GROUPSPACE
Legal · dpa

Data processing addendum

The processor terms that apply when GROUPSPACE handles member data on a customer's behalf. Required before chat history can be enabled on any workspace.

Last updated 10 August 2026

Draft. This document is a working draft prepared for GROUPSPACE and has not been reviewed by a lawyer. Do not publish it as binding policy until counsel has read it — particularly the sections covering children’s data, and the Roblox and Discord platform terms it depends on.

Parties and scope

This addendum is between the customer identified in the order or workspace record (the controller) and GROUPSPACE LLC, an Ohio limited liability company of c/o ZenBusiness Inc., 100 E Broad St Ste 1350, Columbus, OH 43215, United States (the processor, “GROUPSPACE”).

It forms part of the terms of service and applies to all personal data GROUPSPACE processes on the controller’s behalf. On that subject it takes precedence over the terms.

Terms such as personal data, processing, controller, processor, data subject and personal data breach carry the meanings given in the UK GDPR and the EU GDPR.

This is not the signable version. A signable addendum needs an execution block, the controller’s details, the jurisdiction-specific clauses, and the transfer annexes filled in against the actual hosting arrangements. This page is the substance so both sides know what they are agreeing to. Ask legal@groupspace.xyz for the countersigned copy.

Roles

DataControllerProcessor
Workspace content: members, positions, records, ledger entries, operations, attendance, quotas, game sessions, chat messagesThe customerGROUPSPACE
Customer's own account, sign-in, billing, support conversations, GROUPSPACE service and security logsGROUPSPACE
Aggregated, de-identified service statistics with no user or workspace identifierGROUPSPACE

Each party is independently responsible for its own compliance in its own role. The controller warrants that it has a lawful basis for the processing it instructs, and that it has given the data subjects whatever notice the law requires.

Subject matter and duration

  • Subject matter. Provision of the GROUPSPACE community management service, including the organisation, records, economy, operations, moderation and game integration features the controller has enabled.
  • Nature and purpose. Hosting, storing, structuring, retrieving, transmitting, and deleting personal data so the controller can run its community, together with the security, backup, support and audit activity that goes with operating a service.
  • Duration. For as long as the controller’s subscription is in place, plus the deletion window in the return and deletion section.

Data subjects and data

Categories of data subject

  • Workspace members and staff of the controller.
  • Applicants to the controller’s organisations.
  • Players in the controller’s connected games, who are not GROUPSPACE users and may be children. This is the largest category and the most sensitive one.
  • People who are the subject of a record filed by the controller’s staff.

Categories of personal data

CategoryContents
IdentifiersPlatform user id and username. Where the person is a GROUPSPACE account holder, also display name and email address.
Organisational dataPositions held, unit membership, permissions, application history.
Conduct recordsArrests, warnings, citations, notes, flags, commendations, incident reports and disciplinary entries, with author and timestamp.
Economic dataLedger entries in the workspace currency, payroll accruals, fines, tax computations, payout run lines.
Activity dataGame sessions, presence, join and leave events, door checks, clock-ins and clock-outs, operation participation, quota progress.
CommunicationsPlatform-filtered in-game chat messages, where the controller has enabled chat history.
Technical dataIP address, user agent and request metadata in service logs; audit log entries recording who did what.

Special category data

GROUPSPACE is not designed to process special category data and the controller must not instruct it to. Free-text fields — record narratives, notes, incident reports — could contain such data if the controller’s staff type it in. That is outside the intended use, and the controller is responsible for it.

Controller instructions

GROUPSPACE processes personal data only on the controller’s documented instructions, except where law requires otherwise — in which case we tell the controller first, unless the law prohibits it.

The documented instructions are:

  • this addendum and the terms of service;
  • the configuration the controller sets in the application — retention settings, permission model, enabled features, integrations;
  • the actions the controller’s authorised users take in the application or through the API;
  • any further written instruction the parties agree.

If we consider an instruction to infringe data protection law, we will say so and may decline to act on it.

