This Data Processing Agreement ("DPA") forms part of the Curlingclubs.cc Software as a Service Agreement ("SaaS Agreement") between the organization using the Service ("Club", "Controller") and Tmi Markus Aarne Pentti Sipilä, Business ID 3497538-3, Kolapuuntie 5A, 02620 Espoo ("Provider", "Processor").
Where this DPA and the SaaS Agreement conflict on matters concerning personal-data processing, this DPA prevails.
1. Background and Roles
The Club uses the Curlingclubs.cc service ("Service") to manage its activities. In providing the Service, the Provider processes personal data on behalf of the Club.
For those processing activities, the Club is the controller and the Provider is the processor within the meaning of applicable data-protection law, including the EU General Data Protection Regulation ("GDPR").
The Club is responsible for determining the purposes and means of processing Club operational personal data. The Provider processes that data only as described in this DPA, the SaaS Agreement and the Club's documented instructions.
If the Club consists of more than one legal entity acting as joint controllers toward data subjects, the Club is responsible for arranging their internal roles and contact arrangements. The Provider needs one designated contact for instructions and data-protection matters under this DPA.
2. Scope of This DPA
2.1 Processing Covered by This DPA
This DPA covers personal data processed by the Provider on behalf of the Club through the Service in connection with Club operations, including:
- person profiles and related contact and demographic information;
- user accounts used to access the Club's Service;
- Commerce customer profiles used for checkout and billing, including name and address details;
- external system mappings that link a person to identifiers in third-party systems;
- memberships, bookings and event registrations;
- club credit balances and credit transaction history;
- tasks and volunteer assignments;
- badges and other person honors;
- teams, competitions, games and other competition records, including player participation and results;
- orders, payments and related commerce records processed through the Service;
- event participant lists and other event-related information entered by the Club, which may include dietary or allergy information if the Club chooses to collect it;
- website analytics data processed through the Service where the Club enables a supported analytics integration for the Club's site;
- newsletters and other communications sent by the Club through the Service; and
- other personal data entered, generated or stored in the Service by or on behalf of the Club.
2.2 Processing Not Governed by This DPA
The following processing is outside the processor role covered by this DPA:
- the Provider's own B2B processing of information about the Club as a customer, such as contract, invoicing and support contact details;
- processing for which the Provider acts as an independent controller, including platform-level account and identity processing that is not limited to one Club, and processing connected with Curlingresults.cc and other common services operated by the Provider as its own services; and
- processing carried out directly by third parties with whom the Club has its own relationship, such as payment service providers.
Where the Provider acts as controller for its own services, that processing is governed by the Provider's applicable privacy documentation and legal obligations.
3. Details of Processing
The main details of processing are:
| Item | Description |
|---|---|
| Subject matter | Provision of the Curlingclubs.cc hosted software service to the Club |
| Duration | For the duration of the Club's subscription and until personal data has been deleted or returned in accordance with this DPA and the SaaS Agreement |
| Nature of processing | Hosting, storage, organisation, retrieval, use, disclosure by transmission, restriction, erasure and other processing necessary to provide and operate the Service |
| Purpose | Enabling the Club to manage memberships, bookings, events, registrations, tasks, competitions, communications, e-commerce, optional website analytics and related activities through the Service |
| Categories of data subjects | Club members, customers, participants, volunteers, managers and other persons whose data the Club processes through the Service |
| Types of personal data | Identification and contact data; demographic data such as birthdate, gender and student status; account and authentication data; Commerce customer profile and billing address data; membership, booking, registration, task and volunteer-assignment data; club credit balances and transaction history; badge and honor records; external system identifiers linked to persons; payment-related and order records processed through the Service; competition participation, team roster and results data; event participant and related event information; website usage and device data where the Club enables website analytics; communications content and delivery metadata; technical logs and security records where necessary to operate the Service |
The Club determines which of these data types are actually processed through its use of the Service.
Special categories of personal data under Article 9 GDPR are not intended to be processed through the standard Service features unless the Club chooses to include such data in content or records it enters, for example allergy or dietary information on events or registrations.
4. Club Instructions and Responsibilities
The Provider processes personal data on documented instructions from the Club.
The Club's instructions include:
- this DPA;
- the SaaS Agreement, including its provisions on Competition Data, publication through Curlingresults.cc and use of Competition Data for analytics and related data products;
- the Club's configuration and use of the Service; and
- additional written instructions given by the Club's designated contact where they are consistent with the Service and this DPA.
