1. Who is what
If a club uses Loyal2Sports, it decides which personal data it records and for what purpose. It is the data controller. We supply the system and process those data solely for the club. We are the processor.
This data processing agreement belongs to our general terms and conditions and applies for as long as the club uses the platform. If a club agrees something different with us, that agreement prevails, provided it is in writing.
Where this text says "the club", we also mean a foundation, school or other organisation that takes the platform.
2. Only on instruction
We process personal data only as the club instructs us. That instruction lies in the use of the platform itself: what it enters, configures and publishes. In addition it can give us further written instructions.
We never use the data for our own purposes. We do not sell them, we do not rent them out, and we do not use them to profile or track anyone.
If we consider an instruction to be contrary to privacy legislation, we say so and we do not carry it out until it has been amended.
If a law nonetheless obliges us to process something outside the instruction, we notify the club in advance, unless that same law prohibits us from doing so.
3. What is processed
Exactly which data those are depends on the modules the club uses and on what it enters itself. Annex A lists the categories that occur in practice and whom they concern.
The club ensures that it is allowed to process those data, that it informs the data subjects, and that it has consent where required. Where the data concern children, it obtains consent from a parent or guardian where the law requires it.
4. Confidentiality
Everyone at our end who can access the data is bound to confidentiality. This is recorded and continues to apply after someone leaves us.
Access to a club's data is given only to those who need it for their work, and only for as long as they need it.
We do not look into a club's data, except when it asks us for help or when we have to resolve a malfunction. That is done by a person, it is logged, and it never happens unasked.
5. Security
We take appropriate technical and organisational measures to protect the data against loss and unlawful processing. What we currently do is set out in Annex C.
Those measures are not a snapshot: we adjust them when technology or risk calls for it. We may replace a measure with another that is at least as good.
The club is itself responsible for what happens at its end: handling login details carefully, switching on two-step verification where we offer it, and revoking administrators who leave the club.
6. Sub-processors
We engage other parties in order to deliver the service. Who they are and what for is set out in Annex B. By entering into this agreement the club gives its consent for this.
If we want to add or replace a sub-processor, we announce it at least thirty days in advance. If the club has a well-founded objection, we discuss it. If we cannot resolve it, it may terminate the agreement as of the date the change takes effect, at no cost.
We impose on every sub-processor the same obligations we enter into here, and we remain responsible towards the club for what they do.
7. Data outside Europe
Our servers and databases are located within the European Union. For two components data nevertheless go outside the European Economic Area, and only if the club uses those components.
If it connects its Facebook page or Instagram account, the posts it publishes go to Meta in the United States, together with the reference to that page or account. We do not send any member data to Meta.
If someone switches on notifications in the parent portal, an address of the device goes to the push service of Google, Apple or Mozilla. The content of the notification is encrypted by us and unreadable to that service.
The European Commission's standard contractual clauses apply to these transfers, and for Meta the EU-US Data Privacy Framework applies in addition. If a club wants no transfer outside the EEA, it does not use these two components and then it does not happen.
8. Rights of data subjects
Anyone wanting access, rectification, erasure, restriction, objection or portability must approach the club. It is the controller and it decides.
We help the club with the means the platform offers: looking up, amending, exporting and erasing it can largely do itself. If something cannot be done by the club, we do it at its request, within ten working days.
If such a request reaches us by mistake, we do not handle it ourselves. We forward it to the club and let the requester know that we have done so.
9. Data breaches
If we discover a security breach involving personal data, we notify the club without undue delay, and in any case within 24 hours after we became aware of it.
We report what happened, which data and roughly how many people it concerns, what the consequences may be and what we are doing about it. If we do not yet know everything, we report what we do know and supplement it.
The club itself decides whether to report it to the Dutch Data Protection Authority and to the data subjects. That is its duty, not ours. We supply the information it needs for that.
We never report a breach to a supervisory authority on the club's behalf of our own accord, and we make no public statements about an incident at a club without consulting it.
10. Help with assessments
If the club has to carry out a data protection impact assessment, or if a supervisory authority wants information, we help it with what we know about how the platform works and how it is secured.
11. Audits
The club may check whether we comply with this agreement. We provide the information it reasonably needs for that.
If it wants an on-site audit or one by an independent expert, it announces this at least thirty days in advance, at most once a year, unless there is a concrete reason. The expert signs a confidentiality undertaking, and the audit must not affect our service to other clubs.
The costs of such an audit are for the club, unless it shows that we were not complying with this agreement.
12. End of the agreement
When the agreement ends, the environment remains accessible for thirty days so the club can export its data. If it wants an export in a particular format, it requests that within those thirty days.
After that we delete the data and the environment, and within ninety days also the back-ups in which they appear. We confirm that deletion in writing if the club asks for it.
If we have to keep something longer because the law requires it, invoices for example, we keep only that, only for as long as we must, and we use it for nothing else.
13. Liability
For liability under this data processing agreement the arrangement in our general terms and conditions applies. A fine imposed on the club by a supervisory authority is for its account, except insofar as it results from a failure on our part.
14. Order of precedence and governing law
If this agreement states something different from the general terms and conditions, this agreement prevails, but only for the processing of personal data.
This agreement is governed by Dutch law.