Data Processing Agreement (DPA)
This Data Processing Agreement (hereinafter "DPA") specifies the data protection obligations of the parties for the processing of personal data in connection with the use of the "DartClubRanking" service.
Parties
Controller (hereinafter "Customer"): the club using the Service – [Club name and address are entered in the individual contract].
Processor (hereinafter "Provider"): Stefan Huber, Am Steig 22
93309 Kelheim,
Email: info@dartclubranking.com.
§ 1 Subject Matter and Duration
The subject matter is the processing of personal data by the Provider on behalf of the Customer for the provision of the Service. The duration corresponds to the term of the main contract (Terms and Conditions).
§ 2 Nature, Scope, and Purpose of Processing
Purpose: Operating the ranking, recording match results, and generating statistics/analyses for the Customer.
Type of data: in particular player names, match results (legs, wins), highlights/records, dates, and access credentials of the Customer's authorized users.
Categories of data subjects: members/players of the Customer as well as persons authorized by the Customer to enter and manage data.
§ 3 Customer's Right to Issue Instructions
The Provider processes data exclusively on documented instructions from the Customer, unless legally required to process it otherwise. If the Provider considers an instruction to be unlawful, it informs the Customer.
§ 4 Provider's Obligations
- Committing the persons involved in the processing to confidentiality (Art. 28(3)(b), Art. 29 GDPR).
- Implementing and maintaining appropriate technical and organizational measures (§ 5).
- Supporting the Customer in responding to data subject requests and in data protection impact assessments, insofar as necessary and possible.
- Notifying the Customer without undue delay of any breach of the protection of personal data.
§ 5 Technical and Organizational Measures (Art. 32 GDPR)
The Provider takes, in particular, the following measures:
- Tenant separation: logical separation of each club's data via a unique club identifier; access is restricted server-side to the respective club.
- Access protection: password-protected areas for data entry and administration; passwords are stored exclusively as cryptographic hashes (bcrypt).
- Transport encryption: delivery via HTTPS, plus HSTS in production.
- Protection against misuse: CSRF protection on forms, rate limiting of login attempts, restrictive security headers (including Content Security Policy).
- Session security: server-side sessions, session ID regeneration after login.
- Logging: security-relevant events are logged; internal log/status files are blocked from public access.
- Data backup: regular automated database backup by the hosting provider.
§ 6 Sub-processors
The Customer agrees to the use of the following sub-processors:
Hosting/server operation: netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany.
The Provider informs the Customer of intended changes regarding sub-processors and grants the Customer a right to object. Data protection obligations are contractually agreed with each sub-processor.
§ 7 Support with Data Subject Rights
The Provider supports the Customer with appropriate measures in fulfilling data subject rights (access, rectification, erasure, restriction, data portability, objection). Requests from data subjects received by the Provider are forwarded to the Customer.
§ 8 Deletion and Return
After termination of the contract, the Provider deletes the data processed on behalf of the Customer or returns it at the Customer's choice, unless a statutory retention obligation applies.
§ 9 Evidence and Audits
The Provider provides the Customer with the information necessary to demonstrate compliance with this DPA and enables reasonable audits.
§ 10 Liability
The liability provisions of the GDPR apply, as do the supplementary provisions of the main contract (Terms and Conditions).
