Skip to main content

Data Processing Agreement

Version 2.0. Published 12 August 2026.

This DPA forms part of the Organisation Subscription Terms and applies to an organisation from the date it subscribes. It is published for review before subscribing.

This Data Processing Agreement (“DPA”) is between Badminton Clubhouse Ltd (company number 17391781, England and Wales; “BC”) and the Organisation. Defined terms follow the Agreement. “Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003 and successor legislation, as amended.

1. Roles and scope

1.1 For personal data in Organisation Data (“Member Data”), the Organisation is controller and BC is its processor. 1.2 BC is an independent controller for: (a) platform user accounts; (b) the Organisation’s billing and administrative contacts; (c) processing in BC’s own legitimate interests in the safety and integrity of the Service, including welfare holds (applied with human review) and their audit trail. 1.3 BC determines the means of the anonymisation process instructed under 2.2(b) only as processor; the anonymised output is not personal data and no party is its controller. 1.4 Controller obligations: the Organisation will have a lawful basis (and any required condition) for Member Data; provide its members with privacy information covering this DPA’s processing, including the aggregation instruction in 2.2(b), using or covering the substance of the notice wording BC supplies (and warrants that it has done so); keep Member Data accurate; give lawful instructions; and handle its members’ requests. BC also surfaces its own privacy information to members directly in the Service, including the aggregation description and objection route. 1.5 Processing details are in Annex 1.

2. Processing on instructions

2.1 BC processes Member Data only on the Organisation’s documented instructions, including with regard to transfers to a third country or international organisation, unless required otherwise by law applying to BC (in which case BC informs the Organisation unless prohibited). 2.2 The documented instructions are: (a) provide the Service per the Agreement and the Organisation’s configuration; (b) as a standing instruction, aggregate and anonymise Member Data per clause 9 of the Agreement; (c) disclose competition participation data per clause 10.4 of the Agreement; (d) further agreed written instructions. The standing instruction is withdrawable with prospective effect. 2.3 For 2.2(b): the Organisation’s Article 6 basis is its legitimate interest in understanding and demonstrating participation; for special category fields the parties rely on Article 9(2)(j) with DPA 2018 Schedule 1 paragraph 4 and the section 19 safeguards (statistics only, no measures or decisions about individuals, no substantial damage or distress); under-18 records are excluded from commercial aggregation inputs per clause 9.2(b) of the Agreement. 2.4 BC informs the Organisation if an instruction appears to infringe Data Protection Law.

3. Special category and criminal offence data

3.1 The Service can hold emergency medical notes (Article 9) and criminal records check status and safeguarding records (Article 10). 3.2 The Organisation is responsible for its own condition: ordinarily DPA 2018 Sch 1 Part 2 para 18 (safeguarding) for safeguarding data, and the data subject’s explicit consent (Article 9(2)(a)), captured by the Service, for medical notes. BC’s Appropriate Policy Document covers BC’s own processing only and does not satisfy the Organisation’s obligation to maintain its own where required; BC provides a template. 3.3 BC maintains its own Appropriate Policy Document for its Article 10 processing, available on request. 3.4 The Annex 2 safeguards apply, including exclusion of this data from all aggregation. 3.5 The Service records check outcomes and dates only (including the re-check due date); certificates and disclosure content must not be uploaded; BC does not carry out checks or Update Service status checks.

4. Confidentiality

Every person BC authorises to process Member Data is subject to a contractual or statutory duty of confidentiality.

5. Security

BC implements and maintains the measures in Annex 2 without material degradation, designed to ensure security appropriate to the risk.

6. Sub-processors

6.1 General written authorisation for the Annex 3 sub-processors and changes. 6.2 At least 30 days’ email notice of additions or replacements (plus the published list); on an unresolved reasonable objection, the Organisation may terminate the affected subscription with a pro-rata refund. 6.3 BC imposes on each sub-processor the same data protection obligations as this DPA, or no less protective, and remains fully liable for their performance. 6.4 Payment providers (Stripe, GoCardless) are not sub-processors: they act under the Organisation’s own agreements and are independent controllers for their own regulatory obligations.

7. Data subject rights

BC assists the Organisation through the Service’s built-in export, rectification and erasure tools (no additional charge) and refers direct requests to the Organisation without undue delay.

8. Personal data breach

8.1 BC notifies the Organisation without undue delay, and in any event within 48 hours of confirming a breach affecting Member Data, with the information needed for the Organisation’s Articles 33 and 34 obligations (nature, categories and approximate numbers, BC’s data protection contact, likely consequences, measures), initially with what is then known and supplemented as available. 8.2 BC cooperates and mitigates; will not notify the Information Commissioner or data subjects on the Organisation’s behalf unless instructed or legally required; may delay notification where required by law enforcement. Notification is not an admission.

9. DPIAs and consultations

BC provides reasonable assistance with data protection impact assessments and prior consultation under Articles 35 and 36.

