1. What this document is
This data processing agreement (“DPA”) is the contract required by Article 28(3) of the UK GDPR between a club that uses Blades and us. It applies whenever we process personal information on the club’s behalf. It forms part of the terms of service. A club customer accepts it when it accepts those terms, and does not need to sign it separately. If your club needs a signed counterpart, email [email protected] and we will provide one. This is a contract between two organisations. It is not the privacy policy, which is the notice we give to individuals, and it does not replace the privacy information the club must give its own members. In this DPA, “we”, “us” and “our” mean Tahmid Azam, trading as Blades Rowing. “You” and “the club” mean the club customer. “UK data protection law” means the UK GDPR and the Data Protection Act 2018. “Personal data”, “controller”, “processor”, “data subject”, “processing”, “personal data breach” and “supervisory authority” have the meanings given in UK data protection law.2. Roles
For the club records described in Annex 1, the club is the controller and we are its processor. We are a controller in our own right for account administration, authentication and security, customer relationships and correspondence, invoicing, and service analytics. This DPA does not apply to that processing. The privacy policy explains it, and we do not act on the club’s instructions for it. Neither party is a joint controller with the other, and nothing in this DPA makes us a controller of the club records described in Annex 1.3. The club’s obligations
The club confirms that it has a lawful basis for the personal data it puts into Blades or asks us to process, that it has any additional condition required for special category data, and that it has given its members the privacy information UK data protection law requires. Section 4 of the terms of service sets out what the club must do before adding a member. The club must not instruct us to process personal data in a way that breaks UK data protection law, and must not put special category data into free-text fields unless it has established the condition that allows it.4. Our obligations
Instructions. We will process personal data only on the club’s documented instructions, including in relation to transfers outside the United Kingdom, unless UK law requires otherwise. If UK law requires us to process without an instruction, we will tell the club before doing so unless the law forbids it. The club’s documented instructions are this DPA, the terms of service, the order confirmation, and the ordinary use of the features of Blades by the club’s authorised users. We will tell the club if we consider an instruction to break UK data protection law. Confidentiality. We will ensure that everyone authorised to process the personal data is bound by an appropriate duty of confidentiality. Security. We will implement and maintain the technical and organisational measures described in Annex 2, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as required by Article 32. Subprocessors. The club gives us general written authorisation to engage the subprocessors listed in Annex 3. We will impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain fully liable to the club for a subprocessor’s performance. We will give the club at least 30 days’ written notice before adding or replacing a subprocessor that processes club records. If the club has a reasonable data protection objection, it should tell us within that period. We will work with the club to resolve it, and if we cannot, the club may end the affected service and receive a refund for its unused prepaid period. Data subject rights. Taking account of the nature of the processing, we will help the club meet its obligation to respond to requests from data subjects, by appropriate technical and organisational measures and as far as is reasonably possible. If a request reaches us directly, we will not respond to it ourselves beyond directing the person to the club, unless the club instructs us otherwise or we are the controller for the processing concerned. Other assistance. Taking account of the nature of the processing and the information available to us, we will help the club comply with its obligations on security, personal data breaches, data protection impact assessments and prior consultation with the Information Commissioner’s Office, under Articles 32 to 36. Breach notification. We will tell the club about a personal data breach affecting its personal data without undue delay after becoming aware of it, whether or not the breach is one the club must report. Our notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected as far as we know them, the likely consequences, the measures we have taken or propose, and a contact point. Where we cannot provide all of that at once, we will provide it in stages without further undue delay. Deletion or return. At the end of the club’s access, we will delete or return the club’s personal data at the club’s choice, and delete existing copies, unless UK law requires us to keep them. Section 13 of the terms of service gives the club at least 30 days after closure to request a copy. We will delete active copies within 60 days of the later of that request being fulfilled and the end of that window. Backups follow their own rolling deletion cycle and are not restored into live