Back to Legal

Data Processing Agreement (DPA)

Last updated:

This Data Processing Agreement ("DPA") forms part of the Terms of Service between ScalarRatio LLC ("Fieldio", processor) and the customer (a club, or a coach acting on behalf of a club, as controller).

1. Subject matter and duration

Fieldio processes personal data on the customer's behalf to provide the Service. This DPA applies for as long as Fieldio processes personal data on the customer's behalf.

2. Definitions

Terms such as "personal data", "processing", "controller", "processor", "sub-processor" and "data subject" have the meaning given in the GDPR (Regulation (EU) 2016/679). This DPA is usable by customers inside and outside the EU.

3. Instructions and purpose limitation

Fieldio processes personal data only on the documented instructions of the customer (including this DPA and the configuration of the Service) and not for its own purposes.

4. Confidentiality

Personnel and sub-processors are bound by confidentiality and are granted access on a need-to-know, least-privilege basis.

5. Security

Fieldio implements appropriate technical and organisational measures; see Annex II.

6. Sub-processors

The customer grants general authorisation for the sub-processors listed in Annex III. Fieldio announces new sub-processors at least 30 days in advance; the customer may reasonably object and, absent a reasonable resolution, terminate.

7. International transfers

For transfers to countries outside the EEA lacking an adequacy decision, Fieldio relies on the Standard Contractual Clauses (Module 3, processor-to-sub-processor), incorporated by reference.

8. Assistance with rights and DPIAs

Fieldio provides reasonable assistance to the customer with: (a) data subject requests, (b) DPIAs, (c) prior consultations with supervisory authorities, and (d) breach notifications.

9. Personal data breaches

Fieldio informs the customer without undue delay, and typically within 72 hours of becoming aware, of a personal data breach affecting the customer, with the information reasonably available.

10. Audits

On request, Fieldio provides documentation demonstrating compliance with this DPA. On-site audits may be arranged by mutual agreement, subject to being reasonable, announced, and non-disruptive; costs are borne by the customer unless the audit reveals material non-compliance.

11. Return and deletion

On termination the customer may request an export within 30 days. Thereafter Fieldio deletes or anonymises the personal data within 90 days, except data that must be retained by law.

12. Liability

Liability under this DPA follows the Terms of Service.

13. Governing law

This DPA is governed by the laws of the State of Wyoming, USA.


Annex I — Details of processing

  • Nature and purpose: delivering the Fieldio application for team management, match planning, playing minutes, substitution planning, and AI support.
  • Categories of data subjects: coaches, club administrators, youth players.
  • Categories of data: identification data, team role, attendance, statistics, match and training data; no special categories of personal data.
  • Duration: for as long as the customer uses the Service, plus the retention periods in the Privacy Policy.

Annex II — Technical and organisational measures

  • Encryption in transit (TLS 1.2+).
  • Row-level access control at the database layer (RLS).
  • MFA for administrative access; least-privilege permissions.
  • Customer data stored in the EU region (Supabase).
  • Automated backups and restore procedures.
  • Access logging and anomaly monitoring.
  • Security review on changes; secure development lifecycle.
  • Incident-response process with internal escalation and customer notification.

Annex III — Approved sub-processors

PartyPurposeRegion
SupabaseAuthentication, database, storageEU
StripePayments and subscriptionsEU/US (SCCs)
Lovable AI GatewayAI featuresEU/US (SCCs)
ResendTransactional emailEU/US (SCCs)
Google AnalyticsMarketing page analyticsEU/US (SCCs)

Questions about this DPA? Use our contact form.