Data Processing Agreement

Version 1.0 · Last updated 29 May 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Use between Olemco Ltd (“Olemco”, “Processor”) and the club that subscribes to the Olemco platform (the “Club”, “Controller”). It records the terms on which Olemco processes personal data on the Club’s behalf, in line with Article 28 of the UK GDPR.

Capitalised terms not defined here have the meaning given in the Terms of Use. “Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other applicable data protection or privacy law.

1. Roles

For Club Data, the Club is the Controller and Olemco is the Processor. Olemco will process Club Data only on the Club’s documented instructions (which are set out in this DPA, the Terms of Use, the normal operation of the platform features the Club uses, and any further written instructions the Club gives).

For data Olemco controls (account, billing and website data), Olemco is the controller and its handling is governed by the Privacy Policy, not this DPA.

2. Subject matter, duration, nature and purpose

  • Subject matter: the provision of the Olemco platform to the Club.
  • Duration: for as long as the Club has an active Olemco account, plus any further period agreed for data return or retention under section 11.
  • Nature: hosting, storage, transmission, organisation, retrieval, access control, backup, and other technical processing of Club Data needed to operate the Service.
  • Purpose: to enable the Club to run its football club through Olemco — managing teams, registrations, qualifications, safeguarding workflows, communications and payments.

3. Categories of data and data subjects

Data subjects

  • club admins, designated safeguarding officers, treasurers;
  • welfare officers;
  • managers and assistant coaches;
  • players (typically children under 18);
  • parents and guardians of players.

Categories of personal data

  • identity and contact data: name, date of birth, address, phone, email, FA Number (FAN), profile photo;
  • role and team membership data: which club, which team, which role, since when;
  • qualification and verification data: DBS dates, FA Safeguarding, First Aid, Coaching, FA Welfare Officer (where applicable), with certificate files, expiry dates, and who verified each;
  • player registration data: medical information, consents (photo, medical attestation), policy acknowledgements;
  • safeguarding case records;
  • communications sent through the platform;
  • payment-adjacent data: amounts owed, paid, outstanding (full bank details are held by GoCardless, not Olemco).

Special category data

The data above includes special category data within the meaning of Article 9 of the UK GDPR — in particular medical information about players and information about safeguarding allegations or actions. Olemco processes this data on the Club’s instructions and only as necessary to provide the Service. The Club is responsible for identifying an appropriate Article 9 condition (in many cases, Schedule 1 of the Data Protection Act 2018 — safeguarding of children).

4. Olemco’s obligations as Processor

Olemco will:

  • process Club Data only on the Club’s documented instructions, and tell the Club promptly if it believes an instruction breaches Data Protection Law;
  • make sure everyone who has access to Club Data is bound by appropriate confidentiality obligations;
  • implement and maintain the technical and organisational measures described in Annex A;
  • help the Club, taking into account the nature of the processing, to respond to data subject requests (access, rectification, erasure, restriction, portability, objection);
  • help the Club with its obligations on security, breach notification, data protection impact assessments and prior consultation with the ICO;
  • notify the Club without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Club Data;
  • on termination, return or delete Club Data in accordance with section 11;
  • make available all information needed to demonstrate compliance with this DPA and allow for, and contribute to, audits as described in section 9.

5. Sub-processors

The Club authorises Olemco to engage the following sub-processors at the date of this DPA:

  • Supabase — database, file storage and authentication; EU (London) region.
  • Vercel — application hosting (US, with appropriate transfer safeguards).
  • Google Workspace (Gmail) — transactional and service email delivery.
  • GoCardless — Direct Debit payment processing (subject to onboarding; engaged only once a Club uses paid subscriptions).

Olemco will impose data protection obligations on each sub-processor that are at least as protective as those in this DPA. Olemco will give the Club at least 30 days’ written notice (which may be by email) of any intended change to its sub-processor list. If the Club reasonably objects to a new sub-processor on data protection grounds, the parties will work in good faith to resolve the objection; failing that, the Club may terminate the affected part of the Service.