The Club is responsible for:
- having a lawful basis for processing;
- providing appropriate privacy information to data subjects;
- ensuring that instructions given to the Provider comply with applicable data-protection law;
- the accuracy, quality and lawfulness of personal data entered into the Service;
- decisions about retention, erasure and publication of personal data, except where this DPA or the SaaS Agreement states otherwise;
- handling data-subject requests for matters within the Club's responsibility as controller;
- informing players and other affected persons that Competition Data may be published through Curlingresults.cc and other common services operated by the Provider, and may be aggregated, analysed and used to create statistics, rankings and other data products as described in the SaaS Agreement, and reflecting this in the Club's own privacy notice; and
- website analytics enabled by the Club, including any cookie consent, privacy-notice and provider-contract requirements that apply to the Club's site.
The Provider will inform the Club if, in the Provider's opinion, an instruction infringes applicable data-protection law.
5. Competition Data and Curlingresults.cc
Competition-related personal data processed for the Club through the Service may form part of public competition or results information ("Competition Data") as described in the SaaS Agreement.
The Club authorises the Provider to:
- make Competition Data available for publication through Curlingresults.cc and other common services operated by the Provider;
- aggregate, analyse and otherwise process Competition Data to create rankings, statistics, benchmarks, analyses, datasets, models, metrics and other derived information and data products; and
- develop, provide, license and commercially exploit products and services based on Competition Data and such derived information,
in each case in accordance with the SaaS Agreement.
This authorisation relates to Competition Data only. It does not authorise use of the Club's private membership, booking, e-commerce, task-management or other operational personal data for these purposes.
For publication through Curlingresults.cc, for cross-Club aggregation and analysis, and for related data products operated by the Provider as its own services, the Provider will act as controller for its own purposes. The Club remains responsible for informing data subjects and for having an appropriate legal basis for the Club's own publication and collection of competition results.
Historical Competition Data may continue to be published and used as described in the SaaS Agreement after the Club's subscription ends.
6. Provider Obligations
The Provider will:
- process personal data only on documented instructions from the Club, unless required by applicable law;
- ensure that persons authorised to process personal data are bound by appropriate confidentiality obligations;
- implement appropriate technical and organisational security measures as described in section 8;
- respect the conditions for engaging subprocessors in section 9;
- assist the Club, taking into account the nature of processing, with data-subject requests and related controller obligations as described in section 10;
- assist the Club with security, breach notification and impact-assessment obligations as described in sections 11 and 12;
- at the Club's choice, delete or return personal data at the end of the provision of services relating to processing, subject to section 13 and the SaaS Agreement; and
- make available information reasonably necessary to demonstrate compliance with this DPA and allow audits as described in section 14.
The Provider will promptly inform the Club if the Provider becomes aware that personal-data processing in the Service is likely to result in a high risk to the rights and freedoms of natural persons and the Club has not already assessed that risk.
7. Provider Personnel and Confidentiality
The Provider limits access to personal data to personnel and subprocessors who need access to provide the Service.
The Provider ensures that persons processing personal data on the Provider's behalf are subject to confidentiality obligations with respect to that data.
8. Security Measures
The Provider implements appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage.
These measures are proportionate to the nature of the Service and the risk involved. They may include, as appropriate:
- access controls and role-based permissions in the Service;
- use of encryption in transit;
- separation of Club data in the multitenant Service;
- backup and recovery arrangements for system continuity;
- logging and monitoring for security and operational purposes;
- procedures for managing security incidents; and
- contractual requirements for subprocessors.
The Provider may update security measures from time to time, provided that the overall level of protection is not materially reduced.
9. Subprocessors
The Club gives general written authorisation for the Provider to use subprocessors in providing the Service.
The Provider will maintain an up-to-date list of subprocessors that process personal data on behalf of Clubs. The current list is published at https://curlingclubs.cc/en/privacy/sub-processors and forms part of this DPA by reference.
The Provider will inform the Club of intended changes to subprocessors by updating that list and, where practicable, giving reasonable advance notice before a new subprocessor begins processing personal data for the Service.
The Club may object to a new subprocessor on reasonable data-protection grounds by notifying the Provider in writing within 14 days of receiving notice. If the parties cannot resolve the objection within a reasonable time, the Club may terminate the affected part of the Service or the subscription in accordance with the SaaS Agreement.
The Provider remains responsible to the Club for the performance of subprocessors engaged by the Provider under this DPA.
Each subprocessor is subject to data-protection obligations substantially similar to those in this DPA.
