Data Processing Agreement

Pursuant to Article 28 of the General Data Protection Regulation (GDPR)

Τελευταία ενημέρωση: August 3, 2026

Αυτό το έγγραφο διατίθεται μόνο στα αγγλικά.
Η αγγλική έκδοση είναι η νομικά δεσμευτική.

This is the reference copy of the Data Processing Agreement between a club or academy as Data Controller and Tactye Oy, located in the European Union, as Data Processor. The signed copy names the Controller and its contact details and is exchanged separately; write to admin@tactye.com for it.

This Agreement forms part of the Terms of Service and governs the processing of personal data by the Processor on behalf of the Controller, in accordance with Article 28 of the GDPR (and, where applicable, the UK GDPR).

1. Subject Matter

The Processor provides a digital sports coaching platform including:

  • Team and player management
  • Training planning and scheduling
  • Tactical board tools
  • AI-assisted coaching features

Processing occurs solely to deliver these services to the Controller.

2. Duration

This Agreement applies for the duration of the Controller’s use of the Service and continues until all personal data is deleted or returned in accordance with this Agreement.

3. Nature and Purpose of Processing

Personal data is processed to:

  • Manage team and player information
  • Support training and coaching activities
  • Generate tactical boards and analyses
  • Provide AI-assisted coaching insights
  • Maintain service functionality and security

4. Categories of Data Subjects

Data subjects may include:

  • Players (including minors)
  • Parents and legal guardians
  • Coaches and staff
  • Team officials

5. Types of Personal Data

Personal data may include:

  • Names, dates of birth, team assignments
  • Training attendance and event-specific notes
  • Tactical board participation records

6. Roles and Responsibilities

6.1 Controller Obligations

The Controller shall:

  • Ensure a lawful basis for processing (including parental consent for minors)
  • Comply with GDPR Articles 5, 6, and 8
  • Respond to data subject rights requests related to data it controls
  • Ensure only necessary data is uploaded to the Service

6.2 Processor Obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller
  • Ensure confidentiality obligations are imposed on all authorised personnel
  • Implement appropriate technical and organisational measures (Article 32 GDPR)
  • Assist the Controller in fulfilling its GDPR obligations
  • Not disclose personal data without authorisation or legal requirement
  • Notify the Controller without undue delay upon becoming aware of a personal data breach

7. Processing Involving Minors

Where personal data of minors is processed:

  • The Controller confirms that valid parental or legal guardian consent has been obtained prior to data entry
  • The Processor processes such data solely to provide the Service
  • The Service is not designed for direct, unsupervised use by minors
  • The Controller bears responsibility for all safeguarding obligations outside the platform

8. AI-Assisted Processing

The Service includes AI-assisted functionality. In this context:

  • Personal data may be technically processed by AI systems to deliver coaching insights
  • AI outputs are advisory only and do not constitute professional coaching advice
  • Where feasible, data used for AI model improvement is aggregated or anonymised before use
  • Personal data is not sold or used for advertising or profiling unrelated to coaching

Lawful basis for AI processing: Where personal data is used to train or improve AI systems, processing will be based on an appropriate lawful basis under Article 6 GDPR. The Controller will be notified before any new AI processing activities are introduced.

9. Sub-Processors

The Controller authorises the use of sub-processors solely for:

  • Hosting and infrastructure
  • Security monitoring
  • Analytics related to platform performance

All sub-processors:

  • Are located within the European Union or subject to appropriate GDPR safeguards
  • Are bound by data protection obligations equivalent to those in this Agreement

Notification: A current list of sub-processors is available upon request and will be published on the Processor’s website. The Processor will notify the Controller at least 14 days before adding any new sub-processor. If an objection cannot be resolved, either party may terminate this Agreement on written notice.

