Data Processing Agreement
Last updated: 21 September 2026
This Data Processing Agreement (the “DPA”) forms an integral part of the Terms and Conditions or of the service agreement entered into between [CLUB COMPANY NAME] (the “Club”) and Marc Piera Secall (“Spooru”).
Where the Club uses Spooru to manage personal data on the Club's behalf, this DPA governs the processing of that data in accordance with Article 28 of Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”).
1. Parties
1.1. Data controller
- [CLUB COMPANY NAME]
- Tax ID (NIF): [NIF]
- Address: [ADDRESS]
- Email: [EMAIL]
Hereinafter, the “Controller” or the “Club”.
1.2. Data processor
- Marc Piera Secall
- Tax number (Steuernummer): 11 44 198 41243 57 2642
- Address: Froschau, 24, 74925 Epfenbach, Germany
- Email: info@spooru.com
Hereinafter, the “Processor” or “Spooru”.
The Club and Spooru may jointly be referred to as the “Parties”.
2. Purpose
This DPA governs the processing of personal data that Spooru carries out on the Club's behalf as a result of providing the contracted technology services.
Spooru will process personal data solely to provide the features contracted by the Club and in accordance with the Club's documented instructions, unless processing is required by European Union law or by the law applicable to the Processor.
This DPA does not make Spooru the controller for processing where the Club determines the purposes and essential means of the processing.
3. Scope of the processing
The nature, purpose, duration, categories of data and categories of data subjects covered by the processing are described in Annex I to this DPA.
The Club is responsible for determining the purposes of the processing and for ensuring that the instructions given to Spooru are lawful.
Spooru will not use data processed on the Club's behalf for its own purposes independent of the Club's instructions, except where such use is necessary to comply with a legal obligation applicable to Spooru or where Spooru acts as controller for a different processing activity with an independent legal basis.
4. The Club's instructions
The Club instructs Spooru to process personal data to the extent necessary to:
- host and store the data;
- allow authorised access to the platform;
- manage teams, seasons and players;
- manage calendars and call-ups;
- manage sports statistics;
- provide messaging features;
- manage the payment-collection features enabled by the Club;
- perform backups and maintenance operations;
- provide technical support;
- ensure the security and availability of the platform;
- carry out the other features contracted by the Club.
Spooru's processing of data will be limited to the purposes above and to the documented instructions provided by the Club.
Where Spooru considers that an instruction infringes the GDPR or other applicable data-protection provisions, it will inform the Club without undue delay.
5. Duration
Processing will take place for as long as the contractual relationship between the Parties is in force.
Once the provision of services ends, Spooru will stop processing personal data on the Club's behalf, unless a legal obligation requires its retention or the Club requests its retention for the period necessary to carry out a migration or export.
6. The Club's obligations as controller
The Club represents and warrants that it:
- has an appropriate legal basis for the processing it entrusts to Spooru;
- complies with the information obligations owed to data subjects;
- has determined the purposes and means of the processing it carries out as controller;
- will not give Spooru instructions that are contrary to applicable regulations;
- will ensure that the data provided to Spooru is adequate, relevant and not excessive;
- will properly manage its users' permissions;
- will handle requests to exercise rights where it is the data controller;
- will determine the retention periods applicable to the data it manages;
- will carry out data protection impact assessments where necessary;
- will determine appropriate security measures based on risk;
- will obtain any necessary consents where this is the applicable legal basis.
Where processing affects minors, the Club is responsible for complying with the specific obligations that apply.
7. Spooru's obligations as processor
Spooru undertakes to:
- process personal data only in accordance with the Club's documented instructions;
- ensure that persons authorised to process data are subject to confidentiality obligations;
- apply appropriate technical and organisational measures;
- maintain the confidentiality of personal data;
- assist the Club in complying with its obligations;
- inform the Club of data subject requests where applicable;
- inform the Club of personal data breaches;
- reasonably cooperate on impact assessments;
- cooperate with the Club on prior consultations with supervisory authorities where appropriate;
- maintain the documentation necessary to demonstrate compliance with its obligations;
- allow audits under the terms set out in this DPA.
