Data processing addendum
The processor terms that apply when GROUPSPACE handles member data on a customer's behalf. Required before chat history can be enabled on any workspace.
Last updated 10 August 2026
Parties and scope
This addendum is between the customer identified in the order or workspace record (the controller) and GROUPSPACE LLC, an Ohio limited liability company of c/o ZenBusiness Inc., 100 E Broad St Ste 1350, Columbus, OH 43215, United States (the processor, “GROUPSPACE”).
It forms part of the terms of service and applies to all personal data GROUPSPACE processes on the controller’s behalf. On that subject it takes precedence over the terms.
Terms such as personal data, processing, controller, processor, data subject and personal data breach carry the meanings given in the UK GDPR and the EU GDPR.
Roles
Each party is independently responsible for its own compliance in its own role. The controller warrants that it has a lawful basis for the processing it instructs, and that it has given the data subjects whatever notice the law requires.
Subject matter and duration
- Subject matter. Provision of the GROUPSPACE community management service, including the organisation, records, economy, operations, moderation and game integration features the controller has enabled.
- Nature and purpose. Hosting, storing, structuring, retrieving, transmitting, and deleting personal data so the controller can run its community, together with the security, backup, support and audit activity that goes with operating a service.
- Duration. For as long as the controller’s subscription is in place, plus the deletion window in the return and deletion section.
Data subjects and data
Categories of data subject
- Workspace members and staff of the controller.
- Applicants to the controller’s organisations.
- Players in the controller’s connected games, who are not GROUPSPACE users and may be children. This is the largest category and the most sensitive one.
- People who are the subject of a record filed by the controller’s staff.
Categories of personal data
Special category data
GROUPSPACE is not designed to process special category data and the controller must not instruct it to. Free-text fields — record narratives, notes, incident reports — could contain such data if the controller’s staff type it in. That is outside the intended use, and the controller is responsible for it.
Controller instructions
GROUPSPACE processes personal data only on the controller’s documented instructions, except where law requires otherwise — in which case we tell the controller first, unless the law prohibits it.
The documented instructions are:
- this addendum and the terms of service;
- the configuration the controller sets in the application — retention settings, permission model, enabled features, integrations;
- the actions the controller’s authorised users take in the application or through the API;
- any further written instruction the parties agree.
If we consider an instruction to infringe data protection law, we will say so and may decline to act on it.
Confidentiality
Personnel authorised to process the controller’s personal data are bound by confidentiality obligations that survive the end of their engagement, and are given access only where it is needed for a specific purpose.
- Access to production data is least-privilege, granted for a reason, and logged when used.
- Staff access to a workspace happens for support the controller asked for, for a security investigation, or where the law requires it — and it is recorded.
- Personnel receive data protection guidance appropriate to their role, including on the sensitivity of chat history and children’s data.
Security measures
GROUPSPACE implements appropriate technical and organisational measures under Article 32. The current measures are listed in Annex B. They are described as practices; GROUPSPACE holds no security certification and does not claim one.
Highlights, because these are the ones customers ask about:
- Encryption. In transit on every connection. Chat history is encrypted at rest and held separately from the main tables.
- Access control. A permission model enforced at query time rather than by post-filtering results, because post-filtering leaks the existence of records through counts.
- Audit logging. Append-only, covering privileged actions, with each chat read logged individually against the reader and the subject.
- CASA-aligned development. We build against the CASA (OWASP-based) requirements Roblox applies to third-party applications. Alignment is not assessment and we do not present it as one.
- Segregation. Workspace data is scoped per workspace at the data layer, not by application-level filtering alone.
Measures may change as the product develops, provided the level of security is not reduced.
Subprocessing
The controller gives general authorisation for GROUPSPACE to appoint subprocessors. The current categories are on the subprocessors page.
- Each subprocessor is bound by written terms imposing data protection obligations no less protective than these.
- GROUPSPACE remains fully liable to the controller for a subprocessor’s performance.
- We give at least 30 days’ notice before adding or replacing a subprocessor. Notice is by email to workspace owners who have subscribed to the list and by an update to the subprocessors page.
- The controller may object on reasonable data protection grounds within the notice period. If we cannot resolve the objection, the controller may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.
- Where a change is urgent — a provider fails, or there is a security reason to move — we may act first and notify immediately, with the same objection right running from the notice.
Data subject requests
The controller answers requests from its own data subjects. GROUPSPACE assists.
Platform erasure
Where Roblox sends a signed RightToErasureRequest, GROUPSPACE purges that user’s records, sessions, operation participation and chat messages across every affected workspace, and writes the erasure to the audit log. The handler is continuously available, verifies the HMAC signature before parsing, and enforces a 300-second replay window.
This runs without the controller’s approval and cannot be suspended by instruction. It is a platform obligation. The controller should assume records for an erased user will disappear from its workspace and should not build processes that depend on them persisting.
Where a data subject revokes GROUPSPACE’s access to their platform account, the data obtained through that connection is expunged on the same basis.
Assistance with Articles 32 to 36
GROUPSPACE provides reasonable assistance with data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us. A DPIA covering chat history is strongly recommended, and we will contribute the technical detail for it.
Personal data breach
GROUPSPACE notifies the controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the controller’s personal data.
