Important launch note
This agreement is a practical startup draft, not a substitute for advice on your specific club, safeguarding or international-transfer arrangements. CoolSmash’s full legal operator name, registered address and final sub-processor schedule must be inserted before this agreement is offered for acceptance.
1. Parties and status
This Data Processing Agreement (“DPA”) forms part of the agreement between the club, association, organiser or other customer using CoolSmash (“Customer”) and CoolSmash (“Provider”). It applies where Provider processes Customer Personal Data on the Customer’s behalf.
The Customer is the controller and Provider is the processor for that processing. Each party must comply with applicable data-protection law, including the UK GDPR and Data Protection Act 2018. CoolSmash remains a separate controller for its own account security, billing, legal compliance and appropriately disclosed platform analytics.
2. Processing details
3. Customer instructions
Provider will process Customer Personal Data only on documented instructions from the Customer, including instructions given through authorised use and configuration of the service, unless UK law requires other processing. If law requires processing, Provider will inform the Customer beforehand unless the law prohibits that notice.
Provider will promptly tell the Customer if it believes an instruction infringes applicable data-protection law. Provider may pause the affected processing while the parties resolve the concern.
4. Customer responsibilities
The Customer is responsible for:
- having a lawful basis and giving suitable privacy information to members and applicants;
- collecting only information that is necessary for its stated club purposes;
- keeping organiser access and permissions accurate;
- handling safeguarding, sensitive-data and junior-participation requirements;
- responding to data-subject requests and regulator enquiries, with Provider’s assistance; and
- ensuring its instructions are lawful.
5. Confidentiality and personnel
Provider will limit access to people who need Customer Personal Data to deliver, secure or support the service. Those people will be bound by confidentiality obligations and receive appropriate privacy and security guidance.
6. Security measures
Provider will maintain technical and organisational measures appropriate to the risk, including:
- encrypted network transport and protected credential storage;
- role-based permissions and least-privilege operational access;
- authentication safeguards, access revocation and audit events;
- segregation of club access within the application;
- backup, recovery, patching and vulnerability-management processes;
- logging, incident triage and periodic review of access; and
- secure deletion or anonymisation at the end of applicable retention periods.
Provider may update measures as technology and risks change, provided the overall protection is not materially reduced.
7. Sub-processors
The Customer gives general written authorisation for Provider to use hosting, database, email delivery, monitoring, support and payment-related sub-processors needed to deliver the service. Provider will bind each processor to data-protection obligations offering equivalent protection for the relevant processing.
A current schedule, including provider, service, location and transfer safeguard, will be available from support@coolsmash.co.uk. Provider will give reasonable advance notice of a new sub-processor. The Customer may object on reasonable data-protection grounds; the parties will work in good faith on a commercially reasonable alternative.
8. International transfers
Provider will not transfer Customer Personal Data outside the UK unless it uses a lawful transfer mechanism. Where needed, the parties incorporate the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, together with supplementary safeguards appropriate to the transfer risk.
9. Requests, assessments and regulator support
Taking into account the nature of processing, Provider will reasonably assist the Customer with data-subject requests, security obligations, breach notifications, data-protection impact assessments and regulator consultations. Provider will not respond to a request on the Customer’s behalf unless authorised or legally required.
If assistance is unusually extensive or caused by the Customer’s unlawful or out-of-scope instruction, the parties may agree a reasonable fee in advance.
10. Personal-data breaches
Provider will notify the Customer without undue delay after becoming aware of a breach affecting Customer Personal Data. Available information will include the nature of the incident, likely consequences, affected records or people, mitigation taken and a contact for follow-up. Information may be provided in phases as the investigation progresses.
The Customer remains responsible for deciding whether to notify the ICO or affected people. Provider will preserve relevant evidence and reasonably assist that decision.
11. Return, deletion and anonymisation
During the agreement, the Customer may export information using available product features or a reasonable support request. On termination, Provider will make a final export available for 30 days where reasonably practicable, then delete Customer Personal Data from live systems unless law requires retention.
Residual backup copies will be isolated from routine use and age out within 90 days. Provider may retain records required for security, fraud, financial or legal purposes in a restricted form. Provider may also retain statistics that have been irreversibly anonymised so they no longer identify a person or Customer.
12. Information and audits
Provider will make information reasonably necessary to demonstrate compliance available to the Customer. The parties will ordinarily use security summaries, policies and independent reports before an on-site audit.
If those materials are insufficient, the Customer may conduct one audit per year on reasonable notice, during business hours, subject to confidentiality and without compromising other customers or service security. More frequent audits are permitted following a material breach or regulator request.
13. Priority and liability
If this DPA conflicts with the main service agreement on personal-data processing, this DPA prevails. Liability under this DPA is subject to the service agreement’s lawful liability provisions, but nothing excludes liability that cannot legally be limited.