8. Confidentiality
Spooru will ensure that persons authorised to process personal data have committed to confidentiality or are subject to an appropriate statutory confidentiality obligation.
The confidentiality obligation will continue after the contractual relationship ends for as long as the information remains confidential.
9. Security measures
Spooru will apply technical and organisational measures appropriate to the risk to protect personal data.
These measures may include, as applicable:
- access control;
- authentication;
- permission management;
- encryption of communications;
- infrastructure protection;
- backups;
- logging of certain security events;
- recovery procedures;
- continuity measures;
- vulnerability management;
- incident response procedures;
- measures designed to ensure the confidentiality, integrity, availability and resilience of systems.
Specific measures may be updated where necessary to keep pace with technological developments and risks.
Current technical and organisational measures are described in more detail in Annex II.
10. Sub-processors
The Club authorises Spooru to engage other processors for certain operations necessary to provide the service.
Depending on the features contracted, the sub-processors that may be used include:
- Supabase, for infrastructure, database hosting and storage services.
- Resend, for sending electronic communications.
- Stripe, for certain payment-related features, where relevant to processing carried out on the Club's behalf.
- Other technology providers that Spooru may add in accordance with the procedure set out in this DPA.
Spooru will keep an up-to-date list of the sub-processors used available to the Club, including their identity and, where applicable, location and function.
The Club gives general authorisation for the addition of new sub-processors.
Spooru will inform the Club of any addition or replacement of sub-processors with reasonable notice.
The Club may raise a reasonable objection on grounds specifically related to the protection of personal data.
If the Parties do not reach a reasonable solution, either may exercise the rights available to it under the main contract.
11. Obligations regarding sub-processors
Spooru will ensure, by contract, that sub-processors are subject to data-protection obligations equivalent to those set out in this DPA, to the extent required by the GDPR.
Spooru will remain liable to the Club for compliance with the obligations of its sub-processors under the GDPR and this DPA.
12. Exercising rights
Taking into account the nature of the processing, Spooru will assist the Club, through appropriate technical and organisational measures, where possible, so that the Club can respond to data subjects' requests to exercise their rights.
Where Spooru directly receives a request from an individual relating to data processed on the Club's behalf, Spooru will:
- not respond on the merits unless authorised to do so;
- forward the request to the Club where appropriate;
- provide the Club with the information available that is necessary to handle the request.
Spooru will reasonably cooperate to locate, modify, export, restrict or delete data where these operations are technically necessary to fulfil a legally exercisable right.
13. Personal data breaches
Spooru will notify the Club, without undue delay, of any personal data breach affecting data processed on the Club's behalf of which it becomes aware.
Where possible, the notification will include:
- the nature of the incident;
- the categories of data affected;
- the approximate categories of data subjects affected;
- the likely consequences;
- measures taken or proposed;
- contact details for further information.
Spooru will provide further information as it becomes available.
The Club is responsible for assessing and, where applicable, notifying the breach to the supervisory authority and to data subjects.
Spooru will reasonably cooperate with the Club to enable it to comply with these obligations.
14. Impact assessments and prior consultations
Taking into account the nature of the processing and the information available to it, Spooru will reasonably assist the Club, where necessary, to:
- carry out data protection impact assessments;
- identify risks;
- define mitigation measures;
- carry out prior consultations with the supervisory authority.
The Club remains responsible for determining whether it is required to carry out an impact assessment and for making the corresponding decisions.
15. International transfers
Spooru will not make international transfers of personal data processed on the Club's behalf unless there is a valid legal basis under Chapter V of the GDPR.
Where it is necessary to transfer personal data outside the European Economic Area, Spooru will ensure that a valid transfer mechanism is used, such as:
- an adequacy decision;
- standard contractual clauses approved by the European Commission;
- or another legally recognised mechanism.
Where necessary, Spooru will apply appropriate supplementary measures.
Spooru will provide the Club with the information reasonably necessary to comply with its obligations regarding international transfers.
