Legal · Club agreement

Data Processing Agreement

These terms govern CoolSmash’s processing of personal data on behalf of a club or organiser and are intended to meet UK GDPR Article 28 requirements.

Last updated: 31 July 2026

Important launch note

This agreement is a practical startup draft, not a substitute for advice on your specific club, safeguarding or international-transfer arrangements. CoolSmash’s full legal operator name, registered address and final sub-processor schedule must be inserted before this agreement is offered for acceptance.

1. Parties and status

This Data Processing Agreement (“DPA”) forms part of the agreement between the club, association, organiser or other customer using CoolSmash (“Customer”) and CoolSmash (“Provider”). It applies where Provider processes Customer Personal Data on the Customer’s behalf.

The Customer is the controller and Provider is the processor for that processing. Each party must comply with applicable data-protection law, including the UK GDPR and Data Protection Act 2018. CoolSmash remains a separate controller for its own account security, billing, legal compliance and appropriately disclosed platform analytics.

2. Processing details

Subject matterHosting and operating club membership, applications, roles, session, attendance, ticketing and communication features.
DurationFor the customer agreement plus the deletion and backup periods in section 11.
NatureCollection, recording, organisation, storage, retrieval, display, transmission to authorised users, analysis, restriction, deletion and anonymisation.
PurposeTo provide and secure the CoolSmash service in accordance with the Customer’s configuration and documented instructions.
Data subjectsClub applicants, members, guests, players, organisers, volunteers, staff and guardians where junior participation is supported.
Personal-data typesNames, contact details, date of birth, profile data, images, club membership, roles, tags, application answers, session registration, attendance, ticket and payment status, communications and audit records.
Special-category dataNot intended for routine collection. A Customer must not request it through free text unless it has established a lawful basis, additional condition and suitable safeguards.

3. Customer instructions

Provider will process Customer Personal Data only on documented instructions from the Customer, including instructions given through authorised use and configuration of the service, unless UK law requires other processing. If law requires processing, Provider will inform the Customer beforehand unless the law prohibits that notice.

Provider will promptly tell the Customer if it believes an instruction infringes applicable data-protection law. Provider may pause the affected processing while the parties resolve the concern.

4. Customer responsibilities

The Customer is responsible for:

  • having a lawful basis and giving suitable privacy information to members and applicants;
  • collecting only information that is necessary for its stated club purposes;
  • keeping organiser access and permissions accurate;
  • handling safeguarding, sensitive-data and junior-participation requirements;
  • responding to data-subject requests and regulator enquiries, with Provider’s assistance; and
  • ensuring its instructions are lawful.

5. Confidentiality and personnel

Provider will limit access to people who need Customer Personal Data to deliver, secure or support the service. Those people will be bound by confidentiality obligations and receive appropriate privacy and security guidance.

6. Security measures

Provider will maintain technical and organisational measures appropriate to the risk, including:

  • encrypted network transport and protected credential storage;
  • role-based permissions and least-privilege operational access;
  • authentication safeguards, access revocation and audit events;
  • segregation of club access within the application;
  • backup, recovery, patching and vulnerability-management processes;
  • logging, incident triage and periodic review of access; and
  • secure deletion or anonymisation at the end of applicable retention periods.

Provider may update measures as technology and risks change, provided the overall protection is not materially reduced.

7. Sub-processors

The Customer gives general written authorisation for Provider to use hosting, database, email delivery, monitoring, support and payment-related sub-processors needed to deliver the service. Provider will bind each processor to data-protection obligations offering equivalent protection for the relevant processing.

A current schedule, including provider, service, location and transfer safeguard, will be available from support@coolsmash.co.uk. Provider will give reasonable advance notice of a new sub-processor. The Customer may object on reasonable data-protection grounds; the parties will work in good faith on a commercially reasonable alternative.

8. International transfers

Provider will not transfer Customer Personal Data outside the UK unless it uses a lawful transfer mechanism. Where needed, the parties incorporate the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, together with supplementary safeguards appropriate to the transfer risk.

9. Requests, assessments and regulator support

Taking into account the nature of processing, Provider will reasonably assist the Customer with data-subject requests, security obligations, breach notifications, data-protection impact assessments and regulator consultations. Provider will not respond to a request on the Customer’s behalf unless authorised or legally required.

If assistance is unusually extensive or caused by the Customer’s unlawful or out-of-scope instruction, the parties may agree a reasonable fee in advance.

10. Personal-data breaches

Provider will notify the Customer without undue delay after becoming aware of a breach affecting Customer Personal Data. Available information will include the nature of the incident, likely consequences, affected records or people, mitigation taken and a contact for follow-up. Information may be provided in phases as the investigation progresses.

The Customer remains responsible for deciding whether to notify the ICO or affected people. Provider will preserve relevant evidence and reasonably assist that decision.

11. Return, deletion and anonymisation

During the agreement, the Customer may export information using available product features or a reasonable support request. On termination, Provider will make a final export available for 30 days where reasonably practicable, then delete Customer Personal Data from live systems unless law requires retention.

Residual backup copies will be isolated from routine use and age out within 90 days. Provider may retain records required for security, fraud, financial or legal purposes in a restricted form. Provider may also retain statistics that have been irreversibly anonymised so they no longer identify a person or Customer.

12. Information and audits

Provider will make information reasonably necessary to demonstrate compliance available to the Customer. The parties will ordinarily use security summaries, policies and independent reports before an on-site audit.

If those materials are insufficient, the Customer may conduct one audit per year on reasonable notice, during business hours, subject to confidentiality and without compromising other customers or service security. More frequent audits are permitted following a material breach or regulator request.

13. Priority and liability

If this DPA conflicts with the main service agreement on personal-data processing, this DPA prevails. Liability under this DPA is subject to the service agreement’s lawful liability provisions, but nothing excludes liability that cannot legally be limited.