Baseliners HQ Data Processing Agreement
Version 1.0 · Dated 16/09/2026
1. Purpose and parties
1.1 This Data Processing Agreement (DPA) is between Ability Software Limited, trading as Baseliners HQ (the Processor), and the club named in the Order Form (the Controller). It forms part of the Agreement described in the Baseliners HQ Subscription Terms, and meets the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (GDPR).
1.2 Words defined in the Subscription Terms have the same meaning here. Personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the meanings given in the GDPR. Data Protection Law means the GDPR and the Data Protection Acts 1988 to 2018.
1.3 This DPA covers personal data the Processor processes on behalf of the Controller in providing the Service (Club Personal Data), as described in Annex 1. It does not cover the login account a person uses across all clubs on the Service, or information about people who contact the Processor about buying the Service. The Processor is the controller of that data.
2. The Controller's instructions
2.1 The Processor will process Club Personal Data only on the Controller's documented instructions, including with regard to transfers outside the European Economic Area (EEA), unless the law requires otherwise. In that case the Processor will tell the Controller before processing, unless the law prohibits it.
2.2 The Controller's instructions are: this DPA; the Subscription Terms; the settings the Controller's Administrators choose in the Service; and actions Administrators take in the Service. Further instructions must be in writing and consistent with the Agreement.
2.3 The Processor will tell the Controller promptly if, in its opinion, an instruction breaches Data Protection Law.
2.4 The Controller is responsible for having a lawful basis for the processing, for giving data subjects the information Data Protection Law requires, and for the lawfulness of its instructions.
3. Confidentiality
3.1 The Processor will make sure every person it authorises to process Club Personal Data is under a written or statutory duty of confidentiality, and has access only as far as needed for their role.
3.2 The Processor will access Club Personal Data only to provide, maintain, secure and support the Service, to investigate a problem reported by the Controller or its members, or where the law requires.
4. Security
4.1 The Processor will take appropriate technical and organisational measures to protect Club Personal Data, as required by Article 32 of the GDPR, taking into account the nature of the data, including data about children and any vetting records. The measures in place on the date of this DPA are described in Annex 2.
4.2 The Processor may update those measures, provided the overall level of protection is not reduced.
4.3 The Controller is responsible for the security measures within its own control, including choosing Administrators, assigning their permission areas, and removing access when someone leaves a role.
5. Sub-processors
5.1 The Controller gives general authorisation for the Processor to use sub-processors. The sub-processors in use on the date of this DPA are listed in Annex 3.
5.2 The Processor will give the Controller at least 30 days' notice by email before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period. The parties will discuss the objection in good faith. If it is not resolved, the Controller may end the Agreement by written notice, and the Processor will refund the fees paid for the unused part of the Subscription Year.
5.3 The Processor will put in place with each sub-processor a written contract with data protection obligations equivalent to those in this DPA, and remains responsible to the Controller for each sub-processor's performance of those obligations.
5.4 Stripe. Payments taken through the Service are processed in the Controller's own Stripe account, under the Controller's own agreement with Stripe. Stripe acts under that agreement, not as a sub-processor of the Processor.
6. Transfers outside the EEA
6.1 The Service is hosted in the EEA. The Processor will not transfer Club Personal Data outside the EEA, or allow a sub-processor to do so, unless the transfer is covered by an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for a certified recipient) or by appropriate safeguards under Article 46 of the GDPR, such as the Standard Contractual Clauses. Where a sub-processor in Annex 3 may transfer data outside the EEA, the safeguard relied on is stated there.
7. Helping the Controller
7.1 Data subject requests. The Service gives the Controller tools to respond to requests from data subjects: a data request form on the Club's public site and an inbox for Administrators; an export of a member's personal data; correction of member records; and anonymisation of a member's records. Where those tools are not enough, the Processor will give reasonable further help on request.
7.2 If the Processor receives a request directly from a data subject about Club Personal Data, it will pass the request to the Controller without undue delay and will not respond to it itself, except to tell the data subject that the request has been passed on.
7.3 Other assistance. Taking into account the information available to it, the Processor will give reasonable help with the Controller's obligations on security, breach notification, data protection impact assessments and prior consultation with the supervisory authority (Articles 32 to 36 of the GDPR). The Processor may charge a reasonable fee for help that goes significantly beyond what this DPA already provides, and will agree it with the Controller in advance.
8. Personal data breaches
8.1 The Processor will notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Club Personal Data. It will notify the Controller's data protection contact in the Order Form, and the Club contact for the Agreement.
8.2 The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. The Processor will provide further information as it becomes available.
8.3 The Processor will take reasonable steps to contain and investigate the breach and reduce its effects, and will co-operate with the Controller. Deciding whether to notify the Data Protection Commission or data subjects is the Controller's decision, unless the law requires the Processor to notify.
8.4 A notice under this clause is not an admission of fault or liability.
9. At the end of the Agreement
9.1 For 60 days after the Agreement ends, the Controller may export Club Personal Data as set out in clause 11.1 of the Subscription Terms.
9.2 Within 90 days after that period, the Processor will delete Club Personal Data, or irreversibly anonymise it so that no individual can be identified from it, and confirm this in writing on request. This applies unless the law requires the Processor to keep some of the data. In that case the Processor will keep it confidential, keep only what the law requires, and process it only for that purpose.
9.3 Copies in backups will be removed as the backups expire under their normal cycle of 14 days, and will not be restored in the meantime except to recover the Service.
