Creator Data Processing Addendum
Effective date: September 28, 2026
1. Introduction and scope
1.1 This Creator Data Processing Addendum (this "DPA") is entered into between Summer Labs, Inc., a Delaware corporation with offices at 2810 N Church St, STE 89812, Wilmington, DE 19802, United States ("Summer", "we", "us"), and the Creator (as defined in the Summer Dictionary) identified in the applicable agreement ("Creator", "you"). This DPA forms part of, and is incorporated by reference into, the Multiplayer Hosting Terms and the Developer Tooling and API Terms (together, the "Hosting Agreements") whenever you use Hosting Services (as defined in the Summer Dictionary), backend APIs, or other Services provided by Summer in connection with an Exported Game (as defined in the Summer Dictionary).
1.2 Role flip. On the Summer Games Platform, Summer determines how Players' personal data is processed, and the Summer Games Privacy Policy applies. This DPA addresses the opposite situation. When you distribute an Exported Game outside the Platform (for example through Steam or another third party store) and connect it to Summer's Hosting Services or backend APIs, you are the publisher and operator of that game. You decide what data the game collects from its players, why, and for how long. In that situation, you are the business and controller with respect to the personal data of players of your Exported Game, and Summer is your service provider and processor.
1.3 What this DPA covers. This DPA applies to Summer's Processing of Creator Personal Data (defined in Section 2) on your behalf in the course of providing Hosting Services and related backend services for Exported Games, including multiplayer session orchestration, matchmaking, relay, save data storage, telemetry ingestion, and crash reporting, each as further described in Annex A.
1.4 What this DPA does not cover. This DPA does not apply to: (a) personal data of Users of the Summer Games Platform, including data processed when a Game is played on the Platform, which is governed by the Summer Games Privacy Policy, the US State Privacy Addendum, and the Data Retention and Deletion Policy; (b) your own Account data, billing data, Summer Creator Program data (enrollment, identity verification results, sanctions screening results, Payout Account references, Earned Sparks records and Program Payment history) and tax data (Tax Forms, Withholding Determinations, the Player Country records used to compute the US-Source Share, and withholding and reporting records), for which Summer is the business or controller and which are governed by the Summer Games Privacy Policy and, where applicable, the Creator Program Terms and the Creator Tax Addendum; Stripe (as Summer's Payout Provider) and Persona (as Summer's Identity Verification Provider) process that data as Summer's service providers under Summer's agreements, and you have no agreement with either; (c) personal data Summer processes as an independent business or controller for the limited purposes described in Section 3.4; and (d) data that is not personal data under Applicable Data Protection Laws, including data that has been aggregated or deidentified in accordance with Section 5.6.
1.5 Acceptance. This DPA takes effect automatically, without signature, on the earlier of (a) the date you first cause an Exported Game to connect to the Hosting Services or backend APIs, and (b) the effective date of the Hosting Agreements, and it remains in effect for as long as Summer Processes Creator Personal Data on your behalf. If you and Summer have executed a separate data processing agreement covering the same Processing, that executed agreement controls to the extent of any conflict.
1A. Paid Games lane (dormant)
1A.1 Status. Summer may later offer a Paid Games lane in which a Creator sells a Game License for a fiat price as the Seller of Record through Stripe Connect. This Section 1A and Annex A-2 are DORMANT and take effect only when Summer publishes the Paid Games Terms as an Additional Term and you open a Seller Account under them. Nothing in this Section applies to the Summer Games lane, where Summer is the sole seller and the Summer Games Privacy Policy governs. 1A.2 Roles for Paid Game sales. When active: (a) you are the business and controller for the record of each sale of your Paid Game (the buyer's identity and contact details, price, tax, delivery, refund and dispute history) and for the privacy notice shown to buyers of your Paid Game; (b) Summer is your service provider and processor for that record for the limited purposes of listing and presenting the Game, presenting checkout on your behalf, delivering the Game License to the buyer's Account, handling refund requests under the Paid Games refund floor, and supporting chargeback and dispute responses, as described in Annex A-2; (c) Summer remains an independent business and controller for the buyer's Summer Account, Platform activity, safety, fraud and legal compliance, and for Summer's own application fee records; and (d) Stripe processes your Seller Account data, the payment and the payout under your own Stripe Connected Account Agreement, and is not a Subprocessor of Summer under this DPA for that data. 1A.3 What does not change. Sections 4 to 18 apply to Summer's Processing under this Section 1A as they apply to Exported Games, except that Annex A-2 replaces Annex A for the description of the Processing. Sparks, Earned Sparks and Program Payments have nothing to do with the Paid Games lane, and no Program Payment data is processed under this Section. Paid Game sale proceeds are not Program Payments; the US federal tax characterization of Program Payments, the Tax Forms, the US-Source Share withholding and the information reporting described in the Creator Tax Addendum do not apply to them, and as Seller of Record you are responsible for the tax treatment of your own sales.
