CoachTools Data Processing Agreement
Review draft — operational schedules and acceptance process must be completed before use.
This Data Processing Agreement (DPA) forms part of the CoachTools service agreement between Plan&Care Sports Oy, Finnish Business ID 2845110-2, Lahti, Finland (the Processor), and the customer identified in the signed agreement or recorded online order (the Controller). It takes effect when that agreement or order is accepted. The Controller’s identity and notice contact are recorded with the order and form part of Schedule 1.
For a club subscription, the club is the contracting customer and an authorised club representative accepts this DPA. Individual team licenses are normally purchased without a separately signed agreement; a coach, team leader, treasurer or sponsor may pay. The payer is not automatically the controller or authorised to instruct the Processor. The individual or legal entity that determines the purposes of team-data processing and accepts this DPA on that controller’s behalf must be identified in Schedule 1 or in a recorded purchase/activation flow. A team name alone does not establish separate legal capacity. A federation using its own national-team view is a separate customer/controller; it does not thereby gain access to a club’s or team’s workspace.
This DPA applies to personal data processed by the Processor on behalf of the Controller through CoachTools (the Customer Data). Plan&Care Sports Oy acts as an independent controller for its own billing, customer relationship, support administration, account security and legal records; those activities are described in its privacy notice and are outside this DPA to the extent they are genuinely its own controller activities. The allocation of roles follows the parties’ actual decisions about processing, regardless of contractual labels.
If a conflict concerns Customer Data, this DPA prevails over the service agreement. The service agreement governs other commercial matters. This DPA does not itself provide a transfer mechanism for transfers of personal data outside the EEA.
1. Scope and instructions
- The subject matter, duration, nature and purposes of processing, categories of people and types of data are set out in Schedule 1. Processing lasts for the service term and any agreed return, deletion and backup wind-down period.
- The Controller instructs the Processor to process Customer Data only as needed to supply the functions selected and configured by the Controller, maintain and secure the service, provide requested support, and perform the specific operations in this DPA and its schedules. The service agreement, configuration choices and written requests through the designated support channel (currently dev@coachtools.net) are documented instructions insofar as they are consistent with this DPA. The Processor shall not use Customer Data for its own advertising, independent athlete profiling or unrelated purposes.
- The Processor shall process Customer Data only on documented instructions, including for a transfer to a third country, unless Union or Member State law requires otherwise. In that case it shall inform the Controller of the legal requirement before processing unless the law prohibits that notice on important grounds of public interest.
- The Processor shall promptly inform the Controller if it considers an instruction to infringe applicable EU or Member State data protection law. It may suspend the disputed instruction while the parties resolve it. The Controller is responsible for its own lawful basis, any Article 9 condition for health information, transparency notices, role assignments, access decisions and instructions to its staff and users.
- The Controller shall use the service in accordance with data-minimisation and access-control principles. User-created questionnaires, absence reasons and free text can contain health or injury information; the service does not block such disclosure. No use of the app alone constitutes explicit consent to such processing.
2. Personnel and security
- The Processor shall ensure that persons authorised to process Customer Data are bound by confidentiality or an appropriate statutory duty and receive access only as needed for their tasks.
- The Processor shall implement and maintain appropriate technical and organisational measures under Article 32 GDPR, taking account of the risks presented by children’s data, feedback, possible health information, messages and media. The agreed measures are described in Schedule 2. The Processor may update measures without materially reducing the overall level of protection and shall notify the Controller of material changes affecting protection.
- The Controller controls its own users, team and club roles, invitation decisions and content-sharing settings. The parties shall cooperate on access issues that arise from the platform’s design or implementation.
3. Subprocessors
- The Controller grants general written authorisation for the subprocessors listed in Schedule 3 solely for their stated services. The Processor shall maintain an up-to-date versioned list on the CoachTools website at the URL identified in the service agreement or order confirmation, including identity, service, processing location and relevant safeguards.
