Data Processing Addendum (US)
Updated: March 18, 2025
1. United States
With respect to Authorized Users in the United States, the following provisions shall apply:
2. Definitions
Capitalized words used in this Data Processing Addendum ("DPA") that are not expressly defined in this DPA have the meaning set forth in the Agreement.
- "Data Protection Legislation" means applicable federal, state, local, and municipal laws and regulations in the United States that relate to the privacy, data protection or data security of Personal Data.
- "Personal Data" means information about a specific individual that is provided, submitted, or otherwise made available to Playlab by or on behalf of Customer or any Authorized User in connection with any of the Services that constitutes "personal data", "personal information", "personally identifiable information" or similar term under applicable law.
- "Process" shall have the same meaning as set out in the applicable Data Protection Legislation or if no such meaning or concept exists, it shall be the means by which Playlab collects, uses, stores, discloses, or transfers Personal Data.
3. Compliance with Laws; Roles
Each Party shall comply with all Data Protection Legislation applicable to it in its respective Processing of Personal Data under the Agreement. For purposes of this DPA and as between the Parties, Customer is the controller of the Personal Data and Playlab is the processor of such data.
4. Notices and Consents
Customer shall provide all notices and obtain all such consents required under applicable Data Protection Legislation (including, without limitation, consents required under the Family Education Rights and Privacy Act, 20 U.S.C. § 1232g and its implementing regulations, 34 C.F.R. Part 99 (together, "FERPA")) from the Authorized Users to allow Playlab to Process the Personal Data to provide the Service and as otherwise described in the Agreement, including in this DPA (the "Notices and Consents"). Customer represents and warrants that it has obtained and will maintain the Notices and Consents for all Authorized Users through the entire term of the Agreement.
5. Details of Processing
Personal Data will be Processed for the purposes set forth in the Agreement and any applicable Order Forms.
6. Playlab Obligations
(a) Playlab shall implement and maintain reasonable administrative, technical and organizational measures that are designed to preserve the confidentiality and availability of Personal Data Processed by Playlab via the Service. Playlab shall implement the technical and organizational measures, as set forth in Annex 1 (Security Measures) ("Security Measures"). Customer has reviewed Security Measures and agrees that such measures are appropriate taking into account the state of the art, the costs of implementation, nature, scope, context and purposes of the processing of Personal Data hereunder.
(b) Playlab shall take reasonable steps to ensure that any employees who have access to the Personal Data are trained on applicable Data Protection Legislation and to ensure that employees do not disclose Personal Data for reasons other than those necessary for their Processing of the Personal Data.
(c) Playlab engages certain third-party entities to Process the Personal Data on Playlab's behalf ("Sub-processors"). Playlab shall enter into an agreement with each Sub-processor containing terms that offer substantially similar levels of data protection obligations and protection for Personal Data as those set out in this Section. Customer consents to Playlab engaging the Sub-processors for the purposes set forth in the Agreement and this DPA.
(d) If Playlab becomes aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to the Personal Data (a "Security Incident"), Playlab shall inform Customer, within a reasonable amount of time, taking into account the timeframes required by Data Protection Legislation, with respect to the Security Incident. Playlab will provide reasonable information, cooperation, and updates of material developments to enable Customer to fulfill any data breach reporting obligations it may have under Data Protection Legislation. However, Playlab provision of information and cooperation shall be at Customer's cost and expense to the extent any Security Incidents were caused by Customer or its Authorized Users or Data Subjects (as defined below). Playlab may take such other measures as it deems appropriate to mitigate the effects of the Security Incident.
