PARKERSYNDICATION

Data Processing Addendum

For publisher diligence · Version 1.0 · Last updated July 23, 2026

This Data Processing Addendum ("DPA") supplements the Partner Terms between Advanced Learning Academy LLC ("ALA", "we") and the publisher partner ("Partner", "you"). It describes how personal data is processed when Partner embeds ParkerSyndication games. On execution of an order form or partner agreement referencing this DPA, it forms part of that agreement.

Reviewer note: This DPA is provided as a complete, good-faith template ready for legal review. It is not legal advice. A signed, counsel-reviewed copy is available for enterprise procurement on request. Where a jurisdiction requires specific clauses (for example EU/UK Standard Contractual Clauses), those are incorporated by reference and finalized in the executed agreement.

1. Roles and scope

  • For player personal data collected through the embedded games, ALA generally acts as an independent controller (for scoring, Brain Report, membership, and fraud controls) and, where Partner directs specific processing, as a processor on Partner's behalf.
  • For Partner account data (site name, URL, payout details, aggregates), ALA is the controller for operating the partner program.
  • This DPA governs processing carried out in connection with the Service and applies to the extent data protection laws apply to that processing.

2. Nature of processing and data categories

  • Purposes: serving daily games; scoring and Brain Report; membership and entitlement; revenue attribution; fraud and abuse prevention; support.
  • Player data: anonymous play telemetry; an attribution identifier (ps_afmid cookie, up to 90 days); optional account email if a player registers; membership status via Stripe.
  • Partner data: business contact and site details, payout email/method, play and revenue aggregates.
  • Not processed by default: Partner CMS credentials, Partner's own reader passwords, or full payment card numbers (handled by Stripe).

3. Subprocessor register

ALA engages the following subprocessors. We will give notice of intended changes so Partner may object on reasonable data-protection grounds.

SubprocessorFunctionLocation
Cloudflare, Inc.Edge hosting, Workers, storage (D1/KV/R2), CDN, DDoS protectionUnited States / global edge
Stripe, Inc.Payment processing and subscription billingUnited States
Mailgun (Sinch)Transactional and newsletter email deliveryUnited States
Google (Analytics, where enabled)Aggregate traffic measurementUnited States

4. Security measures

  • Encryption in transit (HTTPS/TLS, HSTS preload). Data at rest protected by managed platform controls.
  • Least-privilege administrative access; separate operator credentials; salted password hashing (PBKDF2) and HMAC-signed sessions for accounts.
  • Rate limiting, CSRF protection, and server-side validation on state-changing and scoring endpoints.
  • Single CI source of truth for production; no ad-hoc deploys. Further detail in the Security overview.

5. International transfers

Where personal data of individuals in the EEA, UK, or Switzerland is transferred to the United States, the transfer is made under an appropriate mechanism (for example the EU/UK Standard Contractual Clauses, incorporated by reference and completed in the executed agreement), together with supplementary technical measures described in Section 4.

6. Data-subject rights & assistance

  • ALA assists Partner, taking into account the nature of processing, in responding to data-subject requests (access, correction, deletion, portability, objection).
  • Player rights requests may be sent directly to [email protected]; see the Privacy Policy.
  • On termination, ALA deletes or returns personal data processed on Partner's behalf, except where retention is legally required.

7. Breach notification

ALA will notify Partner without undue delay, and in any case within 72 hours of becoming aware of a personal-data breach affecting Partner's data, with the information reasonably available to support Partner's own notification obligations.

8. Audit

On reasonable prior written notice and no more than once per year (unless required by a supervisory authority), ALA will make available information necessary to demonstrate compliance with this DPA, which may be satisfied by up-to-date documentation and responses to a reasonable security questionnaire.

9. Contact

Data protection contact: [email protected]. Postal: Advanced Learning Academy LLC, United States. Federal identifiers (UEI / CAGE / SAM.gov) available on request.

10. Related documents