Last updated: 12 June 2026. This Data Processing Agreement ("DPA") forms part of the Terms of Service between the server owner who installs and operates Ecstacy Anticheat (the "Customer", acting as Data Controller) and Simone B., operator of Ecstacy Anticheat (the "Processor", "we"). It governs the processing of in-game player personal data that we carry out on the Customer's behalf, and reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR). Where this DPA conflicts with the Terms on the subject of player-data processing, this DPA prevails.
For data about the Customer's own account, licence and billing, Ecstacy acts as an independent Controller (see our Privacy Policy). For data about the players who connect to a server running Ecstacy, the Customer is the Controller and Ecstacy is the Processor, processing only on the Customer's documented instructions. The act of installing and configuring the Software constitutes those instructions.
As Processor, we undertake to:
The Customer grants general authorisation for us to engage the sub-processors below, each bound by data- protection terms no less protective than this DPA. We will give reasonable notice of any intended addition or replacement and the Customer may object on reasonable data-protection grounds.
Our payment provider (Stripe) is not a player-data sub-processor. It processes Customer billing data as an independent controller, as described in the Privacy Policy.
Raw behavioural records are kept for a limited period and then deleted or aggregated. Detection records flagged for human review are kept while the review is open. On licence termination, or on the Customer's written request, we delete or return the player personal data we hold for that Customer within a reasonable period, subject to any overriding legal-retention obligation.
Taking account of the state of the art and the risks, we maintain measures including: encryption of data in transit (TLS) across our service mesh; least-privilege access controls and authenticated, audited admin access; network isolation of internal services; storage of licence keys only as irreversible hashes; segregation of customer and player data; and logging and monitoring to detect and respond to incidents.
On reasonable prior written notice and no more than once per year (unless required by a supervisory authority), we will make available information reasonably necessary to demonstrate compliance with this DPA and cooperate with audits conducted by the Customer or a mandated independent auditor bound by confidentiality, in a manner that does not compromise the security or confidentiality of other customers.
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's player data, and provide the information the Customer reasonably needs to meet its own notification obligations under Articles 33–34 GDPR.
Player personal data is processed within the European Union. If any processing or sub-processing would involve a transfer outside the EU/EEA, it will be carried out only under an appropriate Article 46 GDPR safeguard (such as the European Commission's Standard Contractual Clauses).
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA is governed by Italian law, consistent with the governing-law clause of the Terms.
For any matter relating to this DPA, contact the Processor at support@ecstacy.ac.
This document is provided for transparency and may be updated; material changes will be announced. It is a standard-form agreement and does not constitute legal advice.