1.1. Scope of this notice
This notice supplements our Privacy Policy. The Privacy Policy tells you what we do with personal data. This notice tells you what you can require of us, how to ask, what happens next, and who to complain to if we get it wrong.
Both the EU General Data Protection Regulation and the UK GDPR apply to our processing. One of our revenue partners, Adoptavia Germany UG, is established in Germany and provides infrastructure, so personal data may be processed inside the European Union. Another, D3kryption Studios Ltd, is established in the United Kingdom and provides engineering support. We do not treat one regime as a subset of the other: where they differ, we apply whichever gives you the stronger protection.
2.2. Controller and contact point
The controller is Narrative, operating NarrativePro Addons ([COUNSEL] insert full registered name, company number and registered office).
Contact point for all data protection matters: [email protected]. Postal address for formal notices: [COUNSEL] insert registered office address.
We have not designated a Data Protection Officer under Article 37. Our core activity is operating a marketplace, not large-scale monitoring or large-scale processing of special category data, and we have assessed that the appointment threshold is not met. That assessment is reviewed annually and whenever the service changes materially. If it changes, the DPO's contact details will be published here.
[COUNSEL] Confirm the Article 37 assessment, and confirm whether an Article 27 representative is required in the EU, in the UK, or in both, given where the controlling entity is established. Publish the representative's name and address here if one is appointed.
3.3. Your rights at a glance
- Access: get confirmation of whether we process data about you, a copy of it, and information about how and why.
- Rectification: have inaccurate data corrected and incomplete data completed.
- Erasure: have data deleted where we no longer have a good reason to hold it.
- Restriction: have us pause processing while something is disputed.
- Portability: receive the data you gave us in a machine-readable form, or have it sent to another provider.
- Objection: object to processing based on legitimate interests, and object absolutely to direct marketing.
- Withdraw consent: at any time, for anything we do on the basis of consent.
- Automated decisions: not be subject to a solely automated decision with legal or similarly significant effects, and to ask for human review where one is made.
- Complain: to a supervisory authority, and to seek a judicial remedy.
Exercising a right is free and does not put your account at risk.
4.4. Right of access
You can ask for a copy of the personal data we hold about you, together with the purposes, the categories of data, the recipients, the retention periods, the source where we did not get it from you, and whether it is transferred outside the EEA or the UK and under what safeguard.
In practice this means your account record, your orders and receipts, your entitlements and licence keys, your download history, your reviews, your support correspondence and, if you sell, your seller profile and ledger.
We provide the copy electronically in a common format unless you ask for another. Where the data includes information about other people, for example a support thread involving a seller, we redact what we cannot lawfully release.
5.5. Right to rectification
You can correct most account data yourself from your account settings, which is faster than asking us. For anything you cannot edit, tell us what is wrong and what it should say.
Some records are deliberately immutable: the title, price and tax of an order are snapshotted at the time of sale so that a receipt still says what it said. If one of those is genuinely wrong we issue a corrective record rather than rewrite history, and we tell you which we have done.
Where we have shared incorrect data with a recipient, we tell them about the correction unless that is impossible or would take disproportionate effort, and we tell you who was informed.
6.6. Right to erasure
You can ask us to delete your data where it is no longer needed for the purpose we collected it, where you withdraw consent and there is no other basis, where you successfully object, or where it has been processed unlawfully.
Some things we cannot delete on request, and it is fairer to say so plainly than to promise deletion and then explain later:
- Records of sales, refunds, payouts and the revenue ledger, which we must keep for tax and accounting purposes.
- The record of a licence you hold, for as long as that licence subsists, because the licence is perpetual and it protects you as much as the seller.
- Data we need to establish, exercise or defend a legal claim, including an open dispute or chargeback.
- Suppression records that exist purely to remember that you asked not to be emailed.
