TOXO
Data Processing Agreement.
1. Parties and scope
This Data Processing Agreement (“DPA”) is entered into between CodeEnsis Ltd, a company registered in Cyprus (“Processor”, “we”), and the archery club whose owner accepted it in the Toxo app (“Controller”, “the club”).
It applies to all personal data the club processes through Toxo, and forms part of the Toxo Terms of Use. Where this DPA and the Terms disagree about personal data, this DPA wins. It is concluded under Article 28 of Regulation (EU) 2016/679 (“GDPR”) and, where applicable, the UK GDPR.
2. Roles
The club determines the purposes and means of the processing: which people it enrols, which sessions it schedules, what it records about attendance, and how long it keeps any of it. The club is the controller.
We provide the software and the infrastructure that carries out those decisions. We are the processor, and we act only on the club’s documented instructions — instructions the club gives principally by using the app’s features, and otherwise in writing to [email protected].
Where we decide something in our own right — keeping the service secure, billing, our own analytics about how the app itself is used — we act as a controller for that, and our Privacy Policy describes it. We do not do that with club membership data.
3. Subject matter, duration, nature and purpose
| Item | Detail |
|---|---|
| Subject matter | Running an archery club: membership, training schedules, attendance, and communication between the club and its members. |
| Duration | For as long as the club uses Toxo, plus the retention period in section 9. |
| Nature | Collection, storage, organisation, retrieval, transmission, erasure. |
| Purpose | Solely to provide Toxo to the club and its members, as instructed by the club. |
| Data subjects | Club members (adults and minors), parents and guardians, coaches and club administrators. |
Categories of personal data
- Identity — name, and the email address a member signs in with.
- Age — date of birth, where the club records it. Toxo uses it to tell a minor from an adult.
- Family links — which adult is a guardian of which child.
- Participation — club and group membership, roles, RSVPs, attendance.
- Consents — what a guardian has agreed to about a child, and when.
- Device — push notification tokens, so the club’s messages reach a phone.
Toxo is not built to hold special-category data under Article 9 GDPR, and the club should not put health information, or anything else in those categories, into free-text fields.
4. Children
A club may not enrol anyone under 18 in Toxo until the club has been verified by us. Verification is the point at which the club identifies itself and accepts this DPA. This is deliberate: a self-serve sign-up is not enough to start holding children’s records.
The club is responsible for obtaining, and for being able to demonstrate, whatever consent or other lawful basis its own jurisdiction requires for a minor’s participation. Toxo records the consents a guardian gives, with a timestamp and a version, so the club has that evidence — but the obligation is the club’s.
A child’s name is not shown to other families unless a guardian has turned that on.
5. Our obligations
- We process personal data only on the club’s documented instructions, including on transfers, unless EU or member state law requires otherwise — in which case we tell the club before processing, unless that law forbids it.
- We tell the club if, in our opinion, an instruction infringes the GDPR.
- Everyone at CodeEnsis authorised to access personal data is bound by confidentiality.
- We implement the measures in section 8 and keep them under review.
- We never sell club data, never use it to train models, and never use it for advertising.
6. Sub-processors
The club gives general authorisation for the sub-processors below. We will give the club at least 30 days’ notice, by email to the club’s registered contact, before adding or replacing one, and the club may object on reasonable data-protection grounds; if we cannot resolve the objection, the club may stop using Toxo and ask for its data to be deleted.
| Sub-processor | What it does | Where |
|---|---|---|
| Google Ireland Ltd — Firebase (Authentication, Firestore, Cloud Functions, Cloud Messaging, Crashlytics) | Sign-in, the database, the server-side logic, push notifications, crash reports | Database and server logic in Frankfurt, Germany (europe-west3) |
| Mailjet (Sinch Email, France) | Delivering the club’s emails to members | EU |
| Geoapify GmbH (Germany) | Rendering a static map picture of a venue from coordinates the club enters | EU |
Each sub-processor is engaged under a written contract imposing data-protection obligations no less protective than this DPA. We remain fully liable to the club for their performance.
7. International transfers
The club’s data is stored in the European Union. Some of our sub-processors are part of groups with entities outside the EEA; where that leads to a transfer, it is covered by the European Commission’s Standard Contractual Clauses or another Article 46 safeguard. Geoapify receives coordinates the club typed for a venue, never a person’s data.
8. Security
Taking account of the state of the art, the costs, and the risks involved, we maintain appropriate technical and organisational measures, including:
- Encryption in transit (TLS) and at rest.
- Authorisation enforced on the server for every read and write, so a member of one club cannot reach another club’s data, and a member cannot reach what only staff may see.
- Access to production systems limited to named CodeEnsis personnel, protected by multi-factor authentication.
- Separate development and production environments; real club data is never copied into development.
- Written-down, exercised procedures for restoring availability after an incident.
9. Retention and deletion
The club sets its own retention period in Toxo; the default is three years, which suits a club that needs to show who trained when. We delete or return personal data at the club’s choice when this DPA ends, unless EU or member state law requires us to keep it.
A member can delete their own account from inside the app. That erases their profile, their memberships, their RSVPs and the consents about them; what survives is impersonal counts on sessions that already happened. A child is not the guardian’s property: deleting a guardian’s account removes the guardian link and revokes the consents that guardian gave, and the child’s membership remains the club’s to manage.
10. Assistance to the club
Taking into account the nature of the processing, we assist the club by appropriate technical and organisational measures in:
- responding to requests from members exercising their rights under Chapter III GDPR — access, rectification, erasure, restriction, portability, objection;
- meeting its obligations under Articles 32 to 36 — security, breach notification, impact assessments, prior consultation.
Most of this the club can do itself in the app. Where it cannot, write to [email protected] and we will help within the time the club needs to meet its own deadline.
11. Personal data breaches
We notify the club without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting the club’s data. The notice describes what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing about it — and is updated as we learn more. Notifying a supervisory authority or the people affected is the club’s decision to make, as controller.
12. Audit
We make available to the club the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the club or an auditor it mandates. In practice we answer written questions first; an on-site inspection is on reasonable notice, no more than once a year unless an incident warrants it, during business hours, and without disrupting the service to other clubs.
13. Term and changes
This DPA takes effect when the club owner accepts it in the app and lasts as long as we process personal data for the club. We may publish a new version as the service changes; a club that accepted an earlier version is asked to accept the new one, and is not silently held to terms it never read. The version and date at the top of this page identify the text.
14. Governing law
This DPA is governed by the laws of the Republic of Cyprus, and the courts of Cyprus have jurisdiction — without prejudice to a data subject’s rights and remedies under the GDPR, which are unaffected.
15. Contact
CodeEnsis Ltd, Cyprus. Data protection enquiries: [email protected].