2. Definitions
2.1 Capitalized terms not defined in this DPA have the meanings given in the Summer Dictionary or, if not defined there, in the Hosting Agreements. The following terms have the meanings set out below.
2.2 "Applicable Data Protection Laws" means all laws and regulations applicable to the Processing of Creator Personal Data under this DPA, including, as applicable: (a) US State Privacy Laws; (b) the Children's Online Privacy Protection Act of 1998 and its implementing regulations ("COPPA"); (c) once and to the extent applicable, the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"), the GDPR as incorporated into United Kingdom law ("UK GDPR"), and the Swiss Federal Act on Data Protection; and (d) any other similar law applicable to that Processing.
2.3 "US State Privacy Laws" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations ("CCPA"), and all other US state comprehensive privacy laws applicable to the Processing of Creator Personal Data, including those of Colorado, Connecticut, Texas, Utah, and Virginia.
2.4 "Creator Personal Data" means personal data (including "personal information" as defined in the CCPA) relating to players or other end users of your Exported Games that Summer Processes on your behalf in providing the Hosting Services and backend services described in Annex A. Creator Personal Data does not include the data described in Section 1.4.
2.5 "Processing" (and "Process") means any operation performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, restriction, erasure, or destruction.
2.6 "Data Subject" means the identified or identifiable natural person to whom Creator Personal Data relates, including a "consumer" as defined in the CCPA.
2.7 "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Creator Personal Data Processed by Summer or its Subprocessors. Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Creator Personal Data, such as unsuccessful log in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
2.8 "Subprocessor" means any third party engaged by Summer to Process Creator Personal Data on Summer's behalf in connection with the services described in Annex A.
2.9 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914, as amended or replaced from time to time.
2.10 "sell", "share", "business", "service provider", "business purpose", and "commercial purpose" have the meanings given in the CCPA. "controller" and "processor" have the meanings given in the GDPR, and include the equivalent terms under other Applicable Data Protection Laws.
3. Roles of the parties
3.1 Creator as business and controller. As between the parties, you are the business (under the CCPA and other US State Privacy Laws) and the controller (under the GDPR, where applicable) with respect to Creator Personal Data. You are solely responsible for: (a) the lawfulness of your collection and disclosure of Creator Personal Data to Summer; (b) providing all legally required notices to, and obtaining all legally required consents from, players of your Exported Games, including a privacy policy for your Exported Game that accurately discloses your use of Summer as a service provider; (c) the accuracy, quality, and legality of Creator Personal Data and the means by which you acquired it; and (d) responding to Data Subjects who exercise privacy rights with respect to your Exported Game.
3.2 Summer as service provider and processor. As between the parties, Summer is your service provider (under the CCPA and other US State Privacy Laws) and your processor (under the GDPR, where applicable) with respect to Creator Personal Data. Summer will Process Creator Personal Data only as described in this DPA and Annex A.
3.3 No consumer relationship for this data. Summer's provision of Hosting Services for Exported Games is a business to business service to you. Summer does not, by providing those services, form a direct consumer relationship with the players of your Exported Game, and nothing in this DPA makes those players third party beneficiaries of the Hosting Agreements, except to the extent the SCCs, when they apply under Section 14, expressly grant Data Subjects third party beneficiary rights.
3.4 Limited independent processing. Notwithstanding Section 3.2, you acknowledge and instruct that Summer acts as an independent business or controller, and not as your service provider or processor, where Summer Processes data (a) to secure and protect the Services, including detecting and preventing fraud, cheating, denial of service, and other abuse of Summer infrastructure; (b) to comply with legal obligations, including responding to legal process in accordance with the Law Enforcement Guidelines and detecting, removing, and reporting child sexual abuse and exploitation material in accordance with the Child Safety and CSAE Policy; (c) to enforce the Exported Game Runtime License and the Hosting Agreements; and (d) to produce billing, capacity, and service integrity records. Summer will limit such independent Processing to what is reasonably necessary and proportionate for those purposes.
4. Processing instructions
4.1 Documented instructions. Summer will Process Creator Personal Data only on your documented instructions, including with regard to transfers of Creator Personal Data to a third country, unless required to do otherwise by applicable law. Where applicable law requires other Processing, Summer will inform you of that legal requirement before Processing, unless the law prohibits that disclosure on important grounds of public interest.
4.2 What counts as instructions. Your complete and final documented instructions consist of: (a) this DPA, including the Annexes; (b) the Hosting Agreements; (c) your configuration choices made through the Editor, the developer dashboard, and the APIs (for example, which telemetry events to collect, which regions to host sessions in, retention windows, and whether voice or text relay is enabled); and (d) any additional written instructions agreed by the parties in a signed writing or an agreed ticketing channel. You are responsible for ensuring that your instructions comply with Applicable Data Protection Laws.