Standing limits on what any instruction can achieve. Some things cannot be instructed into existence because they are platform obligations, not our policy: we will not disable the erasure webhook or exempt a workspace from it; we will not retain chat beyond 30 days; we will not remove the audit logging of chat reads; we will not use personal data to train AI or language models; we will not sell or share platform-derived data; and we will not enable cross-experience tracking or a cross-workspace reputation graph.

Confidentiality

Personnel authorised to process the controller’s personal data are bound by confidentiality obligations that survive the end of their engagement, and are given access only where it is needed for a specific purpose.

  • Access to production data is least-privilege, granted for a reason, and logged when used.
  • Staff access to a workspace happens for support the controller asked for, for a security investigation, or where the law requires it — and it is recorded.
  • Personnel receive data protection guidance appropriate to their role, including on the sensitivity of chat history and children’s data.

Security measures

GROUPSPACE implements appropriate technical and organisational measures under Article 32. The current measures are listed in Annex B. They are described as practices; GROUPSPACE holds no security certification and does not claim one.

Highlights, because these are the ones customers ask about:

  • Encryption. In transit on every connection. Chat history is encrypted at rest and held separately from the main tables.
  • Access control. A permission model enforced at query time rather than by post-filtering results, because post-filtering leaks the existence of records through counts.
  • Audit logging. Append-only, covering privileged actions, with each chat read logged individually against the reader and the subject.
  • CASA-aligned development. We build against the CASA (OWASP-based) requirements Roblox applies to third-party applications. Alignment is not assessment and we do not present it as one.
  • Segregation. Workspace data is scoped per workspace at the data layer, not by application-level filtering alone.

Measures may change as the product develops, provided the level of security is not reduced.

Subprocessing

The controller gives general authorisation for GROUPSPACE to appoint subprocessors. The current categories are on the subprocessors page.

  • Each subprocessor is bound by written terms imposing data protection obligations no less protective than these.
  • GROUPSPACE remains fully liable to the controller for a subprocessor’s performance.
  • We give at least 30 days’ notice before adding or replacing a subprocessor. Notice is by email to workspace owners who have subscribed to the list and by an update to the subprocessors page.
  • The controller may object on reasonable data protection grounds within the notice period. If we cannot resolve the objection, the controller may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.
  • Where a change is urgent — a provider fails, or there is a security reason to move — we may act first and notify immediately, with the same objection right running from the notice.

Data subject requests

The controller answers requests from its own data subjects. GROUPSPACE assists.

RequestHow we assist
Access or portabilitySelf-service workspace export covering the org structure, members, records, ledger, operations and configuration. Where the export does not reach it, we help retrieve it.
RectificationThe controller edits its own data in the application. We do not amend a controller's records on our own initiative.
ErasureSelf-service deletion in the application. Platform-originated erasure requests are handled automatically as described below.
Restriction or objectionWe support the controller in giving effect to a decision it has taken, including by suspending processing for a specific data subject.
Requests that reach us directlyWe do not respond substantively. We tell the person who the controller is and pass the request on without undue delay — except where the data subject is a child and the controller does not act, in which case we may act ourselves.

Platform erasure

Where Roblox sends a signed RightToErasureRequest, GROUPSPACE purges that user’s records, sessions, operation participation and chat messages across every affected workspace, and writes the erasure to the audit log. The handler is continuously available, verifies the HMAC signature before parsing, and enforces a 300-second replay window.

This runs without the controller’s approval and cannot be suspended by instruction. It is a platform obligation. The controller should assume records for an erased user will disappear from its workspace and should not build processes that depend on them persisting.

Where a data subject revokes GROUPSPACE’s access to their platform account, the data obtained through that connection is expunged on the same basis.

Assistance with Articles 32 to 36

GROUPSPACE provides reasonable assistance with data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us. A DPIA covering chat history is strongly recommended, and we will contribute the technical detail for it.

Personal data breach

GROUPSPACE notifies the controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the controller’s personal data.

The notification includes, so far as we know it at the time:

  • what happened and when we became aware;
  • the categories and approximate volume of data and data subjects affected;
  • the likely consequences;
  • the measures taken or proposed, including anything the controller should do;
  • a contact point for further information.

We will not delay an initial notification to make it complete. Information that is not available at first follows in stages. Notifying the controller is not an admission of fault by either party.

