Poker Club Admin, LLC — Data Processing Addendum
Version 1.0 Effective Date: August 25, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other agreement (“Agreement”) between Poker Club Admin, LLC, 3511 Tahoe Blvd, Normal, Illinois 61761, United States (“PCA,” “Processor,” “we,” “us,” or “our”) and the customer accepting the Agreement (“Customer,” “Controller,” or “you”).
This DPA applies where PCA processes Personal Data on behalf of Customer in connection with the Poker Club Admin service.
If there is a conflict between this DPA and the Agreement regarding processing of Customer Personal Data, this DPA controls to the extent of the conflict.
1. Definitions
For purposes of this DPA:
“Applicable Data Protection Law” means applicable United States federal and state privacy, security, breach-notification, and data-protection laws governing processing under this DPA.
“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” “Personal Data Breach,” and “Supervisory Authority” have the meanings given to them under Applicable Data Protection Law.
“Customer Personal Data” means Personal Data contained in Customer Data that PCA processes on behalf of Customer.
“Subprocessor” means a third party engaged by PCA to process Customer Personal Data on behalf of Customer in connection with the Service.
“Service” means the Poker Club Admin software and related services provided under the Agreement.
2. Roles of the Parties
Customer generally acts as the Controller with respect to Customer Personal Data it submits to or manages through PCA.
PCA generally acts as the Processor with respect to that Customer Personal Data.
Examples may include:
- player-directory information;
- player contact information entered by Customer;
- league memberships;
- tournament participation and results;
- cash-game participation and results;
- standings;
- attendance;
- invitations and communications;
- seating information;
- buy-ins, rebuys, payouts, bounties, fees, and other customer-managed game records;
- notes and other club-administration information entered by Customer.
PCA may separately act as an independent Controller for information processed for PCA’s own account administration, authentication, security, billing, legal compliance, support, and similar purposes. Such Controller processing is governed by PCA’s Privacy Policy rather than this DPA.
3. Customer Instructions
PCA will process Customer Personal Data only:
- on Customer’s documented instructions;
- as necessary to provide and support the Service;
- as described in the Agreement and this DPA; or
- where required by applicable law.
Use of the Service and configuration of its features constitute documented instructions to PCA for processing reasonably necessary to provide those features.
Instructions may also be provided in another written and retainable form, including email.
If PCA is legally required to process Customer Personal Data contrary to Customer’s instructions, PCA will inform Customer before the processing unless applicable law prohibits that notice.
If PCA reasonably believes a Customer instruction violates Applicable Data Protection Law, PCA may notify Customer and suspend the affected processing until the issue is resolved.
4. Customer Responsibilities
Customer is responsible for:
- determining the purposes and lawful basis for Customer’s processing of Customer Personal Data;
- providing legally required notices to Data Subjects;
- obtaining legally required consents where applicable;
- determining which Personal Data is appropriate to enter into PCA;
- responding to Data Subjects where Customer is the Controller;
- using the Service in compliance with Applicable Data Protection Law;
- ensuring that authorized users process Customer Personal Data appropriately.
Customer must not knowingly submit Personal Data concerning individuals under 18.
Customer must not use PCA as a repository for unnecessary highly sensitive information, including government identification numbers, medical records, biometric or genetic data, authentication credentials, complete payment-card information, financial-account credentials, or other sensitive information unrelated to PCA’s intended functionality.
5. Details of Processing
The subject matter, nature, purpose, duration, data types, and categories of Data Subjects are described in Schedule 1 to this DPA.
The processing will generally continue for the term of Customer’s use of the Service and for any limited retention period described in the Agreement, Privacy Policy, and this DPA.
6. Confidentiality
PCA will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
PCA will limit access to Customer Personal Data to personnel and service providers who reasonably require access to perform their authorized functions.
PCA will not permit personnel to process Customer Personal Data for unrelated personal purposes.