4.3 Unlawful instructions. Summer will inform you without undue delay if, in Summer's opinion, an instruction infringes Applicable Data Protection Laws. Summer may suspend performance of the affected instruction until you confirm or modify it. Summer is not obligated to perform a legal review of your instructions, and informing you under this Section is not legal advice.
4.4 No processing outside instructions. Summer will not Process Creator Personal Data for Summer's own commercial purposes, for advertising, for profiling of players unrelated to your instructions, or for training artificial intelligence foundation models. For clarity, the opt-in AI training program described in the AI Features and Generated Content Terms applies only to content and data you affirmatively enroll, and enrollment of Creator Personal Data belonging to players of Exported Games is not offered.
5. Service provider certifications under US State Privacy Laws
5.1 This Section 5 applies to the extent Creator Personal Data includes personal information subject to the CCPA or another US State Privacy Law. The parties acknowledge that Creator Personal Data is disclosed by you to Summer only for the limited and specified business purposes described in Annex A, and that this DPA is a contract of the type described in Cal. Civ. Code section 1798.140(ag) and the corresponding provisions of other US State Privacy Laws.
5.2 No selling or sharing. Summer will not sell Creator Personal Data and will not share Creator Personal Data for cross-context behavioral advertising.
5.3 No retention, use, or disclosure outside the relationship. Summer will not retain, use, or disclose Creator Personal Data (a) for any purpose other than the business purposes specified in Annex A, including any commercial purpose other than the business purposes, or (b) outside the direct business relationship between you and Summer, except in each case as permitted by the CCPA and its regulations (for example, to detect Security Incidents, to protect against fraudulent or illegal activity, to comply with law, or to retain and employ Subprocessors consistent with Section 9).
5.4 No combining. Summer will not combine Creator Personal Data with personal information that Summer receives from or on behalf of another person, or that Summer collects from its own interactions with the Data Subject, except as permitted by the CCPA and its regulations. In particular, Summer will not use Creator Personal Data to enrich Summer Games Platform profiles of Players, even where the same natural person holds a Summer Account and also plays your Exported Game, except where the person links the two contexts themselves through a feature you enable (for example Summer Passport sign in, where offered) and the linking is disclosed to the person.
5.5 Certification and compliance. Summer certifies that it understands the restrictions in this Section 5 and will comply with them. Summer will (a) comply with all obligations applicable to service providers under US State Privacy Laws, (b) provide the same level of privacy protection for Creator Personal Data as US State Privacy Laws require of you, (c) notify you without undue delay if Summer determines that it can no longer meet its obligations under US State Privacy Laws, and (d) upon such notice, permit you to take reasonable and appropriate steps under Section 13 to stop and remediate unauthorized use of Creator Personal Data.
5.6 Deidentified data. To the extent Summer receives or creates deidentified data derived from Creator Personal Data, Summer will (a) maintain and use it only in deidentified form, (b) take reasonable measures to ensure it cannot be associated with a Data Subject or household, (c) publicly commit to maintain and use it only in deidentified form and not attempt to reidentify it, except as permitted by law to test the effectiveness of deidentification, and (d) contractually obligate any recipient to the same requirements. Aggregated, deidentified service metrics (for example, session counts, latency distributions, and crash rates) that do not identify any Data Subject or any player of your Exported Game may be used by Summer to operate, benchmark, and improve the Services.
6. Confidentiality
6.1 Summer will ensure that all Summer personnel authorized to Process Creator Personal Data are subject to written confidentiality obligations or an appropriate statutory obligation of confidentiality, and Process Creator Personal Data only as needed to perform their roles.
6.2 Summer will restrict access to Creator Personal Data to personnel who require access to provide the services described in Annex A, on a least privilege basis, consistent with Annex C.
6.3 Confidentiality obligations survive termination of this DPA for as long as Summer or its personnel retain Creator Personal Data.
7. Security
7.1 Security measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects, Summer will implement and maintain appropriate technical and organizational measures designed to protect Creator Personal Data against Security Incidents, including the measures described in Annex C.
7.2 Updates. Summer may update the measures in Annex C from time to time, provided the updates do not materially reduce the overall protection of Creator Personal Data during the term of the Hosting Agreements.
7.3 Creator responsibilities. You are responsible for (a) securing your own systems, including the builds of your Exported Game, your signing keys, and your API credentials; (b) configuring the Hosting Services appropriately for the sensitivity of the data your game collects, using available controls (for example, retention settings and regional hosting options); (c) not causing your Exported Game to send Summer categories of data beyond those described in Annex A without Summer's prior written agreement; and (d) promptly reporting suspected vulnerabilities in the Services through the process described in the Vulnerability Disclosure Policy.
7.4 Sensitive data. The Hosting Services are not designed for, and you must not use them to Process, government identifiers, payment card data, health data, biometric identifiers, or precise geolocation of players of Exported Games, unless the parties agree otherwise in a signed writing that includes any additional required terms.
