Data processing agreement
Last updated: 18 September 2026. This DPA is written in plain English and states only what we actually do — including where our protections stop. It is a working draft and should be reviewed by a UK-qualified solicitor before you rely on it as final.
1. Who this is between, and who is responsible for what
This agreement is between your club, school or organisation (“you”, the Controller) and Slashbit Ltd, company no. 17220107, registered in England & Wales, operator of Adminished (“we”, the Processor). It forms part of our Terms of business.
You decide what personal data goes into Adminished and why. We process it only to provide the service, on your instructions. In UK GDPR terms you are the controller and we are your processor.
One exception worth stating plainly: for card payments, Stripe is an independent controller of the payment data it holds, under its own terms with you. Full card numbers never reach our servers.
2. What we process, and for how long
Subject matter and purpose: running your club's administration — registers, membership, scheduling, communications, consent records, and collecting fees.
Duration: for as long as you have an account, plus the deletion period in section 9.
Categories of data subject: your members and their children; parents, guardians and other responsible adults; your coaches, staff and volunteers.
Categories of personal data: names, dates of birth, contact details, addresses where you enter them, attendance and booking records, payment records and amounts (not card numbers), messages sent through the platform, consent and waiver records, and photographs where you or a parent upload them.
Special category and children's data — read this part. Adminished is designed for clubs working with children, so you will almost certainly be entering:
- Health data — medical notes, allergies, SEND information recorded against a member.
- Children's personal data, including of children under 13.
- Criminal-records-adjacent data — DBS check dates and status for your staff and volunteers. We store the status and expiry; we are not a DBS umbrella body and do not process certificate contents.
This raises the bar for both of us. You must have a lawful basis and an Article 9 condition for that data, and a safeguarding policy that governs who in your club may see it.
3. Our obligations
- We process personal data only on your documented instructions — using the product as intended is such an instruction — unless the law requires otherwise, in which case we will tell you first unless legally barred.
- Everyone with access is under a duty of confidentiality.
- We apply the security measures in section 4.
- We help you meet your obligations under Articles 32–36 (security, breach, DPIAs) so far as is reasonable given the information available to us.
- We do not sell personal data, and we never use children's data for advertising or profiling.
4. Security measures — and their limits
These are the measures actually in place. We have deliberately not listed controls we do not have.
- Encrypted in transit. TLS on every connection, with HSTS.
- Tenant isolation enforced in code. Business queries are refused at the data-access layer unless they are scoped to a single club, so one club cannot read another's records.
- Role-based access — owner, coach, assistant and parent roles, with medical notes and member records withheld from roles that do not need them.
- Passwords hashed with bcrypt, never stored in plain text. Session identifiers are rotated on every authentication.
- Children's photographs are not publicly reachable — they are served only through authenticated routes, never from a public file path, and only where photo consent is recorded.
- Backups. The database is backed up nightly. Off-site copies are encrypted with GPG and retained 14 daily and 8 weekly. Restores are periodically tested end to end, not merely assumed.
- Production access is restricted and logged.
What we do not claim: the database is not encrypted at rest. It sits on access-controlled infrastructure with encrypted, off-site backups, but the stored files themselves are not encrypted. We would rather tell you that than let you assume otherwise. If at-rest encryption is a requirement for your organisation, tell us before you sign and we will say honestly whether and when we can meet it.
5. Sub-processors
We keep this list deliberately short. Each is bound by terms no less protective than this agreement.
| Sub-processor | What it does | Where |
|---|---|---|
| Stripe | Card and Direct Debit payments (PCI-DSS Level 1) | UK / EU / US |
| Resend | Transactional and reminder email | EU (eu-west-1) |
| Cloudflare | DNS, CDN and DDoS protection | Global edge |
| Our hosting provider | Application servers and database | United Kingdom |
We will give you reasonable notice before adding or replacing a sub-processor. If you object on reasonable data-protection grounds, tell us and we will either propose an alternative or you may terminate the affected service without penalty.
6. International transfers
Your club's data is stored in the United Kingdom. Some sub-processors operate globally — notably Cloudflare's edge network and parts of Stripe's infrastructure. Where personal data leaves the UK, it is transferred under UK International Data Transfer Agreement terms, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision.
7. Helping you answer your members
Adminished gives you self-service tools to action most requests yourself: parents can export or delete their own data from the parent portal, and you can export or delete member records in the app. Where a request needs us, contact [email protected] and we will assist without undue delay, at no charge for reasonable volumes.
8. If there is a breach
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 48 hours of becoming aware, with what we know: what happened, which categories and roughly how many people are affected, the likely consequences, and what we are doing about it. Because you are the controller, reporting to the ICO within 72 hours is your decision and your duty — we will give you what you need to make it.
9. Deletion and return
You can export your club's data from the app at any time, in a machine-readable format, without asking us. On termination, or on your written instruction, we delete personal data within 30 days, except where the law requires us to keep it — principally financial records for HMRC. Encrypted backups age out on the retention schedule in section 4; we do not surgically edit historic backups, and deleted data therefore persists in them until they expire.
10. Audit
We will provide the information reasonably needed to demonstrate compliance with this agreement, and will answer a security questionnaire once in any 12-month period. For an on-site or third-party audit, we will agree scope and timing with you in advance; we are a small company and will meet a reasonable request proportionately.
11. Liability and precedence
Liability under this agreement is subject to the limits in our Terms of business. If this agreement and those terms conflict on the processing of personal data, this agreement wins.
12. Contact
Data protection questions, sub-processor objections and DSARs: [email protected].
You have the right to complain to the Information Commissioner's Office at ico.org.uk.
Slashbit Ltd, registered in England & Wales, company no. 17220107. Registered office: Unit 11 Waterside Business Park, Lamby Way, Cardiff, South Glamorgan, CF3 2ET, United Kingdom.