Data processing agreement
Last updated 18 September 2026
The Article 28 terms for the members, posts and uploads on your project — the data you decide about and we carry out.
Your players' data is deliberately not covered here. We are not your processor for it, and section 1 says why.
1. What this covers, and what it does not
This agreement is between you — the person or organisation running a project on Enderbeam — and Enderbeam. It forms part of the creator agreement, and it applies automatically. There is nothing to sign.
It covers the data where you decide what happens and we carry it out:
- Members of your site: username, email address, avatar, a short bio where they write one, linked Discord or Minecraft account, and when they joined.
- What members write on your site: forum threads and replies, comments, wall messages, poll votes, live chat, reactions, and images and files they upload. Editing a forum post keeps its previous body for 60 days. And what your own staff write: news posts, with their title, body, image and author.
- Applications and build submissions they send you, and the notes and votes your staff attach to them.
- Roles and tags you assign, and moderation records your staff create.
- Reports your members file about posts on your site: who reported it, what they picked, what they wrote, and a short copy of the reported text.
- Messages sent to you through a Contact Form module — the sender's name, email and message, passed to your account email and not stored by us.
- Invitations you send to collaborators: the email address you invited. Declining deletes it, and so does deleting the project; accepting keeps it as that collaborator’s address of record.
- The Minecraft username a visitor types to open a basket in your shop, passed to Tebex on your instruction to open it in that name. We keep none of it. Tebex is your processor here rather than our sub-processor — the store is your account with them, under your contract, and the purchase is between them and your buyer.
- If we host your EnderMap: its pictures of your world — tile data, overview pictures, and the textures, models and fonts it is drawn with — kept as a cache under clause 7a of the creator agreement. World imagery rather than anybody’s data, though a build can spell out a name. Not the players on the map: see below.
It does not cover the data your server sends about its players. That means all of it: who is online and which town, faction or land they belong to; leaderboards and statistics; what a players list shows about them; and where a player is on a hosted live map, which we pass on and never keep. The first of those was previously not named here, which left it looking like it might fall inside this agreement by omission — it does not, and it never did. We are not your processor for any of it and we will not pretend to be: we decide what the plugin can send, how a player objects or agrees, and what is published when they have done neither. You and Enderbeam are joint controllers of it under Article 26, and section 11 of the privacy notice sets out the arrangement between us and what it means for a player.
It does not cover your own account with us, our billing records, or our visitor counting. We are the controller of those. Nor the address a shop basket is opened from: we count those in memory to stop a script filling your Tebex dashboard with abandoned baskets, which we do for our own protection and Tebex’s rather than on your instruction. Nothing is stored and nothing is passed on.
Nor does it cover a report about your project or about you. Those come to us alone, you do not see them, and we are the controller of them — a complaint about somebody, held on that person's instructions, would not be a complaint anybody could safely make.
2. Processing on your instructions
We process the data in section 1 only to provide Enderbeam to you, and only on your instructions. Your instructions are: this agreement, the creator agreement, and the settings you choose in the product. Using a feature is an instruction to do what that feature does.
The subject matter is hosting a community website. The duration is for as long as your project exists, plus the grace period in section 7. The nature and purpose is storing, displaying and moderating what your members send you, and, where we host your map, keeping its pictures of your world to show to visitors. The categories of data and of data subject are listed in section 1.
If we think an instruction breaks data protection law, we will tell you rather than quietly following it.
There is one thing that overrides your instructions, and it is the law. If US, UK, EU or member state law compels us to process your members' data in some other way — including compelling us to transfer it somewhere — we will comply, and we will tell you about the legal requirement before we do, unless that same law forbids us from telling you on important grounds of public interest. This is Article 28(3)(a) and it was missing: an agreement saying we act only on your instructions, with no exception written in it, is a promise that the first subpoena breaks.
We will not sell your members' data, use it to advertise to them, or use it to train anything.
3. Who can see it
Access to production data is limited to the people who need it to operate the service, which today means one person. Anyone who ever has access is bound to keep it confidential, and that obligation does not end when they stop working on Enderbeam.
We will not look at your members' private data — messages, applications, moderation notes — except where it is necessary to fix a fault, answer a support request from you, or comply with the law.
4. Security
We keep appropriate technical and organisational measures under Article 32. In particular: everything is encrypted in transit with TLS; passwords are hashed and never stored in a form we could read; uploads are stored in object storage that is not publicly listable; access to the production database requires a key held by the operator and is not exposed to the internet; and backups are taken and are subject to the same access limits.
Section 10 of the privacy notice describes the same measures in plainer terms, and is part of this agreement by reference.