8. Security Incidents and personal data breaches
8.1 Notice to you. Summer will notify you without undue delay, and in any event within [72] hours, after confirming a Security Incident affecting Creator Personal Data. Notice will be delivered to the security contact you designate in the developer dashboard or, absent a designation, to the email address associated with your Account.
8.2 Content of notice. To the extent known at the time, and supplemented as information becomes available, Summer's notice will describe: (a) the nature of the Security Incident, including, where possible, the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address the Security Incident and mitigate its effects; and (d) a contact point for further information.
8.3 Cooperation. Summer will take reasonable steps to contain, investigate, and remediate the Security Incident, and will provide reasonable assistance to enable you to meet your own breach notification obligations to regulators and Data Subjects. As between the parties, you are responsible for deciding whether and how to notify regulators and players of your Exported Game, except where the law imposes a notification obligation directly on Summer.
8.4 No admission. Summer's notification of, or response to, a Security Incident is not an acknowledgment of fault or liability.
8.5 No unauthorized disclosure by Creator. You will not represent to any third party that Summer, or any Summer product, was the cause of a Security Incident unless and until that cause has been reasonably established, and you will give Summer a reasonable opportunity to review the factual accuracy of any legally required public statement that names Summer, to the extent the law permits.
9. Subprocessors
9.1 General authorization. You provide Summer with a general authorization to engage Subprocessors to Process Creator Personal Data, subject to this Section 9. Summer's current Subprocessors, and the categories of services they provide, are listed at [SUBPROCESSOR LIST URL]. The categories of Subprocessors are summarized in Annex B.
9.2 Notice of changes. Summer will provide notice of any intended addition or replacement of a Subprocessor at least [30] days before the new Subprocessor Processes Creator Personal Data, by updating the list at [SUBPROCESSOR LIST URL] and sending notice through a mechanism you can subscribe to (email or dashboard notification). For changes required urgently to maintain the security or availability of the Services, Summer may engage the Subprocessor sooner and will give notice as soon as reasonably practicable.
9.3 Objection right. You may object to a new Subprocessor on reasonable, documented data protection grounds by notifying Summer within [15] days of the notice in Section 9.2. The parties will discuss the objection in good faith. If Summer cannot reasonably accommodate the objection (for example, by offering a configuration that avoids the Subprocessor), you may terminate the affected Hosting Services on written notice, and Summer will refund any prepaid, unused fees for the terminated services. Continued use of the affected Hosting Services after the change takes effect constitutes acceptance of the new Subprocessor.
9.4 Subprocessor obligations. Summer will enter into a written agreement with each Subprocessor containing data protection obligations that are, in substance, no less protective of Creator Personal Data than those in this DPA, to the extent applicable to the services the Subprocessor provides.
9.5 Liability. Summer remains responsible for the performance of each Subprocessor's obligations, and liable for the acts and omissions of its Subprocessors with respect to Creator Personal Data, to the same extent Summer would be liable if performing those services directly, subject to Section 16.
10. Assistance with privacy requests and obligations
10.1 Data Subject requests. Taking into account the nature of the Processing, Summer will provide reasonable assistance, including appropriate technical and organizational measures, to enable you to respond to requests from Data Subjects exercising rights under Applicable Data Protection Laws (including rights to know, access, correct, delete, port, and opt out). At launch, this assistance is provided primarily through self service tooling: the developer dashboard and APIs allow you to locate, export, correct, and delete Creator Personal Data associated with a player identifier.
10.2 Requests received by Summer. If Summer receives a request directly from a Data Subject that identifies your Exported Game, Summer will not respond substantively (except to direct the Data Subject to you or to acknowledge receipt) and will forward the request to you without undue delay, unless the law requires Summer to respond.
10.3 Assessments and consultations. Taking into account the nature of the Processing and the information available to Summer, Summer will provide reasonable assistance with data protection assessments, data protection impact assessments, and prior consultations with supervisory authorities or regulators that you are required to carry out with respect to the Processing under this DPA, to the extent the required information is not already available in the audit materials described in Section 13.
10.4 Costs. Assistance under this Section 10 is provided at no additional charge up to a commercially reasonable level. Summer may charge a reasonable fee, at rates in the Fee and Rates Schedule or as otherwise agreed, for assistance that is excessive, repetitive, or that requires custom engineering work, except where Applicable Data Protection Laws prohibit charging for the assistance.
11. Children's data
11.1 Your game, your audience. You are the operator of your Exported Game for COPPA purposes and the party responsible for determining whether your Exported Game, or any portion of it, is directed to children under 13, and for complying with COPPA and equivalent laws, including obtaining verifiable parental consent where required.
