Version 10 · Effective 1 November 2026
This Data Processing Agreement (“Agreement”) forms part of and is incorporated into the agreement under which LootLocker AB, a Swedish company, corporation registration no. 559164-9289, with registered address at Kaptensvägen 13B, 132 46 Saltsjö-boo, Sweden (the “Data Processor”, “Processor”) provides the Services to a customer (the “Company”) (the “Principal Agreement”). This Agreement applies to the extent that Processor Processes Company Personal Data on behalf of Company in connection with the Services, and takes effect on the effective date of the Principal Agreement (the “Effective Date”). By entering into the Principal Agreement, Company accepts this Agreement. No separate signature is required.
Company and the Data Processor are hereinafter individually referred to as a “Party” and jointly, the “Parties”.
WHEREAS, the Company and the Data Processor have entered into the Principal Agreement.
WHEREAS, the Company acts as a Data Controller according to the GDPR.
WHEREAS, the Company wishes to subcontract certain Services, which imply the processing of personal data, to the Data Processor.
WHEREAS, the Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing and with the GDPR.
WHEREAS, the Parties wish to lay down their rights and obligations regarding the processing of personal data in connection with the Services provided by the Data Processor.
NOW, THEREFORE, in consideration of the mutual representations, warranties and covenants set forth in this Agreement and other good and valuable consideration, the sufficiency of which is hereby acknowledged, the Parties agree as follows:
1. Definitions and Interpretation
1.1 Unless otherwise defined herein, capitalized terms and expressions used in this Agreement shall have the following meaning:
1.1.1 “Company Personal Data” means any Personal Data Processed by a Contracted Processor on behalf of Company pursuant to or in connection with the Principal Agreement;
1.1.2 “Contracted Processor” means a Subprocessor;
1.1.3 “Data Protection Laws” means (i) EU Data Protection Laws; (ii) the CCPA, to the extent applicable; and (iii) to the extent applicable, the data protection or privacy laws of any other country;
1.1.4 “CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations, as amended or superseded from time to time;
1.1.5 “Sensitive Data” means any special categories of personal data as defined under EU Data Protection Laws (including data revealing racial or ethnic origin, health data, biometric or genetic data, sexual orientation, and criminal history), and any “sensitive personal information” as defined under the CCPA;
1.1.6 “Data Transfer” means:
1.1.6.1 A transfer of Company Personal Data from the Company to a Contracted Processor; or an onward transfer of Company Personal Data from a Contracted Processor to a Subcontracted Processor; or,
1.1.6.2 Between two establishments of a Contracted Processor.
1.1.6.3 In each case, where such transfer would be prohibited by Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws);
1.1.7 “EEA” means the European Economic Area;
1.1.8 “GDPR” means EU General Data Protection Regulation 2016/679 as well as the EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or superseded from time to time;
1.1.9 “Services” means the backend-as-a-service (Software-as-a-Service) platform, enabling game publishers or any relevant party, to authenticate players (based on device/platform ID or via email), store player and game data, manage inventories and wallets, progressions, purchases, and related game systems services the Data Processor provides.
1.1.10 “Subprocessor” means any person appointed by or on behalf of Processor to process Personal Data on behalf of the Company in connection with the Agreement.
1.2 The terms, “Commission”, “Controller”, “Data Subjects”, “Member State”, “Personal Data”, “Personal Data Breach”, “Process”, “Processing” and “Supervisory Authority” shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.
2. Processing of Company Personal Data
2.1 Processor shall:
2.1.1 Comply with all applicable Data Protection Laws in the Processing of Company Personal Data; and
2.1.2 Not Process Company Personal Data other than on the relevant Company’s documented instructions.
2.1.3 To the extent the CCPA applies, Processor acts as a service provider and shall not: (a) sell or share Company Personal Data (as those terms are defined in the CCPA); (b) retain, use, or disclose Company Personal Data for any purpose other than providing the Services, or as otherwise permitted by the CCPA; (c) retain, use, or disclose Company Personal Data outside the direct business relationship between the Parties; or (d) combine Company Personal Data with personal data received from any other party, except as permitted by the CCPA. Processor shall notify Company if it determines that it can no longer meet its obligations under the CCPA.
2.2 The Company shall instruct the Processor to Process the Company's Personal Data and to specify the purpose of such Processing. Company shall inform Data Processor of the general categories of Personal Data on the Data Subjects to be processed on behalf of the Company, as well as all sensitive categories of Personal Data on the Data Subjects.
2.3 Company shall not disclose or make available to Processor any Sensitive Data for Processing under this Agreement unless the Parties have first agreed in writing on any additional measures required to Process such Sensitive Data.
2.4 Company shall notify Processor before making available to Processor any Company Personal Data in connection with a game or service that is directed to, or likely to be accessed by, children under the age of 13. Company shall also notify Processor where Company knows, or has reason to know, that it collects personal data from individuals who are below the age at which they may consent on their own behalf under applicable Data Protection Laws. Company is responsible for determining the ages of consent applicable to its Data Subjects, for age assurance, and for obtaining and recording any parental or guardian consent required under applicable Data Protection Laws. Company shall not make such Company Personal Data available to Processor until Processor has confirmed in writing that the Processing may proceed and the Parties have agreed in writing on any additional measures required.
