Data Processing Agreement

Last updated: August 4, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service and applies whenever an Organization uses the Platform. It is concluded when an Organization is created, and it governs the personal data we process on the Organization’s behalf.

It is required by Article 28(3) of Regulation (EU) 2016/679 (“GDPR”).

1. Parties and roles

Controller — the Organization that created a booking page on the Platform, identified by the name, seat and contact details it enters in its settings.

Processor — Livegames Kft. Registered seat: 1183 Budapest, Vajk utca 18., Hungary Company registration number: 01-09-380396 Tax number: 29135125-1-43 Email: info@nevezz.hu

The Organization decides why and how the personal data of its customers, members and staff is processed. We process that data only to provide the Platform. Each party is an independent controller for its own data — for example, we are the controller of the Organization’s own account and billing data, which this DPA does not cover.

2. Subject matter, duration, nature and purpose

Subject matter and purpose. Providing the Platform: taking bookings, event registrations and memberships; processing payments through the Organization’s own payment provider; issuing invoices through the Organization’s own invoicing provider; sending transactional messages; and producing the Organization’s reports.

Duration. From the creation of the Organization until its account is deleted, subject to Section 9.

Nature of processing. Collection, recording, storage, retrieval, use, transmission to the sub-processors listed in Section 6, restriction, erasure and destruction — carried out by automated means.

3. Types of personal data

  • Identification and contact data: name, email address, telephone number.
  • Booking and membership data: reservations, event registrations, attendance, memberships and their periods, waitlist entries.
  • Payment data: transaction identifiers, amounts, currency, payment status. We do not receive or store card numbers — those go directly to the payment provider.
  • Billing data where the Organization issues invoices: billing name, address, tax number.
  • Any additional fields the Organization itself defines on its booking, membership or staff forms. The Organization is responsible for not collecting special categories of data (Article 9) through those fields unless it has a lawful basis and has informed us in writing.
  • Technical data: IP address, timestamps and log data generated by use of the Platform.

4. Categories of data subjects

Customers who book or register; members and their guardians; the Organization’s staff, coaches and administrators; people who join a waitlist.

5. Our obligations

5.1 Documented instructions. We process the data only on the Organization’s documented instructions, including on transfers to a third country. Using the Platform’s features is itself an instruction. If we believe an instruction infringes the GDPR or other EU or Member State data protection law, we will inform the Organization without delay. Where we are required by law to process data otherwise, we will inform the Organization beforehand unless that law prohibits it.

5.2 Confidentiality. Everyone we authorise to process the data is bound by confidentiality, whether by contract or by statute.

5.3 Security (Article 32). We implement appropriate technical and organisational measures, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risks. These are described in Section 10.

5.4 Sub-processors. As set out in Section 6.

5.5 Assisting with data subject rights. Taking into account the nature of the processing, we assist the Organization with appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise rights under Chapter III of the GDPR — access, rectification, erasure, restriction, portability and objection. The Platform’s own export and deletion functions are the primary means of that assistance. If a data subject contacts us directly about data we process for an Organization, we will not respond substantively; we will refer them to the Organization and inform the Organization.

5.6 Assisting with Articles 32–36. We assist the Organization in ensuring compliance with its obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to us.

5.7 Personal data breach. We notify the Organization without undue delay after becoming aware of a personal data breach affecting data processed on its behalf, with the information available to us, so that the Organization can meet its own Article 33 deadline. Notification is sent to the Organization’s contact email address; the Organization is responsible for keeping that address current.

5.8 Information and audits. We make available to the Organization the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Organization or another auditor it mandates. Audits are conducted no more than once a year unless a breach or a supervisory authority requires otherwise, on at least 30 days’ written notice, during business hours, without disrupting the Platform, and subject to confidentiality. The Organization bears its own audit costs and ours where the audit exceeds one working day.

6. Sub-processors

The Organization gives general written authorisation for us to engage sub-processors. Those we currently use are:

Sub-processorPurposeLocation
Cloudflare, Inc.Hosting, database, storage, CDNEU (data stored in the EU)
Stripe Payments Europe, Ltd.Payment processingEU / USA
The Organization’s chosen invoicing provider (Számlázz.hu or Billingo)Issuing invoicesEU (Hungary)
The Organization’s chosen email and SMS providers as configured on the PlatformTransactional messagesEU

We impose on every sub-processor, by contract, data protection obligations no less protective than those in this DPA, and we remain fully liable to the Organization for their performance.

We will inform the Organization of any intended addition or replacement of a sub-processor at least 30 days in advance by email to its contact address. The Organization may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the Organization may terminate its use of the Platform for the affected processing without penalty, which is its sole remedy.

7. International transfers

Personal data is stored in the European Union. Where a sub-processor processes data outside the EEA, the transfer is covered by an adequacy decision or by the European Commission’s Standard Contractual Clauses together with any supplementary measures required.

8. The Organization’s obligations

The Organization warrants that it has a lawful basis for the processing it instructs, that it has provided its data subjects with the information required by Articles 13–14 — including that we act as its processor — and that any additional fields it defines are lawful and proportionate. The Organization is responsible for the accuracy of the data it enters and for the lawfulness of the instructions it gives.

9. Deletion and return

On termination of the Organization’s use of the Platform, we delete the personal data processed on its behalf, unless EU or Member State law requires storage — for example, accounting records that Hungarian law requires to be retained for eight years. Before deletion the Organization may export its data using the Platform’s export functions. Backups are deleted on their ordinary rotation cycle, which does not exceed 90 days after deletion of the live data.

10. Technical and organisational measures (Article 32)

  • Encryption of all data in transit (TLS) and encryption of data at rest by our hosting provider.
  • Access control: access to production data is limited to personnel who need it, protected by individual accounts and strong authentication; passwords are stored only as salted hashes.
  • Tenant isolation: every record carries the Organization it belongs to, and cross-tenant access is prevented by database-level constraints in addition to application checks.
  • Payment data minimisation: card details are entered directly with the payment provider and never reach the Platform.
  • Resilience: managed, replicated infrastructure with automated backups and the ability to restore availability and access after an incident.
  • Logging of administrative actions relevant to personal data.
  • Testing: automated test suites covering access control and tenant isolation run on every change.

We may update these measures as the state of the art develops, provided the level of protection is not reduced.

11. Liability and precedence

Liability under this DPA is governed by the Terms of Service and by applicable law. In case of conflict between this DPA and the Terms of Service, this DPA prevails for matters concerning the processing of personal data on the Organization’s behalf.

12. Changes

We may amend this DPA where required by law, by a supervisory authority, or by a change in our sub-processors or measures. We will notify the Organization by email and in the Platform at least 30 days before a material change takes effect, and the Organization must accept the new version to continue using the Platform.

13. Governing law

Hungarian law, and the GDPR. The courts of Hungary have jurisdiction.