11.2 Notice to Summer. You must configure the child directed flag for your Exported Game in the developer dashboard accurately, and you must notify Summer in writing before causing an Exported Game that is directed to children, or that has actual knowledge of players under 13, to send Creator Personal Data to the Hosting Services. Upon such notice, Summer will Process the affected Creator Personal Data as a service provider in support of internal operations of your game, consistent with 16 C.F.R. section 312.2, and will not use it for any other purpose.
11.3 Restrictions. Summer will not use Creator Personal Data from a flagged child directed Exported Game for advertising of any kind, consistent with the platform wide rule in the Summer Games Terms of Service that Summer does not serve targeted advertising to known minors.
11.4 Indemnity trigger. Misconfiguration of the child directed flag, or failure to obtain required parental consents for your Exported Game, is your responsibility under the indemnification provisions of the Hosting Agreements.
12. Data retention, deletion, return, and portability
12.1 Retention during the term. Summer will retain Creator Personal Data for the retention periods you configure in the developer dashboard, subject to any minimums and maximums documented in the service documentation and the Data Retention and Deletion Policy.
12.2 Deletion on request. You may delete Creator Personal Data at any time during the term through the dashboard and APIs, including per player deletion to support Data Subject deletion requests under Section 10.
12.3 End of services. Upon termination or expiration of the Hosting Agreements as to an Exported Game, or upon your written request, Summer will, at your choice, delete or return to you all Creator Personal Data for that Exported Game, and delete existing copies, unless applicable law requires or permits continued storage, in which case Summer will isolate and protect the retained data and delete it when the requirement ends. Summer will complete deletion or return within [30] days of the effective date of termination or the request, except that data in encrypted backups will be deleted in the ordinary course of backup rotation and in any event within [90] days.
12.4 Return format and portability. Deletion under Section 12.3 does not begin before the end of the export window in Section 12 of the Multiplayer Hosting Terms unless you request earlier deletion, so that the two windows never conflict. Returned Creator Personal Data will be provided in a commonly used, machine readable export format documented in the developer documentation. This obligation operates alongside, and does not limit, the content portability commitment in the Summer Games Terms of Service and the Multiplayer Hosting Terms: you keep copies of your projects and can export them in a Godot compatible format, including on Account closure or a wind down of the Platform, and Summer will provide a reasonable export window and tooling for hosted save data and player data before any wind down of the Hosting Services.
12.5 Certification. Upon your written request, Summer will confirm in writing that deletion under Section 12.3 has been completed.
13. Audits and reports
13.1 Audit reports. Summer will make available to you, upon written request and subject to reasonable confidentiality protections: (a) Summer's then current third party audit report or certification for the Hosting Services, expected to be a SOC 2 Type II report or industry equivalent ([FIRST REPORT EXPECTED: DATE]); (b) a summary of Summer's most recent penetration test performed by an independent firm, with findings redacted as appropriate; and (c) the security measures summary in Annex C, as updated.
13.2 Written questionnaires. No more than once per 12 month period, and upon at least [30] days written notice, you may submit a reasonable written security and privacy questionnaire, and Summer will respond within a commercially reasonable time. Responses are Summer's confidential information.
13.3 Sufficiency. The parties agree that, given the scale at which Summer serves Creators, the materials in Sections 13.1 and 13.2 are the primary means by which Summer demonstrates compliance with this DPA, and you agree to exercise any audit right first by reviewing those materials.
13.4 Fallback audit. If (a) the materials in Sections 13.1 and 13.2 are not sufficient to reasonably demonstrate Summer's compliance with this DPA, (b) an audit is required by a competent regulator or by Applicable Data Protection Laws, or (c) an audit follows a Security Incident affecting your Creator Personal Data, then, no more than once per 12 month period, you (or an independent third party auditor on your behalf that is not a competitor of Summer and that is bound by confidentiality) may conduct an audit of Summer's Processing of Creator Personal Data. Any such audit: (i) requires at least [30] days written notice, except where a regulator requires otherwise; (ii) occurs during normal business hours, is limited in scope to Summer's compliance with this DPA, and may not access other customers' data or Summer's systems beyond what is necessary; (iii) will follow a mutually agreed audit plan; and (iv) is at your expense, unless the audit reveals material noncompliance by Summer, in which case Summer will bear its reasonable costs of the audit. Nothing in this Section limits any audit right that a supervisory authority holds directly under Applicable Data Protection Laws or that the SCCs grant when they apply.
13.5 Notice of noncompliance findings. Each party will promptly share with the other any audit finding of material noncompliance with this DPA, and Summer will remediate confirmed material noncompliance within a commercially reasonable period.
