DATA PROCESSING ADDENDUM
This Data Processing Addendum ("DPA") forms part of and is incorporated into the Membership Agreement ("Membership Agreement") between Gymnastics Growth Limited, company number 13031738, of Third Floor, 207 Regent Street, London, W1B 3HH ("Processor") and the Member Club ("Controller").
This DPA applies where the Processor processes personal data on behalf of the Member Club in connection with the Programme and related services. It is entered into in accordance with Article 28 of the UK General Data Protection Regulation ("UK GDPR").
Terms used in this DPA that are defined in the UK GDPR carry the meaning given there. "Personal data breach" has the meaning given in Article 4(12) UK GDPR, being a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
ROLES OF THE PARTIES
1.1 For the purposes of this DPA, the Member Club is the Data Controller and Gymnastics Growth Limited is the Data Processor.
1.2 The Controller determines the purposes for which, and the general means by which, personal data relating to its staff, users and authorised participants is processed. The Processor determines the technical and organisational means by which the Programme is delivered, including its infrastructure and its choice of sub-processors, subject to Clause 7.
1.2.1 Documented instructions comprise this DPA, the Membership Agreement, and the actions taken by the Controller's administrators within the platform. Configuring the organisation's account, inviting or removing an authorised user, granting or withdrawing access, and generating a report each constitute a documented instruction for the purposes of Clause 1.3. The Controller may give further instructions in writing to support@gymnasticsos.com.
1.3 The Processor shall process such data only on documented instructions from the Controller, including in relation to any transfer of personal data outside the United Kingdom, except where required to do otherwise by law. Where the Processor is required by law to process personal data other than on the Controller's instructions, it shall inform the Controller of that legal requirement before processing, unless the law prohibits it from doing so.
1.4 The Processor shall immediately inform the Controller if, in its opinion, an instruction given by the Controller infringes the UK GDPR or other applicable data protection law.
1.5 The Processor acts as Data Controller in respect of matters set out in its Privacy Policy. These include a member's own GymnasticsID; the security monitoring of accounts described in Schedule 1; the administrative audit log recording changes made to an account by the Processor's staff; the Processor's own analytics; service and incident notices displayed within the platform; and the checking of memberships to identify a person paying separately for something an organisational licence already includes.
This DPA does not apply to that processing, the Controller may not instruct the Processor in respect of it, and it is not subject to Clause 6.2. Retention of it is governed by the periods stated in the Processor's Privacy Policy.
SUBJECT MATTER AND DURATION
2.1 The subject matter of processing includes staff account management, onboarding, coaching participation, programme administration, certifications, assessments, surveys, benchmarking activities, reporting, analytics, communications, participation monitoring and related support services.
2.2 Processing shall continue for the duration of the Membership Agreement, and thereafter only for so long as is necessary to give effect to Clause 6.2 or as required by law.
NATURE AND PURPOSE OF PROCESSING
3.1 The Processor processes personal data for the purpose of:
(a) providing access to Programme services;
(b) administering memberships and authorised users;
(c) delivering coaching, onboarding and support services;
(d) managing certifications and assessments;
(e) providing the reporting described in Clause 7.8 of the Membership Agreement, being whether an account is active, when it was last used, participation in Programme content and certification status, together with aggregated and anonymised benchmarking against comparable organisations;
(f) facilitating community participation;
(g) supporting organisational development activities;
(h) providing customer support and operational services.
3.2 The Processor shall not use personal data for its own independent purposes where acting as Processor.
CATEGORIES OF DATA SUBJECTS
4.1 Data subjects may include:
(a) coaches; (b) managers; (c) club owners; (d) directors; (e) administrative staff; (f) authorised users; (g) contractors and volunteers where added by the Controller.
CATEGORIES OF PERSONAL DATA
5.1 Personal data processed may include:
(a) names; (b) email addresses; (c) job titles and roles; (d) club affiliation; (e) authentication records, being the single-use sign-in codes issued to a user and the record of their use; (f) participation records; (g) certification and assessment records; (h) onboarding information; (i) survey responses; (j) benchmarking submissions; (k) coaching notes; (l) transcripts and recordings where applicable; (m) platform usage information; (n) communications and support records.
5.2 The Processor does not provide the Programme for the processing of special category data or of personal data relating to criminal offences. The Processor's Terms of Use and Acceptable Use Policy set out what must not be submitted to the platform. The Controller must comply with those restrictions and is responsible for ensuring that its authorised users do so.
