Data Processing Agreement
Version 0.3, effective 26 September 2026. This document is under review by legal counsel ahead of public launch; it applies in full until the reviewed version replaces it.
This agreement applies between every organization (club) that uses the service — the Controller — and Coplanio — the Processor — and forms part of the Terms of Service. It sets out how Coplanio processes the personal data the club stores in the service, as Article 28 of the GDPR requires.
1. Subject matter, duration, nature and purpose
The Processor processes personal data on behalf of the Controller for the purpose of providing the Coplanio service: storing and displaying the Controller's club records, running its training and match administration, and generating reports and exports the Controller requests. Processing lasts as long as the Controller's organization exists in the service, plus the deletion period in section 9.
2. Types of personal data and categories of data subjects
Data subjects and data types:
- Players, including minors: name, date of birth, position, preferred foot, status, coaches' notes, attendance, training load and perceived exertion, assessment results, match involvement.
- Guardians of players: email address, portal access records.
- Coaching staff and members of the organization: name, email, role, team assignments, invitations, actions recorded in the audit trail.
3. Processing on documented instructions
The Processor processes personal data only on the Controller's documented instructions — the Terms of Service, this agreement and the Controller's use of the service's functions — unless required to do otherwise by law, in which case it informs the Controller before processing where the law allows. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR.
4. Confidentiality and security
Persons authorised to process the data are bound by confidentiality. The Processor implements the technical and organisational measures required by Article 32 GDPR, including: isolation of each organization's data at the database level (row-level security), role- and team-based access control, encryption in transit and at rest, hashed credentials, an audit trail of important changes, and restriction of administrative access to what is necessary.
5. Assistance to the Controller
Taking into account the nature of the processing, the Processor assists the Controller with appropriate measures in responding to data subjects' requests (access, rectification, erasure, restriction, portability, objection), and in meeting the Controller's obligations on security, breach notification, data protection impact assessments and prior consultation. The service's export functions — the player roster as CSV or XLSX, the audit trail as CSV (the most recent 5,000 entries per download), the calendar as iCalendar and reports as PDF — and the audit trail itself are part of this assistance; data that no export function covers is provided by the Processor on request, in a structured, commonly used and machine-readable format.
6. Personal data breaches
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and provides the information the Controller needs for its own notification to the supervisory authority and to data subjects: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.
7. Sub-processors
The Controller gives general authorisation to the use of the following sub-processors, each bound by a written agreement imposing the same data protection obligations as this agreement. The Processor remains fully liable to the Controller for their performance.
The Processor informs the Controller's administrators of an intended addition or replacement at least 14 days in advance; the Controller may object on reasonable data protection grounds, in which case the parties discuss the objection in good faith and the Controller may terminate its use of the service if it cannot be resolved.
- Supabase, Inc. — database, authentication, file storage, server-side functions (including the search index of the reference library) and account emails. Data is stored in the London region (eu-west-2, United Kingdom), a jurisdiction covered by an EU adequacy decision.
- Vercel, Inc. — application hosting and content delivery for coplanio.app (United States; transfers covered by the EU–US Data Privacy Framework and standard contractual clauses).
- Anthropic, PBC — the AI model behind the exercise generator and the session planner (United States; standard contractual clauses). Both features are switched off at present, so it receives nothing from your use of the service; when one is switched on, it receives only what is described in the AI section: the text you type, the team's name, age group and level, and your exercise catalogue.
8. International transfers
Personal data is stored in the United Kingdom (adequacy decision). Transfers to sub-processors in the United States are covered by the EU–US Data Privacy Framework or the European Commission's standard contractual clauses, as stated for each sub-processor above.
9. Deletion and return of data
At the end of the service the Controller may download what the service's export functions cover (section 5) and may ask the Processor for a copy of its other records and of the images uploaded to it, which the Processor provides in a structured, commonly used and machine-readable format before deleting them. On the Controller's written request to support@coplanio.app, the Processor deletes the organization's personal data — its records and the images uploaded to it — within 30 days of verifying the request, unless the law requires it to keep some of it, and confirms the deletion.
10. Audits
The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it, with reasonable notice, during business hours, no more than once a year unless a breach or a supervisory authority requires otherwise, and at the Controller's cost.
11. The Controller's responsibilities
The Controller warrants that:
- it has a lawful basis for the processing and has informed players, guardians and staff as the GDPR requires;
- for the records of minors it holds the authority required by the law that applies to it, including parental consent where necessary;
- it enters no health, medical or other special-category data in free-text fields unless it has a lawful basis for it;
- the data it enters is accurate and it manages its members' roles and access.
12. Term, liability and law
This agreement applies for as long as the Processor processes personal data for the Controller. Each party is liable towards the other as provided by the GDPR and the Terms of Service. The agreement is governed by the same law as the Terms of Service.