Data Processing Agreement (DPA)
Last updated: 2026-07-17
Courtesy translation. In case of conflict, the Portuguese version prevails.
Document being finalised: company details are still to be filled in.
This DPA forms part of the Agreement between [Entidade legal a constituir] ("Processor", "we") and the customer (the coach/academy, "Controller", "you") and governs the processing of Personal Data under the GDPR (Regulation (EU) 2016/679).
1. Roles
- For player data the coach enters into the Service, you are the Controller and we are the Processor.
- For your own account data, we act as Controller under our Privacy Policy (outside this DPA).
2. Subject matter, duration, nature and purpose
We process player Personal Data solely to provide the Service (managing players, sessions, evaluations, synergy, scheduling, sharing), for the duration of the Agreement.
3. Types of data and categories of data subjects
- Data subjects: the Controller's players (athletes), including, where the Controller chooses, minors.
- Personal data: name, email, phone (optional), skill level, dominant hand, court side, notes, skill evaluations, synergy ratings, progression history.
- No special-category data is required. The Controller must not enter health, medical or other Art. 9 data into free-text fields.
4. Controller obligations
You warrant that you have a lawful basis to process the player data you enter, that you have informed the data subjects, and that for minors you have obtained the consent of the holder of parental responsibility. You are responsible for the accuracy of the data and for the visibility choices you make on public share pages.
5. Processor obligations
We will:
- Process Personal Data only on your documented instructions (this DPA + your use of the Service).
- Ensure persons authorized to process are bound by confidentiality.
- Implement appropriate technical and organizational measures (Annex II).
- Respect the conditions for engaging sub-processors (Section 6).
- Assist you, taking into account the nature of processing, with data subject requests and with Arts. 32–36 (security, breach notification, DPIA).
- At the end of the Agreement, delete or return Personal Data at your choice, save where storage is required by law.
- Make available information necessary to demonstrate compliance and allow for audits.
6. Sub-processors
You provide general authorization for the sub-processors listed below. We will inform you of intended changes (additions or replacements), giving you the opportunity to object on reasonable data-protection grounds. Each sub-processor is bound by terms no less protective than this DPA.
| Sub-processor | Purpose | Location / safeguard |
|---|---|---|
| Neon | Base de dados principal (Postgres) | UE (Frankfurt, DE) |
| Clerk | Autenticação / gestão de utilizadores | EUA — DPF + SCC |
| Stripe | Pagamentos e subscrições | EUA / Irlanda (UE) — DPF + SCC |
| Resend | Email transacional | EUA — DPF + SCC |
| Vercel | Alojamento da aplicação / edge | EUA (edge global) — DPF + SCC |
Cloudflare R2 (file storage) and Sentry (error monitoring) are planned but not yet active; they will be added to this list when those features ship.
7. International transfers
Where Personal Data is transferred outside the EEA, such transfers are covered by Standard Contractual Clauses and/or the EU-US Data Privacy Framework. The primary database is hosted in the EU (Frankfurt).
8. Personal data breach
We will notify you without undue delay after becoming aware of a Personal Data breach affecting your data, and provide the information you need to meet your 72-hour notification duty to the supervisory authority (in Portugal, the CNPD).
9. Liability
Liability under this DPA is subject to the limitations in the Terms of Service.
Annex II — Technical and organizational measures
- Encryption in transit (HTTPS/TLS).
- Authentication delegated to a specialized provider (Clerk); we never store raw passwords.
- Tenant isolation: every query is scoped to the authenticated coach (
coachId); no cross-tenant access. - Public share pages gated by random, unguessable tokens (122-bit entropy), revocable at any time; level/progression signals off by default.
- EU data residency for the primary database (Neon, Frankfurt).
- Least-privilege access to production; access logging.
- Regular dependency updates and security patching.