3. Data Subjects
3.1 The Data Processor processes Personal Data about the following categories of Data Subjects:
3.1.1 End-users and consumers of Company;
3.1.2 Company’s authorized staff.
3.2 Any changes to the Data Subjects categories must be informed and reasonably requested by Company in writing.
4. Data Processor Personnel
4.1 Data Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to the Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know or access the relevant Company Personal Data, as strictly necessary for the purposes of the Principal Agreement, and to comply with Applicable Laws in the context of that individual's duties to the Contracted Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
5. Security
5.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Data Processor shall in relation to the Company Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR.
5.2 In assessing the appropriate level of security, Processor shall take into account in particular the risks that are presented by Processing, in particular from a Personal Data Breach.
5.3 An overview of the technical and organizational measures Processor applies is set out in Exhibit B. Processor may update these measures from time to time, provided that the overall level of security is not materially reduced.
6. Subprocessing
6.1 Processor shall not appoint (or disclose any Company Personal Data to) any Subprocessor unless required or authorized by the Company.
6.2 Subprocessors in Exhibit A shall be considered authorized by the Company.
6.3 Processor maintains the current list of Subprocessors in Exhibit A and may publish it on its website. Processor shall notify Company of the addition or replacement of a Subprocessor by updating that list. If Company objects on reasonable grounds relating to data protection within fourteen (14) days of the update, the Parties shall discuss the objection in good faith, and if it cannot be resolved, Company may terminate the affected Services. Absent such an objection, the Subprocessor is deemed authorized.
7. Data Subject Rights
7.1 Taking into account the nature of the Processing, Processor shall assist the Company by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Company obligations, as reasonably understood by Company, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
7.2 Processor shall:
7.2.1 Promptly notify Company if it receives a request from a Data Subject under any Data Protection Law in respect of Company Personal Data; and
7.2.2 Ensure that it does not respond to that request except on the documented instructions of Company or as required by Applicable Laws to which the Processor is subject, in which case Processor shall to the extent permitted by Applicable Laws inform Company of that legal requirement before the Contracted Processor responds to the request.
8. Personal Data Breach
8.1 Processor shall notify Company without undue delay upon Processor becoming aware of a Personal Data Breach affecting Company Personal Data, providing Company with sufficient information to allow the Company to meet any obligations to report or inform Data Subjects of the Personal Data Breach under the Data Protection Laws.
8.2 Processor shall co-operate with the Company and take reasonable commercial steps as are directed by Company to assist in the investigation, mitigation, and remediation of each such Personal Data Breach.
9. Data Protection Impact Assessment and Prior Consultation
9.1 Processor shall provide reasonable assistance to the Company with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which Company reasonably considers to be required by article 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors.
10. Deletion or return of Company Personal Data
10.1 Subject to this Section, on cessation of any Services involving the Processing of Company Personal Data (the “Cessation Date”) Processor shall, at Company’s election, return the Company Personal Data to Company or delete it. Company may export the Company Personal Data during the thirty (30) days following the Cessation Date, or during any longer export window provided for in the Principal Agreement. Processor shall delete, and procure the deletion of, all copies of that Company Personal Data within sixty (60) days of the Cessation Date, or within thirty (30) days of the close of any longer export window, save that copies contained in routine encrypted backups shall be deleted in the ordinary course of Processor’s backup rotation and shall remain subject to this Agreement until deleted.
10.2 Processor shall, on Company’s written request, provide written certification that it has complied with this Section.
11. Audit rights
11.1 Subject to this Section, Processor shall make available to the Company all information reasonably necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits, including inspections, by the Company or an auditor mandated by the Company in relation to the Processing of the Company Personal Data by the Contracted Processors. Company may exercise this right no more than once in any twelve (12) month period, except where required to do so by a Supervisory Authority or following a Personal Data Breach affecting Company Personal Data. Company shall give at least thirty (30) days' prior written notice; audits shall take place during normal business hours and without unreasonably disrupting Processor's operations; and Company shall bear its own costs and those reasonably incurred by Processor. Information disclosed in the course of an audit is Confidential Information. Processor may satisfy a request under this Section in the first instance by providing a completed security questionnaire or a relevant third-party report.
11.2 The information and audit rights of the Company arise under the preceding paragraph only to the extent that the Principal Agreement does not otherwise give the Company information and audit rights meeting the relevant requirements of Data Protection Law.
12. Data Transfer
12.1 Company Personal Data is primarily Processed within the EEA. Where Processing or onward transfer to a Subprocessor involves a transfer of Company Personal Data outside the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, that transfer is made under the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 (Module Two, controller to processor), which are incorporated into this Agreement by reference. Company is the data exporter and Processor is the data importer. This Agreement, together with Exhibit A and Exhibit B, provides the information required by the Annexes to those clauses. For transfers subject to UK or Swiss law, the UK International Data Transfer Addendum issued by the UK Information Commissioner, or the equivalent Swiss adaptations, apply respectively. In the event of a conflict, the Standard Contractual Clauses prevail.
