Legal

Data Processing Agreement

UK GDPR controller and processor terms for organisations using ClassControl.

Effective: 18 July 2026 Last reviewed: 18 July 2026 Version: 1.0

1. Scope and roles

This DPA forms part of the agreement between the customer as Controller and Eatwell Tech Solutions as Processor where Eatwell Tech Solutions processes personal data on the customer’s behalf through ClassControl.

2. Processing details

Subject: provision, hosting, support and security of ClassControl. Duration: the service term plus an agreed deletion or return period. Nature: collection, storage, organisation, retrieval, transmission, restriction, support and deletion. Purpose: class and member administration.

Data subjects may include members, prospective members, instructors, employees, contractors and customer administrators. Data may include identity, contact, account, booking, attendance, communication, technical and optional PAR-Q/health information.

3. Documented instructions

The Processor will process personal data only on the Controller’s documented instructions, including instructions in the agreement, configuration and authorised support requests, unless UK law requires otherwise. The Processor will notify the Controller before legally required processing unless prohibited.

4. Confidentiality

Personnel authorised to process personal data will be subject to confidentiality obligations and receive access only where needed for their role.

5. Security

The Processor will implement appropriate technical and organisational measures, taking account of risk, cost, state of the art and the nature of processing. Current measures are described in the Information Security Policy and include HTTPS/TLS, password hashing, role-based access, multi-factor authentication for Super Administrators and AES-256-GCM application-level encryption for protected PAR-Q fields.

6. Sub-processors

The Controller provides general authorisation for the Processor to appoint sub-processors required to deliver the service. The Processor will impose data-protection obligations providing an equivalent level of protection and remain responsible for sub-processor performance. Current categories are listed on the Sub-processors page.

7. Data-subject rights

Taking account of the nature of processing, the Processor will provide reasonable assistance to enable the Controller to respond to requests for access, rectification, erasure, restriction, portability or objection. The Controller remains responsible for assessing and responding to each request.

8. Personal-data breaches

The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data and will provide available information reasonably needed for the Controller’s assessment and notifications.

9. Compliance assistance

Taking account of processing and available information, the Processor will reasonably assist with security obligations, breach notification, data-protection impact assessments and prior consultation where required.

10. Return and deletion

At the end of the service, the Processor will, at the Controller’s choice and subject to the agreement, return or delete personal data and delete copies unless UK law requires retention. Backup copies may remain until overwritten under normal retention cycles, protected from further routine use.

11. Information and audits

The Processor will make information reasonably necessary to demonstrate compliance available to the Controller. Audits must be proportionate, protect other customers, avoid unnecessary disruption and normally follow review of available documentation.

12. International transfers

The Processor will not make a restricted international transfer without an appropriate lawful mechanism and any required supplementary safeguards.

13. Priority and governing law

If this DPA conflicts with the main agreement on processing personal data, this DPA prevails. It is governed by the law stated in the main agreement.