TOXO

Data Processing Agreement.

Version 1.0 · Effective: September 18, 2026

The short version. Your club decides what it records about its members and why — the club is the controller. CodeEnsis Ltd stores and handles that data on the club’s instructions and for nothing else — CodeEnsis is the processor. This page is the agreement between the two, and a club owner accepts it inside the app when asking for the club to be verified. It matters most for children: a club may not add anyone under 18 until it is verified, and verification is what records this agreement.

1. Parties and scope

This Data Processing Agreement (“DPA”) is entered into between CodeEnsis Ltd, a company registered in Cyprus (“Processor”, “we”), and the archery club whose owner accepted it in the Toxo app (“Controller”, “the club”).

It applies to all personal data the club processes through Toxo, and forms part of the Toxo Terms of Use. Where this DPA and the Terms disagree about personal data, this DPA wins. It is concluded under Article 28 of Regulation (EU) 2016/679 (“GDPR”) and, where applicable, the UK GDPR.

2. Roles

The club determines the purposes and means of the processing: which people it enrols, which sessions it schedules, what it records about attendance, and how long it keeps any of it. The club is the controller.

We provide the software and the infrastructure that carries out those decisions. We are the processor, and we act only on the club’s documented instructions — instructions the club gives principally by using the app’s features, and otherwise in writing to [email protected].

Where we decide something in our own right — keeping the service secure, billing, our own analytics about how the app itself is used — we act as a controller for that, and our Privacy Policy describes it. We do not do that with club membership data.

3. Subject matter, duration, nature and purpose

ItemDetail
Subject matterRunning an archery club: membership, training schedules, attendance, and communication between the club and its members.
DurationFor as long as the club uses Toxo, plus the retention period in section 9.
NatureCollection, storage, organisation, retrieval, transmission, erasure.
PurposeSolely to provide Toxo to the club and its members, as instructed by the club.
Data subjectsClub members (adults and minors), parents and guardians, coaches and club administrators.

Categories of personal data

Toxo is not built to hold special-category data under Article 9 GDPR, and the club should not put health information, or anything else in those categories, into free-text fields.

4. Children

A club may not enrol anyone under 18 in Toxo until the club has been verified by us. Verification is the point at which the club identifies itself and accepts this DPA. This is deliberate: a self-serve sign-up is not enough to start holding children’s records.

The club is responsible for obtaining, and for being able to demonstrate, whatever consent or other lawful basis its own jurisdiction requires for a minor’s participation. Toxo records the consents a guardian gives, with a timestamp and a version, so the club has that evidence — but the obligation is the club’s.

A child’s name is not shown to other families unless a guardian has turned that on.

5. Our obligations

6. Sub-processors

The club gives general authorisation for the sub-processors below. We will give the club at least 30 days’ notice, by email to the club’s registered contact, before adding or replacing one, and the club may object on reasonable data-protection grounds; if we cannot resolve the objection, the club may stop using Toxo and ask for its data to be deleted.

Sub-processorWhat it doesWhere
Google Ireland Ltd — Firebase (Authentication, Firestore, Cloud Functions, Cloud Messaging, Crashlytics)Sign-in, the database, the server-side logic, push notifications, crash reportsDatabase and server logic in Frankfurt, Germany (europe-west3)
Mailjet (Sinch Email, France)Delivering the club’s emails to membersEU
Geoapify GmbH (Germany)Rendering a static map picture of a venue from coordinates the club entersEU

Each sub-processor is engaged under a written contract imposing data-protection obligations no less protective than this DPA. We remain fully liable to the club for their performance.

7. International transfers

The club’s data is stored in the European Union. Some of our sub-processors are part of groups with entities outside the EEA; where that leads to a transfer, it is covered by the European Commission’s Standard Contractual Clauses or another Article 46 safeguard. Geoapify receives coordinates the club typed for a venue, never a person’s data.

8. Security

Taking account of the state of the art, the costs, and the risks involved, we maintain appropriate technical and organisational measures, including:

9. Retention and deletion

The club sets its own retention period in Toxo; the default is three years, which suits a club that needs to show who trained when. We delete or return personal data at the club’s choice when this DPA ends, unless EU or member state law requires us to keep it.

A member can delete their own account from inside the app. That erases their profile, their memberships, their RSVPs and the consents about them; what survives is impersonal counts on sessions that already happened. A child is not the guardian’s property: deleting a guardian’s account removes the guardian link and revokes the consents that guardian gave, and the child’s membership remains the club’s to manage.

10. Assistance to the club

Taking into account the nature of the processing, we assist the club by appropriate technical and organisational measures in:

Most of this the club can do itself in the app. Where it cannot, write to [email protected] and we will help within the time the club needs to meet its own deadline.

11. Personal data breaches

We notify the club without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting the club’s data. The notice describes what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing about it — and is updated as we learn more. Notifying a supervisory authority or the people affected is the club’s decision to make, as controller.

12. Audit

We make available to the club the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the club or an auditor it mandates. In practice we answer written questions first; an on-site inspection is on reasonable notice, no more than once a year unless an incident warrants it, during business hours, and without disrupting the service to other clubs.

13. Term and changes

This DPA takes effect when the club owner accepts it in the app and lasts as long as we process personal data for the club. We may publish a new version as the service changes; a club that accepted an earlier version is asked to accept the new one, and is not silently held to terms it never read. The version and date at the top of this page identify the text.

14. Governing law

This DPA is governed by the laws of the Republic of Cyprus, and the courts of Cyprus have jurisdiction — without prejudice to a data subject’s rights and remedies under the GDPR, which are unaffected.

15. Contact

CodeEnsis Ltd, Cyprus. Data protection enquiries: [email protected].