14. International data transfers
14.1 Launch posture. Sparks Packs are sold to Players by App Store Purchase in every launch country on the Sparks purchase country lists in Sections 3.7 and 3.9 of the Fee and Rates Schedule, as updated there, from launch day, Japan, Brazil and Argentina included; Summer's own web checkout sells Sparks Packs in the United States only at launch, and further countries are added to that list only as each is cleared. In Japan, Summer monitors the total unused balance of Purchased Sparks held by Players in Japan against the Payment Services Act threshold for prepaid payment instruments (an unused balance of JPY 10,000,000 on the 31 March and 30 September base dates) and completes the prepaid payment instrument registration and the security deposit before that threshold is reached; until then Summer is within the exemption. Creators, including Creators who use the Hosting Services for Exported Games, may be located in any country Summer supports, as Section 1.5 of the Multiplayer Hosting Terms states. Creator Personal Data is hosted in the United States [CONFIRM HOSTING REGIONS]. Sections 14.3 through 14.5 apply whenever the condition in Section 14.2 is met, without any separate activation step, which may be from launch day for a Creator established in the EU, the EEA, the United Kingdom or Switzerland who connects an Exported Game to the Hosting Services.
14.2 Trigger. Sections 14.3 through 14.5 take effect automatically if and when (a) you or Summer make the Exported Game or Hosting Services available such that Summer's Processing of Creator Personal Data becomes subject to the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection, and (b) that Processing involves a transfer of personal data to a country that has not received an adequacy decision under the applicable law.
14.3 SCC incorporation. In that event, the SCCs are incorporated into this DPA by reference as follows: Module Two (controller to processor) applies where you act as a controller, and Module Three (processor to processor) applies where you act as a processor for a third party; the optional docking clause (Clause 7) is included; option 2 of Clause 9(a) (general written authorization) applies with the notice period in Section 9.2; the optional language in Clause 11(a) is not included; for Clause 17, option 1 applies and the governing law is the law of Ireland; for Clause 18, the courts of Ireland are chosen; Annex A of this DPA (including Section A.9) serves as Annex I of the SCCs, Annex C serves as Annex II of the SCCs, and Annex B serves as Annex III of the SCCs.
14.4 UK and Switzerland. For transfers subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018, with the tables completed by the information in this DPA and its Annexes. For transfers subject to Swiss law, the SCCs apply with the modifications required by the Swiss Federal Data Protection and Information Commissioner's guidance.
14.5 Conflict. Where the SCCs apply, they prevail over this DPA and the Hosting Agreements to the extent of any conflict.
14.6 Successor mechanisms. If a transfer mechanism relied on under this Section 14 is invalidated or superseded, the parties will cooperate in good faith to adopt a replacement mechanism without delay.
15. Term and termination
15.1 Term. This DPA is effective as described in Section 1.5 and continues until the later of (a) termination or expiration of the Hosting Agreements and (b) the date Summer ceases to Process Creator Personal Data on your behalf.
15.2 Survival. Sections 5 (with respect to retained data), 6, 8, 12, 16, 17, and 18 survive termination until Summer no longer holds Creator Personal Data, and Section 16 survives thereafter.
15.3 Suspension. Summer's suspension rights under the Hosting Agreements are unaffected by this DPA, provided that suspension does not relieve Summer of its obligations under Sections 6, 7, 8, and 12 with respect to Creator Personal Data it continues to hold.
16. Liability
16.1 Single agreement, single cap. This DPA is part of the Hosting Agreements. Each party's liability, in the aggregate, arising out of or relating to this DPA (including the SCCs, when they apply, to the maximum extent permitted by the SCCs) and the Hosting Agreements combined is subject to the exclusions of damages and the aggregate limitation of liability set out in the Multiplayer Hosting Terms and the Developer Tooling and API Terms. This DPA does not create a separate or additional cap.
16.2 No limitation where prohibited. Nothing in this DPA limits liability that cannot be limited under applicable law, and nothing in this Section 16 limits either party's liability with respect to a Data Subject's rights under the SCCs when they apply.
16.3 Allocation. Each party is liable for its own violations of Applicable Data Protection Laws in its respective role under Section 3. Claims between the parties under this DPA must be brought under and in accordance with the Hosting Agreements, including the dispute resolution provisions of the Summer Games Terms of Service as incorporated there.
17. Order of precedence
17.1 If there is a conflict among the documents governing the Processing of Creator Personal Data, the following order of precedence applies, from highest to lowest: (a) the SCCs, when and to the extent they apply under Section 14; (b) this DPA, including its Annexes; (c) the Multiplayer Hosting Terms and the Developer Tooling and API Terms; and (d) the Summer Games Terms of Service and any other Additional Terms (as defined in the Summer Dictionary).
17.2 With respect to the subject matter of the Processing of Creator Personal Data, this DPA supersedes any prior data processing terms between the parties, except an individually executed data processing agreement as described in Section 1.5.