PROCESSOR OBLIGATIONS
6.1 The Processor shall:
(a) process personal data only on documented instructions;
(b) ensure that persons authorised to process the personal data are subject to an appropriate duty of confidence;
(c) implement the technical and organisational security measures set out in Schedule 1, and any others appropriate to the risk in accordance with Article 32 UK GDPR;
(d) maintain appropriate access controls, and restrict access to those of its personnel who require it;
(e) taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in responding to requests from data subjects exercising their rights, and forward to the Controller any such request it receives directly within five (5) working days;
(f) notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting Controller data, providing the information the Controller reasonably requires in order to meet its own notification obligations. This period is the Processor's obligation to the Controller. It is separate from, and shorter than, the Controller's own obligation to report a qualifying breach to the Information Commissioner's Office within seventy-two (72) hours, which remains the Controller's responsibility;
(g) assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 UK GDPR, including security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to the Processor;
(h) maintain a record of the categories of processing carried out on behalf of the Controller, as required by Article 30(2) UK GDPR, and make it available to the Controller on request;
(i) at the Controller's written request, provide the information reasonably necessary to demonstrate compliance with this DPA and with Article 28 UK GDPR.
6.1.1 Access During the Term
The Controller may access the personal data processed on its behalf at any time through the administrative tools provided within the platform, This right does not depend on termination, and Clause 6.2.2 explains what happens to that access when the Membership Agreement ends.
6.2 What Happens at the End
On termination of the Membership Agreement, the Controller's access ends and the link between the organisation and each of its authorised users is severed. The Processor does not automatically send the Controller a copy of anything.
6.2.1 What does not end. An authorised user's GymnasticsID is their own account and is not part of the personal data processed on the Controller's behalf. It continues to exist, as does any certification that user has earned, and neither is deleted by the ending of the Controller's membership. The Processor's Club Link Terms explain this to the individual.
6.2.2 Return. The Processor does not provide a self-service export. Throughout the Membership Agreement the Controller can see the personal data processed on its behalf through the administrative tools in the platform, being its staff list, the roles and status of each authorised user, and the reporting described in Clause 7.8 of the Membership Agreement.
Where the Controller wants a copy of that data, whether during the Membership Agreement or within thirty (30) days after it ends, it may ask the Processor in writing and the Processor will provide what it holds in a reasonable electronic format within thirty (30) days.
6.2.3 Deletion. The Controller may at any time, during the Membership Agreement or after it ends, require the Processor to delete the personal data it holds on the Controller's behalf. The Processor shall do so within thirty (30) days of the request and shall confirm when it is done.
Where no such request is made, the Processor retains that data for the periods set out in its Privacy Policy. It is not deleted automatically on cancellation, and the Controller should make a request if it wants it removed.
Neither this clause nor a request under it applies where the Processor is required by law to retain the data, or where the data falls within Clause 1.5, retention of which is governed by the Processor's Privacy Policy.
6.3 Audits and Inspections
The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.
In the first instance the Processor shall satisfy such a request by providing its written responses, its record of processing, and any certification or third-party report it holds. Where that is not sufficient to demonstrate compliance, the Controller may carry out an inspection, on not less than thirty (30) days' written notice, no more than once in any twelve month period unless a breach has occurred, during business hours, subject to reasonable confidentiality and security requirements, and without unreasonable disruption to the Processor's operations. Each party shall bear its own costs.
SUB-PROCESSORS
7.1 The Controller gives the Processor general written authorisation to engage sub-processors for the purposes described in this DPA.
7.2 The Processor maintains a current list of the sub-processors it engages in providing the Programme, together with the purpose of each and the categories of personal data involved. The Controller may obtain the list at any time by writing to support@gymnasticsos.com.
The list is provided to the Controller for the purpose of its own data protection compliance. It is confidential information of the Processor, is subject to the confidentiality provisions of the Membership Agreement, and must not be disclosed to any third party or used for any other purpose.
7.3 Where the Processor intends to add or replace a sub-processor, it shall give the Controller not less than thirty (30) days' written notice before that sub-processor begins processing Controller data.
7.4 The Controller may object to an intended change on reasonable data protection grounds by giving written notice within that period. The parties shall discuss the objection in good faith. Where it cannot be resolved, and the Processor is unable to provide the service without the sub-processor concerned, the Controller may terminate the Membership Agreement in respect of the affected services, and the Processor shall refund the unused portion of any fees paid in advance.
