Data processing agreement

Gebruikt jouw vereniging Loyal2Sports, dan bepaalt zíj wat er van haar leden wordt vastgelegd en verwerken wij dat alleen in haar opdracht. Wat wij daarbij wel en niet mogen staat hieronder, in 14 artikelen en 3 bijlagen. Deze overeenkomst hoort onlosmakelijk bij de algemene voorwaarden.

The agreement

Fourteen articles.

This is what privacy law requires of a processor, written so a board member can read it. Numbered, so we can refer to them in a conversation.

1. Who is what

If a club uses Loyal2Sports, it decides which personal data it records and for what purpose. It is the data controller. We supply the system and process those data solely for the club. We are the processor.

This data processing agreement belongs to our general terms and conditions and applies for as long as the club uses the platform. If a club agrees something different with us, that agreement prevails, provided it is in writing.

Where this text says "the club", we also mean a foundation, school or other organisation that takes the platform.

2. Only on instruction

We process personal data only as the club instructs us. That instruction lies in the use of the platform itself: what it enters, configures and publishes. In addition it can give us further written instructions.

We never use the data for our own purposes. We do not sell them, we do not rent them out, and we do not use them to profile or track anyone.

If we consider an instruction to be contrary to privacy legislation, we say so and we do not carry it out until it has been amended.

If a law nonetheless obliges us to process something outside the instruction, we notify the club in advance, unless that same law prohibits us from doing so.

3. What is processed

Exactly which data those are depends on the modules the club uses and on what it enters itself. Annex A lists the categories that occur in practice and whom they concern.

The club ensures that it is allowed to process those data, that it informs the data subjects, and that it has consent where required. Where the data concern children, it obtains consent from a parent or guardian where the law requires it.

4. Confidentiality

Everyone at our end who can access the data is bound to confidentiality. This is recorded and continues to apply after someone leaves us.

Access to a club's data is given only to those who need it for their work, and only for as long as they need it.

We do not look into a club's data, except when it asks us for help or when we have to resolve a malfunction. That is done by a person, it is logged, and it never happens unasked.

5. Security

We take appropriate technical and organisational measures to protect the data against loss and unlawful processing. What we currently do is set out in Annex C.

Those measures are not a snapshot: we adjust them when technology or risk calls for it. We may replace a measure with another that is at least as good.

The club is itself responsible for what happens at its end: handling login details carefully, switching on two-step verification where we offer it, and revoking administrators who leave the club.

6. Sub-processors

We engage other parties in order to deliver the service. Who they are and what for is set out in Annex B. By entering into this agreement the club gives its consent for this.

If we want to add or replace a sub-processor, we announce it at least thirty days in advance. If the club has a well-founded objection, we discuss it. If we cannot resolve it, it may terminate the agreement as of the date the change takes effect, at no cost.

We impose on every sub-processor the same obligations we enter into here, and we remain responsible towards the club for what they do.

7. Data outside Europe

Our servers and databases are located within the European Union. For two components data nevertheless go outside the European Economic Area, and only if the club uses those components.

If it connects its Facebook page or Instagram account, the posts it publishes go to Meta in the United States, together with the reference to that page or account. We do not send any member data to Meta.

If someone switches on notifications in the parent portal, an address of the device goes to the push service of Google, Apple or Mozilla. The content of the notification is encrypted by us and unreadable to that service.

The European Commission's standard contractual clauses apply to these transfers, and for Meta the EU-US Data Privacy Framework applies in addition. If a club wants no transfer outside the EEA, it does not use these two components and then it does not happen.

8. Rights of data subjects

Anyone wanting access, rectification, erasure, restriction, objection or portability must approach the club. It is the controller and it decides.

We help the club with the means the platform offers: looking up, amending, exporting and erasing it can largely do itself. If something cannot be done by the club, we do it at its request, within ten working days.

If such a request reaches us by mistake, we do not handle it ourselves. We forward it to the club and let the requester know that we have done so.

9. Data breaches

If we discover a security breach involving personal data, we notify the club without undue delay, and in any case within 24 hours after we became aware of it.

