Skip to content
MXO
  • Home
  • Discord Bot
  • Live Studio
  • Games Arcade
DE EN
  1. Home
  2. Data Processing Agreement

Data Processing Agreement (DPA)

Under Article 28 GDPR — for MXO Live Studio with its games arcade · As at 5 August 2026

What is this for? Anyone streaming with MXO Live Studio processes data about their viewers – names in leaderboards, chat messages, scores. For that data you are the controller under the GDPR. The provider merely supplies the application and processes that data on your behalf. Article 28(3) GDPR requires a contract for exactly that – this one. It is concluded together with the subscription; you do not have to sign or send anything.

Overview

  • Section 1 Parties and subject matter
  • Section 2 Nature, scope and purpose of processing
  • Section 3 Processing on instructions only
  • Section 4 Confidentiality
  • Section 5 Technical and organisational measures
  • Section 6 Sub-processors
  • Section 7 Assistance with data subject rights
  • Section 8 Notification of personal data breaches
  • Section 9 Evidence and audits
  • Section 10 Deletion and return
  • Section 11 Liability and final provisions
  • Other legal texts

Section 1 Parties and subject matter

(1) The controller is the customer who has taken out a subscription for MXO Live Studio (the “Customer”).

(2) The processor is the provider named in the imprint (the “Provider”).

(3) The subject matter is the processing of personal data of third parties – essentially viewers – that arises because the Customer uses the application operated by the Provider.

(4) This agreement does not cover the Customer’s own data (e-mail address, subscription status, payments, access logs). For those the Provider is a controller in its own right; the privacy policy applies.

(5) The agreement ends with the subscription; Section 10 continues to apply beyond that.

Section 2 Nature, scope and purpose of processing

(1) Purpose: solely the provision and operation of the subscribed application for the Customer.

(2) Nature of processing: collection, storage, display, evaluation within the application, display in overlays, deletion.

(3) Categories of data subjects: viewers of the Customer’s streams and members of the channels they connect.

(4) Categories of personal data:

  • display names and user identifiers from the TikTok and Twitch platforms,
  • chat messages and their timestamps,
  • events such as gifts, follows, likes, shares, subscriptions and bits,
  • scores, leaderboards, queues and statistics derived from them,
  • profile pictures, in so far as the platform makes them publicly available.

(5) Special categories under Article 9 GDPR are not the subject of processing. The Customer ensures that such data is not deliberately entered into the application.

(6) The place of processing is a data centre in Frankfurt am Main, Germany. Processing outside the EU takes place only via the sub-processors listed in Section 6.

Section 3 Processing on instructions only

(1) The Provider processes the data solely on the Customer’s instructions. Using the application with its settings constitutes the primary instruction: whatever the Customer switches on there is the instruction to do it. Any further instructions are given in text form.

(2) There is no processing for the Provider’s own purposes. In particular, the data is not analysed, not combined with data of other customers, not sold, not used for advertising and not used to train AI models.

(3) If the Provider considers an instruction unlawful, it will say so and may suspend execution until the matter is resolved (Article 28(3) sentence 3 GDPR).

(4) Where the Provider is required to process by Union or Member State law, it informs the Customer beforehand unless that law prohibits it on important grounds of public interest.

Section 4 Confidentiality

(1) Everyone who may have access to the data in the course of the engagement is bound to confidentiality; the obligation continues beyond the end of their activity.

(2) Stated plainly: the Provider is currently a one-person operation. Only the person named in the imprint has access to the servers. If further people join, they are put under a written confidentiality obligation before their first access.

(3) Content of a customer instance is accessed only where necessary for operation, troubleshooting or security – and at the Customer’s request or after prior notice.

