Legal
Data Processing Agreement
Effective date: 1 May 2025 · Last updated: 1 May 2025
This Data Processing Agreement ("DPA") forms part of the Terms of Service between CricClubOS ("Processor") and the cricket club or organisation that subscribes to CricClubOS ("Controller").
This DPA applies where the Processor processes personal data on behalf of the Controller in the course of providing the CricClubOS platform and related services.
1. Definitions
In this DPA:
- "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation), and any equivalent or successor legislation in the United Kingdom or applicable jurisdiction.
- "Personal Data" means any information relating to an identified or identifiable natural person as defined in Article 4(1) GDPR.
- "Processing" has the meaning set out in Article 4(2) GDPR.
- "Data Subject" means the individual to whom Personal Data relates, typically a club member, player, or associated person.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
2. Roles and scope
The Controller determines the purposes and means of processing Personal Data relating to its club members and operations. The Processor processes that Personal Data solely on the Controller's instructions as expressed through the CricClubOS platform and this DPA.
The parties acknowledge that:
- The Controller is the data controller for member personal data entered into CricClubOS.
- CricClubOS acts as a data processor in providing the platform service.
- CricClubOS may act as an independent controller only for data it collects about club administrators for purposes of account management, billing, and service improvement, as described in the Privacy Policy.
3. Nature and purpose of processing
Categories of personal data processed
- Names and contact information (email address, phone number)
- Financial transaction records (membership fees, payments, claims)
- Attendance and participation records (net sessions, events, matches)
- Team and squad membership data
- Board and committee role records
- User account credentials (managed via Keycloak identity service)
Categories of data subjects
- Club members and players
- Club administrators and committee members
- Prospective members who have submitted enquiries
Purpose of processing
Personal data is processed to provide the CricClubOS platform, including member management, financial administration, team and event management, and public club website functionality, as described in the Terms of Service.
Duration
The Processor will process Personal Data for the duration of the subscription and for such period as required by applicable law or as otherwise agreed with the Controller. Upon termination, the Processor will delete or return Personal Data as described in Section 9 below.
4. Processor obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller (including those set out in this DPA), unless required to do so by applicable law.
- Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Section 7.
- Assist the Controller in fulfilling its obligations to respond to Data Subject rights requests as described in Section 8.
- Notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's data.
- Make available all information necessary to demonstrate compliance with this DPA and cooperate with audits or inspections conducted by the Controller or its auditors, subject to reasonable notice and confidentiality obligations.
5. Controller obligations
The Controller shall:
- Ensure it has a valid lawful basis for processing Personal Data and has provided appropriate notices to Data Subjects.
- Ensure the accuracy of Personal Data provided to CricClubOS and respond promptly to any data subject correction requests.
- Use the platform only in accordance with the Terms of Service and applicable data protection law.
- Not instruct the Processor to process Personal Data in a way that would violate applicable law.
6. Sub-processors
The Controller provides general written authorisation for the Processor to engage sub-processors. The Processor will maintain an up-to-date list of sub-processors and will inform the Controller of any intended additions or replacements, giving the Controller a reasonable opportunity to object.
Current sub-processors
- Amazon Web Services (AWS) — Cloud infrastructure, database hosting, and storage. Data stored in EU regions.
- Keycloak (self-hosted on AWS) — Identity and access management, user authentication.
The Processor shall impose data protection obligations equivalent to those in this DPA on all sub-processors and remain liable to the Controller for the performance of those obligations.
7. Security measures
The Processor implements and maintains the following technical and organisational measures:
- Encryption of all data in transit using TLS 1.2 or higher
- Encryption of database volumes at rest using AES-256
- Application-layer encryption of sensitive tokens stored in the database
- Access to production systems restricted to authorised personnel via SSH key authentication
- Regular automated backups with point-in-time recovery
- Database instances hosted within a private VPC with no public access
- Brute-force protection and session management via Keycloak
- Monitoring and alerting for anomalous activity
For more detail, see our Security page.
8. Data subject rights
The Processor will assist the Controller in responding to Data Subject rights requests (access, rectification, erasure, portability, restriction, objection) by providing appropriate tooling within the platform where feasible, and by providing assistance on request where platform tooling is insufficient.
The Controller is responsible for responding to Data Subjects directly. If a Data Subject contacts the Processor directly, the Processor will refer them to the Controller without undue delay.
9. Data return and deletion
Upon termination or expiry of the subscription, the Processor will:
- Make available to the Controller a full export of the Controller's data in a machine-readable format for a period of 30 days following termination.
- Securely delete or destroy all copies of Personal Data after the export window has closed, unless applicable law requires retention for a longer period.
- Confirm deletion to the Controller in writing upon request.
10. International data transfers
Personal data is stored in EU-region AWS data centres. Where any transfer of Personal Data to a third country is required (for example, where a sub-processor operates outside the EEA), the Processor will ensure an appropriate transfer mechanism is in place, such as Standard Contractual Clauses approved by the European Commission.
11. Data breach notification
In the event of a Personal Data breach affecting the Controller's data, the Processor will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. The notification will include, to the extent available:
- A description of the nature of the breach
- The categories and approximate number of data subjects and records affected
- The likely consequences of the breach
- Measures taken or proposed to address the breach
12. Governing law
This DPA is governed by the same law as the Terms of Service. Where the Controller is based in the European Union or the United Kingdom, EU/UK GDPR obligations apply regardless of the governing law of the main agreement.
13. Contact
For questions about this DPA or to request a signed copy, contact us at legal@cricclubos.com.

