Data Processing Agreement

How FluxStore processes personal data on behalf of Store Owners, under UK and EU GDPR.

Effective: June 28, 2026Version 1.0.0

1.Introduction

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the FluxStore Terms of Service(the "Agreement") between SiriusMC Networks ("FluxStore", "we", "us") and the Store Owner ("you"). It governs the processing of personal data that FluxStore carries out on your behalf when you use the Service.

By accepting the Agreement, or by using the Service, you also agree to this DPA. Where there is a conflict between this DPA and the rest of the Agreement on the subject of data protection, this DPA prevails.

This DPA is designed to satisfy Article 28 of the UK GDPR and, where applicable, Article 28 of the EU GDPR. It does not replace either party's own obligations under Data Protection Laws.

2.Definitions

  • Data Protection Laws: the UK GDPR, the Data Protection Act 2018, and, to the extent applicable to the processing, the EU GDPR (Regulation (EU) 2016/679) and any other applicable data protection or privacy laws.
  • Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach: have the meanings given in the Data Protection Laws.
  • Sub-processor: any third party engaged by FluxStore to process Personal Data on your behalf under this DPA.
  • Store Owner, Buyer, Service: have the meanings given in the Agreement.
  • Your Personal Data: Personal Data that FluxStore processes on your behalf in providing the Service, as described in Annex 1.
  • Standard Contractual Clauses / UK Transfer Mechanism: the EU Standard Contractual Clauses, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU SCCs, as applicable to a given restricted transfer.

3.Roles of the parties

In respect of Your Personal Data, you are the Controller (or, where you act on behalf of another controller, the Processor) and FluxStore is the Processor (or sub-processor). FluxStore processes Your Personal Data only to provide the Service, in accordance with your instructions and this DPA.

Separately, FluxStore acts as an independent Controller for Personal Data it processes for its own purposes, such as administering and securing Store Owner accounts, platform billing, fraud prevention, legal compliance, and aggregated, non-identifying analytics. That processing is governed by the FluxStore Privacy Policy, not by this DPA.

You remain solely responsible for establishing a lawful basis for the processing, for providing any required privacy notices to your Buyers, and for the accuracy and lawfulness of the instructions you give us.

4.Scope and processing instructions

FluxStore will process Your Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case FluxStore will, where legally permitted, inform you of that requirement before processing).

Your documented instructions are made up of:

  • the Agreement and this DPA;
  • your configuration and use of the Service through the dashboard and APIs (for example, the packages, commands, servers, integrations, and settings you configure); and
  • any further written instructions you give us that are consistent with the Service.

FluxStore will inform you if, in its opinion, an instruction infringes the Data Protection Laws, although FluxStore is not obliged to carry out a legal review of your instructions.

5.Details of the processing

The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1. The processing will continue for the duration of the Agreement and until deletion or return of the data in accordance with this DPA.

6.FluxStore's obligations

In respect of Your Personal Data, FluxStore will:

  • process it only on your documented instructions, as set out above;
  • ensure that persons authorised to process it are bound by appropriate confidentiality obligations;
  • implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Security measures);
  • respect the conditions for engaging Sub-processors set out below;
  • taking into account the nature of the processing, assist you by appropriate measures, insofar as possible, to respond to requests from Data Subjects exercising their rights;
  • assist you in ensuring compliance with your obligations regarding security of processing, Personal Data Breach notification, data protection impact assessments, and prior consultation (Articles 32 to 36), taking into account the nature of the processing and the information available to FluxStore;
  • at your choice, delete or return Your Personal Data after the end of the provision of the Service, as set out below; and
  • make available to you information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, as set out below.

7.Security measures

FluxStore maintains appropriate technical and organisational measures designed to protect Your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include, as appropriate:

  • encryption of data in transit (TLS) and encryption of sensitive stored data (such as payment gateway credentials);
  • role- and permission-based access controls, with access limited to personnel who need it;
  • authentication controls, including support for two-factor authentication on accounts;
  • network protections including a web application firewall and DDoS mitigation;
  • regular backups of the production database; and
  • logging and monitoring designed to detect and respond to security events.

FluxStore may update these measures from time to time provided the level of protection is not materially reduced.

8.Sub-processors

You provide a general authorisation for FluxStore to engage the Sub-processors listed in Annex 2 to process Your Personal Data. FluxStore will:

  • impose data protection obligations on each Sub-processor that are substantially the same as those in this DPA, by way of a written contract;
  • remain liable to you for the performance of each Sub-processor's obligations; and
  • give you reasonable notice of any intended addition or replacement of a Sub-processor by updating Annex 2, giving you the opportunity to object on reasonable data-protection grounds before the new Sub-processor begins processing.

If you object on reasonable grounds and the parties cannot agree a resolution, you may terminate the affected part of the Service. Payment-related processing depends on the payment integration you choose; where you connect your own payment provider, that provider processes payment data under your own agreement with them, not as a Sub-processor of FluxStore.