The controller is responsible for notifying its supervisory authority and its data subjects. We will provide what is reasonably needed to support that. Notices to the controller go to the workspace owner and any breach contact on file; notices to us go to security@groupspace.xyz.

Return and deletion

On termination, the controller chooses whether personal data is returned or deleted. Export is self-service and stays available through the grace period; if the controller does not choose, we delete.

StageWhat happens
Grace periodFor [export grace period] after termination the workspace can be exported or reinstated.
Deletion from live systemsAfter the grace period, personal data is deleted from production systems.
BackupsDeleted data ages out of backups on the normal rotation, within [backup cycle window]. It is not restored to production in the meantime except as part of a disaster recovery of the whole system, in which case the deletion is re-applied.
What we keepOnly what law requires — billing and tax records, and audit entries recording that a deletion happened. No workspace content.
ChatDeleted on the workspace retention schedule regardless of termination, and immediately on an erasure request.

On request we will confirm deletion in writing.

Audit rights

GROUPSPACE makes available the information needed to demonstrate compliance with this addendum and allows for audits, including inspections, by the controller or an auditor it mandates.

  • In the first instance we answer a reasonable security questionnaire and provide our current description of technical and organisational measures. For most controllers this will be enough.
  • Where it is not, an on-site or remote inspection may be arranged on at least 30 days’ written notice, no more than once in any twelve months unless a regulator requires otherwise or there has been a breach.
  • Audits happen in business hours, must not disrupt the service, and must not expose another customer’s data. The auditor signs confidentiality terms first, and must not be a competitor of GROUPSPACE.
  • The controller bears its own costs and our reasonable costs for time spent supporting an inspection, except where the audit finds a material breach of this addendum.
  • We do not currently hold a third-party audit report to offer in place of an inspection. When one exists we will make it available and it will satisfy this section.

International transfers

Primary hosting — the application and the database — is with Railway in the United States, US East. Payment processing is with Stripe in the United States. Two categories, transactional email and error tracking, are not yet appointed; see the subprocessors page.

Where personal data is transferred out of the UK or the EEA, the transfer relies on an adequacy decision where one applies, and otherwise on the standard contractual clauses — module two or three as appropriate — together with the UK international data transfer addendum where the UK GDPR applies, and a transfer risk assessment. The clauses are incorporated into this addendum by reference, with the annexes populated from the tables on this page and the subprocessors page.

Because all currently appointed subprocessors process in the United States and there is no adequacy decision covering transfers from the UK or the EEA to the US outside the EU–US Data Privacy Framework, transfers of UK or EEA personal data rely on the standard contractual clauses and the UK addendum unless the receiving provider is certified under that framework. [confirm each provider’s DPF certification status and finalise the module and annex wording before this page is published as fact]

Liability and precedence

The limitations and exclusions of liability in the terms of service apply to this addendum and to claims arising out of it, except where the law does not permit them to.

Where this addendum conflicts with the terms of service, this addendum governs on matters of personal data processing. Where it conflicts with the standard contractual clauses, the clauses govern.

This addendum is governed by the law stated in the terms of service: the law of the State of Ohio, United States.

Annex A — children's data

This annex exists because the ordinary text of a processor agreement does not do justice to what is actually happening here. A substantial share of the data subjects in a controller’s workspace are children, and neither party has any shelter from that.

A.1 Acknowledgement

  • Roblox’s audience skews young. A controller running a community on Roblox should assume children are among its members and among the players in its games.
  • Roblox’s own children’s privacy programme applies to Roblox’s platform. It does not extend to GROUPSPACE’s systems or to the controller’s use of them. Each party carries its own obligations, which may include COPPA in the United States, the UK Age Appropriate Design Code, the GDPR provisions on children, and equivalent rules elsewhere.
  • Roblox OAuth requires an account holder to be 13 or older to authorise a third-party application, so GROUPSPACE sign-in has a 13+ floor. Players in a connected game have no floor at all. They never touch a sign-in page, and GROUPSPACE holds data about them regardless of age.