Payment service providers used under the Club's own agreement are not subprocessors of the Provider for Club member payments, except to the extent the Provider's technical integration necessarily processes limited payment-related data on the Club's behalf.
Where the Club enables a supported website analytics integration for its site, the Provider may use the relevant analytics provider as a subprocessor for that Club's domain only. Such subprocessors are listed on the published subprocessor list when they are used to provide the Service.
10. Assistance with Data-Subject Requests
Taking into account the nature of processing and the information available to the Provider, the Provider will assist the Club in fulfilling the Club's obligation to respond to requests from data subjects exercising their rights under applicable data-protection law.
Where the Provider receives a request directly from a data subject relating to personal data for which the Club is controller, the Provider will promptly inform the data subject to contact the Club unless the Provider is required by law to respond directly.
The Club is responsible for verifying the identity of the requester and for deciding how to respond.
11. Personal Data Breaches
The Provider will notify the Club without undue delay after becoming aware of a personal data breach affecting personal data processed by the Provider on behalf of the Club.
The notification will, to the extent known to the Provider at that time, describe:
- the nature of the breach;
- the categories and approximate number of data subjects and personal data records concerned, where possible;
- the likely consequences; and
- the measures taken or proposed to address the breach.
The Provider will provide reasonable further information as it becomes available and will assist the Club with the Club's breach-notification obligations to supervisory authorities and data subjects, where required and taking into account the nature of processing and the information available to the Provider.
12. Impact Assessments and Prior Consultation
The Provider will provide reasonable assistance to the Club with data-protection impact assessments and prior consultations with supervisory authorities where the Club is required to carry them out, taking into account the nature of processing and the information available to the Provider.
13. Return and Deletion of Data
When the Club's subscription ends, the provisions of the SaaS Agreement on data retention, export and deletion apply.
During any post-termination retention period stated in the SaaS Agreement, the Club may request export of relevant personal data in a format supported by the Service.
After that period, the Provider will delete personal data processed on behalf of the Club, unless applicable law requires storage or the SaaS Agreement permits continued retention.
The following may be retained after deletion of the Club's ordinary Service data, as permitted by the SaaS Agreement and applicable law:
- Competition Data that the Provider is entitled to retain and publish;
- platform-level or cross-Club account and profile data that is not exclusively controlled by the Club; and
- backups until they are overwritten in the ordinary course of operation, subject to the backup limitations in the SaaS Agreement.
Upon written request, the Provider will confirm deletion of the Club's personal data when completed, unless confirmation is not reasonably possible because of technical limitations or legal retention duties.
14. Audits and Information
The Provider will make available to the Club information reasonably necessary to demonstrate compliance with this DPA.
The Club may audit the Provider's compliance with this DPA no more than once per calendar year, unless required by a supervisory authority or a confirmed personal data breach makes an additional audit reasonably necessary.
Audits will be conducted:
- on reasonable advance notice;
- during normal business hours;
- in a way that does not unreasonably disrupt the Provider's operations or the Service for other customers; and
- subject to appropriate confidentiality restrictions.
The Club may satisfy an audit request by accepting a recent third-party audit report or certification reasonably covering the Service, if the Provider makes such a report available.
15. International Transfers
The Provider processes personal data primarily within the European Union or European Economic Area.
If personal data is transferred to a country outside the EU/EEA, the Provider will ensure that appropriate safeguards are in place as required by applicable data-protection law, such as an adequacy decision or standard contractual clauses approved by the European Commission.
The Club may request information about relevant transfer safeguards on reasonable grounds.
16. Changes to This DPA
The Provider may update this DPA to reflect changes in law, regulatory guidance, subprocessors or the Service.
Unless a change is required earlier by law or another compelling reason, materially revised terms will normally apply from the beginning of a future subscription period. The Provider will make the revised DPA available to the Club before the Club renews its subscription.
Payment for a new subscription period after the revised DPA has been made available constitutes acceptance of the revised DPA.
17. Governing Law and Disputes
This DPA is governed by the laws of Finland, without regard to conflict-of-law rules that would require the application of another country's law.
Disputes relating to this DPA are resolved in accordance with the dispute-resolution provisions of the SaaS Agreement.
18. Term
This DPA takes effect when the SaaS Agreement becomes effective and remains in effect for as long as the Provider processes personal data on behalf of the Club under the SaaS Agreement, and for any period afterwards during which the Provider retains or processes such data in accordance with this DPA or the SaaS Agreement.