7. Security
PCA will implement and maintain reasonable and appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Measures may include, as appropriate:
- HTTPS-encrypted communications;
- access controls;
- authentication and multi-factor authentication functionality;
- session controls;
- tenant/account isolation;
- rate limiting and automated-abuse protection;
- security and audit logging;
- database and application access controls;
- backup and recovery measures;
- vulnerability and regression testing;
- service-provider security controls;
- incident-response procedures.
Security measures will be appropriate to the nature, scope, context, and risks of the processing.
PCA does not represent that any security system can eliminate all risk.
8. Personal Data Breaches
PCA will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
To the extent reasonably available and applicable, notice will include information concerning:
- the nature of the breach;
- categories of affected data or Data Subjects;
- reasonably known consequences;
- measures taken or proposed to contain or remediate the breach;
- information reasonably necessary to assist Customer with applicable notification obligations.
PCA may provide information in phases as investigation proceeds.
Customer is responsible for determining whether notification to regulators or affected individuals is legally required where Customer acts as Controller.
9. Assistance with Data Subject Rights
Taking into account the nature of the processing, PCA will provide reasonable assistance to Customer in responding to valid requests by Data Subjects exercising rights under Applicable Data Protection Law.
Such rights may include, where applicable:
- access;
- correction;
- deletion;
- restriction;
- portability;
- objection;
- withdrawal of consent where Customer relies on consent.
If PCA receives a request directly from a Data Subject concerning Customer-controlled data, PCA may:
- refer the requester to Customer;
- notify Customer;
- provide reasonable assistance in accordance with Customer’s instructions.
PCA will not independently alter Customer-controlled historical records where Customer is the Controller unless legally required to do so.
10. Assistance with Compliance Obligations
Taking into account the nature of processing and information available to PCA, PCA will provide reasonable assistance to Customer with applicable obligations concerning:
- security of processing;
- Personal Data Breach assessment and notification;
- data-protection impact assessments;
- prior consultation with Supervisory Authorities where required;
- demonstration of processor-related compliance.
The extent of assistance may depend on the complexity and burden of the request.
11. Subprocessors
Customer provides PCA with general authorization to engage Subprocessors necessary to provide the Service.
PCA will maintain a current Subprocessor List identifying relevant Subprocessors.
PCA will impose data-protection obligations on Subprocessors that are materially appropriate to the processing they perform and consistent with PCA’s obligations under this DPA.
PCA remains responsible for performance of its processor obligations to Customer to the extent required by Applicable Data Protection Law.
The current production Subprocessor/service-provider inventory includes, as applicable:
- hosting.com — hosting, database, backups, communications infrastructure;
- OpenAI — optional PCA AI Assistant processing;
- Umami Cloud — privacy-focused analytics, to the extent it processes Customer Personal Data;
- Cloudflare — Turnstile security and automated-abuse prevention;
- other providers identified on PCA’s current Subprocessor List.
Stripe is addressed separately because its privacy role may vary depending on the particular payment-processing activity.
12. Changes to Subprocessors
PCA may add or replace Subprocessors as reasonably necessary to operate and improve the Service.
Where Applicable Data Protection Law requires notice or an opportunity to object, PCA will provide appropriate notice of material Subprocessor changes.
Customer’s objection must be based on reasonable data-protection grounds.
If PCA cannot reasonably resolve a valid objection, the parties may work in good faith toward an alternative or termination of the affected processing where required by law.
13. Processing Locations and Service Providers
PCA is established in the United States and currently offers customer subscriptions only in the eligible U.S. jurisdictions identified in the Terms.
PCA and authorized service providers may process Customer Personal Data in locations reasonably necessary to provide, secure, support, and administer their services, subject to this DPA, applicable contracts, and Applicable Data Protection Law.
14. Return and Deletion of Customer Personal Data
Upon termination of the Service or Customer’s written instruction, PCA will delete or return Customer Personal Data as required by Applicable Data Protection Law, subject to:
- applicable retention periods;
- legal obligations;
- security/fraud records;
- dispute or claims preservation;
- technical backup rotation.
