Business Data Processing Agreement
Article 28 terms for business customers that use Scrap Host to process player personal data.
Effective 24 July 2026
This DPA forms part of the Terms between the business customer as controller and Computerhulp Nick, trading as Scrap Host, as processor. It applies where Scrap Host processes personal data in hosted worlds, access lists, logs, or related service functions on the customer’s documented instructions.
The purpose is to host, connect, secure, back up, support, and delete the customer’s Scrap Mechanic service. Data subjects may include the customer, administrators, invited players, and abuse reporters. Data may include Steam identifiers, player names, access permissions, game logs, connection and technical information, and personal data contained in customer-provided worlds.
Scrap Host processes data only on documented instructions, ensures authorised persons are bound by confidentiality, applies appropriate technical and organisational security measures, assists with data-subject requests and security incidents, and informs the customer if an instruction appears unlawful.
The customer gives general authorisation for the providers on the Provider List. We remain responsible for imposing appropriate data-protection terms on subprocessors. We give reasonable advance notice of a material new subprocessor so the customer can object on substantiated data-protection grounds. International transfers use a lawful Chapter V mechanism.
We notify the customer without undue delay after becoming aware of a personal-data breach affecting data processed for that customer and provide information reasonably available to us. We assist with impact assessments, regulator consultation, and rights requests to the extent appropriate to the service and information available.
Customers can download available saves during service and the 30-day post-termination period. We delete service data after that period unless law requires retention. Backup copies expire through the normal 30-day cycle. We provide information reasonably necessary to demonstrate compliance and permit proportionate audits, subject to confidentiality, security, reasonable notice, and avoiding disruption.
The customer is responsible for a lawful basis, required player information, lawful instructions, appropriate server access, and not uploading unlawful or unnecessary personal data. The Terms’ business-liability provisions apply to this DPA except where data-protection law prohibits a limitation.