13. Authority Requests
13.1 If Processor receives a request from a law enforcement, regulatory, or other governmental authority for access to Company Personal Data, Processor shall, unless legally prohibited, notify Company of the request and direct the authority to Company. Processor shall not disclose Company Personal Data in response to such a request unless required to do so by a legally binding order.
14. Confidentiality
14.1 Confidential Information. Confidential Information includes materials disclosed by the Parties that are designated as confidential or which, under the circumstances surrounding disclosure, should reasonably be deemed to be confidential (the “Confidential Information”). Notwithstanding the foregoing, information will not be deemed Confidential Information if: (i) it was already known to the receiving Party prior to the date of receipt, without any obligations of confidentiality, as established by documentary evidence, (ii) it is in or has entered the public domain through no breach of this Agreement or other wrongful act of the receiving Party, (iii) it has been rightfully received by the receiving Party from a third party and without breach of any obligation of confidentiality of the third party to the owner of the Confidential Information, (iv) it has been approved for release by written authorization of the owner of the Confidential Information, or (v) it is required to be disclosed pursuant to final binding order of a governmental agency or court of competent jurisdiction, provided that the owner of the Confidential Information has been given reasonable notice of the pendency of the order and been given the opportunity to contest it.
14.2 Obligation of Confidentiality. Each Party agrees to hold the Confidential Information in strict confidence and not to disclose the Confidential Information to any third party or to use it for any purpose other than the purposes described herein. Each Party will take all measures necessary to safeguard the other Party’s Confidential Information in order to avoid disclosure, publication, or dissemination, using at least as high a degree of care and scrutiny as is used for its own Confidential Information. Nothing herein shall derogate from the confidentiality provisions in any other agreement, if any, between the Parties, unless the confidentiality obligations under this Agreement require a higher degree of care.
15. Term and termination
15.1 Term. This Agreement enters into force on the Effective Date and will remain in force for the entire duration of the Principal Agreement unless earlier terminated as agreed by the Parties and if permissible by applicable personal data laws.
15.2 Survival. The following sections shall survive termination: Definitions and Interpretation; Deletion or return of Company Personal Data; Confidentiality; and General Terms.
16. General Terms
16.1 Notices. All notices and communications given under this Agreement must be in writing and will be delivered personally, sent by post or sent by email. Notices to Processor shall be sent to the contact address published by Processor for legal notices. Notices to Company shall be sent to the contact details Company has provided in its account or under the Principal Agreement. Either Party may notify the other of a change of address, which shall apply from receipt of that notice.
16.2 Governing Law and Jurisdiction.
16.2.1 This Agreement is governed by the laws of Sweden.
16.2.2 Disputes. Any dispute arising in connection with this Agreement, which the Parties will not be able to resolve amicably, will be submitted to the exclusive jurisdiction of the courts of Stockholm, Sweden.
16.3 Exhibits. The Exhibits to this Agreement are an integral component thereof.
16.4 Validity. If one of the terms of the Agreement should turn out to be wholly or partially invalid, the remaining terms shall not be affected thereby. The invalid term shall be interpreted according to its sense and replaced by a new regulation that achieves the commercial purpose of the invalid term as much as possible.
16.5 No Partnership or Joint Venture. Neither Party is the legal representative, agent, joint venturer, partner, or employee of the other Party for any purpose. Neither Party has any right or authority to assume or create any obligations of any kind or to make any representation or warranty on behalf of the other Party, whether express or implied, or to bind the other Party in any respect.
16.6 Entire Agreement. This Agreement (together with its Exhibits) constitutes the entire agreement and understanding of the Parties relating to the subject matter hereof and supersedes all prior or contemporaneous agreements, negotiations, and understandings between the Parties, both oral and written, regarding the subject matter hereof.
16.7 Assignment. Neither Party may assign this Agreement without the prior written consent of the other Party. Any attempted or purported assignment without the required consent will be ineffective, void, and a material breach of this Agreement.
EXHIBIT A – SUBPROCESSORS
The current list of Subprocessors, including the location of each Subprocessor and a description of its Processing, is published at lootlocker.com/legal/subprocessors and forms part of this Agreement.
EXHIBIT B – SECURITY MEASURES
Processor implements technical and organizational measures intended to protect Company Personal Data against unauthorized access, loss, or disclosure, taking into account the nature of the Processing and the risk to Data Subjects. These measures currently include, as appropriate:
Access control. Access to Company Personal Data is limited to personnel and Subprocessors who need it in order to provide the Services.
Encryption. Company Personal Data is encrypted in transit and at rest, including in backups.
Infrastructure. Company Personal Data is hosted with established infrastructure providers, as listed in Exhibit A.
Confidentiality. Personnel with access to Company Personal Data are bound by confidentiality obligations.
Incident handling. Processor maintains processes for identifying and responding to security incidents affecting Company Personal Data.
Review. Processor reviews these measures periodically and adjusts them as its infrastructure and the applicable risks develop.
These measures describe Processor’s current practice and may change over time, provided that the overall level of security is not materially reduced.