Section 5 Technical and organisational measures

The Provider implements the measures required by Article 32 GDPR. Specifically:

  • Separation of customers: every customer receives their own instance with its own system user and its own data. Instances cannot technically reach one another.
  • Access control: access is via personal addresses containing a secret component; they are renewed on request. The server is reachable from outside only over encrypted connections.
  • Encryption in transit: HTTPS with automatically renewed certificates. Unencrypted requests are redirected.
  • Restriction of outbound connections: an instance can reach only the destinations required for operation; access to other instances or to the internal network is blocked.
  • Availability: daily backups, automatic restart on failure and monitoring that reports persistent errors. Restoration is tested.
  • Logging: access to an instance is logged and deleted after at most 14 days.
  • Separability on deletion: because every instance holds its own data, one customer’s data can be removed completely and without residue.

The measures may be adapted to the state of the art; the level of protection must not fall as a result.

Section 6 Sub-processors

(1) The Customer agrees to the use of the following sub-processors:

Sub-processors used
Company Service Location
Hostinger International Ltd, Larnaca, Cyprus Server operation of the instances Frankfurt am Main, Germany
EulerStream Signing service, without which no connection to TikTok LIVE can be established. The TikTok name of the channel is transmitted – no viewer data. USA, standard contractual clauses
Google or ElevenLabs Only when the read-aloud feature is switched on: generating the voice. The text to be read out is transmitted and may contain display names and chat messages. USA, standard contractual clauses

(2) Further sub-processors are notified to the Customer in text form at least four weeks in advance. The Customer may object within that period. If they object, they may cancel the subscription with effect from the date of the change without notice; amounts already paid for the period after that are refunded.

(3) The Provider binds every sub-processor to a level of protection corresponding to this agreement.

Section 7 Assistance with data subject rights

(1) If a data subject approaches the Provider directly, the Provider forwards the request to the Customer without undue delay and does not answer it itself.

(2) The Provider assists the Customer with access, rectification, erasure, restriction and data portability – where possible through the functions of the application itself, otherwise on instruction. This assistance is included in the subscription.

Section 8 Notification of personal data breaches

(1) The Provider notifies the Customer of a personal data breach without undue delay after becoming aware of it, as a rule within 24 hours.

(2) The notification contains, as far as known: the nature of the breach, the categories of data concerned, the approximate number of data subjects, the likely consequences and the measures taken.

(3) Notification to the supervisory authority under Article 33 GDPR is the Customer’s responsibility; the Provider assists.

Section 9 Evidence and audits

(1) On request, the Provider demonstrates compliance with this agreement in text form.

(2) The Customer may satisfy themselves as to the level of protection. On-site audits are possible with reasonable advance notice, during normal business hours and without disrupting operations. A written statement suffices as an alternative.

(3) Evidence the Provider receives from its sub-processors is passed on upon request.

Section 10 Deletion and return

(1) The Customer can export their data from the application at any time.

(2) After the subscription ends, the data remains available for 30 days so that it can still be exported. After that it is deleted from the instance, and at the latest 30 days later from the backups as well.

(3) If the Customer requests immediate deletion, it is carried out without undue delay; the 30 days then do not apply.

(4) Statutory retention obligations remain unaffected. They concern the Customer’s invoicing data, not the viewer data.

Section 11 Liability and final provisions

(1) Liability is governed by Article 82 GDPR. Otherwise the liability provisions of the terms and conditions apply.

(2) Where this agreement and the terms conflict, this agreement prevails on matters of data processing.

(3) Amendments are made in text form. If a provision is invalid, the rest of the contract remains valid; the statutory rules take the place of the invalid provision.

(4) German law applies. The contract language is German; the English version serves comprehensibility.

Other legal texts

  • Imprint
  • Privacy policy
  • Terms and conditions
  • Right of withdrawal

Products

  • MXO Discord Bot
  • MXO Live Studio
  • Games Arcade

Legal

  • Imprint
  • Privacy
  • Terms
  • Right of withdrawal
  • Data processing

Contact

E-mail: kontakt@mxomedia.online

Postal address and further details are in the imprint.

MXO

© 2026 MXO. All rights reserved.

Not affiliated with Discord Inc., TikTok/ByteDance or Twitch/Amazon; all trademarks belong to their respective owners.