Data Processing Agreement
This Data Processing Agreement ("DPA") is between the Streamer ("Controller") and Aiko van Wingerden, operator of mobrule ("Processor"), effective on the Controller's first use of the hosted service. It forms part of, and is subject to, the Privacy Policy.
When you run mobrule you decide whose data is processed and why — so you are the controller; mobrule processes that data on your instructions, as your processor. This agreement covers the GDPR Art. 28 obligations between us for your viewers' data.
01Subject matter & roles
The Controller (Streamer) uses mobrule to turn their Twitch channel activity into in-game effects. In doing so the Processor (mobrule operator) processes personal data about the Controller's viewers on the Controller's behalf and on the Controller's documented instructions.
The Controller is the controller; mobrule is the processor, for the viewer data described in section 03.
02Duration
For as long as the Controller's Twitch account is connected to mobrule, plus the retention periods in the mobrule Privacy Policy.
03Nature & categories
- Categories of data subject: the Controller's Twitch viewers.
- Categories of personal data: Twitch username / display name / user ID; channel-point redemptions; viewer free text (
user_input); chat messages / votes; refund (undeliverable-redemption) records. - Processing operations: receiving channel events from Twitch, matching them to configured rewards, dispatching effects, refunding failed redemptions, and short-term storage as set out in the Privacy Policy.
04Processor obligations (GDPR Art. 28(3))
The Processor shall:
- (a) Process viewer data only on the Controller's documented instructions — the act of configuring and running mobrule constitutes those instructions.
- (b) Ensure persons authorised to process data are bound by confidentiality.
- (c) Implement appropriate technical and organisational measures — including encryption of Twitch tokens at rest (AES-256-GCM) and access restriction.
- (d) Engage another sub-processor only under the Controller's general authorisation (section 05).
- (e) Assist the Controller in responding to data-subject rights requests.
- (f) Assist with security, breach notification, and DPIA obligations (Art. 32–36).
- (g) On termination, delete or return all viewer data, subject to the retention periods.
- (h) Make available information needed to demonstrate compliance and allow audits.
05Sub-processors
The Controller gives general authorisation for mobrule to engage the sub-processors below. mobrule remains liable for their performance and will give notice of any intended change so the Controller can object.
| Sub-processor | Purpose | Region |
|---|---|---|
| Twitch / Amazon | Source of channel events; recipient of reward provisioning / refund calls | US / global |
| Hetzner | Hosting of the mobrule cloud backend (servers, database) | Germany (EU) |
| Sentry (self-hosted) | Error diagnostics, on mobrule's own infrastructure; no third-party tracker | Germany (EU) |
06Controller obligations — viewer transparency
The Controller is responsible for informing its own viewers that a third-party tool (mobrule) processes their redemptions and chat, and on what basis. Suitable methods include a Twitch channel panel, a chat command, or channel rules. The Processor provides no viewer-facing notice and has no channel to viewers.
07International transfers
All processing carried out by mobrule occurs within the EU/EEA, on servers located in Germany (Hetzner).
Channel events originate from Twitch, operated by Amazon in the United States. That processing takes place under the Controller's own relationship with Twitch and relies on Twitch's transfer safeguards (an EU adequacy decision and/or Standard Contractual Clauses). mobrule makes no further transfer of viewer data outside the EEA.
08Personal data breaches
The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting viewer data, at the Controller's registered contact.