Data Processing Addendum (Schedule 1)
Breezy Clubs OS Ltd (trading as Breezy Tech) · UK GDPR Article 28 Effective date: 18 August 2026 · Version: 2.0
Purpose
This Data Processing Addendum ("DPA") is Schedule 1 to the Operator Terms of Service and is incorporated by reference. It satisfies UK GDPR Article 28, which requires a written contract between Controller and Processor before processing begins. Electronic acceptance of the Operator Terms of Service constitutes acceptance of this DPA; the acceptance record (timestamp, IP, user, document version) is the execution record.
For the related-entity arrangement between Breezy Club and Breezy Clubs OS Ltd (trading as Breezy Tech), this DPA is executed separately as a signed document (DocuSign), not via the platform flow.
Parties
| Role | Party |
|---|---|
| Data Controller | The Operator named in the Operator Terms of Service |
| Data Processor | Breezy Clubs OS Ltd (trading as Breezy Tech), Company No. 17339734, 35 Grafton Way, London, W1T 5DB, ICO No. ZC199357 |
1. Definitions
"Data Protection Laws" means UK GDPR, the Data Protection Act 2018, PECR 2003, and successor legislation. "Controller Personal Data" means personal data processed by the Processor on the Controller's behalf. "Sub-Processor", "Processing", "Personal Data Breach", and "Special Category Data" have the meanings given in Data Protection Laws. "Security Incident" means a Personal Data Breach affecting Controller Personal Data.
2. Scope of Processing
2.1 Subject matter and purpose. Provision of the Platform services: booking management, registers and attendance, staff management, parent communications, and payment facilitation via Stripe Connect.
2.2 Duration. The subscription term plus the wind-down period required for secure deletion.
2.3 Data subjects. Parents/guardians; children attending the Controller's camps; the Controller's staff; nominated emergency contacts.
2.4 Data categories. Identity and contact data; children's medical and health data (Special Category); staff compliance data (DBS numbers, passport, right-to-work); attendance and booking records; payment references; profile photographs (private encrypted storage).
2.5 Instructions. The Processor processes Controller Personal Data only on the Controller's documented instructions (these Terms and the Platform's documented functionality), unless required by law — in which case the Processor informs the Controller before processing unless legally prohibited. The Processor will inform the Controller immediately if it considers an instruction infringes Data Protection Laws.
3. Processor Obligations
3.1 Confidentiality. All persons authorised to process Controller Personal Data are bound by confidentiality obligations. Access is limited to personnel who need it to operate and maintain the Platform.
3.2 Security measures (Art. 32). The Processor maintains appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Row-level security enforcing strict tenant isolation, continuously verified by an automated isolation test suite run before every deployment
- Role-based access control on least-privilege principles; MFA available on all admin accounts
- Private encrypted storage for all sensitive files; no public URLs
- Technically enforced DBS verification gate on all child-data access
- Audit logging of elevated access and access to special category data
- Rate limiting on authentication and payment endpoints
- Automated secret scanning and security checks in CI/CD
- Error monitoring with PII redaction
- Documented secure development methodology
3.3 Special Category Data. Additional controls: access restricted to users with an explicit operational need; access logging; no processing for any purpose beyond safeguarding and camp operations; never used for AI training, profiling, or marketing.
4. Sub-Processors
4.1 General authorisation is granted for the sub-processors listed below:
| Sub-Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase Inc. | Database, auth, storage | UK/EU (London) | DPA + SCCs |
| Stripe | Payment processing | UK/EU | DPA; UK adequacy + SCCs |
| Vercel Inc. | Hosting | EU edge | DPA + SCCs |
| Resend Inc. | Transactional email | EU | DPA + SCCs |
| Functional Software Inc. (Sentry) | Error monitoring | EU residency | DPA + SCCs |
| Upstash Inc. | Rate limiting / cache | EU | DPA + SCCs |
| CookieYes Ltd | Consent management | EU | DPA |
| PostHog Inc. | Analytics (consent-gated) | EU hosting | DPA + SCCs |
4.2 Changes. 30 days' written notice of sub-processor additions or replacements. The Controller may object on reasonable data protection grounds within 14 days; failing agreement, the Controller may terminate without penalty.
