Legal
Data Processing Agreement
v1.0 · Last updated August 2026
This agreement is entered into between the customer organization (the "Controller") and [Your Company Ltd] (the "Processor") and applies whenever the Processor handles personal data on the Controller's behalf in Apex PMS. It forms part of the Terms of Service.
1. Subject matter and duration
The Processor processes personal data solely to provide the athlete performance management service for the duration of the subscription, plus the deletion window set out in clause 8.
2. Nature and purpose of processing
- Storage and retrieval of athlete profiles, teams and availability.
- Collection and scoring of daily wellness submissions.
- Recording of attendance, training load and physical testing results.
- Recording of injuries and return-to-play progression (special category health data).
- Provision of dashboards, alerts, exports and reports to authorised users.
3. Categories of data subject and data
- Data subjects: athletes (including minors), coaches, medical staff, administrators and guardians.
- Personal data: identity and contact details, date of birth, team and position, wellness scores, attendance and training records, test results.
- Special categories: health and injury data, processed on the Controller's documented instructions and on the basis of explicit consent obtained by the Controller.
4. Processor obligations
- Process personal data only on the Controller's documented instructions, including for transfers.
- Ensure personnel with access are bound by confidentiality.
- Implement the technical and organisational measures in clause 6.
- Not engage a sub-processor without the Controller's general authorisation and 30 days' notice of changes.
- Assist the Controller with data subject requests, impact assessments and consultations with the supervisory authority.
- Make available the information needed to demonstrate compliance and allow audits no more than once a year on reasonable notice.
5. Controller obligations
- Establish and document a lawful basis for all data entered into the platform.
- Obtain explicit consent for health data, and parental or guardian consent for athletes under 16.
- Issue a privacy notice to athletes and guardians.
- Assign roles correctly and remove access promptly when staff leave.
- Set an appropriate retention period in the platform settings.
6. Security measures
- Encryption of data in transit (TLS) and at rest.
- Row-level security isolating each organization's data.
- Role-based access control, with health data restricted to medical and admin roles.
- Audit logging of medical record access.
- Managed, regularly backed-up infrastructure with restricted administrative access.
7. Personal data breaches
The Processor will notify the Controller without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting the Controller's data, with the information needed for the Controller to meet its own Article 33 obligations.
8. Return and deletion
On termination the Controller may export its data from the platform. The Processor deletes all personal data within 30 days of the end of the subscription unless retention is required by law.
9. Sub-processors and international transfers
The current list is maintained on the subprocessors page. Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses together with appropriate supplementary measures.
10. Signature
Acceptance of the Terms of Service constitutes acceptance of this agreement. A countersigned copy is available on request from [privacy@yourdomain.com].
This document is a starting template provided with Apex PMS. Replace the bracketed placeholders with your own company details and have it reviewed by a qualified solicitor before you sign customer contracts.