maxlevel
ContactLog inStart free
Legal

Data processing agreement

The processor terms that apply when maxlevel handles personal data on your behalf under Article 28 of the GDPR.

Version 1.0 · Last updated 27 July 2026

Roles

You are the controller of personal data about your members. maxlevel is the processor and acts only on your documented instructions, which include the configuration choices you make in the product.

Scope of processing

Subject matter: operating a gamification platform. Categories of data subject: your members and administrators. Categories of data: identity details, community membership, logged actions and timestamps, XP and level history, badges, and technical logs.

Security measures

Enterprise deployments are physically separate: their own database and their own application containers, with no shared database between clients. On the shared instance, every community-scoped query passes through a single audited helper, and each endpoint carries an automated test that attempts access from another community and requires a refusal. Also: TLS 1.3 for data in transit; role-based access control; and isolated containers per service. Dependency scanning, static analysis, and secret detection are configured in the pipeline but are not running while CI is paused. There is no database-level row-level security on the shared instance.

Sub-processors

You give general authorisation for the sub-processors on our current list, used for hosting, transactional email, and billing. We give notice before adding a new one and you may object on reasonable data-protection grounds.

Personnel and confidentiality

Access to production data is limited to the people who need it to operate or support the service, is logged, and is bound by confidentiality obligations that survive the engagement.

Assisting you

We help you respond to data-subject requests, complete security questionnaires, and carry out a DPIA where the deployment warrants one. Tooling exists for export and deletion so most requests do not need us at all.

Breach notification

We notify you without undue delay and in any case within 72 hours of becoming aware of a personal-data breach affecting your data, with what we know at the time and what we are doing about it.

International transfers

Data can be hosted in the region you specify. Where a transfer outside the EEA occurs, it relies on standard contractual clauses and a documented transfer impact assessment.

Deletion and return

On termination we delete your personal data within 30 days, or return it in a structured export first if you ask, except where retention is legally required.

Audit

You may request our security documentation annually. On-site or third-party audits are available under enterprise agreements, at your cost and with reasonable notice.