9.4 Keeping the Club's own financial records for as long as tax and company law require is the Controller's responsibility. The Controller should export the payment records it needs before the end of the period in clause 9.1.
10. Records and audits
10.1 The Processor will keep the records of processing required by Article 30(2) of the GDPR.
10.2 On written request, the Processor will provide the information reasonably needed to show that it meets this DPA, including an up-to-date description of its security measures and sub-processors.
10.3 If that information is not reasonably enough, the Controller, or an independent auditor bound by confidentiality, may carry out an audit, including an inspection. The Controller will give at least 30 days' notice, carry out no more than one audit in any twelve months unless a personal data breach has occurred or the supervisory authority requires one, and pay its own costs. The audit will take place during business hours and will not give access to other clubs' data or to the Processor's confidential security information beyond what is needed.
11. Liability, duration and changes
11.1 Each party's liability under this DPA is subject to the limits in clause 9 of the Subscription Terms.
11.2 This DPA lasts for as long as the Processor processes Club Personal Data, including after the Agreement ends.
11.3 The Processor may update this DPA under clause 12.2 of the Subscription Terms. The Processor may also make a change that Data Protection Law, a court or the supervisory authority requires, with as much notice as is reasonably possible.
11.4 This DPA is governed by the laws of Ireland, and the courts of Ireland have exclusive jurisdiction.
Annex 1: Details of the processing
| Subject matter | Providing the Baseliners HQ club management platform to the Controller. |
|---|---|
| Duration | The Term of the Agreement, plus the periods in clause 9. |
| Nature of the processing | Hosting and storing data; showing it to members and Administrators; running bookings, memberships, coaching, events, competitions and ladders; sending email and push notifications; passing payment details to the Controller's Stripe account; producing exports and reports; anonymising records on the Controller's instruction; backing up; and giving technical support. |
| Purpose | To allow the Controller to run its club: membership and renewals, court bookings, coaching, events, competitions, communication with members and visitors, payments, club documents and safeguarding records. |
| Data subjects |
|
| Categories of personal data |
|
| Special categories and children | The Service does not ask for special-category data. The Controller may choose to ask about health, for example medical conditions, in its own membership application questions, and is responsible for that decision and its lawful basis. The Service processes data about children where the Controller has junior members or junior course participants. Vetting records may relate to criminal record checks under the National Vetting Bureau (Children and Vulnerable Persons) Acts 2012 to 2016; the Service records the outcome and any document the Controller chooses to upload. |
| Retention during the Agreement |
|
Annex 2: Security measures
Separation between clubs
All clubs share one database. Every club-owned record carries the club's identifier, and the application applies a filter to every database query so that a request made for one club reads only that club's records. Filtering is applied by default to new types of record. Any work that needs to read across clubs must be switched on explicitly in the code.
Access control
Administrators are given access by permission area (for example Membership, Payments, Communications, Documents and Vetting), so that access to sensitive areas such as vetting can be limited to the people who need it. Accounts are locked after repeated failed sign-in attempts. Two-factor authentication is available. A person's sign-in is checked against their account on every request, so signing out everywhere or changing a password takes effect on that person's next request.
Protecting data in transit and at rest
All traffic uses HTTPS, with HTTP Strict Transport Security. Cookies are marked secure and HTTP-only. Connections to the database are encrypted. Data is stored in Microsoft Azure services that encrypt data at rest. Private files, such as vetting documents and problem report screenshots, are held in a private storage container that is not reachable without the application.
Application security
A Content Security Policy and other browser security headers are sent on every page. Every form that changes data is protected against cross-site request forgery. Public forms, such as visitor bookings, are rate limited. Uploaded files are served in a way that prevents them running as web pages. Messages from Stripe and Mailgun are checked for a valid signature and cannot be replayed. Card details are entered only on Stripe's own pages.
Secrets and operations
Passwords, keys and connection strings for production are held in Azure Key Vault and read using a managed identity, not stored in the source code. Production and development use separate vaults. Changes to the Service are tested with automated test suites before release. Application errors and requests are logged in Azure Application Insights, kept for 90 days.
Data minimisation
Email open and click tracking is switched off. The Service does not use advertising or third-party analytics. It sets only the cookies needed to sign in and to protect forms. Copies of emails are removed on the schedule in Annex 1, and links in emails that carry a sign-in or reset token are not kept in the stored copy.
Annex 3: Sub-processors
| Sub-processor | What it does | Where data is processed | Transfer safeguard |
|---|---|---|---|
| Microsoft Ireland Operations Limited (Microsoft Azure) | Hosting the application, database, file storage, secret storage and application logs (App Service, Azure SQL, Blob Storage, Key Vault, Application Insights). | North Europe (Ireland) | Data held in the EEA. Microsoft's Data Protection Addendum applies. |
| Mailgun Technologies, Inc. (part of Sinch) | Sending email to members and visitors, and reporting delivery, bounces and unsubscribes. | Mailgun EU region | Data sent to the EU region. Mailgun's Data Processing Addendum, with EU–US Data Privacy Framework certification or Standard Contractual Clauses for any access from the United States. |
| Browser push services: Apple, Google and Mozilla | Delivering push notifications to a member's device when the member has switched them on. | Operated by the provider of the member's browser, which may be outside the EEA | The notification is encrypted by the Service so the push service cannot read it. The push service receives only a device address and the encrypted message. |
Stripe is not a sub-processor. See clause 5.4.