7. Data Subject Inquiries
Customer shall be solely responsible for responding to and fulfilling any inquiries from Authorized Users and other data subjects, including parents and legal guardians of Authorized Users where the Authorized User is a student of Customer (collectively, "Data Subjects") regarding their Personal Data in connection with the Processing under the Agreement, including any requests to exercise their rights under applicable Data Protection Legislation, and Customer shall handle all Data Subject inquiries in accordance with applicable Data Protection Legislation. Customer understands that Playlab is not required to take any action in response to any requests from Data Subjects except to notify such Data Subjects to contact Customer. To the extent Customer cannot obtain a copy of, delete or amend the Personal Data directly within the Service, Customer may contact Playlab and Playlab, with Customer's express written permission and provided Customer has obtained the appropriate consent from the applicable Data Subject, will provide a copy of, delete or amend such Data Subject's Personal Data in accordance with Customer's instructions. To the extent legally permitted, Customer shall be responsible for reasonable costs arising out of Playlab's provision of assistance with Customer's Data Subject requests. Customer shall indemnify, defend, and hold harmless Playlab and its affiliates, subsidiaries, successors and assigns (and the officers, directors, employees, sublicensees, customers, and agents of Playlab and its affiliates, subsidiaries, successors, and assigns), from and against any and all losses, demands, liabilities, damages, fines, settlements, expenses, and costs (including without limitation reasonable attorneys' fees and costs), arising from, in connection with, Playlab complying with Customer's instructions under this DPA.
8. Authorized Disclosure of Personal Data
(a) Customer acknowledges and agrees that, at Customer's request and reasonable cost, Playlab may provide Personal Data to third-parties or other entities to whom Customer requests Playlab provide Personal Data (e.g., State Board of Education). Customer shall make such a request to disclose Personal Data in writing ("Authorization"). Customer acknowledges and agrees that each Authorization will result in Customer electing, in its sole discretion, to transfer the Personal Data to the recipients that Customer selects.
(b) The entities identified in Section 8(a) are collectively defined as "Recipients."
(c) Customer acknowledges that Customer Content may contain Personal Data and may be subject to Data Protection Legislation. Customer will hold Playlab harmless, and not liable in any way, for Playlab's disclosure of Personal Data to the Recipients in accordance with an Authorization.
(d) Playlab makes no warranty (a) that the use of the Personal Data by the Recipient is valid or in compliance with applicable Data Protection Legislation and Customer's organization's policies or (b) that Personal Data will remain secure upon transfer to the Recipient, and disclaims any responsibility for the transfer. Customer acknowledges that the Personal Data will be provided on an "as is", "as available" basis.
9. Data Retention
Playlab will delete Personal Data within a reasonable amount of time after the termination or expiration of the Agreement, except that Playlab may retain Personal Data as required by applicable legal requirements or as agreed by Customer. For the avoidance of doubt, the foregoing shall not apply to Aggregated and De-identified Data (as defined in the Agreement).
10. Playlab Data
Customer acknowledges and agrees that Playlab may create Performance Data and Aggregated and De-identified Data from Processing related to the Agreement, including in connection with the Service. In generating such data, Playlab shall (a) take reasonable measures to ensure that such data cannot be associated with a Data Subject and (b) not attempt to reidentify such data, except as permitted under Data Protection Legislation.
11. Education Records
As applicable, to the extent Playlab has access to "Education Records" and "Personally Identifiable Information" (as those terms are defined in Family Education Rights and Privacy Act, 20 U.S.C. § 1232g and its implementing regulations, 34 C.F.R. Part 99 (together, "FERPA") in connection with its provision of the Products that is not otherwise permitted under FERPA: (a) Customer agrees that Playlab has met the criteria for being a "School Official" with "Legitimate Educational Interests" (as those terms are used in FERPA) in such Education Records and Personally Identifiable Information; and (b) Playlab agrees that such Education Records and Personally Identifiable Information will be used only for authorized purposes under the Agreement, and it will not redisclose such Education Records or Personally Identifiable Information except with Authorization from Customer or where such redisclosure is otherwise permitted under FERPA.
12. Compliance; Audits
(a) Taking into account the nature of the Processing of Personal Data by Playlab and the information available to Playlab, where required by applicable law, Playlab shall provide such information and assistance to Customer as Customer may reasonably request (insofar as such information is available to Playlab and the sharing thereof does not compromise the security, confidentiality, integrity or availability of any data Processed by Playlab) to help Customer meet its obligations under Data Protection Legislation, including in relation to the security of Personal Data, the reporting and investigation of Security Incidents, the demonstration of Customer's compliance with such obligations and the performance of any data protection assessments.