5. Sub-processors
You give us general authorisation to use sub-processors. The current list is in section 9 of the privacy notice, with what each one does.
We will publish any change to that list there at least 30 days before the new sub-processor starts. If you object on reasonable data protection grounds within those 30 days, tell us and we will either propose an alternative or, if we cannot, let you terminate the affected part of the service and refund the unused portion of anything you have paid.
Every sub-processor is bound by written terms imposing the same data protection obligations that this agreement imposes on us, so far as they apply to what that sub-processor does. If one of them fails to meet those obligations, we remain fully liable to you for it. This is Article 28(4), and saying only that we stay responsible covered the liability and left out the contract, which is the part that makes the obligations reach them at all.
6. International transfers
Enderbeam is operated from the United States and the data is stored there. If you or your members are in the UK or the EEA, that is an international transfer.
We rely on the European Commission's standard contractual clauses of 4 June 2021, Module Two (controller to processor), and on the ICO's international data transfer addendum for the UK. They are incorporated into this agreement in full. By accepting it you enter into them with us — you as data exporter, Enderbeam as data importer — and section 10 sets out their completed annexes. That section is the instrument: there is no separate signed paper, and this page previously offered to send you one, which was a promise of a document that did not exist. If you need a countersigned copy for your own records, ask and we will sign and return one.
One thing to be straight about, because it is unusual and it matters. Those clauses were written for an importer who is not itself subject to the GDPR. Enderbeam is: we offer this service to people in the UK and the EEA deliberately, so Article 3(2) applies to us directly, and the European Commission has acknowledged that the 2021 clauses do not squarely fit that case. We apply them in full anyway, as binding contractual commitments to you. Where a clause would be redundant because the GDPR already binds us directly, it does not reduce what the GDPR requires of us — our direct obligations and these clauses both apply, and the stricter wins.
7. Helping you with your obligations
If one of your members asks us directly for access, correction, deletion or a copy of their data, we will point them to you where it is yours to answer — and we will help you answer it.
The product does a good deal of this without either of us being involved, and it is worth being exact about which. A member can delete their own posts, comments, wall messages and account whenever they like. What has no button of its own is an application they sent you, a build they submitted, or a poll answer — those go when the member deletes their account, which removes all of them, but there is no way to remove just one while keeping the account. If a member asks for that, ask us and we will do it.
We will help you, so far as we reasonably can, with data protection impact assessments and with consulting a supervisory authority, and with keeping your members' data secure.
If we become aware of a personal data breach affecting your members, we will tell you without undue delay and with what we know, so you can meet your own 72-hour deadline.
When we stop providing the service to you — you delete the project, or the agreement ends — you choose whether the data in section 1 is returned to you or deleted. Deletion is what happens if you say nothing. Ask for it back and we will give you a machine-readable export of the members, the posts and the uploads before anything is deleted; ask at any other time and we will do the same, since it is your data and not only ours to hold. Be aware that it is assembled by hand rather than by a button, so it takes days rather than minutes; tell us if you are working to a deadline.
Deletion runs after the 14-day grace period in the creator agreement, which exists so a deletion by mistake can be undone. This said 30 days, and the creator agreement said only "a short grace period"; the code has always said 14, and now so do both documents.
Everything held for the project goes, and that is deliberately wider than this agreement: members, posts and uploads, which are the data in section 1, and also the player data that section 1 excludes because we are not your processor for it. Being joint controllers of something does not mean keeping it after the project it belonged to is gone. We will confirm when it is done if you ask. That includes a hosted map’s cached pictures of your world and our record of the map.
Backups are the honest exception, and every provider that tells you otherwise is glossing. Our backups are whole-system snapshots taken by the hosting provider once a day, between 4am and 8am UTC, and kept for seven days. They cannot be edited to remove one project from inside them, so data deleted from the live system stays in whatever snapshots already hold it — but only until those roll off, which puts an outside limit of seven days on it. They are never used except to restore the whole system after a failure, and if that ever happened we would re-run the deletions the restore undid. Article 28(3)(g) allows copies to be kept where the law requires it; this is not that, it is a technical limit, it is bounded, and it is written here rather than left for you to discover.
8. Showing you that we do this
Ask, and we will give you the information you need to show that we are meeting this agreement.
You may also audit us, yourself or through somebody independent you appoint, at your own cost, once in any twelve months and on 30 days' notice — or sooner without notice if there has been a breach affecting your members. We will cooperate. In return, an audit must not put other customers' data at risk, and anything you learn is confidential.