7.5 The Processor shall impose on each sub-processor data protection obligations no less protective than those in this DPA, and shall remain fully liable to the Controller for the performance of each sub-processor's obligations.
7.6 The notice and objection rights in Clauses 7.3 and 7.4 apply to sub-processors engaged directly by the Processor. Where a sub-processor engages a further processor of its own, that arrangement is covered by the obligations imposed under Clause 7.5, and the Processor remains liable for it. The Processor will notify the Controller of a change at that level where it is material to the processing of Controller data and the Processor is itself given notice of it.
AI-ASSISTED PROCESSING
8.1 The Controller acknowledges that the Processor may use AI-assisted technologies to support transcription, summarisation, organisation, analysis, reporting and service delivery.
8.2 Such technologies are engaged as sub-processors and are subject to Clause 7. The Processor uses business or enterprise accounts operating under a data processing agreement, configured so that Controller data is not used to train the provider's models.
8.3 AI-assisted processing remains subject to human oversight and shall not constitute a decision based solely on automated processing which produces legal effects concerning a data subject or similarly significantly affects them.
INTERNATIONAL TRANSFERS AND LOCATION OF PROCESSING
9.1 The Programme is delivered using infrastructure and sub-processors located outside the United Kingdom, including in the United States and the European Economic Area, and is available to members and organisations internationally. The Controller acknowledges this and instructs the Processor to carry out the transfers necessary to provide the Programme.
9.2 Where personal data subject to UK or EEA data protection law is transferred outside the United Kingdom or the EEA, the Processor shall ensure an appropriate safeguard is in place, being an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or another mechanism permitted under the applicable law.
9.3 The Processor shall identify, on request, the location of processing for any sub-processor it engages and the transfer mechanism relied upon.
9.4 Where the Controller is established outside the United Kingdom, the Controller remains responsible for compliance with the data protection and privacy law applicable to it, and for ensuring that the instructions it gives the Processor are lawful under that law. The Processor does not advise the Controller on the law of any other jurisdiction.
CONTROLLER OBLIGATIONS
10.1 The Controller warrants that it has a lawful basis for the personal data it provides to the Processor or causes to be provided, and that it has given the privacy information required by Articles 13 and 14 UK GDPR to the individuals concerned.
10.2 The Controller is responsible for the accuracy of the personal data it provides and for the instructions it gives.
10.3 The Controller is responsible for determining who among its personnel is an authorised user, for removing access when a person no longer requires it, and for the conduct of its authorised users in relation to Clause 5.2.
LIABILITY
11.1 Liability arising under this DPA shall be subject to the liability provisions contained within the Membership Agreement.
ORDER OF PRECEDENCE
12.1 In the event of conflict between this DPA and the Membership Agreement, this DPA shall prevail in respect of data protection matters.
GOVERNING LAW AND JURISDICTION
13.1 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction in respect of it, save where applicable law requires otherwise.
SCHEDULE 1 - TECHNICAL AND ORGANISATIONAL MEASURES
The Processor implements the following measures, and keeps them under review:
Access. Access to the platform is authenticated by a single-use code sent to the user's registered email address. The Processor does not use or store passwords. Access within the platform is governed by role and by organisation membership, enforced at the database layer rather than in the interface alone.
Encryption. Personal data is encrypted in transit using TLS, and encrypted at rest by the Processor's hosting provider.
Staff access. Access by the Processor's personnel is restricted to those who require it for their role and is scoped to the minimum necessary. Personnel are subject to a duty of confidence. Administrative actions affecting a member's account are recorded in an audit log which is retained and is not editable.
Monitoring. The Processor records devices and sign-in events and applies automated checks for indicators of account sharing or compromise. Accounts may be restricted or locked following review by a member of the Processor's staff.
Segregation. Data belonging to one Member Club is segregated from that of another by access controls enforced at the database layer.
Resilience. The hosting provider maintains backups of the database. The Processor tests restoration of data periodically.
Sub-processors. Each sub-processor is recorded, together with its purpose, the categories of personal data it receives and its processing location, and is subject to Clause 7.
Incidents. The Processor maintains a process for identifying, recording and responding to security incidents, and for notifying the Controller in accordance with Clause 6.1(f).