Data Processing Addendum

Version: 1.0

Effective date: 24 July 2026

Last updated: 24 July 2026

This Data Processing Addendum ("DPA") supplements the Terms of Service or other agreement (the "Agreement") between the customer identified in the Agreement ("Controller") and Ionut-Laurentiu Hurmuz, a UK sole trader trading as hionet, of Flat 1, The Granaries, Bepton Road, Midhurst, GU29 9LU, United Kingdom ("Processor"). It addresses Article 28 UK GDPR and, where applicable, Article 28 EU GDPR requirements. It is incorporated into an order or agreement that links to or expressly references it.

1. Scope and definitions

This DPA applies only where hionet processes personal data in customer content on behalf of Controller to provide game server hosting, Discord bot hosting or related support Services ("Controller Personal Data"). It does not apply to personal data hionet processes as an independent controller for accounts, billing, fraud, security, legal compliance and business operations, which is covered by the Privacy Notice.

"Data Protection Laws" means the UK GDPR, Data Protection Act 2018 and, where applicable to the processing, EU GDPR and binding national implementing law. "Data Subject", "Personal Data Breach", "process", "processing", "controller" and "processor" have their meanings under applicable Data Protection Laws.

2. Roles and compliance

Controller determines the purposes and essential means of processing and is responsible for lawful instructions, notices, lawful bases, rights handling, data accuracy, minimisation and the legality of Controller Personal Data. Processor will process Controller Personal Data only on Controller's documented instructions, including the Agreement, this DPA, product configuration and support requests, unless applicable law requires otherwise.

If law requires processing beyond instructions, Processor will inform Controller before processing unless law prohibits notice for important public-interest reasons. Processor will immediately inform Controller if, in its opinion, an instruction infringes applicable Data Protection Laws, without being required to provide legal advice. Processor may pause the affected processing while the parties resolve the issue.

Controller must not provide data or instructions inconsistent with the Service's stated nature and security. Controller is responsible for special-category, criminal-offence or children's data and will tell Processor before processing it where additional controls are required. Processor does not agree to process such data unless the Service and written instructions expressly support it.

3. Processing details

The subject matter, duration, nature, purpose, data types and data-subject categories are set out in Schedule 1. The Agreement and Controller's use of configuration controls are documented instructions. Additional instructions must be in writing, consistent with the Agreement and technically feasible. Processor may charge reasonable agreed costs for material assistance or changes beyond the included Service.

4. Confidentiality and personnel

Processor will ensure persons authorised to process Controller Personal Data are bound by confidentiality duties or an appropriate statutory obligation, receive relevant data-protection and security guidance, and access data only as needed for assigned duties.

5. Security

Taking account of the state of the art, implementation cost, and the nature, scope, context and purposes of processing and risk to individuals, Processor will maintain appropriate technical and organisational measures under Article 32. Baseline measures are in Schedule 2. Controller acknowledges that security is shared: Controller must secure credentials, applications, operating systems and configurations under its control and maintain independent backups.

No customer-content backup service is included unless a signed order expressly says otherwise. Infrastructure redundancy or recovery copies are not a Controller backup and cannot be relied upon for restoration. Controller must maintain separate tested backups appropriate to risk.

Processor may update measures without materially reducing overall protection. No statement in this DPA constitutes a claim of certification.

6. Subprocessors

Controller gives general written authorisation for subprocessors listed at Subprocessors and Data Locations. Processor will impose written data-protection obligations providing materially equivalent protection for relevant processing and remains responsible to Controller for a subprocessor's performance to the extent required by Data Protection Laws.

Processor will give at least 30 days' advance notice of a new or replacement subprocessor by email to the account contact and publication on the Subprocessors and Data Locations page. Controller may object during that period on reasonable, documented data-protection grounds. The parties will try in good faith to resolve the objection through an alternative configuration or reasonable safeguard. If no reasonable solution is available, Controller may terminate only the affected Service before the subprocessor begins processing and receive a pro-rata refund of unused prepaid fees for it. This does not permit objection based solely on general commercial preference.

Emergency replacement needed for security, continuity or law may occur with notice as soon as reasonably possible.

