Data Processing Agreement
Last updated: 2026-05-15. Placeholder content — review with counsel before public launch.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Rebirth Hosting B.V. ("Rebirth", "we") and the customer ("you") and applies whenever Rebirth processes Personal Data on your behalf.
1. Definitions
- Personal Data, Processing, Data Controller, Data Processor, and Data Subject carry the meanings set out in Regulation (EU) 2016/679 (the "GDPR").
- Customer Data means data uploaded to, generated on, or processed through your Rebirth server instance.
2. Roles
- You are the Data Controller for Customer Data, including any personal data of your players, sub-users, or community members.
- Rebirth is the Data Processor with respect to Customer Data and the Data Controller for Account Data (email, billing address, payment metadata).
3. Scope of processing
We process Customer Data solely to:
- Provision and maintain the hosting environment.
- Perform the daily off-site backups described in our Service Description.
- Respond to lawful requests from the Data Controller (you).
- Carry out our contractual obligations under the Terms of Service.
4. Sub-processors
Rebirth uses the following sub-processors. We will notify you in writing of any addition or replacement.
| Sub-processor | Purpose | Location | |-----------------|----------------------------------------|-------------------------| | Equinix | Colocation (compute & storage) | NL, DE, UK, FR, US, SG | | Mollie B.V. | Payment processing | Netherlands | | Sentry | Error and exception reporting | EU (Frankfurt) | | Postmark | Transactional email delivery | EU (Dublin) |
5. Security
Rebirth maintains industry-standard administrative, physical, and technical safeguards, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256-XTS for backups).
- Role-based access with hardware-key MFA on every privileged account.
- Yearly third-party penetration testing.
- 24/7 monitoring and incident response.
6. Data subject requests
If a Data Subject contacts Rebirth with a GDPR request that concerns Customer Data, we will refer them to you and assist you in fulfilling the request as required by Articles 12-23 GDPR.
7. Personal data breach
In the event of a Personal Data Breach affecting Customer Data, Rebirth will notify you without undue delay and provide all information reasonably necessary to comply with Article 33 GDPR.
8. International transfers
Where Personal Data is transferred outside the EEA, Rebirth implements the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) and any necessary supplementary measures.
9. Term and termination
This DPA remains in force for as long as Rebirth processes Customer Data on your behalf. Upon termination, Rebirth will delete or return Customer Data within 30 days, unless retention is required by law.
10. Contact
For DPA questions or to request the signed PDF version, contact our Data Protection Officer at [email protected].