Data Processing Agreement
Version: 1.1 Effective date: 6 September 2026 (the date this version was first published on thefullsquad.com)
Changes in 1.1: clause 15 (the special-category clause is extended to injury, suspension and safeguarding-concern records, decision 276); Annex 1 A1.3 and A1.5 (new categories of Processing and Personal Data are added for training sessions and attendance, staff qualification/credential tracking, match events, imported-person provenance, club events and RSVPs, audit "before" snapshots, and injury, suspension and safeguarding-concern records, decisions 265, 266, 267, 272, 273, 274, 275, 276, 287; Squad Assist and AI-assisted import mapping are described as not yet available, decisions 279 and 272); Annex 2 A2.10 (Squad Assist not yet available); Annex 3 (Anthropic's appointment is described as not yet active, decision 279).
Between the subscribing Club (the "Club", acting as Controller) and Reload IT Ltd (the "Provider", acting as Processor)
This Data Processing Agreement (the "DPA") forms part of, and is incorporated into, the Platform Terms of Service (the "Terms") between the Provider and the Club for the use of The Full Squad platform. It takes effect on the date the Club accepts the Terms and applies for as long as the Provider Processes Personal Data on the Club's behalf.
Plain-English summary (not part of the operative terms): your club decides why and how your members' data is used — the law calls the club the "controller". Reload IT Ltd runs the software and stores the data strictly on your club's behalf and on your instructions — the law calls us the "processor". This document sets out the rules both sides must follow under UK data protection law, including for children's data, medical information and safeguarding records. Reload IT provides software only; every footballing, coaching, childcare and safeguarding duty stays with the club.
1. Parties
1.1 The Provider: Reload IT Ltd, a company registered in England and Wales with company number 10106178, whose registered office is at Moor Park House, Bawtry Road, Wickersley, Rotherham, South Yorkshire, S66 2BL. The Provider is registered with the Information Commissioner's Office under registration number ZC200891. Contact for data protection matters: info@thefullsquad.com.
1.2 The Club: the club, association or organisation identified in the Club's account on the Platform, being the entity (or, where the Club is an unincorporated association, the members and officers of that association — see clause 17) that has accepted the Terms.
2. Definitions and Interpretation
2.1 In this DPA the following terms have the following meanings. Terms defined in the Terms have the same meaning here unless redefined below.
- "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" (and "Process"), "Special Category Data" and "Supervisory Authority" have the meanings given to them in Data Protection Law.
- "Data Protection Law" means the UK GDPR (as defined in the Data Protection Act 2018), the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, the Data (Use and Access) Act 2025 to the extent relevant to the Processing, and any other applicable law of England and Wales relating to the Processing of Personal Data, each as amended or replaced from time to time.
- "Club Data" means all Personal Data that the Provider Processes on behalf of the Club in connection with the Platform, as described in Annex 1. Club Data does not include Personal Data for which the Provider is itself the Controller (see clause 3.4).
- "Platform" means The Full Squad software-as-a-service platform made available at thefullsquad.app (including club tenant subdomains in the form {club}.thefullsquad.app and any custom domain a club connects) together with related services provided under the Terms.
- "Sub-processor" means any third party appointed by the Provider to Process Club Data on the Club's behalf.
- "UK IDTA" means the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, and "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses so issued, in each case as amended or replaced from time to time.
2.2 Headings are for convenience only. References to clauses and Annexes are to clauses of and Annexes to this DPA. The Annexes form part of this DPA.
2.3 If there is a conflict between this DPA and the Terms in relation to the Processing of Club Data, this DPA prevails to the extent of the conflict. Nothing in this DPA increases the Provider's liability beyond, or otherwise displaces, the exclusions and limitations of liability in the Terms, except as clause 16.2 requires by law.
3. Roles of the Parties
3.1 The parties agree that, for the purposes of Data Protection Law, in respect of Club Data the Club is the Controller and the Provider is the Processor.