- The Processor shall give the Controller 30 days’ advance written notice of an intended addition or replacement by email to the designated customer contact and by updating the list. The Controller may object on reasonable data-protection grounds within 15 days. The parties shall work in good faith on a practical alternative. If no reasonable alternative is available, the Controller may terminate the affected service before the change takes effect, subject to the service agreement’s rules on prepaid fees. No objection is treated as approval of an unlawful transfer.
- The Processor shall impose data-protection obligations on each subprocessor that provide at least the protection required by this DPA for the relevant processing. The Processor remains responsible to the Controller for each subprocessor’s performance of those obligations.
4. International transfers
- The parties shall record in Schedule 3 any transfer or remote access outside the EEA, its destination, the relevant importer and the applicable transfer mechanism. Use of AWS regions in Stockholm and Frankfurt does not, by itself, establish EEA-only processing for CloudFront, Firebase messaging, support or provider access.
- The Processor shall not cause a restricted transfer of Customer Data outside the EEA without documented authorisation, an applicable Chapter V GDPR mechanism and any supplementary assessment or measures required in the circumstances. Where the Processor contracts with a non-EEA subprocessor, it shall put the appropriate transfer arrangement in place and make relevant information available to the Controller on request.
- The Article 28 controller-processor clauses in this DPA are distinct from the European Commission’s standard contractual clauses for international transfers. If transfer SCCs are needed, the relevant parties, module and appendices shall be completed separately; this paragraph does not incorporate unsigned clauses by implication.
5. Assistance and requests
- Taking account of the nature of processing and information available, the Processor shall assist the Controller with requests to access, correct, erase, restrict, port or object to processing of Customer Data. It shall not respond substantively on the Controller’s behalf unless authorised or legally required. Requests received directly from an athlete, guardian or other person shall be forwarded without undue delay to the Controller’s designated privacy contact, unless the request concerns data for which Plan&Care Sports Oy is itself controller.
- The Processor shall provide reasonable assistance with security obligations, assessment and notification of personal-data breaches, data protection impact assessments and prior consultations under Articles 32–36 GDPR. The parties shall agree any extraordinary assistance fees in the service agreement, without limiting assistance required by law.
- The Controller decides whether to notify a supervisory authority or affected people concerning its Customer Data. The Processor shall promptly provide available information and updates needed for that decision.
6. Personal-data breaches
- The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data, using the customer’s designated security contact. The Processor’s security contact is dev@coachtools.net (Ari-Pekka Piiparinen). The initial notice will be sent as soon as possible with the facts then available, followed by updates.
- As information becomes available, the notice shall describe the nature of the incident, likely categories and approximate numbers of affected people and records where known, likely consequences, measures taken or proposed, and a contact point. The Processor shall cooperate on containment, investigation and remediation and document the incident.
- The Processor shall not notify an authority or affected person on the Controller’s behalf without instruction, unless law requires it. Independent controller obligations of Plan&Care Sports Oy remain its own responsibility.
7. Demonstrating compliance and audits
- The Processor shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, including relevant policies, a current subprocessor list and suitable independent audit material if available.
- The Processor shall allow for and contribute to audits, including inspections by the Controller or an independent auditor it mandates, subject to reasonable advance notice, confidentiality, protection of other customers’ data and appropriate security rules. The parties shall first seek to use available documentation and remote review when sufficient. This does not remove the statutory audit right.
- The Processor shall inform the Controller if it believes an audit instruction infringes data protection law.
8. Return, deletion and end of service
- At the end of processing services, at the Controller’s choice, the Processor shall return or delete Customer Data and delete existing copies unless Union or Member State law requires storage. The Controller may give its choice through its designated contact to dev@coachtools.net. Individual drills and plans can currently be exported to PDF. For other Customer Data, the Processor shall provide a reasonable export under Schedule 4. A separately agreed fee may apply to additional custom preparation or conversion, without limiting the return/deletion duties in this DPA.
- During the service term, the Processor shall follow documented deletion instructions for Customer Data subject to technical feasibility, legitimate obligations and the Controller’s own duties. Removing a user’s account or membership is not necessarily the same as deleting all Controller-owned historical records. The Processor shall assist the Controller in assessing individual requests.
