This Data Processing Addendum (“DPA”) forms part of, and is incorporated into, the Terms of Service and Landlord Terms between you (the “Landlord” or “you”) and InWorld·Online (the “Platform”, “we”, or “us”). It sets out the parties’ respective obligations under Articles 26 and 28 of Regulation (EU) 2016/679 (the “GDPR”) and equivalent provisions of the UK GDPR and other applicable data-protection law.
In the event of conflict between this DPA and any other agreement between the parties, this DPA prevails on data-protection matters.
1. Definitions
Terms used in this DPA have the meanings given in Article 4 GDPR. “Visitor” means any natural person who enters land that you operate through the Platform, including avatars whose owners reside in Second Life. “Tenant” means a Visitor who rents from you.
2. Scope and roles
The parties acknowledge that processing of personal data of Visitors and Tenants involves both joint controllership (Art. 26 GDPR) and controller-to-processor (Art. 28 GDPR) elements:
- Joint controllers for data about Visitor and Tenant interactions with your land, where both parties determine purposes (e.g. moderation, rental management, community-tenure recognition).
- The Platform processes on your behalf when it carries out actions you initiate through the Platform’s tooling on data scoped to your land (e.g. issuing a ban, exporting visitor counts, sending a notice through the Platform’s messaging integration).
The Platform is sole controller for all Platform-wide data not scoped to a single Landlord (account credentials, billing, abuse-detection signals across the Platform).
3. Subject-matter, nature, purpose and duration
| Element | Description |
|---|---|
| Subject-matter | Personal data of Visitors and Tenants of the Landlord’s Second Life land managed via the Platform. |
| Nature | Collection, recording, organisation, storage, retrieval, consultation, transmission, restriction, erasure of personal data through the Platform’s infrastructure. |
| Purpose | Enabling the Landlord to manage their land: moderation, security, rental administration, communication with Tenants, community-tenure recognition. |
| Duration | For as long as the Landlord operates land through the Platform, plus the retention periods set out in the Privacy Policy. |
4. Categories of data and data subjects
Data subjects: Visitors, Tenants, and other natural persons who interact with the Landlord’s land or its in-world groups.
Categories of personal data:
- Avatar identity: Second Life UUID, name, display name.
- Visit data: timestamps of entry and exit on the Landlord’s land, duration, last position, first-visit timestamp per area.
- Communications: in-world chat messages exchanged in the Landlord’s groups or rentals managed via the Platform; guestbook entries.
- Moderation records: bans, ejects, guest lists, Landlord remarks.
- Estate and group access caches kept in sync with Linden Lab: estate allow lists, estate banned lists, allowed groups, and members of groups the Landlord uses for access control.
- Payment data: L$ rent transactions associated with the Landlord’s land.
No special categories of personal data (Art. 9 GDPR) are knowingly processed. If you intend to use the Platform in a way that involves special-category data, notify us first; certain features may not be available.
5. Joint-controller allocation (Art. 26)
The parties allocate their respective responsibilities as follows:
| Responsibility | Allocated to |
|---|---|
| Providing the privacy notice to data subjects | Platform |
| Single contact point for data subject requests | Platform — in-world IM to the Second Life resident InworldOnlineSupport |
| Responding to access, rectification, erasure, portability, restriction, objection requests | Platform receives, triages and forwards Landlord-scoped requests to you for action where required |
| Security of the infrastructure | Platform |
| Lawful use of moderation data within the Landlord’s scope | Landlord |
| Notification of supervisory authority of a personal data breach | Platform, after consultation with the affected Landlord(s) where practicable |
The essence of this arrangement is made available to data subjects via the Privacy Policy, in line with Art. 26(2) GDPR.
6. Processor obligations (Art. 28)
To the extent the Platform acts as your processor under section 2, the Platform shall:
- process personal data only on your documented instructions, including those embedded in the features you use through the Platform’s interfaces, unless required to do otherwise by applicable law (in which case the Platform will inform you, save where prohibited);
- ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- take all measures required pursuant to Art. 32 GDPR, as set out in section 8;
- respect the sub-processor conditions set out in section 7;
- assist you, taking into account the nature of the processing, by appropriate technical and organisational measures, in fulfilling your obligation to respond to data subject requests;
- assist you in ensuring compliance with Art. 32 to 36 GDPR taking into account the nature of processing and the information available to the Platform;
- at your choice, delete or return all personal data to you after the end of the provision of services, and delete existing copies unless retention is required by Union or Member State law or permitted under the retention schedule in the Privacy Policy (in particular, payment records retained under accounting law);
- make available all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR, and allow for and contribute to audits conducted by you or another auditor mandated by you (see section 11).