3.2 The Club decides why Club Data is collected and how it is used. The Provider Processes Club Data only on the Club's behalf and only as this DPA and the Club's Documented Instructions (clause 4) allow.
3.3 Software provider only. The Provider is a software provider only. Nothing in this DPA makes the Provider a provider of footballing, coaching, childcare or safeguarding services, and nothing in this DPA transfers to the Provider any of the Club's legal or operational duties towards its members, including its duties as Controller, its safeguarding duties, and its duty to have a lawful basis (and, where required, an Article 9 UK GDPR condition) for every category of Club Data it collects. No Platform feature, alert, report, template or default setting creates a duty of care owed by the Provider to the Club, its members or anyone else, and the presence, absence or failure of any such feature transfers no responsibility to the Provider.
3.4 For the avoidance of doubt, the Provider acts as an independent Controller — and this DPA does not apply — in respect of: (a) club administrator and billing account data held for the Provider's own contract with the Club; (b) marketing-site visitor data; (c) support tickets raised with the Provider; and (d) the Provider's own business records. That Processing is described in the Provider's Platform Privacy Policy.
3.5 Anonymised and aggregated data. The Provider may create and use data that has been fully anonymised or aggregated so that it is no longer Personal Data and no individual (or club) can be identified from it, for the purposes of operating, securing, benchmarking and improving the Platform. Such data is not Club Data and this DPA does not apply to it. The Provider does not use Club Data relating to persons under 18 for enrichment from web or other external sources.
4. Documented Instructions
4.1 The Provider shall Process Club Data only on the Club's documented instructions (the "Documented Instructions"), including with regard to transfers of Club Data outside the United Kingdom, unless Processing is required by law to which the Provider is subject; in that case the Provider shall inform the Club of that legal requirement before Processing, unless that law prohibits it on important grounds of public interest.
4.2 The parties agree that the Documented Instructions are:
(a) this DPA, including Annex 1; (b) the Terms; (c) the Club's use and configuration of the Platform through its documented features (for example: registering members, uploading the Club's own onboarding terms and conditions, configuring retention periods, configuring consent texts, granting or revoking role-based access, initiating exports, and actioning data-subject requests through the Platform); and (d) any further written instructions agreed between the parties.
4.3 The Provider shall inform the Club without undue delay if, in the Provider's opinion, a Documented Instruction infringes Data Protection Law. The Provider is not obliged to carry out an instruction it reasonably believes to be unlawful, and may suspend the affected Processing until the instruction is confirmed, varied or withdrawn. The Provider provides this information as a processor safeguard only; it is not legal advice, and the Provider gives no warranty and assumes no duty that it will detect an unlawful instruction. Responsibility for the lawfulness of all instructions remains with the Club at all times.
4.4 An instruction that falls outside clause 4.2 (including any bespoke Processing, non-standard export or non-standard configuration), or that would involve categories of Personal Data or Data Subjects beyond those described in Annex 1, may be declined, or accepted subject to reasonable additional charges and a written change to this DPA.
5. Club Obligations and Warranties
5.1 The Club warrants and undertakes that:
(a) it is, and will remain, the Controller of the Club Data and has authority to instruct the Provider to Process it; (b) it has, and will maintain, a lawful basis under Article 6 UK GDPR for all Processing of Club Data it instructs, and — for Special Category Data such as medical and safeguarding information — an applicable condition under Article 9(2) UK GDPR and, where required, Schedule 1 of the Data Protection Act 2018; (c) it has provided Data Subjects (including parents and guardians on behalf of children) with all required transparency information, including a privacy notice (the Platform provides a template the Club may adapt; the notice, as issued, remains solely the Club's responsibility); (d) it has obtained, recorded and will keep up to date all consents its Processing requires, including consents relating to children in line with the Platform's age model (Annex 1, A1.6) and the Club's own legal duties; (e) the Club Data it uploads or causes to be collected is accurate, relevant and lawfully obtained, and its Documented Instructions will comply with Data Protection Law; (f) it will configure and use the Platform's data protection features (access roles, retention settings, consent versions) appropriately for its own compliance; (g) it will maintain a data-protection complaints process that facilitates complaints by Data Subjects, acknowledges them within the statutory period, investigates them appropriately and communicates outcomes without undue delay; and (h) it will not instruct or cause the Processing of categories of Personal Data or Data Subjects materially beyond those described in Annex 1 without first agreeing a written change under clause 4.4.
