Legal
Data Processing Addendum
Last updated May 1, 2026
This DPA forms part of the LarpLabs Terms of Service and applies when LarpLabs processes personal data on your behalf.
1. Scope and roles
For personal data submitted to the LarpLabs platform, the customer is the "controller" and LarpLabs is the "processor" as those terms are defined under applicable data protection law, including GDPR and CCPA.
2. Processing instructions
LarpLabs will process personal data only on documented instructions from the customer, including those in the underlying agreement, configurations within the product, and authenticated API calls.
3. Confidentiality
Personnel authorized to process personal data are bound by confidentiality obligations and trained on data-handling practices.
4. Security measures
LarpLabs implements technical and organizational measures described in our Security overview, including encryption in transit and at rest, least-privilege access, and incident response procedures.
5. Subprocessors
Customer authorizes LarpLabs to engage subprocessors to deliver the service. A current list is available on request and we'll notify customers of material changes with a reasonable window to object.
6. International transfers
Where personal data is transferred internationally, LarpLabs relies on appropriate transfer mechanisms, including the EU Standard Contractual Clauses, where required.
7. Data subject rights & assistance
LarpLabs will reasonably assist the customer in fulfilling its obligations to respond to data subject requests and to conduct any required impact assessments.
8. Deletion and return
On termination, LarpLabs will delete or return personal data in its possession within a reasonable period, unless retention is required by law.
9. Contact
Reach our DPO at [email protected].