16. Requests from authorities
If Spooru receives a legally binding request from a public authority to access personal data processed on the Club's behalf, it will inform the Club where legally permitted to do so.
Spooru will limit the information provided to that which it is legally required to provide and will assess the lawfulness of the request where reasonably possible.
Where there is a legal prohibition on informing the Club, Spooru may refrain from doing so.
17. Data retention and deletion
At the end of the services, the Club may request the return or export of the personal data processed by Spooru on its behalf, where this feature is available.
Once the reasonably necessary migration period has ended, Spooru will delete or return the personal data, as determined by the Club, unless applicable law requires its retention.
Where there is a legal obligation to retain data, it will be retained only for the required period and will be subject to appropriate protective measures.
Backups may be kept during Spooru's ordinary backup cycles and will be deleted in accordance with Spooru's retention policies, unless a legal obligation requires their retention.
18. Audits
Spooru will make available to the Club the information necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR.
Where necessary, Spooru may provide documentation relating to its security measures, certifications, independent audits or available security questionnaires.
The Club may carry out, itself or through an independent auditor bound by confidentiality obligations, audits relating to the processing carried out by Spooru on the Club's behalf.
Audits:
- must be notified with reasonable notice;
- will be carried out during normal business hours;
- may not unjustifiably interfere with Spooru's operations;
- must be limited to information relevant to the processing covered by this DPA;
- must respect the confidentiality of Spooru's other customers and its trade secrets.
Unless there is a legal obligation or a relevant security incident, the costs of an audit will be borne by the Club.
Spooru may satisfy audit requests by providing, where sufficient, existing audit reports or independent certifications.
19. Records and documentation
Spooru will maintain the documentation necessary to demonstrate compliance with its obligations as processor.
Where reasonably requested by the Club, Spooru will provide relevant information about its security measures, sub-processors and processing practices.
20. Use of data by Spooru for its own purposes
Data processed by Spooru on the Club's behalf will not be used for Spooru's own commercial purposes that are incompatible with the Club's instructions.
In particular, Spooru will not sell the Club's data or use it to build commercial profiles of players or families for its own purposes.
Where Spooru carries out processing for its own purpose, determining its own purposes and means, that processing will be assessed separately and Spooru will act as an independent controller where applicable, providing the legally required information and having its own legal basis.
21. Aggregated and anonymised data
Spooru may generate aggregated or anonymised statistical information about the operation of the platform, provided that such information does not allow individuals to be identified, directly or indirectly.
Properly anonymised information will not be considered personal data.
Spooru will not use the Club's identifiable personal data for its own analytics purposes without an appropriate legal basis and, where applicable, without providing the corresponding information to data subjects.
22. Minors
The Club acknowledges that the platform may be used to manage data of underage players.
The Club is responsible for ensuring that the processing of minors' data complies with applicable law and for obtaining any consents necessary where the legal basis used is consent.
Spooru will apply reasonable technical and organisational measures to protect the data of minors it processes on the Club's behalf.
The Club undertakes not to enter detailed medical information, clinical histories, diagnoses or other special category data unless the processing is necessary, lawful and expressly compatible with the contracted feature.
23. Special categories of data
The Club must not enter special categories of personal data into Spooru, including health data, unless:
- there is a legitimate and specific need;
- there is a legal basis under Article 9 of the GDPR;
- the processing is compatible with the feature of the service;
- appropriate security measures have been adopted.
The mere existence of an administrative field relating to the validity of fitness-to-play does not authorise the Club to enter diagnoses, medical reports, injuries, treatments or clinical histories.
24. Precedence of the DPA
In the event of a conflict between this DPA and other contractual conditions relating to the processing of personal data on the Club's behalf, this DPA will prevail on data-protection matters.
The main contract between the Parties will continue to apply to all other matters.
25. Liability
Each Party will be liable for compliance with the obligations that apply to it under the GDPR, applicable Spanish law and this DPA.
Spooru will be liable to the Club for breaches that are legally attributable to it in its capacity as processor.