5.2 The Club acknowledges that the Provider has no visibility of, and no responsibility for, the Club's operational relationship with its members, and that the Provider cannot and does not verify the accuracy or lawfulness of Club Data or of the Club's instructions.
5.3 Authorised users act for the Club. Every person the Club authorises to access Club Data through the Platform (including officers, committee members, managers, coaches, staff and volunteers) accesses it on the Club's behalf. Their acts and omissions in relation to Club Data — including what they view, record, export or disclose — are treated as the Club's acts and omissions for the purposes of this DPA. The Club is responsible for choosing, training and supervising its authorised users and for revoking access promptly when no longer appropriate.
5.4 Club-uploaded terms. Where the Club uploads its own onboarding terms and conditions or other membership documents for presentation and acceptance through the Platform, the Platform hosts, versions and records acceptance of those documents as a Processing operation on the Club's instructions only. Those documents, their content and their legal effect are solely the Club's responsibility; the Provider does not review, approve or warrant them.
6. Confidentiality
6.1 The Provider shall ensure that every person it authorises to Process Club Data (including its employees and contractors) is subject to a binding obligation of confidentiality (contractual or statutory) in respect of that data, and Processes Club Data only as needed to perform the Provider's obligations under the Terms and this DPA.
6.2 The Provider shall limit access to Club Data to personnel who need it to operate, support, secure or improve the Platform, in line with the access controls in Annex 2.
7. Security
7.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risks to Data Subjects, the Provider shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 UK GDPR. The measures in place at the date of this DPA are described in Annex 2.
7.2 The parties acknowledge that the risk profile of the Club Data is elevated because it includes children's data and Special Category Data (medical and safeguarding records), and Annex 2 reflects that: UK-resident storage, encryption in transit and at rest, role-based tenant-scoped access, private storage buckets for sensitive files, and audit logging of access to sensitive records.
7.3 The Provider may update the Annex 2 measures from time to time, provided the updates do not materially reduce the overall level of protection for Club Data during the term of this DPA.
7.4 The Club is responsible for the security of matters within its own control, including: the devices and networks its officers, volunteers and members use; the strength and confidentiality of account credentials; its choice of who is granted which role on the Platform (clause 5.3); and the handling of any Club Data it exports out of the Platform. Exported data leaves the Platform's protections, and its subsequent security, storage and use are entirely the Club's responsibility.
8. Sub-processors
8.1 General authorisation. The Club gives the Provider general written authorisation to appoint Sub-processors to Process Club Data. The Sub-processors currently appointed are listed in Annex 3.
8.2 Change notice. The Provider shall give the Club at least 30 days' notice (by email to the Club's administrator account and/or notice within the Platform) before adding or replacing a Sub-processor that will Process Club Data.
8.3 Objection right. If the Club objects on reasonable data protection grounds to a new or replacement Sub-processor within that 30-day period, the parties shall discuss the objection in good faith. If the Provider cannot reasonably accommodate the objection (for example by not using the Sub-processor for that Club's data), the Club may terminate its subscription in respect of the affected services by written notice, in which case the Provider shall refund any prepaid fees for the period after termination. This right of termination and refund is the Club's sole and exclusive remedy for a Sub-processor change or objection. Continued use of the Platform after the notice period without objection constitutes acceptance of the change.
