legalUi.dpa
legalUi.updated
1. Roles of the parties
The customer acts as the controller of player data and transfers it for processing for the purpose of detecting violations. RIFT acts as the processor and processes data only according to the customer’s documented instructions.
2. Types of data
- •Moderator account and role data
- •Game session telemetry and screenshots
- •Evidence, cases and appeal decisions
- •Processing metadata and action logs
3. Protective measures
RIFT applies organizational and technical measures: encryption at rest and in transit, role-based access control, action audit, isolated environments and an incident notification process.
4. Subprocessors
The processor may engage subprocessors to provide the services. The current list is published on the /legal/subprocessors page. Mergers and new engagements are agreed with the customer.
5. Term
Processing is carried out for the term of the agreement or until data is deleted at the customer’s request. Upon completion of processing, data is returned or deleted unless otherwise required by law.