1. Parties and roles
The club or organiser using CoolSmash (“Customer”) is the controller, and CoolSmash is the processor, for club data CoolSmash processes on the Customer’s behalf. CoolSmash remains a separate controller for its own purposes described in the privacy notice.
2. Processing details
Subject matterOperating club, session, ticketing and messaging features.
DurationThe length of the customer agreement.
Nature and purposeStoring, organising, displaying and deleting data to provide the service.
Data subjectsMembers, applicants, guests and organisers.
Data typesNames, contact details, profile, membership, session, attendance and payment status.
3. CoolSmash will
- process the data only on the Customer’s documented instructions, including instructions given by configuring the service, and say if an instruction appears unlawful;
- ensure staff with access are bound by confidentiality;
- keep appropriate security measures, including encryption in transit, role-based access, backups and logging;
- use sub-processors under this general authorisation, inform the Customer before adding or replacing one so it can object, and bind each to equivalent terms; the current list is available on request from support@coolsmash.co.uk;
- transfer the data outside the UK only with a lawful safeguard;
- help the Customer with data-subject requests, security, breach notification (notifying it without undue delay), data protection impact assessments and consultations with the ICO;
- at the end of the agreement, make an export available for 30 days and then delete the data, with backups expiring within 90 days, unless the law requires it to be kept; and
- provide the information needed to demonstrate compliance and allow one audit a year on reasonable notice.
4. Priority
On data protection matters, this agreement prevails over the customer agreement.