18. General terms
18.1 Dispute resolution and governing law. Any Dispute between you and Summer arising out of or relating to this Creator Data Processing Addendum is governed by Section 23 (Dispute resolution and arbitration agreement) and Section 24 (Governing law and venue) of the Summer Games Terms of Service, which are incorporated into this DPA by reference and are not restated here. Those Sections include a mandatory informal resolution period, an agreement to individual arbitration for US Residents with a thirty (30) day right to opt out, a small claims option, a protocol for Coordinated Cases, and class action and jury trial waivers to the extent the law allows. Nothing in this DPA changes, restates, or adds to those Sections; if any text in this DPA appears to do so, Sections 23 and 24 of the Summer Games Terms of Service control. Where Section 14.3 selects a different governing law and forum for the SCCs themselves, that selection applies to the SCCs only.
18.2 Updates. Summer may update this DPA from time to time (a) to reflect changes in Applicable Data Protection Laws or guidance, (b) to reflect changes to the Services, or (c) as otherwise permitted under the Hosting Agreements, provided that no update will materially reduce the level of protection for Creator Personal Data during the term without your consent. Summer will give at least [30] days notice of material updates.
18.3 Notices. Notices to Summer under this DPA must be sent to support@summerengine.com and, for Security Incident and Subprocessor matters, to any additional address specified in the developer documentation. Notices to you will be sent to the email address associated with your Account or through the developer dashboard.
18.4 Severability. If any provision of this DPA is held unenforceable, the remainder remains in effect, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable while preserving the parties' intent.
18.5 No agency. This DPA does not create a partnership, joint venture, or agency relationship between the parties.
18.6 Entire agreement for its subject matter. Except as described in Sections 1.5 and 17.2, this DPA, together with the Hosting Agreements, is the entire agreement between the parties regarding Summer's Processing of Creator Personal Data.
Annex A: Description of the Processing
A.1 Subject matter. Summer's provision of Hosting Services and backend services to the Creator for Exported Games, as described in the Multiplayer Hosting Terms and the Developer Tooling and API Terms. A.2 Duration. The term of the Hosting Agreements, plus the deletion and backup rotation periods described in Section 12. A.3 Nature and purpose of the Processing. Summer Processes Creator Personal Data to provide the following services, in each case only to the extent the Creator enables the corresponding feature: (a) multiplayer session hosting and orchestration, including session creation, join and leave events, host migration, and region selection; (b) matchmaking and lobby services, including skill or preference parameters supplied by the Creator's game; (c) network relay and traversal for game traffic and, if enabled by the Creator, text or voice communication relay (transient Processing; not stored except as configured for moderation or abuse handling); (d) player save data and cloud state storage keyed to a player identifier; (e) telemetry ingestion and analytics dashboards for the Creator (gameplay events, performance metrics, funnels defined by the Creator); (f) crash and error reporting (stack traces, device and OS metadata, and any log content the Creator's game includes); (g) service integrity functions the Creator enables, such as rate limiting and anti-abuse signals; and (h) technical support and troubleshooting at the Creator's request. A.4 Categories of Data Subjects. Players and other end users of the Creator's Exported Games. Where the Creator has flagged a game under Section 11.2, Data Subjects may include children under 13. A.5 Categories of Creator Personal Data. (a) player identifiers: the Creator's player ID, third party platform identifiers passed by the Creator's game (for example a Steam ID), Summer issued session and device tokens; (b) network and device data: IP address, port, connection quality metrics, device type, operating system, hardware capabilities relevant to networking and rendering; (c) session data: timestamps, session membership, match events, in game state replicated through the Hosting Services; (d) telemetry defined by the Creator: gameplay events and attributes the Creator's game emits; (e) crash data: stack traces, breadcrumbs, and log lines emitted by the Creator's game; (f) stored player state: save games and profile data keyed to a player identifier; and (g) if enabled by the Creator: text chat content and voice audio in transit through relay services. A.6 Sensitive data. None intended. The Creator must not submit the categories listed in Section 7.4 without a signed writing. A.7 Frequency. Continuous, for the duration of the services. A.8 Retention. As configured by the Creator, subject to Section 12 and the Data Retention and Deletion Policy. A.9 For SCC purposes (when applicable): data exporter is the Creator; data importer is Summer Labs, Inc.; competent supervisory authority to be determined under Clause 13 of the SCCs at the time the SCCs take effect.
