Data Processing Agreement (DPA)
For clubs, teams and organisations where ThatPlay processes data on your behalf.
Last updated 2026-08-09 · version 1.0
Draft for organisation customers. Requires final legal review before it is used in commercial club or organisation contracts. Individual coach users do not need to accept this document.
1. Parties and scope
This agreement applies between the customer (the controller) and ThatPlay (the processor) where the customer uses ThatPlay to process personal data for the customer's own purposes. It supplements the Terms of Service.
2. Subject matter, nature and purpose
Subject matter: provision of the ThatPlay sports video analysis service. Nature and purpose: storing, organising, retrieving, displaying, exporting and deleting analysis data entered by the customer's authorised users.
3. Duration
Processing continues for as long as the customer uses the service, and afterwards only as needed for deletion or return of data or to meet legal obligations.
4. Categories of data subjects
- the customer's authorised users (coaches, analysts, staff)
- players and other individuals appearing in or referenced by the customer's analysis material
5. Types of personal data
The customer must not enter special categories of personal data (such as health or biometric data) into ThatPlay.
- account and contact data of authorised users
- analysis data: matches, moments, categories, tags, player numbers, positions, classifications, observations and notes
- tactical board data, reviews, comparisons and reference video metadata
- technical and security information generated by use of the service
6. Documented instructions
The processor processes personal data only on the customer's documented instructions, which consist of this agreement, the Terms of Service and the customer's use of the service's functionality — unless required otherwise by law, in which case the processor informs the customer unless the law prohibits it.
7. Confidentiality
Personnel authorised to process the personal data are bound by confidentiality obligations.
8. Security
The processor implements appropriate technical and organisational measures, including authenticated access, per-user and per-tenant data isolation enforced in the database, least-privilege access to production data, server-side authorisation for privileged operations and secure secrets management.
9. Subprocessors
The customer gives general authorisation for the subprocessors listed on the Subprocessors page. The processor informs the customer of intended changes and imposes equivalent data protection obligations on each subprocessor.
10. Assistance
Taking into account the nature of the processing, the processor assists the customer with responding to data subject requests, and with security, breach notification, data protection impact assessments and prior consultation obligations.
11. Personal data breach
The processor notifies the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, with the information reasonably available.
12. Deletion or return
On termination the processor deletes or returns the personal data at the customer's choice, except where storage is required by law. Export functionality is available in the service.
13. Audits
The processor makes available the information reasonably required to demonstrate compliance and contributes to audits, including inspections, conducted by the customer or an auditor mandated by the customer, subject to reasonable notice and confidentiality.
14. International transfers
Any transfer of personal data outside the EU/EEA requires a valid transfer mechanism. The applicable hosting locations and mechanisms are documented on the Subprocessors page and are being confirmed with our infrastructure provider before organisation customers are onboarded commercially.
15. Acceptance
When organisation accounts are introduced, an authorised representative accepts this DPA on behalf of the organisation and the acceptance is recorded with organisation, version, person and timestamp. Individual members do not accept it separately.