Legal
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Tetherra Ltd ("Processor") and the customer organisation ("Controller"). By using OcheOS or any Tetherra service that processes personal data on your behalf, you agree to this DPA.
Contents
01
In this DPA, the following terms have the following meanings:
02
This DPA applies where the Controller uses Tetherra Services to process personal data on behalf of the Controller's organisation. This includes, without limitation, storing member profiles, player performance data, contact information, and booking records through OcheOS.
The Controller acts as the data controller and Tetherra Ltd acts as the data processor in respect of any personal data processed through the Services. Tetherra shall only process personal data on documented instructions from the Controller, unless required to do so by law.
03
The processing of personal data by Tetherra on behalf of the Controller in connection with the provision of the Services.
For the duration of the Controller's subscription to the Services, and for a period of up to 90 days following termination (for the purpose of data export and deletion).
Storage, organisation, retrieval, and display of personal data for the purpose of academy and club management, player development tracking, event scheduling, and league operations.
04
Tetherra Ltd, as Processor, shall:
05
The Controller shall:
06
The Controller grants Tetherra general authorisation to engage sub-processors for the provision of the Services. Tetherra will maintain a current list of sub-processors and will provide notice of any intended changes to sub-processors, giving the Controller the opportunity to object on reasonable grounds.
Current sub-processors used in connection with Tetherra services include cloud hosting providers and email delivery services. A current list is available on request at [email protected].
Where Tetherra engages sub-processors, it shall impose data protection obligations on them equivalent to those set out in this DPA.
07
Tetherra shall, to the extent technically possible, assist the Controller in responding to requests from data subjects exercising their rights under UK GDPR, including rights of access, rectification, erasure, restriction, portability, and objection.
If Tetherra receives a data subject rights request directly, it will promptly forward it to the Controller without acting on the request itself (unless required to do so by law).
08
Tetherra implements and maintains appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:
09
In the event of a personal data breach affecting data processed on behalf of the Controller, Tetherra shall notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Notification shall include, to the extent available: a description of the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences of the breach, and the measures taken or proposed to address the breach.
The Controller remains responsible for notifying the ICO and affected data subjects where required under UK GDPR.
10
Tetherra shall not transfer personal data outside the UK or EEA without the Controller's prior written consent and appropriate safeguards in place. Where transfers do occur, Tetherra will ensure they comply with UK GDPR transfer requirements, including through the use of Standard Contractual Clauses or adequacy decisions.
11
Upon termination of the Services, Tetherra shall, at the Controller's written election:
During the 90-day post-termination period, the Controller may export their data via the platform's data export tools. After this period, data will be permanently deleted.
Tetherra may retain data for longer periods where required by law, such as financial records and audit logs.
12
Tetherra shall make available to the Controller all information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
Audit requests must be submitted in writing with at least 30 days' notice. Audits shall not unreasonably disrupt Tetherra's operations and shall be conducted at the Controller's expense.
13
This DPA enters into force on the date the Controller first uses the Services and remains in effect until all personal data processed by Tetherra on behalf of the Controller has been returned or deleted in accordance with Section 11.
This DPA shall automatically terminate upon termination of the Controller's subscription to the Services.
14
This DPA is governed by the laws of England and Wales. Any disputes arising from or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.
For questions about this DPA or to request a countersigned copy for your records, please contact:
Tetherra Ltd, Data Protection
England, United Kingdom
[email protected]
tetherra.com