8.4 Flow-down. The Provider shall appoint each Sub-processor under a written contract imposing data protection obligations that provide materially the same level of protection for Club Data as this DPA, in particular the obligations of Article 28(3) UK GDPR. The Provider remains fully liable to the Club for the performance of each Sub-processor's data protection obligations, subject always to the exclusions and limitations in clause 16.
9. International Transfers
9.1 The Provider's primary storage of Club Data is in the United Kingdom (Supabase, AWS eu-west-2, London) — see Annex 2.
9.2 The Provider shall not transfer Club Data outside the United Kingdom (and shall not permit a Sub-processor to do so) unless the transfer is:
(a) to a country or territory covered by UK adequacy regulations under section 17A of the Data Protection Act 2018; or (b) subject to appropriate safeguards under Article 46 UK GDPR, being the UK IDTA or the UK Addendum (as applicable), together with any supplementary measures reasonably required; or (c) otherwise permitted by Data Protection Law.
9.3 Certain Sub-processors listed in Annex 3 (for example payment processing, email delivery, hosting and AI-assisted features) may Process limited Club Data outside the United Kingdom under the safeguards in clause 9.2. The Club's general authorisation in clause 8.1 extends to those transfers on those terms.
10. Assistance with Data Subject Rights
10.1 Taking into account the nature of the Processing, the Provider shall assist the Club, by appropriate technical and organisational measures and insofar as reasonably possible, in fulfilling the Club's obligations concerning Data Subject rights under UK data-protection law.
10.2 The Platform provides a My Data / Privacy Request route through which a Data Subject (or linked parent/guardian where appropriate) may submit an access, correction or deletion request. Requests concerning Club Data are routed to the relevant Club as Controller and the request/action history is audit logged.
10.3 The Club remains responsible for assessing and answering the request within the statutory deadline. Where a request cannot be fulfilled through ordinary Platform functions, the Provider will provide reasonable processor assistance.
10.4 Club exports. A Club-wide export is not self-service at launch. On a normal written export request, the Provider will make the requested Club Data available in a commonly used electronic format within 5 working days. Unusually complex, repeated or bespoke export work may be subject to reasonable charges agreed in advance, except where Data Protection Law requires assistance without additional charge.
11. Personal Data Breach
11.1 The Provider shall notify the Club without undue delay after becoming aware of a Personal Data Breach affecting Club Data. The Provider's operational target is to provide the Club with an initial notification within 24 hours of becoming aware. That target is given in good faith to preserve time for the Club to assess its own notification duties and is not a contractual guarantee; the binding obligation remains notification without undue delay. Initial notification may be supplemented in phases as further information becomes available.
11.2 The notification shall, to the extent then known (and may be supplemented in phases as information becomes available), describe: the nature of the breach; the categories and approximate numbers of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point.
11.3 The Provider shall provide reasonable cooperation and assistance to the Club in the Club's investigation of the breach and in the Club's compliance with its own obligations under Articles 33 and 34 UK GDPR.
11.4 Notifying the Information Commissioner and affected Data Subjects in respect of Club Data is the Club's obligation as Controller, and the Club decides whether such notification is required. The Provider shall not notify a Supervisory Authority or Data Subjects of a breach affecting Club Data on the Club's behalf unless required by law or agreed in writing.
11.5 The Provider's notification of, or assistance with, a Personal Data Breach is not an admission of fault or liability by the Provider.
11.6 Where a Personal Data Breach arises from the acts or omissions of the Club or its authorised users (for example compromised Club credentials, misconfigured Club roles, or misuse of exported data), the Provider may charge reasonable fees for its assistance under this clause 11 at its then-current rates, and the Club's indemnity in clause 16.5 applies.
12. DPIAs and Prior Consultation
12.1 Taking into account the nature of the Processing and the information available to it, the Provider shall provide reasonable assistance to the Club with data protection impact assessments under Article 35 UK GDPR and with prior consultation of the Information Commissioner under Article 36 UK GDPR, in each case solely in relation to the Processing of Club Data on the Platform.