Annex A-2: Description of the Processing for the Paid Games lane (DORMANT)
A-2.1 Status. This Annex applies only when Section 1A takes effect. A-2.2 Subject matter. Summer's provision of listing, checkout presentation, Game License delivery, refund-request handling and dispute support to the Creator as Seller of Record for Paid Game sales under the Paid Games Terms. A-2.3 Nature and purpose. Summer Processes Paid Game sale records to: (a) list the Paid Game and present its price; (b) present checkout on the Creator's behalf and pass the buyer to Stripe Connect; (c) deliver the Game License to the buyer's Summer Account and record the entitlement; (d) receive and process refund requests under the Paid Games refund floor and instruct Stripe accordingly; (e) assemble and submit chargeback and dispute evidence with the Creator; and (f) produce sales statements and exports for the Creator. A-2.4 Categories of Data Subjects. Buyers of the Creator's Paid Games who hold a Summer Account. A-2.5 Categories of Creator Personal Data. Buyer Account identifier and username; billing country and, where Stripe provides it, region; price, currency, tax and application fee; purchase, delivery, refund and dispute timestamps and status; the Stripe transaction identifiers. Never full payment instrument details, which Stripe holds. Billing country here is the buyer's country for the Creator's own sales-tax and dispute purposes; it is not the Player Country Summer processes as controller under the Summer Games Privacy Policy to compute the US-Source Share of Creator earnings. A-2.6 Sensitive data. None intended. A-2.7 Duration and retention. The term of the Paid Games Terms for that Game, then as Section 12 provides, subject to the 7-year financial-record period the Creator's own law imposes on it and Summer's own application fee records, which Summer keeps as an independent controller. A-2.8 For SCC purposes (when applicable): data exporter is the Creator; data importer is Summer Labs, Inc.
Annex B: Subprocessor categories
The current list of Subprocessors, with names, locations, and services, is published at [SUBPROCESSOR LIST URL]. At the effective date, Subprocessors fall into the following categories: (a) cloud infrastructure and storage providers ([CLOUD VENDOR NAMES]), for compute, storage, and networking underlying the Hosting Services; (b) content delivery network and DDoS mitigation providers ([CDN VENDOR NAME]); (c) observability, logging, and monitoring providers ([OBSERVABILITY VENDOR NAME]); (d) crash and error reporting infrastructure ([CRASH VENDOR NAME]), where not self hosted; (e) communications relay infrastructure for voice and text, where the Creator enables those features ([RELAY VENDOR NAME]); and (f) customer support tooling used to handle Creator support tickets that may incidentally contain Creator Personal Data ([SUPPORT VENDOR NAME]). For clarity: (i) Stripe, Inc. and its affiliates, as Summer's Payout Provider, process the Creator's own Payout Account details (collected through a Stripe-hosted form) and Program Payment instructions as Summer's service provider under Summer's agreement with Stripe, and, for the Summer Games lane, process Player payments as Summer's payment processor; (ii) Persona processes the Creator's own identity verification and sanctions screening data as Summer's Identity Verification Provider under Summer's agreement with Persona; (iii) Creators have no direct agreement with either; and (iv) neither Stripe nor Persona is a Subprocessor of Creator Personal Data (players of Exported Games) under this DPA, and neither receives any such data. If Section 1A activates, Stripe processes the Creator's Seller Account data under the Creator's own Stripe Connected Account Agreement and is not Summer's Subprocessor for it. Summer, not Stripe, makes each Withholding Determination and files Forms 1099-MISC and 1042-S under the Creator Tax Addendum; whether Tax Forms are collected through Stripe's hosted onboarding or by Summer directly remains open, and in either case the forms, Withholding Determinations and reporting records are Summer's controller data outside this DPA.
Annex C: Technical and organizational security measures (summary)
Summer maintains a written information security program that includes, at minimum, the following measures. Placeholders will be completed before execution. C.1 Encryption. Creator Personal Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent. Game traffic through relay services is encrypted at the transport layer. C.2 Access control. Role based access on a least privilege basis; single sign on with multi factor authentication for all personnel access to production systems; access reviews at least [quarterly]; prompt revocation on role change or departure. C.3 Network security. Segmentation between production and corporate environments; firewalls and security groups with default deny; DDoS mitigation at the edge. C.4 Logging and monitoring. Centralized security logging, alerting on anomalous access, and retention of security logs for [LOG RETENTION PERIOD]. C.5 Vulnerability management. Regular automated scanning; risk based patching within defined SLAs ([PATCH SLA]); an external penetration test at least annually by an independent firm; a coordinated disclosure channel per the Vulnerability Disclosure Policy. C.6 Secure development. Code review requirements, dependency scanning, secrets management, and CI enforcement for services that Process Creator Personal Data. C.7 Resilience. Redundant infrastructure across availability zones; encrypted backups; disaster recovery objectives of [RPO] recovery point and [RTO] recovery time; recovery testing at least [annually]. C.8 Personnel. Background checks where permitted by law; confidentiality obligations under Section 6; security and privacy training at hire and at least annually. C.9 Incident response. A documented incident response plan with defined severity levels, an on call rotation, and post incident reviews; customer notification per Section 8. C.10 Physical security. Provided by the cloud infrastructure providers listed in Annex B, each of which maintains independent certifications (for example ISO 27001 and SOC 2). C.11 Certifications. Summer is pursuing a SOC 2 Type II report covering the Hosting Services, expected [FIRST REPORT EXPECTED: DATE]. Until issuance, Summer will provide the written summary and questionnaire responses described in Section 13. C.12 Data minimization tooling. Creator facing controls for retention windows, per player deletion, telemetry schema definition, and regional hosting selection.