This Data Processing Agreement (the «Agreement») forms part of the terms of contract and governs the processing of personal data that 21points carries out on behalf of the customer when the customer uses the platform to manage tournaments and scoreboards. It is entered into pursuant to Article 28 of the GDPR.
1. Parties and roles
The customer (the user who contracts or uses the service) is the controller. Lajana Sistemas S.L. , owner of 21points, is the processor.
2. Subject matter, nature and purpose
The processor will process personal data on behalf of the controller for the sole purpose of providing the 21points service: hosting, storage and processing of the tournament, team and player data that the controller enters into the platform.
3. Duration
Processing will continue for as long as the service relationship between the parties remains in force. Upon its termination, the provisions on return or deletion will apply.
4. Types of personal data
Identification and sports data of players, teams, referees and the organizer's staff: name, jersey number, category, age or date of birth, statistics and results. They may include data of minors.
5. Categories of data subjects
Players (including potential minors), teams, referees and staff connected to the organizer.
6. Obligations of the processor
In accordance with Art. 28(3) GDPR, the processor undertakes to:
- Process the data only on documented instructions from the controller, including with regard to international transfers, unless required by law.
- Ensure that persons authorized to process the data have committed to confidentiality.
- Implement the technical and organizational security measures required by Art. 32 GDPR.
- Respect the conditions for engaging another processor (sub-processor) set out in clause 7.
- Assist the controller in responding to requests from data subjects exercising their rights.
- Assist the controller in complying with the obligations of Arts. 32 to 36 GDPR (security, breach notification and impact assessments), taking into account the information available.
- At the controller's choice, delete or return the data upon completion of the service and delete existing copies, unless retention is legally required.
- Make available to the controller the information necessary to demonstrate compliance with these obligations and allow audits or inspections.
- Immediately inform the controller if it considers that an instruction infringes data protection law.
7. Sub-processors
The controller grants the processor general authorization to engage sub-processors for the provision of the service. The processor currently uses IONOS (hosting and infrastructure, with servers in the European Union). The processor will impose on its sub-processors, by contract, the same data protection obligations. It will inform the controller of any change concerning the addition or replacement of sub-processors, giving the controller the opportunity to object.
8. International transfers
The processor will not transfer the controller's data outside the European Economic Area without appropriate safeguards (adequacy decision, standard contractual clauses or another GDPR safeguard) and without prior notice to the controller. The infrastructure hosting the tournament and player data is located in the European Union.
9. Personal data breaches
The processor will notify the controller, without undue delay, of any personal data breach of which it becomes aware, providing the information necessary for the controller to comply, where applicable, with its notification obligations to the supervisory authority and the data subjects.
10. Return or deletion of the data
Once the provision of the service has ended, and at the controller's choice, the processor will return or delete the personal data and its copies, unless it must retain them under a legal obligation.
11. Liability
Each party is liable for the damages it causes through the breach of its obligations, in accordance with Art. 82 GDPR. The controller warrants that it has a legal basis for the processing and, where applicable, the consent of the holders of parental authority or guardianship regarding the data of minors.
12. Applicable law
This Agreement is governed by the GDPR, the Spanish Organic Law 3/2018 (LOPDGDD) and the rest of the applicable Spanish data protection legislation.