12.2 The Provider's assistance under this clause 12 will ordinarily be satisfied by making available this DPA, its Annexes and the Provider's standard security and Sub-processor documentation. Material additional work may be charged under clause 10.4 as if it were rights assistance. Conducting, adopting and acting on any DPIA remains the Club's responsibility as Controller.
13. Return and Deletion at End of Processing
13.1 On termination or expiry of the Terms, the Provider shall, at the Club's choice and subject to law, return and/or delete Club Data as follows:
(a) Export window: for 30 days after termination/expiry, the Club may request an export. A normal request is fulfilled within 5 working days in one or more commonly used electronic formats.
(b) Live deletion: after the 30-day export window, the Provider deletes or anonymises Club Data from live systems in accordance with the retention machinery and the Club's documented instructions.
(c) Backup deletion: deleted data may remain in encrypted disaster-recovery backups for no more than a further 30 days, after which it cycles out of the backup rotation. Backup copies are not used for ordinary processing.
(d) Legal/safeguarding holds: data may be preserved where law requires it or where the Club gives a lawful documented instruction to preserve identified safeguarding, complaint, dispute or legal-hold material. Any retained copy remains protected by this DPA and is not used for unrelated purposes.
13.2 Before final deletion of a tenant containing children's records, the Provider will send prominent notice to the registered Club administrator/billing contact and provide a final opportunity to request export. Responsibility for identifying any longer safeguarding or legal retention remains with the Club.
13.3 On written request, the Provider shall confirm completion of the live-system deletion process.
14. Audit and Information
14.1 The Provider shall make available to the Club all information reasonably necessary to demonstrate compliance with its obligations under Article 28 UK GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Club or an auditor mandated by the Club, on the terms of this clause 14.
14.2 Documentation first. The Club agrees that the Provider satisfies its obligations under clause 14.1 in the first instance by providing: this DPA and its Annexes; the current Sub-processor list; summaries of security measures, policies and testing; and any third-party certifications, attestations or audit reports the Provider holds. The Club shall review such documentation before requesting any further audit.
14.3 On-site or remote inspection. Only where the documentation under clause 14.2 is reasonably insufficient to demonstrate compliance, or where an audit is required by a Supervisory Authority or by Data Protection Law, the Club may conduct an audit or inspection, subject to all of the following:
(a) not more than once in any 12-month period, except following a Personal Data Breach affecting the Club Data or where required by a Supervisory Authority; (b) at least 30 days' prior written notice, with a proposed scope agreed in advance; (c) during normal business hours, without unreasonable disruption to the Provider's business; (d) at the Club's cost, including reimbursement of the Provider's reasonable time and expenses in supporting the audit; (e) subject to the auditor (who must not be a competitor of the Provider) entering into reasonable confidentiality undertakings; and (f) not extending to any data of other clubs or tenants, any other customer's confidential information, or any matter that would compromise the security of the Platform; multi-tenant systems are audited by documentation, logs and interview rather than direct system access wherever direct access would create risk to other tenants.
14.4 The Club shall provide the Provider with a copy of any audit findings, which are the confidential information of both parties.
15. Special Category and Children's Data
15.1 The parties record that Club Data includes children's data and Special Category Data (medical and safeguarding records, extended to injury records, suspension records and safeguarding-concern records). The Platform's technical handling of that data is described in Annex 2 (private storage, gated and audited access, versioned consent records) and its account age model is summarised in Annex 1 (A1.6).
15.2 These features are technical measures only. They do not make the Club compliant with its safeguarding, welfare or data protection duties, and the Provider assumes no duty of care, no safeguarding role and no responsibility for the Club's decisions about who may access which records, what is recorded, or how long safeguarding records must be kept. The presence, absence or failure of any Platform feature, alert or report transfers no responsibility to the Provider (clause 3.3).