4.3 Flow-down. Equivalent data protection obligations are imposed on all sub-processors. The Processor remains fully liable for sub-processor performance.
5. Controller Obligations
The Controller warrants that it: complies with all applicable Data Protection Laws, including any registration or notification requirements that apply to it; has a lawful basis for all personal data entered into the Platform; has provided Article 13/14 notices (its own privacy policy) to its data subjects; has obtained explicit consent for children's medical data before entering it; keeps data accurate; will not issue unlawful instructions; and will promptly notify the Processor of data subject requests relating to Platform data.
6. Data Subject Rights Assistance
The Processor will: notify the Controller without undue delay of any data subject request it receives directly; provide data export tooling (access and portability); provide a self-service erasure flow with retention carve-outs; support restriction of processing on instruction. The Controller remains responsible for responding within statutory deadlines.
7. Security Incidents
7.1 The Processor notifies the Controller without undue delay and within 48 hours of becoming aware of a Security Incident, including (as available, in phases if necessary): nature of the incident; categories and approximate numbers of data subjects and records; likely consequences; measures taken or proposed; a contact point.
7.2 The Controller is responsible for its own ICO notification within 72 hours where required (Art. 33) and for data subject notification where required (Art. 34). The Processor provides reasonable assistance and maintains incident documentation.
8. International Transfers
Processing occurs primarily in the UK/EU. Transfers to third countries without adequacy are protected by the UK International Data Transfer Agreement or UK Addendum to the EU SCCs. US-headquartered sub-processors operate UK/EU data residency with SCCs in place.
9. Retention, Return, and Deletion
On termination or written instruction: 30-day export window for the Controller; secure deletion from live systems within 30 days thereafter; deletion from backups within 90 days; statutory-retention data (e.g. payment records) retained only as required by law and then deleted; written confirmation of deletion on request.
10. Audit
The Processor makes available information reasonably necessary to demonstrate Article 28 compliance, and permits audits: maximum once per 12 months, 30 days' written notice, business hours, Controller's cost, subject to confidentiality. The Processor may satisfy audit requests by providing its most recent independent security assessment or penetration test report.
11. Liability
Each party is liable for and indemnifies the other against fines, penalties, and claims arising from its own breach of Data Protection Laws or this DPA. Where both parties are responsible, liability is apportioned to reflect responsibility. Liability under this DPA is subject to the limitations in the Operator Terms of Service, save where Data Protection Laws prohibit such limitation.
12. Governing Law
England and Wales; exclusive jurisdiction of its courts.
Schedule A — Record of Processing (Art. 30 summary)
| Activity | Data categories | Controller's lawful basis | Retention |
|---|---|---|---|
| Parent account management | Identity, contact, account | Contract | Active + 2 years |
| Booking and payment | Identity, booking, payment reference | Contract | 6 years; payment records 7 years |
| Attendance management | Identity, attendance | Contract; legal obligation | 3 years post-last attendance |
| Children's medical data | Health (Special Category) | Explicit consent; vital interests | 3 years post-last attendance |
| Staff compliance | Identity, DBS, passport, RTW | Legal obligation; contract | 1 year post-last assignment |
| Communications | Contact, booking context | Contract; legitimate interests | Account duration |
| Audit logging | User IDs, actions, timestamps | Legitimate interests | 3 years |
Execution
Platform flow (standard operators): acceptance recorded electronically at onboarding — timestamp, IP address, user ID, document version and content hash — in an immutable insert-only record. Valid under the Electronic Communications Act 2000.
Related-entity execution (Breezy Club ↔ Breezy Clubs OS Ltd (trading as Breezy Tech)): signed via DocuSign by authorised signatories of both entities; signed copy retained.
| Data Processor | Data Controller | |
|---|---|---|
| Entity | Breezy Clubs OS Ltd (trading as Breezy Tech) | [Operator name] |
| Signatory | ____________________ | ____________________ |
| Date | ____________________ | ____________________ |
Version 2.0 · Effective 18 August 2026