6. International transfers

Olemco stores Club Data in the EU (London region). Where any sub-processor transfers Club Data outside the UK or EEA, the transfer is protected by an adequacy decision, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, as appropriate.

7. Data subject rights and assistance

Where Olemco receives a request from a data subject relating to Club Data, it will, without responding to the request itself, forward the request to the Club. Olemco will reasonably help the Club to respond to such requests, taking into account the nature of the processing and what is available within the platform (for example, the export, edit and deletion functions in the Club’s admin area).

8. Personal data breaches

Olemco will notify the Club without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Club Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures Olemco has taken or proposes to take. Olemco will cooperate with the Club’s reasonable investigation, mitigation and notification efforts.

9. Records, audits and information

On reasonable written request, Olemco will make available to the Club information necessary to demonstrate compliance with this DPA, which may take the form of summary documentation, written answers to questions, or independent third-party audit reports where they exist.

The Club may, no more than once in any 12 months and on at least 30 days’ written notice, carry out an audit of Olemco’s compliance with this DPA. Audits will be conducted during normal business hours, in a way that does not unreasonably interrupt Olemco’s operations or compromise the confidentiality or security of other customers’ data. The Club bears its own costs of an audit; Olemco bears its own reasonable assistance costs unless the audit identifies a material breach by Olemco, in which case Olemco will reimburse the Club’s reasonable audit costs.

10. Confidentiality

Olemco will treat Club Data as confidential. Olemco personnel who access Club Data are bound by appropriate confidentiality obligations and access is on a need-to-know basis.

11. Return and deletion on termination

On termination of the Service, the Club may within 30 days request a copy of its Club Data in a structured, commonly used, machine-readable format. After that period (or sooner if the Club so instructs), Olemco will delete or anonymise Club Data, except to the extent retention is required by law or by the Club’s safeguarding retention instructions. Backup copies will be deleted in line with our normal backup rotation, typically within 35 days.

Where Club Data includes safeguarding records, the Club is responsible for instructing Olemco on retention or transfer arrangements consistent with the FA’s and any statutory guidance. Olemco will follow those instructions.

12. Liability

Each party’s liability under this DPA is subject to the limits and exclusions in the Terms of Use, except where Data Protection Law requires otherwise.

13. Order of precedence

If there is a conflict between this DPA and the Terms of Use on a data protection matter, this DPA prevails to the extent of the conflict.

14. Changes

Olemco may update this DPA from time to time to keep it aligned with Data Protection Law and current practice. Each version carries a number and date at the top of this page. We will email Club Admins of any material change with at least 14 days’ notice.

Annex A — Technical and Organisational Measures

Olemco maintains the following measures to protect Club Data, proportionate to the risk and the nature of the data:

  • Encryption in transit and at rest. All connections use TLS; the database and file storage encrypt data at rest.
  • Database-level access control. Row-level security enforces least-privilege access by role — a manager only ever sees their own team, a welfare officer only their own club, and so on. The UI is never the security boundary.
  • Authentication. Passwords are stored as one-way cryptographic hashes. Optional multi-factor authentication is on the roadmap.
  • Private file storage. Certificate uploads and profile photos live in private buckets accessed only via short-lived signed URLs.
  • Chain-of-trust verification. Sensitive safeguarding-relevant documents may only be verified along a documented chain (club admin verifies welfare officer; compliant welfare officer verifies managers).
  • Backups and disaster recovery. Automated daily backups with regular restore tests.
  • Sub-processor management. Written contracts with each sub-processor that pass through the protections of this DPA.
  • Personnel. Access to Club Data limited to personnel who need it, bound by confidentiality, with access reviewed periodically.
  • Incident response. Documented procedures for detecting, triaging and reporting personal data breaches within 72 hours of awareness.
  • Audit logging. Append-only audit log of significant actions taken on Club Data (in progress; planned for V1).

Contact

Data protection contact: James Cooper, dpo@olemco.com. Post: Olemco Ltd, 160 Aston Hall Road, Aston, Birmingham, B6 7LA.