16. Liability and Indemnity
16.1 The Provider's liability. The Provider's total aggregate liability arising out of or in connection with this DPA (whether in contract, tort (including negligence), breach of statutory duty, under Data Protection Law as between the parties, or otherwise) is subject to the exclusions and limitations of liability set out in the Terms, including the aggregate cap of the fees paid by the Club in the 12 months preceding the event giving rise to the claim and the exclusion of indirect and consequential loss. This DPA does not create a separate or additional pool of liability beyond that cap.
16.2 Statutory carve-outs. Nothing in this DPA (or the Terms) excludes or limits either party's liability for: (a) death or personal injury caused by its negligence; (b) fraud or fraudulent misrepresentation; or (c) any other liability that cannot lawfully be excluded or limited.
16.3 Data Subjects and regulators. Nothing in this DPA excludes or limits any direct statutory right a Data Subject may have, or either party's liability to Data Subjects or Supervisory Authorities under Articles 82, 83 and 84 UK GDPR, which are allocated by Data Protection Law itself. As between the parties only, recovery of any such amounts from one another is governed by this clause 16.
16.4 Article 82 allocation. As between the parties, each party is responsible for the share of any compensation under Article 82 UK GDPR that corresponds to its own responsibility for the damage, as Article 82(5) contemplates. The Provider's share is subject to clause 16.1.
16.5 Club indemnity. The Club shall indemnify and hold harmless the Provider against all losses, claims, fines, penalties, damages and costs (including reasonable legal costs) suffered or incurred by the Provider arising out of or in connection with: (a) the Club's breach of its warranties and obligations in clause 5; (b) Processing carried out in accordance with the Club's Documented Instructions; (c) the Club's failure to comply with its own obligations as Controller (including transparency, lawful basis, consent, data-subject deadlines, and safeguarding-related retention decisions); or (d) the acts or omissions of the Club's authorised users (clause 5.3) — except in each case to the extent the loss is caused by the Provider's breach of this DPA or of its obligations as a Processor under Data Protection Law.
16.6 Cap protects the Provider only. The cap and exclusions referred to in clause 16.1 limit the Provider's liability. They do not limit: (a) the Club's liability under the indemnity in clause 16.5; or (b) the Club's obligation to pay fees and charges properly due under the Terms or this DPA.
17. Unincorporated Associations; Authority
17.1 Where the Club is an unincorporated association, the officer or committee member accepting the Terms and this DPA warrants that they are authorised by the Club's committee (or equivalent governing body) to bind the Club and its members for the time being, and accepts this DPA both on behalf of the Club and, to the extent the Club cannot be bound as an entity, on behalf of and binding the members of its committee from time to time.
17.2 The Club shall ensure that any change of committee or officers does not interrupt the discharge of its obligations under this DPA, and shall keep its administrator contact details on the Platform current, since notices under this DPA (including Sub-processor change notices under clause 8.2 and deletion notices under clause 13.2) are validly given to those details.
18. General
18.1 Duration. This DPA takes effect on acceptance of the Terms and continues until the Provider ceases to Process Club Data (including completion of deletion under clause 13), notwithstanding earlier termination of the Terms. Clauses 13, 16 and 18 survive termination.
18.2 Changes. The Provider may update this DPA on notice to the Club where reasonably required to reflect changes in Data Protection Law, ICO guidance, or the Platform's Sub-processors or architecture, provided the update does not materially reduce the protection of Club Data or the Club's rights under Article 28 UK GDPR. Other changes require agreement in accordance with the Terms.
18.3 Severance. If any provision of this DPA is or becomes invalid or unenforceable, it shall be deemed modified to the minimum extent necessary to make it valid and enforceable; if that is not possible, it is deemed deleted, and the remainder of this DPA continues in force. Any deemed modification or deletion shall not affect the validity of the rest of this DPA and shall preserve, so far as lawful, the parties' original commercial intent.
18.4 Third parties. Except as required by Data Protection Law, a person who is not a party to this DPA has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any of its terms.