7. Sub-processors
You give the Platform general written authorisation to engage sub-processors. The current list of sub-processors is published at /sub-processors and is deemed incorporated into this DPA.
The Platform will inform you of any intended addition or replacement of sub-processors by updating that page. You may object on reasonable data-protection grounds within thirty (30) days by in-world IM to InworldOnlineSupport; failing agreement, you may terminate the affected services and your account, with refund of any pre-paid amounts for the unexpired term.
The Platform imposes data-protection obligations on each sub-processor by written contract that are no less protective than those in this DPA, and remains liable to you for the acts and omissions of its sub-processors as if performed by the Platform itself.
8. Security measures (Art. 32)
Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks involved, the Platform implements appropriate technical and organisational measures, including:
- encryption of sensitive secrets at rest (two-factor authentication codes, Discord webhook tokens) using authenticated symmetric encryption with a key managed out-of-band from database backups;
- hashing of user passwords with a modern algorithm (bcrypt/argon2);
- role-based access control: data scoped to a Landlord is visible only to that Landlord and their assigned managers; Platform staff access is limited to support and is logged;
- cross-tenant isolation enforced at the query layer for all admin views;
- TLS for data in transit;
- periodic restoration testing of backups;
- regular review of access privileges and removal of leavers’ access;
- incident-response procedure with documented escalation and notification timelines.
9. Data subject requests
Data subjects can exercise access, rectification, erasure, portability, restriction, and objection rights directly via their account settings or by in-world IM to InworldOnlineSupport. The Platform receives, triages, and answers these requests centrally.
If a request requires action only you can take (for example, removing a Landlord-only remark or note), the Platform will forward it to you and you must respond within ten (10) calendar days. If a data subject contacts you directly with a data-protection request, you will inform them that it should be directed to the Platform’s contact above, and you will not act on it outside the Platform.
10. Personal data breach
The Platform will notify you without undue delay and in any event within seventy-two (72) hours after becoming aware of a personal data breach affecting personal data processed under this DPA. The notification will include the information set out in Art. 33(3) GDPR to the extent then available. You agree to assist the Platform in investigation and notification, including by providing access to information about the affected Visitors or Tenants where necessary.
If you become aware of a security incident affecting Visitor or Tenant data (for example, compromise of your management account or that of a manager), you will notify the Platform within twenty-four (24) hours by in-world IM to InworldOnlineSupport.
11. Audit
The Platform will, on reasonable written notice and no more than once per twelve (12) months (additional audits being permitted where required by a supervisory authority or following a personal data breach), make available to you, or to an independent auditor mandated by you and not a competitor of the Platform, the information necessary to demonstrate compliance with this DPA.
Audits are subject to confidentiality undertakings, are conducted during business hours and in a manner that minimises disruption, and are at your cost unless they reveal a material breach by the Platform, in which case the Platform bears the reasonable cost of the audit.
12. International transfers
Where personal data is transferred to a country outside the European Economic Area, the United Kingdom, or other jurisdictions deemed adequate by the relevant authority, the Platform relies on the European Commission’s Standard Contractual Clauses (or the UK Addendum / IDTA where applicable) or another lawful transfer mechanism, supplemented as required by a transfer impact assessment.
13. Return and deletion on termination
On termination of your use of the Platform, the Platform will, at your written choice expressed no later than thirty (30) days after termination:
- provide an export of personal data scoped to your land in a structured machine-readable format (the same export available through the user dashboard for individual data subjects, scaled to your scope); and/or
- delete the personal data processed under this DPA, except where retention is required by Union or Member State law (notably payment records retained under accounting law) or permitted by the retention schedule in the Privacy Policy for security and ban-evasion-prevention purposes.
The Platform will certify deletion in writing on request.
14. Liability
Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service, except where Union or Member State law prohibits such limitation in relation to data-protection claims by data subjects.
15. Governing law and jurisdiction
This DPA is governed by the laws applicable to the Terms of Service. The courts identified in the Terms of Service have jurisdiction over disputes arising from this DPA, subject to mandatory provisions on data subject jurisdiction under Art. 79 GDPR.
16. Contact
Data-protection contact for the Platform: in-world IM to the Second Life resident InworldOnlineSupport.
Version 2026-05-25.