Who this is for
This agreement (“DPA”) forms part of our terms of service between [Company legal name] (“we”) and any customer that uses Drule for an organisation, such as a Team workspace (“you”). It applies whenever we process personal data on your behalf, and it's written to meet Article 28 of the GDPR and the UK GDPR.
Roles
You are the controller of the personal data in your workspace and your games; we are your processor. For our own account holders' login and billing details we act as a separate controller, as described in our privacy policy.
What we process
| Subject matter | Providing Drule: live quizzes, health checks, reports and integrations for your workspace. |
|---|---|
| People | Your workspace members and invitees, and the players who join your organisation's games. |
| Personal data | Members: names, email addresses, roles. Players: nicknames, team, answers (including free-text responses), answer times and scores. Anonymous games store no nicknames. |
| Special categories | None are needed. Please don't ask players for them in questions. |
| Purpose | Running games and showing you the results, as instructed through your use of Drule. |
| Duration | For as long as you use Drule, then until deletion as described below. Report retention can be set to 30, 90, 180 or 365 days. |
What we promise
- We process your data only to provide Drule and on your documented instructions — your use of the product and your settings count as instructions.
- Everyone at [Company legal name] with access to it is bound by confidentiality.
- We protect it with the measures on our security page, and keep them at least as strong while this DPA applies.
- We don't sell it, or use it for advertising or to train AI models.
Subprocessors
You authorise the subprocessors on our subprocessors page. We'll give workspace owners at least [30 days] notice before adding or replacing one, and you may object on reasonable data protection grounds. We hold each subprocessor to data protection terms as protective as these.
Helping with requests
If a player or member asks you to see or delete their data, Drule's tools help: delete a report, remove a member, set automatic report deletion, or export an account's data. If you need more, we'll help within a reasonable time. If a request reaches us directly, we'll pass it to you.
Security incidents
If we become aware of a personal data breach affecting your data, we'll tell you without undue delay and within [48 hours], with what we know and what we're doing about it, and keep you updated.
International transfers
Drule's servers and backups are in the EU. Where a subprocessor handles data outside the EU or UK, the transfer is covered by the European Commission's standard contractual clauses (and the UK addendum) or another lawful mechanism [confirm per provider].
When the service ends
When your workspace or account is deleted, its data is deleted from the live service straight away and from encrypted backups within [backup retention period]. Export anything you want to keep first. Payment records are kept only as the law requires.
Information and audits
We'll answer reasonable security questionnaires and give you the information you need to show compliance. We don't hold a SOC 2 or ISO 27001 certification today; if an audit is needed, we'll agree its scope, timing and cost with you in advance.
Signing a copy
This DPA applies automatically to business use. If you need a signed copy, email support@drule.app with your organisation's legal name and address and we'll send one countersigned by [Company legal name], [Registered address].