7. Data-subject requests

Taking account of the nature of processing, Processor will provide appropriate technical and organisational assistance, insofar as possible, for Controller to respond to requests under Chapter III UK GDPR or EU GDPR. If Processor receives a request relating to Controller Personal Data, it will ordinarily direct the requester to Controller and notify Controller, where identifiable and lawful. Processor will not respond substantively except on Controller's instruction or as required by law.

Controller is responsible for verifying identity, deciding the response and using available self-service tools. Additional assistance may be charged at a reasonable rate where permitted, especially where required because of Controller's design or instructions.

8. Personal Data Breaches

Processor will notify Controller without undue delay after becoming aware of a confirmed Personal Data Breach affecting Controller Personal Data. Notice will include available information reasonably required by Article 33(3), including nature, likely consequences, affected data and subjects, contact point and measures taken or proposed. Information may be provided in phases as investigation continues.

Processor will take reasonable containment and remediation steps and preserve relevant evidence. Notification is not an admission of fault. Controller is responsible for notices to regulators and individuals unless the parties expressly agree otherwise. Controller must give Processor current incident contacts.

9. DPIAs and regulatory consultation

Taking account of the nature of processing and information available, Processor will provide reasonable assistance with Controller's security obligations, data-protection impact assessments and prior consultation under Articles 32 to 36. Controller remains responsible for determining whether they are required. Extensive bespoke assistance may be subject to agreed reasonable fees where permitted.

10. Return and deletion

During the Service, Controller can retrieve Controller Personal Data using available tools. On termination, Controller must export data before the stated access deadline. At Controller's choice communicated before that deadline, Processor will delete or return Controller Personal Data, so far as technically feasible, and delete existing copies within 24 hours after termination, unless law requires retention.

If Controller gives no timely choice, deletion after the published window is the default. Return does not require Processor to create a format not supported by the Service. hionet does not maintain customer-content recovery copies, so there is no residual customer-content recovery schedule. Limited security, billing or legal data independently controlled by hionet is not Controller Personal Data under this DPA.

Processor may retain data subject to a binding legal hold, isolate it from ordinary processing and delete it when the duty ends. At request, Processor will provide reasonable deletion confirmation.

11. Information and audits

Processor will make available information reasonably necessary to demonstrate Article 28 compliance. Controller will first use current documentation and written responses. If these are insufficient, Controller may audit relevant controls no more than once annually, and additionally after a material breach or regulator requirement, subject to reasonable advance notice.

Audits must occur during normal hours, minimise disruption, protect other customers and security, and use an independent qualified auditor bound by confidentiality. No access is permitted to other customers' data, penetration testing, source code, privileged advice or information whose disclosure would create a material security risk. Processor may provide redacted or alternative evidence. Controller bears its audit costs and Processor's reasonable costs for disproportionate or bespoke assistance unless an audit identifies a material Processor breach.

Processor will inform Controller if a lawful competent-authority instruction requires an audit limitation.

12. International transfers

Customer content is hosted in the United Kingdom unless the order expressly states another customer-selected location. Controller authorises processing in the countries listed for relevant subprocessors in the Subprocessors and Data Locations schedule.

For restricted transfers of Controller Personal Data, the parties will use the mechanism selected in Schedule 3. If a transfer mechanism is invalidated or requires supplementary measures, the parties will cooperate to implement a lawful alternative. Controller acknowledges that remote support access can constitute a transfer.

Neither party will make a restricted transfer under this DPA without a valid mechanism or applicable derogation. The parties will provide reasonable information needed for transfer-risk assessments while protecting confidential security information.

13. Government requests

Processor will assess demands under the Law Enforcement and Government Requests Policy. Unless legally prohibited, Processor will notify Controller before disclosing Controller Personal Data, challenge requests that appear unlawful or disproportionate where there are reasonable grounds, and disclose only data legally required.

14. Liability, priority and term

The Agreement's liability provisions apply to this DPA to the maximum extent permitted by law, without reducing data-subject rights or regulatory powers. Nothing relieves either party of its own responsibilities under Data Protection Laws.

If this DPA conflicts with the Agreement on processor obligations, this DPA prevails. An executed applicable transfer mechanism prevails for its subject matter. This DPA ends when Processor has deleted or returned all Controller Personal Data, except provisions intended to survive.

Schedule 1 - Processing description

Item

Description

Subject matter

Hosting, storage, transmission, retrieval, security, technical support and deletion of Controller Personal Data through a purchased game server or Discord bot hosting Service.