We report what happened, which data and roughly how many people it concerns, what the consequences may be and what we are doing about it. If we do not yet know everything, we report what we do know and supplement it.

The club itself decides whether to report it to the Dutch Data Protection Authority and to the data subjects. That is its duty, not ours. We supply the information it needs for that.

We never report a breach to a supervisory authority on the club's behalf of our own accord, and we make no public statements about an incident at a club without consulting it.

10. Help with assessments

If the club has to carry out a data protection impact assessment, or if a supervisory authority wants information, we help it with what we know about how the platform works and how it is secured.

11. Audits

The club may check whether we comply with this agreement. We provide the information it reasonably needs for that.

If it wants an on-site audit or one by an independent expert, it announces this at least thirty days in advance, at most once a year, unless there is a concrete reason. The expert signs a confidentiality undertaking, and the audit must not affect our service to other clubs.

The costs of such an audit are for the club, unless it shows that we were not complying with this agreement.

12. End of the agreement

When the agreement ends, the environment remains accessible for thirty days so the club can export its data. If it wants an export in a particular format, it requests that within those thirty days.

After that we delete the data and the environment, and within ninety days also the back-ups in which they appear. We confirm that deletion in writing if the club asks for it.

If we have to keep something longer because the law requires it, invoices for example, we keep only that, only for as long as we must, and we use it for nothing else.

13. Liability

For liability under this data processing agreement the arrangement in our general terms and conditions applies. A fine imposed on the club by a supervisory authority is for its account, except insofar as it results from a failure on our part.

14. Order of precedence and governing law

If this agreement states something different from the general terms and conditions, this agreement prevails, but only for the processing of personal data.

This agreement is governed by Dutch law.

Annex A

Whom and what it concerns.

What exactly is in an environment is up to the club. These are the categories that occur in practice.

Members and their family

Name, address, email address, telephone number, date of birth, team or group, membership and subscription fees. For youth members also the details of a parent or guardian.

Customers and visitors

Name, email address, telephone number, orders, tickets and payments.

Sponsors and contact persons

Company name, contact person, email address, telephone number, contracts and invoices.

Volunteers and staff

Name, contact details, role or function, availability, and where the club records them hours and allowances.

Pupils and parents (education environment)

Name, group, attendance, progress, and the link between parent and child for the parent portal.

Administrators

Name, email address, role, login details and two-step verification.

Payment details

For direct debit an IBAN with a mandate. We store that encrypted. Card details never reach us: they go straight to the payment provider.

Annex B

The four parties we engage.

This list does not come from a template but from the outgoing connections of the system itself. The last two only come into play if a club uses those components.

PartyWhereWhat for
Strato AGGermanyHosting of the platform and the databases, and sending email on behalf of clubs.
Mollie B.V.the NetherlandsPayments: iDEAL, direct debit and refunds.
Meta Platforms Ireland Ltd.Ireland, with transfer to the United StatesOnly with a connected Facebook page or Instagram: publishing posts on behalf of the club.
Google, Apple and Mozilla (push services)Partly outside the EEAOnly with notifications switched on in the parent portal: delivering an encrypted notification to a device.
Annex C

How it is secured.

None of these points is an intention. They are in the code and are checked again on every change.

  • Every club has its own database. Data from one club are not physically present in another club's environment.
  • Passwords are stored encrypted and irreversibly. Administrators log in with a second step via an authenticator app.
  • Access tokens of connected services and IBAN details are stored encrypted, not as readable text.
  • Who may see what is defined per role and is checked again on every action, not only in the screen.
  • All traffic runs over https. The browser may only load files from our own server; a check in our build pipeline blocks every exception to that.
  • Actions that touch money or data are recorded in a log that cannot be altered afterwards.
  • Daily back-ups, kept for fourteen days, intended to recover from an outage.
  • We work with a small number of people; access to production data is given only to those who need it for their work.
What is not there yet

One thing we say honestly.

Better here than in an audit conversation.

Automatic clean-up within a club environment

We do not clean up by ourselves. A club decides what may go and we carry that out, but there is no period yet that does this independently. This is on our development agenda.

Version 1.0 · updated 21 september 2026 · Chamber of Commerce 84872624 · privacy statement · general terms and conditions