10. Data Location and International Transfers

All primary data storage and processing occurs within the European Union. No personal data is transferred outside the EU without:

  • An adequacy decision by the European Commission, or
  • Appropriate safeguards in accordance with Article 46 GDPR (e.g. Standard Contractual Clauses). For transfers involving UK personal data, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses will be used. The UK and EU currently recognise each other as providing adequate protection, so transfers between the UK and EEA are permitted

11. Security Measures (Article 32 GDPR)

The Processor implements technical and organisational measures including:

  • Access controls and multi-factor authentication
  • Encrypted data transmission (TLS)
  • Logical separation of customer data
  • Regular security reviews and penetration testing
  • Incident detection and response procedures
  • Staff training on data protection obligations

12. Personal Data Breach Notification

In the event of a personal data breach, the Processor shall:

  • Notify the Controller without undue delay upon becoming aware of the breach
  • Provide all information required for the Controller to fulfil its obligations under Articles 33–34 GDPR
  • Cooperate with the Controller to investigate and remediate the breach

Controller obligation: The Controller is responsible for notifying the relevant supervisory authority (e.g. Traficom / Office of the Data Protection Ombudsman in Finland, or the Information Commissioner’s Office (ICO) in the United Kingdom) without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33 GDPR). Where the breach is likely to result in high risk to individuals, affected data subjects must also be notified (Article 34 GDPR).

13. Data Subject Rights Assistance

The Processor shall assist the Controller in responding to data subject rights requests under Chapter III GDPR, including:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20) — data provided in CSV or JSON format upon request
  • Right to object (Article 21)

14. Data Deletion and Retention

Upon termination of the Service, the following retention schedule applies:

14.1 Immediate notification

The Processor will notify the Controller by email within 5 business days of subscription expiry, confirming the data export deadline and deletion date.

14.2 Default 30-day retention period

Personal data is retained for 30 days from the date of subscription expiry. During this period:

  • Data remains stored but the Service is inaccessible
  • The Controller may export all data at any time within this period
  • The Controller may reactivate the subscription to restore full access

After 30 days, all personal data is permanently deleted or irreversibly anonymised, unless a written extension has been granted under §14.3.

14.3 Controller-requested extension

The Controller may request an extension of the 30-day retention period by sending a written request by email to admin@tactye.com before the deadline expires. The following conditions apply:

  • The request must be received by email before the 30-day deadline; late requests cannot be accommodated once deletion has commenced
  • The Company will confirm receipt in writing and log the request as a documented Controller instruction under Article 5(2) GDPR accountability obligations
  • Where an extension is granted, retention is extended by up to 180 days per written request
  • Further extensions beyond the initial 180-day period require a new written request and are granted at the Processor’s discretion, subject to GDPR compliance
  • All extension requests and written confirmations are retained by the Processor as records of the Controller’s documented instruction

14.4 Legal retention obligations

Where a specific legal obligation requires retention of particular data categories (e.g. financial records under Finnish accounting law), only the minimum data necessary is retained for the duration of that legal obligation. Such data is restricted from active processing and deleted as soon as the legal obligation expires.

14.5 Controller responsibility

The Controller is responsible for exporting all required data before the retention deadline. The Processor is not liable for data loss resulting from the Controller’s failure to export data within the applicable retention period.

15. Audits and Compliance

The Processor shall:

  • Make available all information necessary to demonstrate compliance with this Agreement and Article 28 GDPR
  • Allow and contribute to audits and inspections conducted by the Controller or a mandated auditor, with reasonable notice
  • Maintain records of processing activities as required by Article 30 GDPR

16. Liability

Each party is liable for damages caused by its own breach of GDPR obligations within its scope of responsibility. Neither party is liable for breaches caused by the other party’s failure to comply with its obligations under this Agreement or applicable law.

17. Governing Law

This Agreement is governed by the laws of Finland (or the country where Tactye Oy is registered). Disputes shall be resolved in accordance with the dispute resolution clause in the Terms of Service. Where the Controller or data subjects are located in the United Kingdom, references to the GDPR in this Agreement shall be read as including the UK GDPR and the Data Protection Act 2018.

18. Contact

For data protection queries relating to this Agreement: Tactye Oy, admin@tactye.com. The Controller’s contact is the one specified in the signed copy.

19. Governing Language

This Agreement is made available in English and may be translated into other languages for the convenience of the parties. In the event of any conflict, ambiguity, or discrepancy between the English version and any translated version, the English language version shall prevail and be the legally binding version.

Where applicable law requires this Agreement to be provided in a specific language for a particular jurisdiction, the locally required language version shall be authoritative only for parties in that jurisdiction and only to the extent required by law.

Privacy notices and consent information directed at individual data subjects (including parents and guardians of minor players) will be provided in the language of the jurisdiction in which the Service is actively offered, in accordance with Articles 7 and 12 of the GDPR.