18.5 Governing law and jurisdiction. This DPA and any dispute or claim arising out of or in connection with it (including non-contractual disputes or claims) are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1 — Details of Processing
A1.1 Subject matter. The Processing of Club Data by the Provider in the course of providing, supporting, securing and improving The Full Squad platform to the Club under the Terms.
A1.2 Duration. The term of the Terms, plus the export window and deletion process described in clause 13.
A1.3 Nature and purpose of Processing. Hosting, storage, backup, retrieval, display, transmission, structuring, organisation, analysis for the Club's own reporting, communication delivery (email and in-app), payment facilitation records (via Stripe Connect), hosting and versioning of the Club's own uploaded terms and conditions and recording their acceptance (solely the Club's documents, clause 5.4), consent versioning and acceptance records, training-session scheduling and attendance recording, staff qualification/credential tracking, match-event recording, imported-person provenance recording, club-event and RSVP recording, retention-schedule execution as configured by the Club, export, deletion, and such other operations as the Platform's documented features perform, in each case for the purpose of operating the Platform for the Club and on its instructions, and not for the Provider's own purposes (save as clause 3.5 permits for anonymised data). Squad Assist is not yet available; Anthropic is named as its intended sub-processor and will process Club Data only once Squad Assist launches, and only the data required for the requested feature. Squad Assist is designed not to receive medical records, safeguarding records, criminal-record-check information or other highly sensitive Club Data. The person import ships with manual, admin-driven column mapping first; if an AI-assisted import mapping accelerator is added later it will use column headings only or anonymised/redacted sample values and must not include identifiable Member Data or Special Category Data. The Platform does not use Club Data relating to persons under 18 for web enrichment. The Platform displays ticket information only; it does not sell match tickets online.
A1.4 Categories of Data Subjects.
- Members of the Club, including players who are children (see A1.6);
- Parents, guardians and other linked responsible adults;
- Club staff, officers, managers, coaches and volunteers;
- Supporters and other individuals whose data the Club records on the Platform.
A1.5 Categories of Personal Data.
- Identity and contact details (name, date of birth, address, email, phone);
- Family/guardian linkage and household relationships;
- Team, squad, registration, selection, availability and attendance data, including training-session and attendance records (with check-in/check-out times where recorded);
- Match events (scorers and cards, by player where recorded);
- Club events and RSVP responses (whole-club and team events, including an adult's own response);
- Imported-person provenance data (a marker that a record originated from an import, for data-quality and audit purposes);
- Staff qualification/credential tracking records (type, reference, check and renewal dates, and status; not certificates, see below);
- Photographs and video, subject to consent records held on the Platform;
- Communications sent and received through the Platform, including permitted message attachments;
- Payment-related records for club-collected money (payment status and history; card data is processed by Stripe, not stored by the Provider);
- Consent records (versioned texts, acceptance, withdrawal) and acceptance records for the Club's uploaded terms;
- Audit "before" snapshots (the prior state of a record, captured at the time of a change, for accountability);
- Special Category Data: optional medical information (extended to injury and suspension records) and welfare/safeguarding records where the Club chooses to use those features, including safeguarding-concern records held under a legal hold;
- Emergency contact details;
- Disciplinary records and restricted criminal-record-check verification metadata (status/reference/check/review dates, not scanned disclosure certificates);
- Audit and access logs relating to the above;
- Geolocation data only if a future location-dependent feature is enabled after the required privacy/DPIA review.
A1.6 Children's data and the age model. Date of birth is required for player/member records. Under 13: no independent login, managed through parent/guardian. Age 13-17: own login permitted only after a parent/guardian is linked and accepts the link; Club permissions remain age-appropriate. Under-18 private adult-to-child messaging is blocked and supervised group rules apply.
A1.7 Documented Instructions. As set out in clause 4.
Annex 2 - Technical and Organisational Security Measures
The Provider implements and maintains measures appropriate to the risk profile of a multi-tenant youth-sport platform, including:
A2.1 UK-primary hosting. Primary database, authentication and file storage are located in the United Kingdom where the relevant provider supports a UK region (currently Supabase/AWS London for primary Member Data storage). Supporting providers may process limited data internationally under clause 9 safeguards.