A.2 What GROUPSPACE does

  • No collection surface is pointed at players. Everything we hold about a player arrives from the controller’s own game server.
  • Minimisation to platform user id and username. No age, birth date, avatar, contact details or other personal data is taken from the platform.
  • No profiling, no behavioural advertising, no ad system, and no scoring of individuals.
  • No use of any personal data to train AI or language models.
  • Chat history is gated as described in A.3.
  • Erasure requests are honoured immediately and cannot be exempted by the controller.
  • Where a parent or guardian contacts us about a child’s data and the controller does not act, GROUPSPACE may delete its copy and will tell the controller it has done so.

A.3 Chat history — additional conditions

Chat history stores children’s messages. It is available only on the top plan, only with this addendum signed, and only on these conditions.

ConditionDetail
Explicit opt-inOff by default. An owner enables it and acknowledges what they are taking on, including that they become responsible for a store of children's communications.
RetentionHard cap of 30 days, configurable downward only. Enforced by an expiry written at message creation and a purge job, not by a flag.
Filtered text onlyWe store the text the platform's own filter produced. Neither party may capture, reconstruct or attempt to recover unfiltered text.
No client-side relayThe controller must not deploy a client-side capture to obtain messages the game server cannot see. It is spoofable and it defeats platform filtering.
Dedicated permissionReading chat requires a permission that is not in any default position template. The controller grants it deliberately and narrowly.
Audited readsEvery read is logged with reader, subject and time. The controller is expected to review that log.
Encryption at restHeld encrypted and separately from the main tables.
Purpose limitationInvestigation of specific incidents and appeals. Not general monitoring of members.
DPIAThe controller should complete a data protection impact assessment before enabling it. GROUPSPACE will supply the technical detail.

A.4 What the controller undertakes

  • To have a lawful basis for processing children’s data and to meet any parental consent requirement that applies to it.
  • To tell its members and players, in language they can understand, what is recorded and who can see it.
  • Not to use GROUPSPACE to collect personal information from a child through application forms, record fields, notes or custom fields.
  • Not to use records, chat or session data to identify or contact a young player outside the community.
  • To grant the chat permission narrowly, to review the audit log, and to remove access from anyone who does not need it.
  • To respond to requests from children and their parents or guardians, and to tell GROUPSPACE where a request affects data we hold.
This annex is the part to take to a lawyer first. Children’s data is where the exposure is, for both parties. The rest of this addendum is comparatively standard. This part is not, and the underlying rules differ meaningfully between the UK, the EU and the United States.

Annex B — technical and organisational measures

Current measures, described as practices. GROUPSPACE holds no security certification and makes no claim of one.

AreaMeasures
EncryptionTLS on all connections. Chat history encrypted at rest in storage separate from the main tables. Secrets held in a managed secret store, never in source control.
Access controlPer-workspace scoping enforced at the data layer. Permission checks applied at query time rather than by post-filtering. Least-privilege staff access, granted for a reason and logged when used.
Audit loggingAppend-only log of privileged actions with actor, action, resource, before and after state, address and time. Chat reads logged individually.
Integrity of ingestSigned requests, idempotency keys on event ingest, explicit acknowledgement of remote commands, and rate limiting.
Webhook securityHMAC signature verification before parsing, replay windows, and rejection of unsigned requests. Applies in both directions.
Retention enforcementExpiry written at record creation for time-limited categories, with purge jobs performing real deletion.
ResilienceManaged hosting with automated backups and a documented restore path. Backups encrypted.
MonitoringError tracking, structured logs with workspace and request correlation ids, health checks, and separate monitoring of the erasure webhook endpoint.
Secure developmentCode review before merge, dependency scanning, and development against the CASA (OWASP-based) requirements Roblox applies to third-party applications.
PersonnelConfidentiality obligations, role-appropriate data protection guidance, and access removal on departure.
Subprocessor managementWritten terms, a published category list, and 30 days' notice of change.
Incident responseDocumented process, 48-hour controller notification target, and post-incident review.

To execute this addendum, or to ask for the version with the signature block and transfer annexes completed, write to legal@groupspace.xyz.
Unfilled placeholdersNo execution blockNot reviewed by counsel

All legal documentsTerms of servicePrivacy policySubprocessors