SafeGuardBeta

Data Processing Agreement

Version of 2026-09-24. This Agreement is part of the Terms of Service and meets Article 28 of the General Data Protection Regulation (GDPR). The Portuguese version prevails in case of doubt.

1. Parties and roles

  • Controller: the customer, owner of the FiveM server that uses SafeGuard.
  • Processor: SafeGuard, tax ID [to be completed], [to be completed] ("SafeGuard").

2. Subject, nature and purpose

SafeGuard processes data of the players of the customer's server only to protect the server against cheating and abuse: detect forbidden behaviour, compute risk, apply the punishments the customer configured, keep evidence and allow appeals. We use this data for nothing else.

3. Data subjects and data

Data subjects: players who connect to the customer's server and members of the customer's staff.

CategoryExamplesNotes
FiveM identifierslicense, discord, steam, xbl, fivemUsed to recognise the player across sessions and the customer's servers
IP address—Pseudonymised by default (keyed hash); the customer may choose not to store it or to store it in full
FiveM hardware tokens—Stored only as hashes
In-game name and sessionsjoin, leave, server
Game telemetryposition, health, armour, speed, weapon, vehicleTo confirm detections; the customer can switch it off
Detections, risk, banstype, confidence, technical evidence
Screenshots and live framesgame screenScreenshots kept per the customer's retention; live spectate frames are not stored
Appealsplayer's message, optional e-mail

No special categories of data (GDPR Article 9) are processed.

4. Duration and retention

For as long as the customer uses the Service. Retention periods are set by the customer in Settings (defaults: detections 180 days, evidence 90 days, screenshots 30 days, inactive profiles 365 days) and applied automatically. When the contract ends, data is deleted within 30 days unless an export was requested before.

5. SafeGuard's obligations

  • Process data only on the customer's documented instructions (the Service configuration and these Terms).
  • Ensure people with access are bound by confidentiality.
  • Apply appropriate technical and organisational measures (section 7).
  • Help the customer answer data subjects' requests and with impact assessments, as far as possible.
  • Notify the customer of a personal data breach without undue delay and at most 48 hours after becoming aware of it.
  • Delete or return the data when the contract ends.
  • Make available the information needed to show compliance with this Agreement and allow reasonable audits with prior notice.

6. Sub-processors

The customer authorises the subprocessors listed in the Privacy Policy (hosting, database, storage and e-mail). We give at least 30 days' notice before adding or replacing a subprocessor that processes player data; the customer may object and, in that case, end the contract. Subprocessors are bound by obligations equivalent to this Agreement.

7. Security measures

  • Encrypted communication (TLS) and server requests signed with per-session keys.
  • Sensitive identifiers pseudonymised or stored only as hashes; secrets and webhooks encrypted.
  • Role- and permission-based access, with an audit log of every action.
  • License and API keys stored only as hashes and revocable.
  • Automatic retention and deletion per the customer's configuration.

8. Customer's obligations

The customer ensures it has a legal basis for the processing (usually the legitimate interest in protecting the server and other players) and informs players clearly, for example in its privacy policy or server rules.

9. International transfers

When a subprocessor is outside the European Economic Area, transfers rely on the European Commission's standard contractual clauses and/or the EU-US Data Privacy Framework.