Where we cannot delete, we restrict: the data stops being used for anything except the reason it has to be kept. When you close your account we delete or anonymise everything outside those categories, and reviews you left may remain in anonymised form so that a product's rating history is not silently rewritten.
7.7. Right to restriction
You can ask us to stop using data, while continuing to store it, if you dispute its accuracy, if the processing is unlawful but you would rather we restricted it than deleted it, if we no longer need it but you do for a legal claim, or while we consider an objection you have made.
While a restriction is in place we will only store the data, unless you consent to more, or we need it for a legal claim, or to protect someone else. We tell you before we lift a restriction.
8.8. Right to portability
Where we process data you gave us, by automated means, on the basis of consent or of a contract with you, you can receive it in a structured, commonly used, machine-readable format, and have us transmit it to another controller where that is technically feasible.
We provide this as JSON, covering your account profile, orders, entitlements, reviews and, for sellers, listings and ledger records. It does not cover data we inferred or generated, such as fraud signals, or data about other people.
9.9. Right to object
Where we rely on legitimate interests, you can object at any time on grounds relating to your particular situation. We then stop unless we can show compelling legitimate grounds that override your interests, or we need the data for legal claims. We will tell you which it is and why.
Where you object to direct marketing there is no balancing exercise. We stop, immediately and permanently. You can do this yourself from the unsubscribe link in any marketing email or from your notification settings.
Objecting to marketing does not stop transactional email. Receipts, licence keys, download links, security alerts and notices of changes to these documents are part of providing the service, and they continue for as long as you hold an account.
10.10. How to exercise a right, and how long we take
Email [email protected] from the address on your account, or use the privacy controls in your account settings. Tell us which right you are exercising and, where it helps, which data you mean. You do not have to cite an article number.
We acknowledge receipt within 5 business days.
We respond substantively within one month of receiving the request. Where a request is complex, or where you have made several, we may extend by up to two further months; if we do, we tell you within the first month and explain why.
Requests are free. We may charge a reasonable administrative fee, or refuse, only where a request is manifestly unfounded or excessive, in particular where it is repetitive. If we refuse we tell you why, and we tell you about your right to complain and to a judicial remedy.
We may need to verify who you are before releasing data. Where the request comes from the email address on the account and concerns that account, that is normally enough. Where it does not, or where the request is for a large export, we may ask for additional confirmation. We will not ask for a copy of your passport to answer a routine access request.
If someone makes a request on your behalf, we need evidence of their authority.
11.11. Sellers, buyers and who controls what
We are the merchant of record. A buyer's contract is with us, and we are the controller of the buyer data described in the Privacy Policy.
Sellers see aggregated sales and analytics for their own addons, the reviews left on their addons, and the information needed to answer a support request that a buyer has raised with them. Where a seller receives buyer personal data for that purpose, the seller acts as an independent controller of it and must handle it lawfully, use it only to provide support, and not use it for their own marketing. The Seller Agreement imposes those obligations.
We do not give sellers a list of their buyers' email addresses for marketing, and a seller who extracts and repurposes buyer data is in breach of the Seller Agreement.
[COUNSEL] Confirm the controller/processor characterisation of the seller relationship, and whether a short Article 28 or joint-controller annex should be attached to the Seller Agreement instead of the independent-controller position taken here.
12.12. Sub-processors
We use the processors listed below. The list is maintained here rather than in a contract annex so that it is visible without asking.
- Stripe - Card and wallet payments, fraud screening, seller onboarding and identity verification, payouts by transfer. Data: Name, email, billing details, payment method metadata, transaction records; for sellers, identity and bank details collected directly by Stripe. Region: EU/US, group entities worldwide. Transfer basis: Standard Contractual Clauses with UK Addendum; provider is an independent controller for its own compliance processing.
- PayPal - Wallet payments, refunds, and payouts to sellers and partners. Data: Email address, transaction records, payout destination address. Region: EU/US. Transfer basis: Standard Contractual Clauses with UK Addendum; provider is an independent controller for its own compliance processing.
