Data Processing Addendum
Effective July 1, 2026. Incorporated into the Club Terms of Service.
This Data Processing Addendum ("DPA") supplements the Club Terms of Service ("Agreement") between Blue Sargo Ventures, LLC ("PicklPass", "Processor") and the customer identified in the Agreement ("Customer", "Controller"). Capitalized terms not defined here have the meaning given in the Agreement or in applicable Data Protection Laws.
1. Definitions
Data Protection Laws means the EU GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, and other applicable privacy laws. Personal Data, Processing, Controller, Processor, and Data Subject have the meaning given by the GDPR; equivalent CCPA/CPRA terms apply where CCPA/CPRA applies. For CCPA/CPRA purposes, PicklPass is a Service Provider and will not sell or share Personal Data or process it outside the business purposes documented in the Agreement.
2. Roles and Scope
For Customer Personal Data (including player roster data), Customer is the Controller and PicklPass is the Processor. The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are as described in Annex A.
3. Processor Obligations
- Process Personal Data only on Controller's documented instructions, including as set out in the Agreement and to comply with law.
- Ensure persons authorized to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organizational measures under GDPR Art. 32 (see Annex B).
- Assist Controller in responding to Data Subject requests, taking into account the nature of processing.
- Assist Controller with DPIAs and consultation with supervisory authorities as reasonably required.
- Notify Controller of a Personal Data Breach without undue delay after becoming aware.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
4. Subprocessors
Customer provides general authorization for PicklPass to engage subprocessors. The current list is maintained in the Service Providers section of the Privacy Policy. PicklPass will provide at least thirty (30) days' notice of intended new subprocessors (email notice to the administrator on file is sufficient). Customer may reasonably object on data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected part of the Service and receive a pro-rata refund of unused prepaid fees. PicklPass remains liable for its subprocessors' acts and omissions relating to this DPA.
5. International Transfers
To the extent Personal Data of individuals in the EEA, UK, or Switzerland is transferred to PicklPass in the United States or another third country, the parties agree that the transfer is governed by the EU Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (controller-to-processor), the UK International Data Transfer Addendum (IDTA), and, for Swiss transfers, references in the SCCs to the GDPR are read as references to the FADP. These clauses are incorporated by reference; Docking, options, and Annexes I and II are populated by the details in this DPA and its Annexes.
6. Audit Rights
PicklPass will respond to reasonable written information requests, including a standard security questionnaire, no more than once per year (unless required more often by a supervisory authority). On-site audits are permitted only for cause, with at least 30 days' written notice, during business hours, without disrupting the Service, and at Customer's expense. PicklPass may provide independent third-party audit reports in lieu of on-site audits where available.
7. Return and Deletion
On termination, Customer may export Personal Data for 30 days. After that period, PicklPass will delete Personal Data within 90 days, except as required by law and in backups, which are deleted on their rolling schedule.
8. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.
9. Execution
This DPA is deemed executed by Customer's continued use of the Service after the effective date. A countersigned copy is available on request to legal@picklpass.com.
Annex A. Processing Details
- Subject matter: Provision of the PicklPass Service.
- Duration: Term of the Agreement plus retention windows in the Privacy Policy.
- Nature and purpose: Hosting, storage, transmission, display, screening, analytics, communications.
- Categories of Data Subjects: Customer's admins, staff, and players.
- Categories of Personal Data: Identity, contact, DUPR IDs and ratings, match history, attendance, usage.
- Special categories: None intentionally processed.
- Frequency: Continuous while the Service is in use.
- Retention: As described in the Privacy Policy.
- Competent supervisory authority: the Massachusetts Attorney General for US matters; for GDPR transfers, the authority of the Customer's establishment or a chosen EU representative.
Annex B. Technical and Organizational Measures
- Encryption of data in transit (TLS 1.2+) and at rest for managed databases.
- Postgres Row-Level Security policies and least-privilege service-role access.
- Access controls, MFA on administrative accounts, and audit logging.
- Isolated production environment; secrets stored in encrypted secret stores.
- Backups with a rolling retention window and tested restore procedures.
- Vulnerability monitoring and dependency scanning; security patching of the platform.
- Employee onboarding, confidentiality obligations, and security training.
- Incident response plan with defined roles and notification workflow.
- Vendor review of subprocessors before engagement.
Annex C. Subprocessors
See the Service Providers section of the Privacy Policy for the current list.