10. Deletion and return

10.1 The Organisation can export Member Data at any time via the Service’s export tools or, until tenant-level bulk export ships, by written request fulfilled within 14 days. 10.2 On termination, after the export window, BC will at the Organisation’s choice return Member Data (CSV per entity plus documented JSON) or delete it (deletion by default), and delete remaining copies except: (a) Aggregated Data already created; (b) legally required records per the published Retention Schedule; (c) encrypted backups clearing within 90 days, to which this DPA continues to apply. 10.3 Written confirmation of deletion on request.

11. Audit and information

11.1 Subject to 11.2, BC makes available the information necessary to demonstrate Article 28 compliance and allows and contributes to audits and inspections. 11.2 Documentation and attestations first; an interactive or on-site audit once per 12 months, 30 days’ notice, business hours, at the Organisation’s cost (including BC’s reasonable costs), under confidentiality, excluding other customers’ data. The limits and cost recovery do not apply after a breach affecting the Organisation’s Member Data or where a supervisory authority requires an audit, and BC bears its own costs where material non-compliance by BC is found.

12. International transfers

12.1 Member Data is stored at rest in the EU (Supabase, eu-west-1, Ireland); some processing occurs where sub-processors’ personnel or infrastructure are located (Annex 3). 12.2 Each restricted transfer is covered by the EU Standard Contractual Clauses with the UK International Data Transfer Addendum (as incorporated in the sub-processor’s terms), supported by a transfer risk assessment on the ICO’s methodology, retained by BC; copies of safeguards available on request. 12.3 No other restricted transfers without a valid mechanism. 12.4 Government access: on a legally binding public-authority request for Member Data, BC notifies the Organisation unless prohibited, uses reasonable lawful efforts to redirect or challenge overbroad requests, discloses the minimum required, and where notification is prohibited seeks a waiver and keeps a record.

13. Liability and precedence

This DPA forms part of the Agreement. It prevails on the subject matter of processing, BC’s processing obligations and roles; clause 14 of the Agreement (including its 14.4 exceptions) governs all liability and prevails over this DPA in relation to liability.

Annex 1: Details of processing

  • Subject matter and duration: provision of the platform for the term plus the export, deletion and backup periods; the 2.2(b) anonymisation instruction runs during the term and the anonymised output is retained indefinitely (not personal data).
  • Nature and purposes: hosting, storage, display, transmission, backup, member administration, communications, event and competition administration, payment-status reconciliation, safeguarding administration, aggregation and anonymisation, competition data disclosure.
  • Data subjects: members and former members; junior members (via guardian-managed profiles); guardians and emergency contacts; officers, volunteers and coaches; visitors and event attendees. Data subjects of other organisations in a shared competition are processed under those organisations’ own agreements (Agreement clause 10.4).
  • Personal data: identity and contact data; membership records; attendance and participation; team, fixture and result data; payment metadata (no cardholder data); communications; photographs (consent-gated).
  • Special categories: emergency medical notes (explicit consent); safeguarding concerns; equality-monitoring fields (ethnicity, disability) where recorded, for statistics only under 2.3.
  • Criminal offence data: check outcome, level, issue date, Update Service flag, re-check due date; safeguarding case records that may reference alleged conduct.

Annex 2: Technical and organisational measures

  • Encryption in transit (TLS 1.2+) and at rest.
  • Row-level security on every tenant-scoped table; role-based access per club, association and county; multi-factor authentication on platform-administrative access.
  • Passwords stored only as salted hashes.
  • Safeguarding materials in private storage behind short-lived signed URLs; safeguarding data excluded from all aggregation.
  • Append-only audit logging; where an erasure right applies, identifiers within entries are pseudonymised rather than entries deleted.
  • Statistical disclosure control applied before any external disclosure, per the version-controlled Statistical Disclosure Control Policy (minimum cell sizes, complementary suppression, differencing controls, higher thresholds for under-18 and named-organisation outputs), enforced at the database function layer.
  • Under-18 records excluded from commercial aggregation inputs, enforced at the point of aggregation with automated tests.
  • Junior-specific measures: default-private visibility for under-18 profiles; guardian mediation; the 18th-birthday transition workflow.
  • Production/non-production segregation; restricted, logged production access.
  • Encrypted rolling backups (max 90 days); tested disaster recovery.
  • Regular testing and evaluation of these measures (Article 32(1)(d)), including dependency and vulnerability scanning; documented incident response plan.
  • Sub-processor due diligence and contractual flow-down.

Annex 3: Approved sub-processors

  • Supabase, Inc. (US): database, authentication, storage. Data at rest in the EU (Ireland) on AWS; US support access covered by EU SCCs with UK Addendum (Supabase DPA); TRA on file.
  • Vercel, Inc. (US): hosting, serverless functions, cookieless analytics. EU SCCs with UK Addendum (Vercel DPA); function region and TRA on file.
  • Brevo (Sendinblue SAS, FR): transactional and bulk email. EU; UK-EEA adequacy.

The list is maintained as complete; additions are notified under clause 6.2. Stripe and GoCardless are the Organisation’s own providers, not sub-processors. No personal data is currently shared with any governing body; any such sharing would be notified under 6.2 or documented as an Organisation instruction.


Badminton Clubhouse Ltd · Company number 17391781 (England and Wales) · Registered office: Vicarage Court, 160 Ermin Street, Swindon, England, SN3 4NE · privacy@badmintonclubhouse.com