- Mailgun - Transactional email (receipts, licence keys, download links, payout notices) and newsletter delivery. Data: Email address, message content and subject, delivery, bounce and complaint events. Region: European Union (EU region deliberately configured). Transfer basis: Processed in the EU; Standard Contractual Clauses with UK Addendum cover support access from outside the EEA.
- Cloudflare R2 - Object storage for addon packages and delivery of expiring signed download links. Data: Addon files, request logs which may include IP address and user agent. Region: Global edge network. Transfer basis: Standard Contractual Clauses with UK Addendum; content encrypted at rest.
- GitHub - Optional sign-in, and mirroring of seller releases from linked repositories. Data: GitHub account identifier and login, repository and release metadata. Region: US/EU. Transfer basis: Standard Contractual Clauses with UK Addendum; used only where a user chooses GitHub sign-in or a seller links a repository.
- Application hosting and database - Running the marketplace application, its database and its scheduled jobs. Data: All categories described in the Privacy Policy. Region: European Union. Transfer basis: Processed in the EU; Article 28 contract in place. [COUNSEL] confirm named provider before publication.
Each is engaged under a written contract meeting Article 28: they process only on documented instructions, impose confidentiality on their staff, apply appropriate technical and organisational measures, engage further sub-processors only with our authorisation, assist us with your rights requests and with breach notification, and delete or return the data at the end of the engagement.
We will give notice here before adding a sub-processor that materially changes where or how your data is processed.
13.13. International transfers and our SCC posture
Our default is to process in the European Economic Area and the United Kingdom. That is why our email provider is configured to its EU region and why our infrastructure sits with an EU-established partner.
Where a transfer to a third country is unavoidable, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) in the module appropriate to the relationship, together with the UK International Data Transfer Addendum, or the UK IDTA where that is the cleaner instrument. Where a US recipient is certified under the EU-US Data Privacy Framework and its UK extension, and the certification covers the data in question, we may rely on that instead.
We carry out a transfer impact assessment before relying on the clauses, covering the law and practice of the destination country, the likelihood of government access to the specific data, and what supplementary measures close the gap. Our standard measures are encryption in transit and at rest, minimisation of what leaves the EEA, and contractual commitments requiring the recipient to challenge unlawful access requests and to tell us where it is legally permitted to do so.
You can request the mechanism relied on for any specific transfer from [email protected]. We will provide it, redacted only for commercial terms.
14.14. Personal data breaches
We keep an incident response process, and we log every incident whether or not it is notifiable.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where we cannot give full details in that time, we notify in phases rather than delay the first notification.
Where a breach is likely to result in a high risk to you, we tell you directly and without undue delay, in plain language: what happened, what data was involved, what the likely consequences are, what we are doing about it, and what you should do. We will not soften that message to protect ourselves.
We do not need to notify you individually where the data was rendered unintelligible to anyone unauthorised, for example by strong encryption with keys that were not compromised, where we have taken measures that mean the high risk is no longer likely to materialise, or where individual notification would involve disproportionate effort, in which case we make a public announcement instead.
Our processors are contractually required to notify us without undue delay after becoming aware of a breach, so that we can meet these deadlines.
15.15. Records, assessments and accountability
We maintain a record of processing activities under Article 30 covering purposes, categories of data and data subject, recipients, transfers, retention and security measures.
We carry out a Data Protection Impact Assessment before starting processing likely to result in a high risk, and we review the existing assessments when the service changes materially. We document our legitimate interests balancing tests and will share the reasoning behind any of them on request.
Data protection is considered at design time rather than retro-fitted: expiring signed download links instead of public URLs, signature-verified and idempotent webhooks, minimised download logging, and default retention limits on log data are examples of that in the current system.
17.17. Changes to this notice
Changes are published here with a new effective date. Where a change affects your rights or adds a sub-processor that materially changes where your data is processed, we will give notice before it takes effect.