RIIP
Get started
Legal

Data Processing Addendum

Draft of 13 August 2026 — a summary, pending review and approval by qualified counsel. Not legal advice, and not yet in force.

Roles

For business API customers, RIIP is a processor for the data you route through the API and for the webhook endpoints and events you register, acting only on your documented instructions. We are a controller for your account and billing data, for security and abuse prevention, and for our own aggregated Roblox intelligence. Worth stating plainly: the API is built around public Roblox game and server data — a typical integration sends a place identifier and receives a ranked server list, with no personal data involved at all.

What we process

As processor: any identifier you choose to include in a request, your webhook configuration and its event payloads, and the technical metadata of each call. As controller: studio account details and verification status, credential metadata — a one-way hash of each key with its prefix and last four characters, environment and scopes — metered usage and invoices, campaign and moderation records, and audit records. We process no card data, no government identifiers, no precise location and no special-category data, and we collect no age from anyone.

Subprocessors

We maintain a current register of subprocessors covering hosting, the delivery and security edge, payments, transactional email and encrypted backup storage, with purpose, data categories and location for each. We give advance notice before a new subprocessor begins processing your data, with a right to object on reasonable data-protection grounds, and we impose obligations no less protective than these on each one while remaining fully liable for them.

Security measures

TLS on every external hop. Passwords stored as scrypt hashes and never reversibly; API keys stored as one-way peppered hashes so even we cannot recover them; two-factor secrets and webhook signing secrets encrypted with an encrypt-then-MAC construction. Five cryptographically distinct credential schemes, four operator roles with two-factor authentication, and least-privilege API-key scopes that are default-deny and bounded by your plan. Outbound webhooks are HMAC-signed with a timestamp and validated against server-side request forgery before dispatch, with bounded retries. Every privileged action writes an append-only audit record in the same transaction as the change itself, and logs and metrics are scrubbed of secrets and personal data by design. Our observability stack is self-hosted.

Transfers, breach & deletion

Where personal data leaves the UK or EEA to a country without an adequacy decision, we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, with a documented transfer impact assessment. We notify you without undue delay of a personal data breach affecting your data, with the information you need for your own notification duties. On termination we delete or return the data we process for you, with two exceptions we state up front: financial records retained under accounting law in anonymised form, and data in encrypted backups until they age out.

Audit rights

We make available the information reasonably needed to demonstrate compliance, ordinarily through our documentation and a completed security questionnaire. Where that is genuinely insufficient you may audit annually on notice, during business hours, subject to confidentiality and without access to other customers' data. We hold no SOC 2 or ISO 27001 certification today and imply none.

This page summarises the document. The complete text is being finalised with counsel and will be published here on approval — email help@riip.gg for the current draft in the meantime.

TermsPrivacyAcceptable UseDPA