PCA’s ordinary policy is to retain operational Customer Data for 30 days after paid access ends to allow short-term recovery or reactivation.
After that period, operational Customer Data is deleted or anonymized unless continued retention is legally required or reasonably justified.
A verified deletion request may result in earlier deletion where appropriate.
Data may temporarily remain in protected backups until those backups expire through ordinary retention and rotation processes.
PCA will not restore deleted Customer Personal Data into ordinary production use except where reasonably necessary for disaster recovery, legal obligations, or security purposes.
Information may remain temporarily in protected hosting-provider backups until ordinary backup rotation removes it. PCA does not publish a specific hosting.com backup-retention period because that period has not been confirmed.
15. Records and Demonstration of Compliance
PCA will maintain records reasonably necessary to demonstrate its processor obligations under Applicable Data Protection Law.
PCA will make information reasonably necessary to demonstrate compliance with this DPA available to Customer upon reasonable request.
PCA will maintain appropriate internal records concerning processing activities, subprocessors, security measures, incidents, and applicable retention practices.
16. Audits
Where required by Applicable Data Protection Law, PCA will allow for and contribute to reasonable audits or inspections concerning processing under this DPA.
To avoid unnecessary security risks and disruption:
- Customer should ordinarily rely first on available compliance documentation, policies, questionnaires, certifications, and similar evidence;
- audits should be requested on reasonable advance notice;
- audits should occur during reasonable business hours;
- audits must not unreasonably disrupt PCA or compromise another customer’s confidentiality or security;
- auditors must be subject to appropriate confidentiality obligations;
- audits should ordinarily occur no more than once annually unless required by law, a Supervisory Authority, or a material security incident.
Customer will bear its reasonable audit costs unless Applicable Data Protection Law requires otherwise or an audit identifies a material breach by PCA.
17. Government and Legal Requests
If PCA receives a legally binding request from a government or public authority seeking Customer Personal Data, PCA will, where legally permitted:
- review the validity and scope of the request;
- limit disclosure to information legally required;
- notify Customer where permitted and reasonably appropriate;
- challenge requests where there are reasonable grounds and applicable law supports doing so.
PCA will not voluntarily provide Customer Personal Data to governmental authorities except where authorized by Customer, required by law, or reasonably necessary to protect PCA or others from serious unlawful conduct.
18. Security Incidents Not Involving Personal Data
PCA may notify Customer of significant security incidents affecting the availability, integrity, or confidentiality of the Service even where they do not meet the legal definition of a Personal Data Breach, when PCA reasonably determines notice is appropriate.
Such notice does not constitute an admission that a legally reportable Personal Data Breach occurred.
19. Liability
The liability provisions of the Agreement apply to this DPA except where Applicable Data Protection Law requires otherwise.
Nothing in this DPA limits liability that cannot legally be limited.
20. Duration and Termination
This DPA becomes effective when the Agreement becomes effective and applies for as long as PCA processes Customer Personal Data on Customer’s behalf.
Provisions that by their nature must continue following termination—including confidentiality, deletion, legal retention, and audit/compliance obligations—remain effective for as long as relevant Personal Data remains subject to those obligations.
21. Governing Terms
Except where mandatory privacy or transfer law requires otherwise, this DPA is governed by the governing-law provisions of the Agreement.
Mandatory provisions of Applicable Data Protection Law take precedence where required.
22. Contact
Data-protection questions and instructions concerning this DPA may be directed to:
Poker Club Admin, LLC 3511 Tahoe Blvd Normal, IL 61761 United States
Privacy: privacy@pokerclubadmin.com Legal: legal@pokerclubadmin.com
Schedule 1 — Details of Processing
1. Subject Matter
Provision, hosting, support, maintenance, security, and operation of the Poker Club Admin SaaS platform on Customer’s behalf.
2. Duration
For the duration of Customer’s use of PCA and for applicable post-termination retention, deletion, backup, legal, and security periods.
