Fighting Game · Legal

V2 Sub-Processor Registry

Material additions are announced through the section 85.3 player announcement channel and mirrored on the public legal page at

4sections3 minread1table

On this page

Last updated: 2026-05-18.

Oshun publishes this registry for V2 player services, web services, platform commerce, online features, safety operations, and support. New production sub-processors require DPO/legal approval and at least 30 days' notice to the player base before live player data is routed to the vendor.

Player Notice#

Material additions are announced through the section 85.3 player announcement channel and mirrored on the public legal page at apps/v2/web/legal/sub-processors/. Emergency security replacements can be activated earlier only with DPO, legal, security, and release-owner approval; the public notice is still posted as soon as the emergency reason allows.

Platform And Cloud DPA Requirement#

Per-platform DPAs and security addenda are required before production launch with Sony, Microsoft, Nintendo, Steam, Epic, AWS, Azure, Google Cloud, and Cloudflare. The DPA inventory owner is privacy legal; engineering cannot enable production traffic without an active contract reference below.

Registry#

Vendor Processing purpose Jurisdiction Contract reference Data categories accessed
Sony Interactive Entertainment PlayStation identity, entitlement, family-management, platform reporting United States, Japan, EU regional entities DPA-PLATFORM-SONY-V2-2026 Platform id, entitlement records, parental restriction state, crash/support metadata
Microsoft Xbox Xbox identity, entitlement, family safety, platform reporting United States, EU regional entities DPA-PLATFORM-MICROSOFT-V2-2026 Platform id, entitlement records, family restriction state, crash/support metadata
Nintendo Nintendo identity, entitlement, parental controls, platform reporting Japan, United States, EU regional entities DPA-PLATFORM-NINTENDO-V2-2026 Platform id, entitlement records, parental restriction state, crash/support metadata
Valve Steam Steam identity, entitlement, store/refund integration, Steam Family View United States, EU regional entities DPA-PLATFORM-STEAM-V2-2026 Platform id, purchase receipts, entitlement records, family-view restriction state
Epic Games Epic identity, entitlement, cross-play account linking, store integration United States, EU regional entities DPA-PLATFORM-EPIC-V2-2026 Platform id, linked account token, entitlement records, purchase receipts
Amazon Web Services Regional hosting, compute, storage, telemetry ingest, encrypted backups United States with EU, Brazil, Japan, Korea regional hosting DPA-CLOUD-AWS-V2-2026 Account, gameplay, telemetry, replay, moderation, audit, backup data by residency zone
Microsoft Azure Regional failover, security analytics, enterprise identity for operations United States with EU regional hosting DPA-CLOUD-AZURE-V2-2026 Operational logs, security events, audit records, limited support metadata
Google Cloud Regional analytics isolation and BigQuery-style aggregate reporting United States with EU regional hosting DPA-CLOUD-GCP-V2-2026 Aggregated telemetry, privacy-reviewed analytics exports, crash aggregates
Cloudflare CDN, DDoS protection, WAF, bot protection, public legal pages United States with global edge network DPA-CLOUD-CLOUDFLARE-V2-2026 IP address, request metadata, public web logs, security event metadata
Stripe PC/web payment processing where platform commerce does not apply United States, EU regional entities DPA-COMMERCE-STRIPE-V2-2026 Payment token, receipt id, billing country, refund metadata; no raw card storage by V2
Zendesk Customer support ticketing and DSR support intake United States, EU regional entities DPA-SUPPORT-ZENDESK-V2-2026 Support contact, account id, ticket text, attachment metadata, DSR support status
Sentry Crash triage and client error aggregation United States, EU regional entities DPA-OBS-SENTRY-V2-2026 Crash reports, stack traces, device model, app version, scrubbed identifiers

Review Cadence#

Privacy legal reviews this registry quarterly, before each launch region opens, and before any new vendor receives production data. The sanitized public summary records additions, removals, emergency changes, and material purpose changes without exposing security-sensitive architecture details.