Data Processing Addendum
Last updated: July 21, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer", the data controller) and Gameverse, LLC ("genvi", the data processor) for the provision of the Service, and reflects the parties' agreement on the processing of personal data under the GDPR and comparable laws. To execute a countersigned copy, contact support@genvi.co.
1. Roles and scope
For personal data you submit to the Service, you act as the controller (or processor on behalf of a third party) and genvi acts as your processor. genvi processes personal data only on your documented instructions, which include your use of the Service's features, unless required by law.
2. Subject matter, nature, and purpose
The subject matter is the provision of a node-based AI creative studio. The nature and purpose of processing is hosting, storing, and transmitting your content to the AI providers you choose in order to generate outputs, plus account, billing, and security operations. Processing continues for the duration of your account.
3. Categories of data and data subjects
- Data subjects: you, your authorized users, and any individuals depicted or described in the content you submit.
- Personal data: account and profile data, authentication identifiers, prompts and uploaded/generated media, billing metadata, and server/security logs (including IP address).
4. Subprocessors
You authorize genvi to engage the subprocessors listed at genvi.co/subprocessors. genvi imposes data-protection obligations on each subprocessor and remains responsible for their performance. We will update that page before adding a new subprocessor; you may object on reasonable data-protection grounds by contacting us.
5. Security
genvi maintains technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest, row-level access controls, least-privilege access to production data, an append-only audit log of security-relevant events, and rate limiting on sensitive endpoints.
6. Data-subject requests
The Service lets you fulfil most data-subject requests directly (data export and account deletion from Account settings). genvi will, to the extent you cannot do so yourself, provide reasonable assistance to help you respond to requests under Articles 12–23 GDPR.
7. Personal-data breaches
genvi will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with information reasonably available to assist your own notification obligations (including the 72-hour GDPR timeline).
8. Deletion and return
On account deletion, genvi erases personal data from primary systems as described in the Privacy Policy (a 30-day grace period, then permanent purge). Residual copies in encrypted backups age out on a fixed rolling schedule and are not restored except for disaster recovery. Certain records (e.g. tax and payment records) may be retained where required by law.
9. International transfers
Where personal data is transferred outside the EEA/UK, the transfer is made under an appropriate safeguard such as the EU Standard Contractual Clauses (and the UK Addendum), which are incorporated by reference into this DPA.
10. Audits
On reasonable written request and subject to confidentiality, genvi will make available information necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an auditor you mandate.
11. Governing law
This DPA is governed by the laws of the State of Arizona, United States, and in the event of conflict with the main agreement, this DPA prevails with respect to the processing of personal data.