Who the parties are, and when this agreement applies
On one side the sports club, which is the CONTROLLER: it decides what data to collect about its athletes, for what purposes and for how long. On the other ► LEGAL NAME, ► REGISTERED OFFICE, VAT number ► VAT, which is the PROCESSOR: it processes that data on the controller’s behalf and on its instructions.
Inside the software a club processes health data (Art. 9 GDPR) and, in youth sectors, data about minors. Art. 28(3) GDPR requires processing of that kind to be governed by a contract: this one.
The agreement is accepted before any data is uploaded, and we keep a record of who accepted which version and when. The version published here is 1.0.
The signed version also carries the club’s own details, which obviously are not here. Everything else is what you read on this page.
1Subject matter, nature and purpose of the processing
1.1 The processor processes personal data solely to provide and maintain the software, and for no other purpose.
1.2 The features of the processing are set out in Annex A, which constitutes the controller’s documented instruction under Art. 28(3)(a).
1.3 The controller states that it has identified a valid legal basis for each purpose and has given data subjects the notice required by Art. 13. The processor is not liable for the lawfulness of the processing the controller decides, but must tell it if an instruction appears to infringe the law.
2The controller’s instructions, and what we do not do with its data
2.1 The processor processes data only on the controller’s documented instructions, including instructions on transfers to third countries.
2.2 The following count as documented instructions: this agreement and its annexes, the software documentation, and the settings the controller configures inside the software — roles, permissions, metrics, thresholds, the list of roles allowed to see health data.
2.3 The processor does not use the controller’s data for its own purposes. In particular it undertakes not to use it to build archives, reference values, statistics or benchmarks across clubs, not even in aggregated form; not to use it to train, tune or evaluate machine learning systems or statistical models; not to disclose it or make it available to third parties other than the authorised sub-processors; and not to use it for commercial or promotional purposes.
2.4 The processor may process anonymous data — carrying no direct or indirect reference to an identifiable person — for technical diagnostics and to improve the software. A series of daily measurements of a single athlete is not anonymous data for the purposes of this clause, and is not covered by it.
3Confidentiality
3.1 The processor ensures that the persons authorised to process the data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.2 Access to the controller’s data is limited to staff who genuinely need it, and only to what is necessary for the support requested or for maintenance.
3.3 The processor does not access the controller’s health data unless the controller expressly asks for support, and in that case records the fact in writing.
4Security measures
4.1 The processor implements the technical and organisational measures described in Annex B.
4.2 The measures may be updated, but no update may lower their overall level of security.
4.3 The controller acknowledges that security also depends on its own conduct — keeping credentials safe, assigning roles, choosing who may see health data, managing the public links used to collect the questionnaire — and takes responsibility for it.
5Sub-processors
5.1 The controller gives general authorisation to use the sub-processors listed in Annex C.
5.2 The processor informs the controller of any intention to add or replace a sub-processor with at least 30 days’ notice. The controller may object within that period on reasonable and documented grounds; the parties then look for a solution in good faith, and failing that the controller may terminate, without penalty, the part of the service concerned.
5.3 The processor imposes on every sub-processor, by contract, the same obligations as this agreement, and remains liable to the controller for their failures.
6Transfers outside the European Economic Area
6.1 Data is stored and processed within the European Union. The database sits in Ireland; the application runs in the ► APPLICATION REGION region.
6.2 The processor does not transfer data outside the European Economic Area without the controller’s written authorisation. Should a transfer become necessary, it would take place only on the basis of an adequacy decision or the standard contractual clauses approved by the Commission, together with a transfer impact assessment.
6.3 The processor tells the controller if a sub-processor’s technical support may access data from a third country, stating the safeguards that apply.
7Assistance to the controller
7.1 The processor assists the controller in handling data subject requests. The software gives the club, on its own: a complete export of a single athlete’s data in a structured format, rectification from the management screens, and permanent deletion with anonymisation of the audit entries concerning that athlete.
7.2 If an athlete contacts the processor directly, the processor does not answer on the merits and passes the request to the club without delay.
7.3 The processor notifies the controller of any personal data breach without undue delay and in any case within 24 hours of becoming aware of it, with the Art. 33(3) information available to it. Those 24 hours are tighter than the regulation asks of a processor, and exist to leave the club a usable margin inside its own 72.
7.4 The processor assists the controller with the data protection impact assessment and with any prior consultation of the supervisory authority, providing the technical information needed.
8Liability
8.1 Each party is liable for the damage caused by its own breach, within the limits of Art. 82 GDPR.
8.2 The processor’s liability for damages arising out of this agreement is limited to ► LIABILITY CAP per contract year. The cap does not apply in case of wilful misconduct or gross negligence, nor to administrative fines imposed on one party for an act attributable to the other.
8.3 As to professional indemnity and cyber insurance cover, the processor states ► INSURANCE COVER.
9Audits
9.1 The processor makes available to the controller the information needed to demonstrate compliance with Art. 28.
9.2 The controller may carry out one audit per year, with at least 30 days’ notice, during working hours and without prejudice to service continuity. Further audits are allowed after a data breach or on a reasoned request from the supervisory authority.
9.3 The processor may discharge the obligation under 9.1 by providing the software’s technical documentation, its sub-processors’ security reports and any certifications held. The cost of the audit is the controller’s, unless it establishes a failure by the processor.