A2.2 Encryption. TLS or equivalent encryption in transit and storage/backups encrypted at rest. Messages are not end-to-end encrypted because authorised access may be required for reported-message, safeguarding, legal or security investigations.
A2.3 Tenant and Club separation. Logical multi-tenant separation, row-level/tenant-scoped controls and Club-context checks prevent one Club from accessing another Club's data. A global user may belong to multiple Clubs, but role and permission evaluation is performed separately for each Club.
A2.4 Role-based access. Fixed core roles include Club Admin, Safeguarding Officer, Coach/Manager, Player and Parent/Guardian. Additional custom roles may be supported but must not inherit sensitive permissions by default. Medical, safeguarding and criminal-record-check verification data is limited to specifically authorised roles; emergency-contact data may be team-scoped to relevant coaches/managers.
A2.5 Higher-risk authentication. Email/password authentication is used at launch. Multi-factor authentication is required for Club Admin and Safeguarding Officer roles. Invitations must be accepted and passwords set before account activation.
A2.6 Sensitive-data audit. Create, view, edit and delete activity for medical, safeguarding and DBS/PVG/AccessNI verification records is audit logged with user/action/time and relevant record context. DOB corrections, role changes, parent links and privacy-request actions are also auditable.
A2.7 Private storage and attachments. Sensitive files are held in non-public storage. Message attachments are subject to supported file-type/size restrictions and security/malware controls before distribution where technically practicable.
A2.8 Backups. Encrypted backups operate on a 30-day rotation. Data deleted from live systems cycles out of backups within a maximum further 30 days, subject to lawful holds.
A2.9 Secure development and operations. Version control, review before deployment, separation of production privileges, least-privilege access, monitoring/alerting, incident handling and prompt revocation of staff access on role change/departure.
A2.10 AI data minimisation. Squad Assist is not yet available; once launched it will be blocked from medical, safeguarding, criminal-record-check and other highly sensitive data. Import mapping ships manual and admin-driven first; if an AI-assisted mapping accelerator is added later it will use column headings or anonymised/redacted samples only, and special-category data and identifiable Member Data must not be included in AI samples.
A2.11 Children's privacy defaults. Under-18 public profile publication is off by default; geolocation is off by default and any future live-location feature requires a separate privacy/DPIA review before activation.
The Provider may improve or vary these measures under clause 7.3 provided the overall level of protection is not materially reduced.
Annex 3 — Approved Sub-processors
General authorisation under clause 8 covers the following Sub-processors as at the date of this DPA:
| Sub-processor | Service | Processing location(s) |
|---|---|---|
| Supabase | Database, authentication, file storage | United Kingdom (AWS eu-west-2, London) |
| Stripe | Payment processing (Stripe Billing; Stripe Connect for club-collected money) | UK / international, under Article 46 safeguards (clause 9) |
| Resend | Transactional and club email delivery | International, under Article 46 safeguards (clause 9) |
| Vercel | Application and site hosting | International, under Article 46 safeguards (clause 9) |
| Anthropic | AI-assisted features (Squad Assist and import column mapping), appointed now, not yet processing Club Data; will begin only once Squad Assist launches | International, under Article 46 safeguards (clause 9) |
| Sentry | Application error monitoring (error reports may contain limited personal data; disabled at launch until enabled) | International, under Article 46 safeguards (clause 9) |
An SMS provider has not yet been selected. Automated SMS must not be enabled until the selected supplier has completed the Provider's privacy/security review and, where it will Process Club Data, has been added to this list under clause 8.2. Changes to this list are notified under clause 8.2, and the Club's objection right in clause 8.3 applies.
End of Data Processing Agreement.
The canonical, machine-readable source for this document is held by Reload IT Ltd. Questions: info@thefullsquad.com.