Where Spooru uses sub-processors, it will remain liable to the Club under the GDPR for the obligations it has delegated to them.
The liability limitations set out in the main contract will apply to this DPA to the extent permitted by applicable law.
Nothing in this DPA limits any liability that cannot legally be excluded.
26. Cooperation with supervisory authorities
The Parties will cooperate in good faith with data protection authorities where necessary to comply with their legal obligations.
Spooru will inform the Club when a supervisory authority requests information specifically relating to processing carried out on the Club's behalf, unless there is a legal prohibition against doing so.
27. Duration and termination
This DPA will remain in force for as long as Spooru processes personal data on the Club's behalf.
Obligations that, by their nature, must survive termination of the contract will remain in force for as long as necessary, including confidentiality obligations and those relating to the deletion or legally required retention of data.
28. Governing law
This DPA is governed by Regulation (EU) 2016/679, applicable Spanish data-protection law and any other rules applicable to the processing.
Any dispute relating to the DPA will be resolved under the jurisdiction regime set out in the main contract, without prejudice to the mandatory powers of data-protection authorities and the rights legally granted to data subjects.
Annex I — Processing details
A. Subject matter
Provision of technology services for the management and administration of sports clubs through the Spooru platform.
B. Duration
The duration of the processing will match the duration of the contractual relationship between the Club and Spooru, plus any additional periods necessary for migration, deletion, backup or legally required retention.
C. Nature of the processing operations
The operations may include:
- collection;
- recording;
- organisation;
- structuring;
- storage;
- consultation;
- alteration;
- retrieval;
- communication within the platform;
- export;
- erasure;
- backup;
- hosting;
- technical support.
D. Purposes
- Club management.
- Team management.
- Season management.
- Player management.
- Calendar management.
- Call-up management.
- Statistics management.
- Internal communications.
- Administrative management.
- Payment management where the Club uses these features.
- Security and maintenance of the service.
E. Categories of data subjects
These may include:
- players;
- underage players;
- parents and guardians;
- coaches;
- staff members;
- club administrators;
- contact persons;
- payers.
F. Categories of data
These may include:
- first and last name;
- date of birth;
- photograph;
- email address;
- contact information;
- team;
- category;
- shirt number;
- position;
- sports statistics;
- call-ups;
- information contained in messages;
- technical identifiers;
- payment-related information;
- information relating to the validity of certain fitness-to-play check-ups, where this feature is used.
G. Special categories
In general, the service is not intended for the processing of special categories of data.
If the Club enters special categories of data, it must ensure that such processing is lawful, necessary and compatible with the feature used.
H. Frequency
Processing may take place continuously while the service is being provided and according to actions carried out by authorised users.
Annex II — Technical and organisational measures
Spooru will apply technical and organisational measures appropriate to the risk, including, as applicable:
Access control
- User and permission management.
- Role-based access.
- Authentication.
- Restriction of access to authorised personnel.
Communications protection
- Use of encrypted connections.
- Protection of communications between clients and servers.
Infrastructure protection
- Use of specialised infrastructure providers.
- System access control.
- Credential management.
- Updating components where necessary.
Backups
- Performing backups where necessary.
- Protection against accidental loss.
- Recovery procedures.
Development security
- Code access control.
- Change management.
- Review of updates.
- Vulnerability management.
Incident management
- Internal procedures for detecting and responding to incidents.
- Impact assessment.
- Communication to the Club where appropriate.
Personnel
- Access limited to people who need to process data.
- Confidentiality obligations.
- Security training and awareness where appropriate.
These measures may be modified and updated provided that a level of security appropriate to the risk is maintained.
Annex III — Sub-processors
An up-to-date list of sub-processors will be kept available to clubs.
| Provider | Service | Purpose |
|---|---|---|
| Supabase | Infrastructure / database / storage | Hosting and technical management |
| Resend | Sending communications | |
| Stripe | Payments | Processing certain payment transactions |
Spooru will report the addition or replacement of sub-processors in accordance with the procedure set out in this DPA.