Data Processing Agreement
This DPA forms part of the B2B Terms between the customer identified in the account or order (“Controller”) and The Applications Cloud, Sociedad Limitada (S.L.U.), Placa La Pau 1, piso 3, puerta 1, 08960 Sant Just Desvern (Barcelona), Spain, NIF/CIF B44614964 (“Processor”). It is automatically incorporated when the Controller accepts the Terms and is also available for separate signature.
1. Scope and hierarchy
The Processor processes Personal Data only to provide, secure and support padelisto under the Controller’s documented instructions, including configured product actions, support tickets and this DPA. GDPR terminology applies. If this DPA conflicts with the Terms on processing, this DPA prevails.
2. Processor duties
- Process only on documented instructions unless EU or Member State law requires otherwise, in which case notify the Controller unless prohibited.
- Ensure authorised personnel are bound by confidentiality.
- Maintain the technical and organisational measures in Annex III and Article 32 GDPR.
- Notify the Controller without undue delay and no later than 48 hours after becoming aware of a Personal Data Breach, with available facts, likely consequences and mitigation; provide updates as the investigation progresses.
- Taking account of the nature of processing, assist with data-subject requests, Articles 32–36 obligations, DPIAs and prior consultation.
- Maintain records and provide information reasonably necessary to demonstrate compliance.
- Inform the Controller if an instruction appears to infringe applicable data-protection law.
3. Subprocessors
The Controller grants general authorisation for the subprocessors in the versioned register. Processor will give at least 30 days’ notice before a new subprocessor starts processing Controller Personal Data. The Controller may object within that period on reasonable, documented data-protection grounds. The parties will seek a practical mitigation; if none is available, the Controller may terminate the affected feature or service without penalty. Processor imposes materially equivalent obligations and remains responsible for each subprocessor’s performance.
4. International transfers
Processor will use an applicable adequacy decision or EU-US Data Privacy Framework where valid. Otherwise the parties incorporate the current EU Standard Contractual Clauses: Module 2 for Controller-to-Processor transfers and Module 3 where Processor transfers on behalf of a Controller to another Processor. Processor will perform a transfer impact assessment, implement supplementary measures where required, and make relevant information available. The SCCs prevail over conflicting terms.
5. Audit
Once per year, and additionally after a material incident or regulator request, Processor will provide current independent reports, certifications and written answers reasonably sufficient to demonstrate compliance. If insufficient, Controller may conduct or appoint a qualified independent auditor for a narrowly scoped audit on 30 days’ notice, during business hours, subject to confidentiality and security controls. Controller bears cost unless a material breach is found.
6. Return and deletion
On termination or instruction, Processor will return an export where requested and delete active Controller Personal Data unless law requires retention. Deletion is irreversible. Railway volumes and backups are finally removed within 48 hours after tenant deletion. Temporary export archives are deleted after download or expiry. Minimal pseudonymous legal evidence may be retained for the published period and isolated from operational use.
7. Liability and term
This DPA continues while Processor holds Controller Personal Data. Liability follows the Terms to the extent permitted by mandatory data-protection law.
Annex I — Processing details
| Subject matter | Hosting and operation of club administration, scheduling, communications, attendance, balances, support and optional AI/calendar integrations. |
|---|---|
| Duration | For the active tenant and deletion/retention periods in the Privacy Policy. |
| Nature and purpose | Collection, storage, organisation, retrieval, transmission, support, automated assistance, export and deletion as configured by Controller. |
| Data subjects | Players, prospective players, children, parents/guardians, coaches, staff, club contacts and message participants. |
| Data | Contact data; WhatsApp/Telegram IDs; messages/audio; bookings; attendance; balances/payments; notes; child/guardian data; AI input/output; calendar/OAuth data; technical and security logs. |
| Sensitive data | Not intended. Controller must not submit special-category data unless separately agreed and legally supported. |
| Frequency | Continuous while the service is used. |
Annex II — Authorised subprocessors and transfers
The live, versioned table at /subprocessors.html is incorporated here. It identifies purpose, location, transfer basis and status. Meta/WhatsApp, Telegram and user-authorised Google Calendar are separately controlled platforms/recipients unless a documented operation makes them a subprocessor.
Annex III — Technical and organisational measures
- tenant-isolated deployments and tenant-specific internal keys;
- role-based administrative access, MFA where available, CSRF protection and session expiry;
- TLS in transit; encryption of OAuth and communication credentials at rest; secrets kept outside exports and logs;
- least privilege, provider allowlists and Zero Data Retention for AI calls;
- backup controls, tested deletion, retention jobs and idempotent deprovisioning;
- audit metadata, pseudonymised requester/IP references and incident response;
- dependency review, patching, secure development review and restore testing;
- data minimisation, export deny-lists and staff confidentiality.
Annex IV — Signatures (optional separate execution)
Controller: ____________________ Name/title: ____________________ Date: __________
Processor: The Applications Cloud, Sociedad Limitada (S.L.U.) Authorised signatory: ____________________ Date: __________