(b) Subject to Section 12(c) below, where required by applicable law, Playlab shall make available to Customer such information as Customer may reasonably request for Playlab to demonstrate compliance with Data Protection Legislation and this DPA. Without limitation of the foregoing, Customer may conduct (in accordance with this DPA), at its sole cost and expense, and Playlab will reasonably cooperate with, reasonable audits (including inspections, manual reviews, automated scans and other technical and operational testing that Customer is entitled to perform under Data Protection Legislation), in each case, whereby Customer or a qualified and independent auditor appointed by Customer using an appropriate and accepted audit control standard or framework may audit Playlab's technical and organizational measures in support of such compliance and the auditor's report is provided to Customer and Playlab upon Customer's request.
(c) Customer shall give Playlab reasonable advance notice of any such audits. Playlab need not cooperate with any audit (a) performed by any individual or entity who has not entered into a non-disclosure agreement with Playlab on terms acceptable to Playlab in respect of information obtained in relation to the audit; (b) conducted outside of Playlab's normal business hours at the relevant site; or (c) on more than one occasion in any calendar year during the term of the Agreement, except for any additional audits that Customer is required to perform under Data Protection Legislation. The audit must be conducted in accordance with Playlab's safety, security or other relevant policies, must not impact the security, confidentiality, integrity or availability of any data Processed by Playlab and must not unreasonably interfere with Playlab's business activities. Customer shall not conduct any scans or technical or operational testing of Playlab's applications, websites, services, networks or systems without Playlab's prior approval (which shall not be unreasonably withheld).
13. State Specific Privacy Addenda
If applicable, the Parties agree to the State Specific Data Protection Addenda for the applicable state(s).
14. Updates to this DPA
Notwithstanding anything to the contrary in the Agreement, Playlab reserves the right to modify this DPA from time to time in its sole discretion and without Customer's prior consent except where required by applicable law ("Updated DPA"). Customer agrees that any Updated DPA will be effective immediately upon Playlab emailing the Updated DPA to Customer, unless Playlab is required by applicable law to obtain Customer's consent, in which case, such Updated DPA will be effective immediately upon the provision of such consent. Playlab will also endeavor to notify Customer of any material revision to this DPA at least ten (10) days prior to such revision coming into effect, using Customer's email address as set forth in the most recently executed Order Form.
Annex 1: Security Measures
As from the Effective Date, Playlab will implement and maintain the Security Measures as set out in this Annex.
-
Organizational management and dedicated staff responsible for the development, implementation and maintenance of Playlab's information security program.
-
Audit and risk assessment procedures for the purposes of periodic review and assessment of risks to Playlab's organization, monitoring and maintaining compliance with Playlab's policies and procedures, and reporting the condition of its information security and compliance to internal senior management.
-
Data security controls which include at a minimum: logical segregation of data, restricted (e.g., role-based) access and monitoring, and utilization of commercially reasonable encryption technologies for Personal Data.
-
Logical access controls designed to manage electronic access to data and system functionality, based on authority levels and job functions.
-
Password controls designed to manage and control password strength, expiration and usage.
-
System audit or event logging and related monitoring procedures to proactively record Authorized User access and system activity.
-
Physical and environmental security of data centers, server room facilities and other areas containing Personal Data designed to protect information assets from unauthorized physical access or damage.
-
Operational procedures and controls to provide for configuration, monitoring and maintenance of technology and information systems, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from Playlab's possession.
-
Change management procedures and tracking mechanisms designed to test, approve and monitor all material changes to Playlab's technology and information assets.
-
Incident management procedures designed to allow Playlab to investigate, respond to, mitigate and notify of events related to Playlab's technology and information assets.
-
Network security controls that provide for the use of enterprise firewalls and intrusion detection systems designed to protect systems from intrusion and limit the scope of any successful attack.
-
Vulnerability assessment and threat protection technologies and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
-
Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergency situations or disasters.
