Data Processing Agreement for Billion Game Clients
Billion Game
Book a strategy call

{{ col.title }}

{{ feature.tag }}

{{ feature.title }}

{{ feature.copy }}

{{ feature.cta }} {{ feature.cta }}
Last updated 9 August 2026

Data processing agreement

When we work on your site we handle personal data that belongs to you — analytics, form submissions, sometimes customer records inside a CMS. This sets out the terms we process it under. We will sign it as a standalone document before any engagement begins.

On this page
01

Roles

For personal data inside your systems, you are the data controller and Billion Game is the data processor. You decide why the data exists; we act on your documented instructions.

For our own website visitors and enquiries, we are the controller, and our privacy policy governs that instead.

02

Scope of processing

  • Subject matter: search, content and development services under an agreed statement of work.
  • Duration: the engagement term, plus the retention periods below.
  • Categories of data: website analytics, Search Console query and URL data, form submissions, and any personal data present in CMS content we are asked to edit.
  • Data subjects: your website visitors, leads and customers.

We process only what the work requires. We do not export customer databases, and we ask for read-only access wherever read-only is enough.

03

Our obligations

  • Process only on your documented instructions, and tell you if an instruction appears to breach applicable law.
  • Ensure everyone with access is bound by confidentiality.
  • Apply the security measures described below.
  • Assist you with data subject requests, impact assessments and regulator queries.
  • Delete or return the data at the end of the engagement, at your choice.
  • Make available the information you need to demonstrate compliance, and allow audits on reasonable notice.
04

Sub-processors

We use a short, stable list: Google, for Analytics and Search Console; our email and document hosting provider; and SEO tooling including Semrush, Ahrefs and Screaming Frog, which process URLs and site data rather than customer records.

We will tell you at least thirty days before adding a sub-processor that handles your data, and you may object. If we cannot resolve an objection, you may terminate the affected part of the engagement without penalty.

05

Security measures

  • Access granted per person, least-privilege, and revoked when an engagement ends or someone leaves.
  • Two-factor authentication mandatory on every account that touches client data.
  • Full-disk encryption on all devices, and encrypted transport for anything transferred.
  • Credentials held in a password manager, never in shared documents or spreadsheets.
  • Access reviewed at the start and end of every engagement.
06

International transfers

We process in India. Where you are in the UK or EU, transfers rely on the UK IDTA or EU Standard Contractual Clauses, which we will execute alongside this agreement.

We apply the same technical and organisational measures regardless of where the data sits, and we do not move client data to a jurisdiction you have not agreed to.

07

Breach notification

We notify you without undue delay and within seventy-two hours of becoming aware of a personal data breach affecting your data.

The notification states what happened, which categories and roughly how many records are affected, the likely consequences, and the steps taken or proposed. We help you meet your own regulator and data-subject notification duties.

08

Retention and deletion

At the end of the engagement we return or delete your personal data at your election, within thirty days, except where law requires us to keep a copy.

Deliverables such as reports, content and documentation remain yours and are handed over in a usable format regardless of how the engagement ended.

09

Liability and precedence

This agreement is incorporated into our terms of service. Where the two conflict on data protection specifically, this document takes precedence.

Liability under this agreement is subject to the limits in our terms of service, except where applicable data protection law does not permit limitation.

Requesting a signed DPA

Email us and we will return a signed copy, usually the same day. If your procurement team has its own template we will review and sign that instead rather than insisting on ours.

Billion Game
2nd Floor, 103, Velachery Main Road, Guindy
Chennai, Tamil Nadu 600032, India
sales@thebilliongame.com