- Customer Data may be retained in truly anonymous form for aggregate statistics only if individuals can no longer reasonably be identified, including by combination with other data available to the Controller or Processor. Pseudonymised records remain personal data and are subject to this DPA.
- The Processor shall protect any temporarily retained backup data, limit access and restore use, and erase it according to the verified schedule in Schedule 4. It shall confirm completion of return or deletion on written request, subject to any legally required retention and disclosed backup period.
Dormant subscription period (to be enabled before these terms take effect): A lapsed subscription enters a 12-month dormant storage phase as a defined part of the service. Normal customer access and active use stop; access for restoration, support or legal duties is limited. The Controller may renew, request return or instruct earlier deletion. The Processor gives at least 30 days’ notice before the phase ends. By accepting this schedule, the Controller instructs deletion after the 12-month phase if it has not requested return or renewal; this default instruction must be stated clearly in the service terms. The Processor deletes live Customer Data within 30 days after the dormant phase and backup copies within the period specified in Schedule 4, unless law requires storage. If return is requested on time, the Processor provides the agreed export and then deletes its copies under the agreed timetable. An individual erasure request must be assessed separately and cannot simply be held until the archive period ends.
9. Term and other provisions
- This DPA ends when the Processor has completed the agreed return and deletion of Customer Data, subject to continuing confidentiality, audit and legal obligations for any retained data.
- Material changes to this DPA require written agreement, except updates to the subprocessor list and security measures made under the procedures above.
- For clubs, this DPA is incorporated into the signed service agreement. For individual licenses, it may be incorporated through an online order that records the Controller, its authorised acceptor, the accepted DPA version and the date. The service agreement governs notices, applicable law and disputes. Nothing in it limits duties that the GDPR requires under this DPA.
Schedule 1 — Parties and description of processing
| Item | Description to complete |
|---|---|
| Controller | The customer legal entity or natural person, address and privacy contact recorded in the signed service agreement or online order |
| Processor | Plan&Care Sports Oy, Finnish Business ID 2845110-2, Lahti, Finland; dev@coachtools.net |
| Service and duration | CoachTools coaching platform; service term plus Schedule 4 return/deletion periods |
| Nature of operations | Collection, recording, organisation, storage, retrieval, access, sharing according to roles, transmission, adaptation, analysis requested by the customer, export and deletion |
| Purposes | Team and club administration; practices, events and participation; coaching content and communication; athlete feedback, training load and development; customer-selected features |
| Data subjects | Athletes including children, guardians, coaches, club/team staff, other authorised users, and people appearing in uploaded media |
| Ordinary data | Identifiers, contact and account data, affiliations and roles, event and attendance data, plans, chats, feedback, questionnaires, goals, test results, notes, images, video, documents, device and operational data associated with the service |
| Sensitive data that may occur | Health and injury information in responses, absence reasons or notes; wellbeing and perceived exertion may also require careful contextual assessment. Controller to state its Article 6 basis and Article 9 condition where applicable. |
| Instructed disclosures | Within customer-configured team/club roles and audiences, including general and event discussion; individual feedback discussion between athlete and coaching staff. Club staff can access club teams subject to feature-specific viewing/editing restrictions. Federation views manage national teams without access to club/team workspaces. Where a federation has bought team licences, CoachTools may report numbers of licences assigned and used under that federation purchase. No athlete identities, wellbeing, feedback, test results or other coaching records are included. Club/team and guardian access remain limited by the applicable service roles and settings. |
| Controller contact for rights and incidents | The customer privacy/security contact recorded in the signed agreement or online order |
| Processor contact for rights and incidents | Ari-Pekka Piiparinen, dev@coachtools.net |
The Controller must check that any person signing for a team has authority to bind the actual controller. A coach using a personal license may be controller if they determine purposes independently; a coach operating under a club’s instructions may instead act for the club.
Schedule 2 — Technical and organisational measures
The measures below describe the agreed baseline. The operational details marked [confirm] must be checked and completed before this DPA is used.
