook delivery to Discord webhook URLs that the Controller configures for its own server alerts. | USA (DPF / SCCs; End-User consent within the verify flow per Art. 49(1)(a) GDPR) |
| DDoS mitigation provider (planned) | Specialised L7/UDP DDoS protection for the Controller's FiveM server; processes connection metadata only. Until activated, network protection runs exclusively on hoaxeye's own Hetzner infrastructure. The concrete provider, country and applicable transfer safeguards will be published here in advance, in line with Section 6 (2) above. | EU edge node operated by hoaxeye; upstream provider location to be published before activation |
Each sub-processor is bound by written contract to data-protection obligations equivalent to those set out in this DPA.
No external AI / LLM sub-processor. The language model used internally to grade resource-code findings and to support detection-engine tuning runs exclusively on the Processor's own EU infrastructure (Hetzner, Germany). No Controller data, End-User data or resource code excerpts are transmitted to any external AI provider (OpenAI, Anthropic, Microsoft, Alibaba or others). If this changes in the future, the relevant provider will be added to the table above in advance under the procedure of Section 6 (2)–(4).
7. Data Subject Rights
The Processor shall, insofar as possible, assist the Controller by appropriate technical and organisational measures in responding to requests by data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection, Art. 22). Requests addressed directly to the Processor by a data subject will be forwarded without undue delay to the Controller, together with any contextual information available to the Processor that is necessary to identify the data subject and respond within the statutory period.
8. Personal Data Breach
(1) The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach. The notification shall contain at least the information set out in Art. 33(3) GDPR, to the extent available at the time, and shall be sent by email to the account-registered contact address of the Controller.
(2) Assistance with Art. 34 GDPR. Where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller remains responsible for communicating the breach to the affected data subjects under Art. 34 GDPR. The Processor shall assist the Controller with this communication, in particular by providing the information needed to draft the notice, by identifying the affected data-subject records where technically feasible, and by coordinating on the wording where the same breach affects multiple Customers.
(3) Nothing in this Section limits any direct notification obligation that the Processor may itself have vis-à-vis its own supervisory authority under Art. 33 GDPR in respect of processing where the Processor acts as controller.
9. International Transfers
Where the Processor transfers personal data to a country outside the EEA, such transfer is based on the EU Standard Contractual Clauses (SCCs) adopted by the European Commission or other lawful transfer mechanisms under Chapter V GDPR. The Processor has carried out transfer impact assessments where required.
10. Audits
The Controller may audit the Processor's compliance with this DPA once per calendar year (and additionally in the event of a personal data breach). Audits shall be announced at least 30 days in advance, conducted during regular business hours, not disrupt operations, and respect the confidentiality of third-party customer data. Each party bears its own costs. The Processor may satisfy audit requests by providing recent third-party audit reports, ISO/SOC certifications or similar, where available.
11. Technical and Organisational Measures (TOM)
The Processor maintains appropriate technical and organisational measures pursuant to Art. 32 GDPR. The following list states the concrete measures in effect at the effective date above:
- Encryption in transit: TLS 1.2 or higher on all public endpoints, modern cipher suites only; HSTS on the root domain.
- Encryption at rest: full-disk encryption (LUKS) on all production database and application volumes hosted at Hetzner; encrypted backups stored on geographically separated EU backup servers.
- Authentication & credential protection: user passwords hashed with a modern password-hashing function (e.g. bcrypt/Argon2-family); service secrets and API keys stored hashed or in a dedicated secret store; MFA for administrative tooling; SSH-key-only admin access; least-privilege role-based access control.
- Identifier & log integrity: SHA-256 (or stronger) for identifier hashing and audit-log integrity; tamper-resistant audit logs with change-control via version control.
- Availability & resilience: EU-hosted primary infrastructure (Hetzner), automated encrypted backups with rolling retention up to 90 days on geographically separated EU backup servers, regular restore tests, Cloudflare DDoS and bot-management at the edge, monitoring and alerting, documented incident-response process, separation of production environments, configuration as code.
- Staff & confidentiality: all persons authorised to process personal data are bound to confidentiality or subject to an appropriate statutory confidentiality obligation; documented onboarding/offboarding procedures.
- Security review cadence: internal code and configuration reviews around each deployment plus two to three dedicated security audits per calendar year (internal and/or independent third-party); additional ad-hoc reviews on any personal-data breach or material change to the processing.
- Supplier-risk management: data-processing agreements concluded with each sub-processor; annual review of supplier safeguards; incident documentation and lessons-learned cycle.
- AI / LLM processing locality: the language model used internally for resource-code finding evaluation and detection-engine tuning runs exclusively on the Processor's own EU infrastructure (Hetzner, Germany). No Controller or End-User data is transmitted to external AI providers. Resource-code excerpts (Section 3) are pseudonymised where technically feasible and hard-deleted within 90 days of the scan.
- Signature catalog integrity: the static signature-catalog distributed to the Controller's server is signed with HMAC-SHA-256 over the canonical payload bytes; signing keys are 32-byte random values held in the Processor's production environment and rotated on a ninety-day cadence (or sooner on suspicion). The asset on the Controller's server fails closed on signature-verification errors and pauses until the catalog can be re-fetched.
Detailed, current TOM documentation, including configuration baselines and audit evidence, is available on request under NDA to [email protected]. The Processor may update the concrete measures over time to reflect the state of the art; the level of protection shall at no time fall below the level described above without prior notice to the Controller.
12. Liability
Liability of the parties under this DPA is governed by the liability provisions of the Agreement. Nothing in the Agreement excludes or limits liability which cannot lawfully be excluded or limited, including liability for intent or gross negligence, or liability directly imposed by mandatory provisions of the GDPR.
13. Term and Termination
This DPA enters into force on the effective date above and remains in force for the term of the Agreement. Upon termination, the Processor shall, at the Controller's choice, delete or return all personal data within 30 days, unless applicable law requires storage.
14. Miscellaneous
This DPA is governed by the law of the Federal Republic of Germany. In the event of a conflict between this DPA and the Agreement, this DPA prevails with respect to data-protection matters. Should any provision of this DPA be or become invalid, the validity of the remaining provisions shall remain unaffected.
Controller / Customer Details
The Controller is the customer identified in the billing and account information submitted during checkout or API key activation. That information is hereby incorporated by reference. A signed counterpart version referencing the Controller's full legal details can be requested from [email protected].