3. Nature and Purpose of Processing
Processing may include:
- collection;
- receipt;
- storage;
- organization;
- retrieval;
- display;
- transmission;
- calculation;
- reporting;
- communication;
- backup;
- security monitoring;
- troubleshooting;
- deletion;
- anonymization.
Purposes include providing Customer with functionality to administer poker clubs, leagues, tournaments, cash games, players, standings, communications, reports, schedules, and related records.
4. Categories of Data Subjects
Depending upon Customer’s use:
- Customer’s players;
- league members;
- tournament participants;
- cash-game participants;
- invitees;
- other individuals Customer legitimately manages through PCA;
- authorized Customer users where PCA processes their information on Customer’s behalf.
All individuals entered into PCA are required by PCA’s contractual rules to be at least 18 years old.
5. Categories of Personal Data
Depending upon Customer’s configuration and use:
- names;
- email addresses;
- telephone numbers;
- player identifiers;
- membership information;
- league/season affiliations;
- event invitations and RSVP information;
- tournament registrations;
- attendance;
- seating/table assignments;
- tournament/cash-game results;
- standings;
- poker-game financial records such as buy-ins, rebuys, payouts, prizes, bounties and customer-recorded fees;
- communications sent through Customer’s PCA account;
- notes;
- other ordinary club-management information entered by Customer.
PCA is not intended for Customer to submit unnecessary special-category or other highly sensitive Personal Data.
6. Special Categories
PCA does not require special-category Personal Data to provide its intended poker-club administration functionality.
Customer is instructed not to enter such data unless PCA has expressly authorized the processing and the parties have established an appropriate lawful basis and safeguards.
7. Frequency
Processing is continuous or recurring while Customer actively uses the Service.
Schedule 2 — Security Measures
PCA's implemented safeguards include the following categories without publishing security-sensitive configuration details:
Access and authentication
- authenticated access;
- role-based permissions;
- Owner/Admin distinctions;
- multi-factor authentication support;
- session controls;
- passwordless authentication features.
Network and transmission security
- HTTPS;
- secure provider/API connections;
- security headers and browser protections.
Application/database security
- tenant/account isolation;
- server-side authorization checks;
- input validation;
- parameterized database access;
- CSRF protections;
- rate limits and automated-abuse controls;
- security/audit logging.
Operational security
- restricted infrastructure access;
- secret/environment configuration management;
- provider backups;
- vulnerability/security testing;
- incident-response procedures.
Data minimization
- PCA does not collect complete payment-card information;
- PCA does not collect DOB or identification documents solely for 18+ attestation;
- production AI Assistant does not automatically transmit Customer databases or unrelated customer records to OpenAI;
- analytics is configured to minimize identifiers.
PCA's implemented security architecture also includes registration throttling, honeypot and server-measured completion-time protections, mandatory server-validated Cloudflare Turnstile for registration, risk-based Turnstile escalation after repeated login failures, bounded/expiring rate-limit state, privacy-minimized security audit events, and hashed, single-use, expiring email verification.
Schedule 3 — Service Providers
The separately maintained PCA Subprocessor List is the authoritative current provider disclosure.
The production inventory is:
| Provider | Purpose | Processing information |
|---|---|---|
| hosting.com | Hosting, MySQL, backups, email/SMS infrastructure | Provider processing and security documentation applies; provider-specific DPA review and backup-retention confirmation remain pending |
| OpenAI | Optional AI Assistant | OpenAI DPA/API business terms; current PCA architecture uses store:false; standard abuse-monitoring retention may apply up to 30 days |
| Umami Cloud | Privacy-focused analytics | Cookie-free, identifier-minimized PCA implementation |
| Stripe | Subscription/payment processing | Role may include independent controller activities and is not characterized solely as a PCA subprocessor |
| Cloudflare | Turnstile security and automated-abuse prevention | Provider processing and security documentation applies |
The public Subprocessor List will provide the authoritative current vendor disclosure.