10Record of processing activities
10.1 The processor keeps the record required by Art. 30(2) and makes it available to the controller and to the supervisory authority on request.
11Term, return and deletion
11.1 The agreement lasts as long as the supply contract.
11.2 On termination, at the controller’s choice expressed within 30 days, the processor returns the data in a structured, machine-readable format, or deletes it.
11.3 Failing a choice within that period, the processor deletes the data 90 days after termination and says so. The delay exists so that a club’s inattention does not cause the irreversible loss of its athletes’ data.
11.4 The processor may keep the data beyond that period only if and for as long as a legal obligation requires, informing the controller. 11.5 Backups follow their own rotation cycle and are deleted at the latest within ► BACKUP ROTATION DAYS days of the deletion of the live data; until then they remain subject to every measure in this agreement.
12Governing law and jurisdiction
12.1 The agreement is governed by Italian law, supplemented by the Italian Privacy Code (Legislative Decree 196/2003 as amended by Legislative Decree 101/2018).
12.2 The courts of ► JURISDICTION have exclusive jurisdiction over any dispute.
Annex A — Description of the processing
This annex is the controller’s documented instruction: it says what is processed, about whom and why. It is the part a data protection officer reads first.
| Item | Content |
|---|
| Subject matter | Provision of the software for monitoring athlete workload and protecting athlete health |
|---|
| Duration | The term of the supply contract |
|---|
| Nature of the operations | Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, comparison, erasure |
|---|
| Purposes | Planning and monitoring workload; managing injuries and return to play; producing reports and printable documents; keeping proof of consent; security and traceability of access |
|---|
| Categories of data subjects | Adult athletes; athletes who are minors; holders of parental responsibility (name and relationship); staff members with an account |
|---|
| Categories of ordinary data | Personal and sporting details; GPS data from training and matches; perceived exertion and duration; attendance and minutes played; staff accounts; access log |
|---|
| Special categories (Art. 9) | Health data: daily wellness questionnaire; injuries (type, area, side, severity, days lost, notes); force plate tests; anthropometric measurements including body fat and the method used |
|---|
| Data about minors | Yes, in youth sectors |
|---|
| Excluded data | Genetic data; biometric data for identification; criminal offence data; data on beliefs, opinions, trade union membership, sex life or sexual orientation |
|---|
| Automated processing | The software computes descriptive indices (rolling averages, ACWR, monotony, deviations from personal norm) and produces reading flags. It performs no profiling with legal effects and no automated decisions under Art. 22: it produces no diagnosis, computes no injury risk and expresses no fitness judgement |
|---|
Annex B — Technical and organisational measures
These are the Art. 32 measures. Where a measure is enforced in the DATABASE and not only in the interface we say so, because that is the difference between a permission that is drawn and a permission that can be bypassed.
| Area | Measure |
|---|
| Encryption in transit | HTTPS/TLS required on every connection |
|---|
| Encryption at rest | Volume-level encryption at the hosting sub-processor |
|---|
| Separation between customers | Access rules enforced in the database, on every table, by organisation identifier: one customer cannot read another’s data even in the face of an application defect |
|---|
| Access to health data | Enforced in the database and not only in the interface: the diagnosis is available to the administrator, to the roles the club expressly enables, and to the athlete for their own data. The absence period alone, without diagnosis, is available to the staff who manage workload |
|---|
| The “athlete” role | Limited in the database to that person’s own data |
|---|
| Authentication | Passwords of at least 10 characters, kept as hashes; no password in clear text; public sign-up disabled — accounts are created by the club’s administrator |
|---|
| No self-promotion | A user cannot raise their own role to administrator: the ban is enforced in the database |
|---|
| Write log | Automatic recording of creations, changes and deletions |
|---|
| Read log | Recording of the opening of a medical record, of the consent register, and of the complete export of an athlete’s data. Every single read for statistics is not recorded: it would be hundreds of rows per person per day, and nobody opens a log like that |
|---|
| Minimisation | Data a screen does not draw is not sent to the browser |
|---|
| Deletion and anonymisation | Permanently deleting an athlete removes measurements, injuries, anthropometrics, consents and links, and anonymises the audit entries concerning them: the proof that an operation happened remains, the name and the diagnosis disappear |
|---|
| Export | Complete export per athlete in a structured format, which states what it does not contain |
|---|
| Backups | ► BACKUPS — frequency, retention, encryption and how often the restore is tested |
|---|
| Continuity | ► CONTINUITY — recovery objectives |
|---|
| Environment separation | Development and production kept apart; production data is not used in development |
|---|
Annex C — Authorised sub-processors
These are the suppliers that process data on our behalf. An undeclared sub-processor breaches Art. 28(2), and is also the easiest breach to prove: that is why the list is here rather than on request.
No other recipients. While in use the software calls no external services: fonts are served from the software’s own domain, and no user IP address is disclosed to anyone.
| Sub-processor | Service | Place of processing | Safeguards |
|---|
| Supabase Inc. | Database, authentication, file storage | AWS infrastructure, region eu-west-1 (Ireland) | Supabase data processing agreement; data at rest in the Union |
|---|
| ► HOSTING PROVIDER | Running the web application | ► APPLICATION REGION | ► SAFEGUARDS |
|---|
| ► EMAIL SERVICE PROVIDER | Sending service emails | ► DATA LOCATION | ► SAFEGUARDS |
|---|