- Access: Role-based access for athletes, guardians, coaches and club staff; staff access limited to assigned duties; account invitation and revocation procedures. [Confirm the administrative access review process.]
- Authentication: Several privileged administrator logins use MFA. [Confirm the full privileged-access inventory and password/session controls.]
- Transport and storage: Protected network communications; new AWS S3 objects receive AWS default server-side encryption. [Confirm older objects, database encryption and key management.]
- Infrastructure: Production application data is hosted in AWS Stockholm; video services and SES use Frankfurt; CloudFront delivers content and Cloudflare proxies WebSocket traffic. [Confirm exact data stores and proxy configuration.]
- Availability: Database backups are currently taken weekly and stored on an encrypted physical hard drive. [Confirm custody, retention and restore testing; specify backup deletion in Schedule 4.]
- Operations: Operational application logs are normally retained for seven days. [Confirm log exceptions and incident response procedure.]
- Data separation: Access to team, club and federation workspaces is restricted according to account roles and service permissions. [Confirm technical isolation controls.]
- Media and messaging: AWS MediaConvert video processing, AWS SES email delivery, Firebase Cloud Messaging push delivery and Reverb real-time communication. [Confirm media access and notification payload controls.]
- Deletion and export: PDF export of individual drills and plans; other return or deletion requests are handled under Schedule 4. [Confirm manual export process and completion records.]
Schedule 3 — Authorised subprocessors and transfer register
Complete the legal entities, processing locations and transfer safeguards before accepting this DPA.
| Provider | Purpose and data | Known location | Transfer / further verification |
|---|---|---|---|
| Amazon Web Services [legal entity to confirm] | Production hosting/data in Stockholm; video services in Frankfurt; SES transactional email in Frankfurt; CloudFront content delivery | Stockholm (eu-north-1) and Frankfurt (eu-central-1) for stated regional services | Confirm each service’s storage and processing region, CloudFront edge locations, remote support/access, legal entity and Chapter V mechanism where relevant |
| Google / Firebase [legal entity to confirm] | Firebase Cloud Messaging push token and notification delivery | [verify] | Confirm payload content, processing locations, legal entity, transfer mechanism and whether any other Firebase SDKs are present |
| Cloudflare [legal entity to confirm] | WebSocket traffic proxy; connection metadata and any content visible to the proxy | [verify] | Confirm entity, traffic/data handling, processing locations, retention and transfer mechanism |
Reverb is an application component operated within CoachTools infrastructure and is not listed as a separate supplier. App-store analytics are outside this subprocessor schedule unless their role in processing Customer Data changes.
Schedule 4 — Export, deletion and retention procedure
Complete the bracketed operational periods and export details before accepting this DPA.
| Decision | Agreed rule |
|---|---|
| How the Controller requests export or end-of-service deletion | The authorised Controller contact writes to dev@coachtools.net; the Processor verifies authority before acting |
| Available export format and scope | Individual drills and plans: self-service PDF. Other Customer Data: [specify agreed manual format and scope] |
| Export availability after termination | The Controller may request return throughout the 12-month dormant phase. The Processor provides the agreed export within 30 days after a verified request, subject to [confirm capability and scope] |
| Live-system deletion after valid end-of-service instruction | Within 30 days, subject to [confirm deletion process] |
| Backup expiry and restoration safeguards | Weekly encrypted physical-drive backup; [specify maximum expiry and handling after restoration] |
| Individual account deletion and club-controlled records | Account access removal and deletion of Controller coaching records are separate instructions; [specify process and lawful exceptions] |
| Cross-team or club transfer | [specify controller instruction and receiving controller, if applicable] |
| Legally required retention | Limited to [specify applicable legal categories and periods]; separate Processor controller records fall outside this schedule |
| Completion evidence | Written confirmation on request to the Controller’s designated contact |
Additional bespoke formatting or conversion may be charged at an hourly rate agreed in advance. This does not limit the ordinary return/deletion process or statutory assistance.
Signature / incorporation
Controller: [name, title, date, signature or accepted service-agreement reference]
Processor: Plan&Care Sports Oy, 2845110-2, Lahti Finland