9.International transfers

FluxStore stores Your Personal Data primarily within the European Economic Area. Some Sub-processors are located outside the UK and EEA. Where FluxStore transfers Your Personal Data to a country that has not received an adequacy decision, it will ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, together with any supplementary measures required.

You authorise FluxStore to enter into such transfer mechanisms with Sub-processors on your behalf where necessary to provide the Service.

10.Data subject requests

Taking into account the nature of the processing, FluxStore will assist you, by appropriate technical and organisational measures and insofar as reasonably possible, to fulfil your obligation to respond to requests from Data Subjects to exercise their rights (such as access, rectification, erasure, restriction, portability, and objection).

If FluxStore receives a request directly from one of your Buyers or other Data Subjects relating to data we process on your behalf, we will, where lawful, promptly forward it to you and will not respond directly except on your instructions or as required by law.

11.Personal data breaches

FluxStore will notify you without undue delay after becoming aware of a Personal Data Breach affecting Your Personal Data. The notification will, to the extent available, describe the nature of the breach, the likely consequences, and the measures taken or proposed to address it.

FluxStore will provide reasonable assistance to help you meet your own breach-notification obligations to supervisory authorities and Data Subjects. A notification is not an acknowledgement of fault or liability.

12.Return and deletion

On termination or expiry of the Agreement, FluxStore will, at your choice, delete or return Your Personal Data, and delete existing copies, unless retention is required by applicable law.

FluxStore may retain certain Personal Data where required to comply with legal, tax, accounting, or regulatory obligations, or to resolve disputes and enforce agreements (for example, transaction and order records). Any retained data remains subject to the protections of this DPA for as long as it is held. Routine deletion may also be subject to a reasonable backup-retention cycle.

13.Audits

FluxStore will make available to you information reasonably necessary to demonstrate compliance with this DPA and Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you.

Audits are subject to reasonable conditions: reasonable prior written notice, no more than once per year (except where required following a Personal Data Breach or by a supervisory authority), conduct during normal business hours, appropriate confidentiality undertakings, and no access to other customers' data or to information that would compromise security. FluxStore may satisfy audit requests by providing relevant documentation or third-party reports where available.

14.Liability and term

This DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA takes effect on your acceptance of the Agreement and continues for as long as FluxStore processes Your Personal Data, after which the obligations that by their nature should survive (including confidentiality and deletion) continue to apply.

This DPA is governed by the laws of England and Wales, and disputes are subject to the jurisdiction set out in the Agreement, without prejudice to any mandatory rights under the Data Protection Laws.

15.Annex 1 - Details of processing

  • Subject matter: FluxStore's provision of the Service to you under the Agreement.
  • Duration: the term of the Agreement, plus any period of retention required by law or permitted under the Return and deletion section.
  • Nature and purpose: hosting your storefront, processing checkout and orders, delivering commands to your game servers, sending transactional emails, providing analytics and dashboard tooling, and operating optional integrations (such as Discord), in each case to enable you to sell to and serve your Buyers.
  • Types of Personal Data: Buyer Minecraft username and UUID; email address; IP address and derived country; order and transaction metadata (amounts, status, identifiers); Discord user, guild, and role identifiers where the Discord integration is used; and any other data you choose to collect through your storefront configuration.
  • Special category data: the Service is not intended to process special category data, and you should not submit it.
  • Categories of Data Subjects: your Buyers and prospective Buyers, and your authorised team members.

16.Annex 2 - Sub-processors

The following Sub-processors are currently engaged to process Your Personal Data. This list may be updated as described in the Sub-processors section.

Sub-processorPurposeRegion
Cloud hosting providerCloud hosting and data storage for the production infrastructureGermany (EEA)
Cloud backup storage providerEncrypted off-site backups of the production databaseUnited States
Cloudflare, Inc.CDN, DNS, TLS, DDoS protection, and edge securityUnited States / global
Auth0 / Okta, Inc.Authentication and identity for account sign-inUnited States / EEA
SMTP2GODelivery of transactional email (receipts, notifications, verification)United States / global
Discord Inc.Optional Discord integration (notifications and role syncing)United States
Stripe, Inc.Payment processing and transaction data, where Stripe Connect or platform billing is usedUnited States / global
PayPal (Europe)Payment confirmation data, where PayPal is usedUnited States / global

Minecraft username and UUID lookups are performed via Mojang / Microsoft and PlayerDB to verify player identity. Where you connect your own payment provider with your own API keys, that provider processes payment data under your own agreement with them rather than as a Sub-processor of FluxStore.

17.Contact

For any questions about this DPA, to send data protection notices, or to exercise the rights set out here, contact:

FluxStore - SiriusMC Networks

Email: [email protected]