Data Processing Agreement (DPA)
Pursuant to Art. 28 General Data Protection Regulation (GDPR) · Effective: September 16, 2026
Contracting Parties:
Between the sports academy, sports club, or sports federation utilizing the platform (hereinafter "Customer" or "Data Controller")
and
Concepts for You GmbHHardtstr. 43b
85247 Schwabhausen
Germany
(hereinafter "Contractor" or "Data Processor")
the following Data Processing Agreement is entered into electronically.
§ 1 Subject Matter, Duration and Purpose of Processing
- The subject matter of this agreement is the provision and operation of the web-based software platform MedalMaker as a Software-as-a-Service (SaaS) solution for digital management of training, periodization, performance, and athlete data.
- The duration corresponds to the term of the Main Agreement (SaaS Subscription).
- Processing exclusively serves the purpose of equipping the Customer with athlete monitoring, workload optimization (ACWR), wellness tracking, fitness testing, and team communication workflows.
§ 2 Scope, Nature and Purpose of Processing
- Categories of Data Subjects:
- Athletes and youth participants.
- Coaches, assistant coaches, head coaches, and federation directors.
- Physiotherapists, medical staff, and healthcare professionals.
- Parents and legal guardians of minor athletes.
- Club and organization administrators.
- Categories of Personal Data:
- Master & Contact Data: Name, email address, phone number, birth date, gender, emergency contacts, sport discipline.
- Training & Performance Data: Training plans, session RPE load values, duration, periodization grid blocks, fitness test results (e.g. FMS), strength training logs, video form checks.
- Special Categories of Data (Health Data per Art. 9 GDPR): Daily wellness check-in scores (sleep, stress, soreness), injury and rehab logs, 2D/3D pain mapping, menstrual cycle tracking data, wearable biometric metrics (resting heart rate, HRV, sleep stages).
- Organizational & Scheduling Data: Attendance logs, absence reasons, tournament participation and travel statuses, calendar events.
- Communication Data: In-app messages and automated WhatsApp check-in reminders (athlete first name, organization name, phone number, timestamp, encrypted portal link; strictly zero special category health data per Art. 9 GDPR).
§ 3 Obligations of the Customer (Data Controller)
- The Customer is solely responsible for the lawfulness of the data processing and for safeguarding the rights of the data subjects (Art. 4 No. 7 GDPR).
- The Customer expressly warrants that it has collected all necessary legal bases (in particular explicit consent pursuant to Art. 9(2)(a) GDPR for special category health data) prior to entering data into MedalMaker.
- Minor Athletes (< 16 Years): The Customer expressly guarantees that valid consent of parents or legal guardians is obtained for all athletes under 16 years of age (Art. 8 GDPR).
§ 4 Obligations of the Contractor (Data Processor)
- Bound by Instructions: The Contractor shall process personal data exclusively on documented instructions from the Customer (Art. 28(3)(a) GDPR).
- Confidentiality: The Contractor ensures that persons authorized to process personal data have committed themselves to confidentiality (Art. 28(3)(b) GDPR).
- Security of Processing (Art. 32 GDPR): The Contractor shall implement all necessary technical and organizational measures (TOMs) to protect personal data (see Annex 1).
- Support for Data Subject Rights: The Contractor supports the Customer with automated technical tools (e.g. automated Art. 20 GDPR ZIP data export, Art. 17 data erasure workflows).
- Data Breach Notification: The Contractor shall notify the Customer without undue delay upon becoming aware of a personal data breach (Art. 33(2) GDPR).
§ 5 Sub-processors (Art. 28(2) & (4) GDPR)
- The Customer grants the Contractor general authorization to engage sub-processors.
- The currently approved sub-processors are listed in Annex 2.
- The Contractor shall notify the Customer at least 14 days in advance of any intended changes concerning the addition or replacement of sub-processors, giving the Customer the right to object on reasonable data protection grounds.
§ 6 Deletion and Return of Data
- Upon termination of the Main Agreement, the Contractor shall permanently delete all personal data within 30 days, unless statutory retention obligations (e.g. tax/commercial laws) prevent immediate deletion.
- Prior to contract termination, the Customer may export all organization data at any time via the integrated GDPR export feature in machine-readable format (JSON/CSV).
Annex 1: Technical and Organizational Measures (TOMs per Art. 32 GDPR)
The Contractor implements the following state-of-the-art security measures:
1. Confidentiality (Art. 32(1)(b) GDPR)
- Physical Access Control: Hosting in certified data centers (ISO 27001, SOC 2) of Google Cloud Platform and Supabase in Frankfurt am Main (Germany) with biometric access controls and 24/7 security.
- Logical Access Control: Strong password hashing (scrypt / Argon2 / bcrypt), JWT authentication with refresh token rotation, and single sign-on (Google/Apple OAuth).
- Access Restrictions & Tenant Isolation: Strict multi-tenant isolation. All database queries enforce organizational boundaries (`organizationId`). Cross-tenant access is structurally impossible.
- Encryption: End-to-end transport encryption via TLS 1.3 for all web and API traffic. Encryption at rest using AES-256 for all databases and backups.
2. Integrity (Art. 32(1)(b) GDPR)
- Transfer Control: Encrypted data transmission via HTTPS/TLS 1.3, signed API requests, and parameterized database queries (Prisma ORM) preventing SQL injection.
- Input & Audit Control: Immutable audit logging (`AuditLog`) for security-sensitive operations (role changes, data export, member deletion, DPA acceptance).
3. Availability & Resilience (Art. 32(1)(b) & (c) GDPR)
- Automated Backups: Daily automated encrypted database backups with a 30-day retention policy and automated disaster recovery keepalives.
- High Availability: Serverless container deployment via Google Cloud Run with automatic scaling, zero-downtime rolling updates, and health monitoring.
Annex 2: Approved Sub-processors
| Provider / Company | Service / Function | Server Location | Legal Safeguards |
|---|---|---|---|
| Google Ireland Ltd. Dublin, Ireland |
Cloud Infrastructure & Cloud Run Hosting | Frankfurt am Main, Germany (EU) | Art. 28 GDPR DPA, ISO 27001 |
| Supabase Inc. / AWS EU Frankfurt, Germany |
PostgreSQL Database Hosting & Connection Pooling | Frankfurt am Main, Germany (EU) | Art. 28 GDPR DPA, SOC 2 Type II |
| Stripe Payments Europe Ltd. Dublin, Ireland |
Payment Processing & Subscription Invoicing | EU / Global | Art. 28 GDPR DPA, PCI-DSS Level 1 |
| Resend Inc. | Transactional Email Delivery (Invites, Password Resets) | EU Region | Art. 28 GDPR DPA, EU SCCs |
| Meta Platforms Ireland Ltd. Dublin, Ireland |
Automated WhatsApp Check-in Reminders (Meta WhatsApp Cloud API) | EU / Global (Meta Cloud Infrastructure) | WhatsApp Business Data Processing Terms (Art. 28 GDPR), EU SCCs, EU-US Data Privacy Framework (DPF) |
Questions regarding data protection? Contact our Data Protection Officer at: privacy@medalmaker.app