Data Processing Agreement
Our Article 28 commitments for the personal data your servers send us. This is the part that matters most, because that data is about your players, not about you.
Version 2026-09-05 · Applies to the Titan Logs service
1. Scope and roles
This agreement is between you (the Controller) and Titan Software z.s., zapsaný spolek (registered association), Ametystová 702/46, 153 00 Praha, Česká republika, IČO 29738725 (the Processor). It forms part of the Terms of Service and takes effect when you accept them.
It covers only the log data your servers send us. Your own account data is processed by Titan as an independent controller and is governed by the Privacy Policy.
2. Subject-matter, duration, nature and purpose (Art. 28(3))
| Subject-matter | Receiving, storing, indexing, searching and returning log events generated by the Controller's FiveM servers. |
| Duration | For as long as the Controller has an account, plus the plan's retention period for stored events and the backup window below. |
| Nature | Collection by API, structured storage, indexing for search, transmission back to authorised members of the Controller's organization, and scheduled erasure. |
| Purpose | Providing the Titan Logs service to the Controller. Nothing else — no analytics, no profiling, no model training, no cross-customer aggregation of personal data. |
| Categories of data subject | Players and staff on the Controller's game servers. |
| Categories of personal data | Game platform identifiers (license, license2, discord, steam, xbox, live, fivem), IP addresses (optional — see §4), player display names, and whatever the Controller includes in event messages and metadata, which may include chat content, ban and kick reasons, and in-game transactions. |
| Special categories (Art. 9) | None requested or required. Free-text fields could contain anything, so the Controller should avoid logging special-category data. |
3. Processing on documented instructions (Art. 28(3)(a))
We process the data only on your documented instructions. Your instructions are: this agreement, the Terms of Service, and the configuration you set in the product (which servers exist, what retention applies, whether player IPs are stored, who has access).
We will not transfer the data to a third country except through the subprocessors listed at /legal/subprocessors. If a legal obligation requires us to process beyond your instructions, we will tell you before doing so unless the law forbids that notice.
4. Controls we give you
These are the levers you have, and we would encourage you to use them:
- Player IP addresses can be switched off in Settings → Privacy. When off, the
ipfield is discarded at ingest, before anything is written. The FiveM resource attaches it by default, so this is worth a deliberate decision. - Identifiers are allowlisted. Only the fields listed above are stored; anything else your scripts send is dropped at the boundary rather than kept.
- Retention can be shortened below your plan default, per organization and per server.
- Access is role-based. Only roles you grant log access can read the data.
- Chat logging is your choice. The SDK offers it; nothing requires you to use it. It is the single highest-risk category in the product.
5. Confidentiality (Art. 28(3)(b))
Everyone we authorise to process the data is bound by confidentiality. Titan staff cannot browse your logs: the internal operator view exposes cross-organization counters only, there is no “sign in as customer” capability in the product, and every access to that view is recorded in a platform audit trail.
6. Security measures (Art. 28(3)(c), Art. 32)
- Encryption in transit for all API and dashboard traffic.
- Ingest credentials and session tokens stored only as hashes, never recoverable; credential secrets displayed exactly once, at creation.
- Identity-provider tokens encrypted at rest with AES-256-GCM.
- Organization isolation enforced at the query layer — every query for tenant-owned data requires a verified organization id — and covered by automated tests that assert one organization cannot reach another's logs, servers, credentials or invitations.
- Role-based access control with a capability model, and a rule that nobody can grant a role more senior than their own.
- Rate limiting on authentication, ingestion, exports and streams.
- An append-only audit log of security-relevant control-plane actions, retained for 730 days.
- Encrypted, off-host database backups with a tested restore procedure.
- Automated dependency, secret and static-analysis scanning in continuous integration.
7. Subprocessors (Art. 28(2), (4))
You give general authorisation for us to use the subprocessors listed at /legal/subprocessors. We impose the same data-protection obligations on each of them, and we remain fully liable to you for their performance.
We will give you at least 30 days' notice by email before adding or replacing a subprocessor. If you object on reasonable data-protection grounds, you may terminate the affected service and receive a pro-rata refund of any prepaid fees.
8. Helping you with data subject requests (Art. 28(3)(e))
Players will ask you, not us — they have no relationship with Titan. We help as follows:
- Search and export in the product already let you find and extract every event referencing a given player: actor and target identifiers are indexed, so a per-player lookup is fast.
- For erasure or restriction of a specific player's events, contact us and we will execute it against your data, normally within 5 working days and always within a period that lets you meet your own one-month deadline.
- Log data cannot meaningfully be rectified — a log entry records what happened. A rectification request will normally be handled by erasure or annotation.
We will notify you without undue delay if a data subject contacts us directly about your data, and we will not respond to them ourselves beyond telling them to contact you.
9. Personal data breaches (Art. 28(3)(f), Art. 33(2))
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 24 hours, so that you can meet your own 72-hour obligation to your supervisory authority.
Our notification will include, as far as known at the time:
- the nature of the breach, and the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures taken or proposed, including any mitigation;
- a contact point for further information.
We will also assist you with any Art. 34 communication to affected individuals, and with data protection impact assessments and prior consultations under Arts. 35 and 36.
10. Deletion and return (Art. 28(3)(g))
Log events are deleted automatically once they pass your retention period. On termination, or on your instruction, all log data is deleted; you can export it beforehand if your plan includes export, and we will help you export it if it does not.
Organization deletion runs after a 7-day grace period, during which you can cancel it. Once it runs, it removes all servers, credentials, members and log events. Only the audit record that the deletion happened is retained, because an audit log that erases the record of an erasure is not an audit log.
Backups are the honest exception. Encrypted backups taken before a deletion still contain the data until they rotate out after 30 days. They are encrypted at rest, access-controlled, and never restored selectively to recover deleted customer data.
11. Audits (Art. 28(3)(h))
We will make available the information needed to demonstrate compliance with this agreement, and will contribute to audits conducted by you or an auditor you mandate. In practice this means answering a reasonable security questionnaire and providing our documentation; we ask for reasonable notice and that audits do not disrupt the service or expose other customers' data.
12. International transfers (Chapter V)
Where a subprocessor processes data outside the EEA, the safeguard relied on is stated against that subprocessor at /legal/subprocessors. We will provide a copy of the relevant Standard Contractual Clauses or adequacy basis on request.
13. Your obligations as controller
By using Titan Logs you confirm that:
- you have a lawful basis under Art. 6 for the player data you send us;
- you have provided the information required by Arts. 13 and 14 to the people that data describes — we cannot reach them;
- you have considered whether logging chat content and IP addresses is necessary for your purpose, and configured the product accordingly;
- you have considered that your player base may include children, and what that means for the data you log;
- your instructions to us do not require us to breach the GDPR.
14. Contact
Data protection matters: [email protected]. Security reports: responsible disclosure.
Version 2026-09-05. Supersedes any earlier version on acceptance.