The notification includes, so far as we know it at the time:
- what happened and when we became aware;
- the categories and approximate volume of data and data subjects affected;
- the likely consequences;
- the measures taken or proposed, including anything the controller should do;
- a contact point for further information.
We will not delay an initial notification to make it complete. Information that is not available at first follows in stages. Notifying the controller is not an admission of fault by either party.
The controller is responsible for notifying its supervisory authority and its data subjects. We will provide what is reasonably needed to support that. Notices to the controller go to the workspace owner and any breach contact on file; notices to us go to security@groupspace.xyz.
Return and deletion
On termination, the controller chooses whether personal data is returned or deleted. Export is self-service and stays available through the grace period; if the controller does not choose, we delete.
On request we will confirm deletion in writing.
Audit rights
GROUPSPACE makes available the information needed to demonstrate compliance with this addendum and allows for audits, including inspections, by the controller or an auditor it mandates.
- In the first instance we answer a reasonable security questionnaire and provide our current description of technical and organisational measures. For most controllers this will be enough.
- Where it is not, an on-site or remote inspection may be arranged on at least 30 days’ written notice, no more than once in any twelve months unless a regulator requires otherwise or there has been a breach.
- Audits happen in business hours, must not disrupt the service, and must not expose another customer’s data. The auditor signs confidentiality terms first, and must not be a competitor of GROUPSPACE.
- The controller bears its own costs and our reasonable costs for time spent supporting an inspection, except where the audit finds a material breach of this addendum.
- We do not currently hold a third-party audit report to offer in place of an inspection. When one exists we will make it available and it will satisfy this section.
International transfers
Primary hosting — the application and the database — is with Railway in the United States, US East. Payment processing is with Stripe in the United States. Two categories, transactional email and error tracking, are not yet appointed; see the subprocessors page.
Where personal data is transferred out of the UK or the EEA, the transfer relies on an adequacy decision where one applies, and otherwise on the standard contractual clauses — module two or three as appropriate — together with the UK international data transfer addendum where the UK GDPR applies, and a transfer risk assessment. The clauses are incorporated into this addendum by reference, with the annexes populated from the tables on this page and the subprocessors page.
Because all currently appointed subprocessors process in the United States and there is no adequacy decision covering transfers from the UK or the EEA to the US outside the EU–US Data Privacy Framework, transfers of UK or EEA personal data rely on the standard contractual clauses and the UK addendum unless the receiving provider is certified under that framework. [confirm each provider’s DPF certification status and finalise the module and annex wording before this page is published as fact]
Liability and precedence
The limitations and exclusions of liability in the terms of service apply to this addendum and to claims arising out of it, except where the law does not permit them to.
Where this addendum conflicts with the terms of service, this addendum governs on matters of personal data processing. Where it conflicts with the standard contractual clauses, the clauses govern.
This addendum is governed by the law stated in the terms of service: the law of the State of Ohio, United States.
Annex A — children's data
This annex exists because the ordinary text of a processor agreement does not do justice to what is actually happening here. A substantial share of the data subjects in a controller’s workspace are children, and neither party has any shelter from that.
A.1 Acknowledgement
- Roblox’s audience skews young. A controller running a community on Roblox should assume children are among its members and among the players in its games.
- Roblox’s own children’s privacy programme applies to Roblox’s platform. It does not extend to GROUPSPACE’s systems or to the controller’s use of them. Each party carries its own obligations, which may include COPPA in the United States, the UK Age Appropriate Design Code, the GDPR provisions on children, and equivalent rules elsewhere.
- Roblox OAuth requires an account holder to be 13 or older to authorise a third-party application, so GROUPSPACE sign-in has a 13+ floor. Players in a connected game have no floor at all. They never touch a sign-in page, and GROUPSPACE holds data about them regardless of age.
A.2 What GROUPSPACE does
- No collection surface is pointed at players. Everything we hold about a player arrives from the controller’s own game server.
- Minimisation to platform user id and username. No age, birth date, avatar, contact details or other personal data is taken from the platform.
- No profiling, no behavioural advertising, no ad system, and no scoring of individuals.
- No use of any personal data to train AI or language models.
- Chat history is gated as described in A.3.
- Erasure requests are honoured immediately and cannot be exempted by the controller.
- Where a parent or guardian contacts us about a child’s data and the controller does not act, GROUPSPACE may delete its copy and will tell the controller it has done so.
A.3 Chat history — additional conditions
Chat history stores children’s messages. It is available only on the top plan, only with this addendum signed, and only on these conditions.
A.4 What the controller undertakes
- To have a lawful basis for processing children’s data and to meet any parental consent requirement that applies to it.
- To tell its members and players, in language they can understand, what is recorded and who can see it.
- Not to use GROUPSPACE to collect personal information from a child through application forms, record fields, notes or custom fields.
- Not to use records, chat or session data to identify or contact a young player outside the community.
- To grant the chat permission narrowly, to review the audit log, and to remove access from anyone who does not need it.
- To respond to requests from children and their parents or guardians, and to tell GROUPSPACE where a request affects data we hold.
Annex B — technical and organisational measures
Current measures, described as practices. GROUPSPACE holds no security certification and makes no claim of one.