9. Where this sits
This agreement is part of the creator agreement. If a term here conflicts with one there about the data in section 1, this one wins. If a term here conflicts with the standard contractual clauses, the clauses win.
It lasts as long as we process the data in section 1 for you, and the obligations that should survive it — confidentiality, and deletion — do.
Questions, or a countersigned copy of the clauses: support@enderbeam.com.
10. The annexes to the clauses
The standard contractual clauses are only operative once their annexes are filled in, and an agreement that gestures at them without completing them has not really entered into anything. This is them, completed. It applies to the UK addendum too, whose tables are at the end.
Annex I.A — the parties.
- Data exporter: you, the person or organisation running the project, at the account details we hold for you. Role: controller. Activities: operating a community website for your members. Contact: the email on your Enderbeam account.
- Data importer: Ryan Exner, trading as Enderbeam, 440 N Barranca Ave #1779, Covina, CA 91723, United States. Role: processor. Activities: hosting that website and storing what your members write on it. Contact: support@enderbeam.com.
- Signature and date: entering into this agreement, which happens when you create a project or when these terms change and you carry on using it. The date is the one recorded against your acceptance.
Annex I.B — description of the transfer.
- Data subjects: members of your site — people who sign in on it and post there. Incidentally, players whose builds appear in a hosted map’s pictures of your world.
- Categories of data: those listed in section 1. Username, email address, avatar, a short bio, linked Discord or Minecraft account, join date; news posts written by your staff, with their author; forum threads and replies, comments, wall messages, poll votes, live chat, reactions, the previous bodies of edited posts, uploaded images and files; applications and build submissions with your staff’s notes and votes; notifications; roles and tags; moderation records; reports your members file; contact-form messages passed to you; collaborator invitations; the Minecraft username a visitor gives to open a basket in your shop; and a hosted map’s cached pictures of your world.
- Special categories: none are asked for, and none of the fields are for it. Free-text written by members and by your staff can contain anything a person chooses to type, which is a risk of any text box rather than a category we collect. The retention limits in section 7 of the privacy notice exist partly for this.
- Frequency: continuous, for as long as the project exists.
- Nature and purpose: storing, displaying and moderating what your members send you, as described in section 2.
- Retention: as set out in section 7 of the privacy notice, and until deletion under section 7 of this agreement. Note in particular the categories with a clock of their own, deleted on a schedule rather than on request: the previous bodies of edited forum posts after 60 days, decided applications with their notes and votes 60 days after the decision, notifications after 30 days, and reports 90 days after they are closed.
- Sub-processors: those in Annex III, for the duration and purpose given there.
Annex I.C — competent supervisory authority. The authority of the member state in which you are established. If you are not established in the EEA but are subject to the GDPR under Article 3(2), the authority of the member state where your Article 27 representative is. For the UK addendum, the Information Commissioner.
Annex II — technical and organisational measures. Those in section 4 of this agreement and section 10 of the privacy notice, which are part of this annex by reference. In summary: TLS for everything in transit; passwords hashed with no reversible form held; uploads in object storage that is not publicly listable; the production database reachable only with a key held by the operator and not exposed to the internet; production access limited to one person; backups under the same access limits; retention windows enforced by scheduled deletion rather than by intention.
Annex III — sub-processors. Today: Supabase (authentication), Cloudflare (the network in front of everything, object storage for uploads and, in a separate private bucket, hosted map pictures, and the plugin downloads), Resend (email), Stripe (payments), DigitalOcean (hosting), Discord (sign-in, account linking, and pushing a site role onto a guild role where you have set that up). Section 5 of this agreement governs how that list changes and what you can do about it.
Section 9 of the privacy notice names more parties than this annex does, and the difference is deliberate rather than an omission here. That section lists everyone who receives data at all; this annex lists only those processing it on our instructions under Article 28. Mojang and GeyserMC are neither: we query their public interfaces for a player’s skin the way any client would, on nobody’s instruction and under no contract with them. Tebex is a processor, but yours and not ours — the store is your account, under your agreement with them. Section 9 remains the authoritative list of who sees anything; this one is the authoritative list of who is under our instruction.
The UK addendum, tables 1 to 4.
- Table 1, parties: as in Annex I.A above. Start date: the date of your acceptance.
- Table 2, selected clauses: the approved EU standard contractual clauses of 4 June 2021, Module Two, with the annexes above.
- Table 3, appendix information: Annexes I, II and III above.
- Table 4, ending the addendum when the approved addendum changes: either party may end it.
This is drafting done carefully rather than drafting done by a solicitor, and the difference is worth stating on the one page where it matters most. If you are relying on these clauses for a transfer that matters to you, have your own adviser read them.