Duration

The Service term plus the export and deletion period, and longer only where law requires.

Nature and purpose

Automated and occasional authorised manual collection, storage, organisation, retrieval, transmission, troubleshooting, security monitoring, restriction, export and deletion to provide and protect the Service on Controller's instructions.

Data subjects

Controller's players, Discord community members, bot users, moderators, administrators, personnel, contractors, contacts and any other individuals whose data Controller chooses lawfully to host or process through the Service.

Personal-data types

Depending on Controller configuration: names or usernames; player, account, Discord user, guild/server and role identifiers; IP/device data; commands and interactions; message or game-chat content and metadata; gameplay, server, moderation and security logs; allow/ban lists; bot databases; configuration; files; and other data selected by Controller. Special-category, criminal-offence and children's data only if expressly supported and lawfully instructed.

Frequency

Continuous or as initiated by Controller and its users during the Service.

Controller instructions

Agreement, order, product configuration, support requests and documented written instructions accepted by Processor.

Return/deletion

Self-service export during service; deletion under section 10 and the published retention schedule.

Controller-specific additions are those expressly stated in the order, product configuration or a signed addendum. If none are stated, the table above is complete.

Schedule 2 - Technical and organisational measures

Measures applicable to the Service include:

  • documented access authorisation, least privilege and prompt access removal;

  • strong authentication and multi-factor authentication for privileged access where supported;

  • encryption in transit for the website, account panel and supported administrative/file-transfer connections; customer files, databases, configuration and bot tokens are not promised to have application-level encryption at rest;

  • tenant, account, network or virtualisation separation appropriate to the service model;

  • security logging, monitoring, vulnerability and patch-management processes proportionate to risk;

  • malware, abuse and denial-of-service controls appropriate to the platform;

  • secure configuration, change control and incident-response procedures;

  • confidentiality commitments and role-appropriate personnel guidance;

  • subprocessor diligence and contractual controls;

  • infrastructure redundancy and supplier continuity measures where available, without maintaining customer-content backups or recovery copies;

  • secure deletion or media disposal processes; and

  • periodic review and testing of relevant controls.

Privileged access is limited to hionet in the United Kingdom and authorised support contractors in Romania, is used only as needed for support, security, abuse handling or legal compliance, and is subject to confidentiality. Ordinary logs, metrics and security records follow the retention periods in the Privacy Notice. Customer content is deleted within 24 hours after termination. The Controller must secure credentials and bot tokens, configure applications lawfully, patch software it controls and maintain independent tested backups.

Schedule 3 - UK and EU restricted transfers

1. Parties and roles

The data exporter is the Controller identified in the Agreement. The data importer is hionet and, for an onward transfer, the relevant provider identified in the Subprocessors and Data Locations schedule. Contact details are those in the Agreement and provider schedule.

2. Applicable mechanism

  • A transfer from the UK to a destination covered by UK adequacy regulations relies on those regulations.

  • A transfer to a US recipient certified for the UK Extension to the EU-US Data Privacy Framework may rely on that framework.

  • Other UK restricted transfers use the UK International Data Transfer Agreement or the UK Addendum to the 2021 EU Standard Contractual Clauses, normally using Module 2 for controller-to-processor transfers or Module 3 for processor-to-subprocessor transfers, as applicable.

  • An EEA restricted transfer uses an applicable adequacy decision or the 2021 EU Standard Contractual Clauses, normally Module 2 or Module 3 as applicable.

The processing description is Schedule 1, the technical and organisational measures are Schedule 2, and the relevant recipient, destination and provider terms are identified in the public subprocessor schedule and the applicable supplier DPA.

3. Supplementary measures and assessments

hionet documents the applicable transfer assessment before enabling a restricted transfer. Measures may include encryption in transit, minimisation, least-privilege access, confidentiality, logging, customer location choice, contractual government-request protections and technical separation. If no lawful mechanism can be maintained, hionet will stop the affected transfer or offer an available alternative location.

4. Incorporation and acceptance

This DPA is accepted when the customer accepts an order or agreement that links to or identifies it. No separate signature is required unless either party requests a signed copy. The Controller may request details needed to complete a regulator, audit or transfer record, subject to reasonable confidentiality and security restrictions.