use; any personal data still present in a backup remains subject to this DPA until the backup is overwritten. Records and audits. We will make available to the club the information reasonably necessary to demonstrate compliance with Article 28, and allow and contribute to audits. We will normally satisfy this by answering the club’s written questions and providing documentation, including our record of processing activities and the information in Annex 2. If that is not sufficient, the club may audit us in person no more than once in any 12-month period, on at least 30 days’ written notice, during business hours, at the club’s own cost, without unreasonable disruption, and subject to confidentiality. The club may audit more often where a supervisory authority requires it or following a personal data breach affecting its data.5. International transfers
Annex 3 says where each subprocessor processes personal data. Some processing takes place outside the United Kingdom. Where we or a subprocessor make a restricted transfer, we will ensure an appropriate transfer mechanism is in place under Chapter V of the UK GDPR, such as UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, together with any transfer risk assessment required. The club can ask us which mechanism applies to a particular recipient and request a copy. The club instructs us to make the transfers described in Annex 3 for the purpose of providing Blades.6. Liability, precedence and law
Our liability under this DPA is subject to the limits in section 15 of the terms of service, except where UK data protection law does not allow those limits to apply. Nothing in this DPA limits a data subject’s rights or their right to compensation. Where this DPA conflicts with the terms of service or an order confirmation on a matter of personal data processing, this DPA prevails. On all other matters the terms of service prevail. The laws of England and Wales govern this DPA, and the courts of England and Wales have exclusive jurisdiction.Annex 1: description of the processing
Subject matter. Providing the Blades application to the club so that it can plan and administer its rowing. Duration. For as long as the club has access, plus the deletion period described in section 4. Nature and purpose. Hosting, storage, retrieval, organisation, display, transmission, backup and deletion of club records, so that the club can manage its members, collect availability, build crews and lineups, plan sessions and outings, book equipment, record coaching feedback and generate calendar subscriptions. Types of personal data.- Identity and contact details: name, email address, account identifier, verification status, club and crew memberships, permissions.
- Rowing profile: programme of study, British Rowing competition category, novice status, and ability to cox, coach, scull or row on either side.
- Availability: busy-time entries, including any free-text note the member adds.
- Club activity: crews, lineups, seat assignments, session dates, locations, outing plans, equipment bookings, and whether a session was marked as read.
- Coaching feedback: notes about a session or an individual participant, with the author and intended recipient.
- Calendar subscription data: a private subscription token and the session data included in the feed.
Annex 2: technical and organisational measures
Access control. Every request is authorised on the server against the caller’s club membership, crew membership and role. Organisers can reach the records needed to administer their own club. Availability and profile data is readable by members who share a club with the data subject, which is a documented feature described in section 5 of the privacy policy. Administrative access by Blades personnel is limited to support, fault investigation, security and legal obligations. Authentication. Sign-in is by emailed one-time code or registered passkey. We do not use or store passwords. One-time codes expire after five minutes. Session cookies are HttpOnly, Secure and carry an appropriate SameSite attribute, and session tokens are not persisted in browser storage. Encryption. Traffic between the browser and Blades is encrypted in transit using TLS. Our hosting, database and email providers encrypt data at rest. Pseudonymisation and minimisation. Account lookup by email address returns only an account identifier and the email address supplied. Product analytics runs without cookies or persistent identifiers, sends no personal data from form fields, and error reports have the error message removed before transmission. Resilience and backup. The database provider maintains backups on a rolling cycle. Backups are not restored into live use except to recover from an incident. Segregation. Club records are segregated by club identifier and every read is scoped to the caller’s memberships. Testing and review. Changes are covered by an automated test suite that includes authorisation and access-control regression tests, run before each deployment. Personnel. Blades is operated by one person, who is bound by the confidentiality obligation in section 4. Any future personnel or contractor with access will be bound before access is granted.Annex 3: subprocessors
Your chosen calendar provider receives the contents of any subscription feed a member connects to it. That provider acts on the member’s own instructions, not ours, and is not our subprocessor.