Data processing agreement
Version 1.0 · 3 September 2026
This is the data processing agreement version 1.0 of 3 September 2026. It applies when your club accepts a Pro Season proposal. This is contract text, not a brochure.
Contents
- Introduction
- Part 1: Parties
- Part 2: Definitions
- Part 3: Subject matter and purpose of the processing
- Part 4: Categories of data subjects and personal data
- Part 5: Obligations of Pro Season (Processor)
- Part 6: Obligations of the Customer (Controller)
- Part 7: Sub-processors
- Part 8: Rights of data subjects
- Part 9: Retention periods and deletion
- Part 10: Third-party sharing, scouting, and the player-passport demarcation
- Part 11: International transfers
- Part 12: Liability and indemnification
- Part 13: Audit and inspection
- Part 14: Termination and data deletion
- Part 15: Governing law and dispute resolution
- Part 16: Conclusion of the Agreement and signature
- Annex A: Sub-processors
- Annex B: Technical and organisational measures
Introduction
This data processing agreement governs the processing of personal data by Pro Season International B.V. (the Processor) on behalf of an academy or association (the Customer, and also the Controller) in connection with use of the Pro Season platform. This Agreement gives effect to the obligations under Article 28(3) of the General Data Protection Regulation (GDPR) and forms a binding appendix to the main agreement (the terms of service) between the Parties.
This Agreement is written for general platform use by an academy or association: player records, development assessments, attendance, training planning, invoicing-related data entered by the Customer itself, and club communication. This Agreement does not cover the processing of scouting data by a professional club within Pro Season's scouting module. That processing is governed by a separate, dedicated document, because the role allocation, retention periods, and nature of the data are materially different there (see the separate data processing agreement for the scouting module).
Part 1: Parties
Controller: the academy or association named as the customer in the quote, with the name, business address, Chamber of Commerce number or local equivalent, and representative as stated in that quote (hereinafter: "the Customer" or "the Controller")
Processor: Pro Season International B.V. P.J. Oudweg 41, 1314 CJ Almere, the Netherlands Chamber of Commerce 42082965 · RSIN 869628616 · VAT NL869628616B01 (hereinafter: "Pro Season" or "the Processor")
The Controller and the Processor are together referred to as "the Parties." The details of the Parties and of the authorised signatory follow from the quote to which this Agreement is an appendix. No details are entered again here, so that no discrepancy can arise between the quote and this appendix.
Part 2: Definitions
For the purposes of this Agreement, the following definitions apply. Terms not defined here carry the meaning given to them in the GDPR.
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
"Platform" means the Pro Season software-as-a-service environment, accessible via the web application and the mobile application.
"Customer Data" means all personal data that the Customer, or users authorised by the Customer (administrators, coaches, team managers), enter, upload, or generate within the Platform, including player records, development assessments, attendance data, training notes, and images.
"Player" means a natural person about whom data is processed in the Platform in connection with participation in the Customer's sports activities, regardless of age.
"Data Subject" means a natural person to whom Customer Data relates, including Players, parents or legal guardians of minor Players, and coaches or other club staff.
"Sub-processor" means any third party engaged by Pro Season to carry out processing activities on the Customer's behalf.
"Player Passport" means a Player's development profile within the Platform, as further described in Part 10.
Part 3: Subject matter and purpose of the processing
3.1 Subject matter
Pro Season processes Customer Data on behalf of the Customer as part of the Platform. The subject matter of the processing is the storage, organisation, structuring, and technical retrieval of Customer Data entered by the Customer or its authorised users.
3.2 Purpose
The purpose of the processing is the purpose determined by the Customer: tracking Players' development, planning and organising training sessions and matches, recording attendance, facilitating communication within the Customer, and supporting the Customer's administrative and operational processes within the Platform. Processing is limited to this purpose. Pro Season does not use Customer Data for its own commercial purposes, does not sell or license the data to third parties, and does not combine Customer Data with data from other customers.
3.3 Nature of the processing
The processing activities carried out by Pro Season include: storage of Customer Data on European infrastructure, structured retrieval and display of Customer Data to the Customer's authorised users, application of automated retention rules, technical access logging for security and audit purposes, and facilitating export of Customer Data on the Customer's instruction.
3.4 Duration
This Agreement applies for the duration of the main agreement between the Parties. Processing continues until the agreement is terminated and all data has been deleted in accordance with Part 14.
3.5 Pro Season's own processing activities
In addition to processing on behalf of the Customer, Pro Season processes a limited set of data for its own purposes, and acts as controller for those purposes. This concerns: administration and invoicing of the Customer's subscription, securing and maintaining the availability of the Platform (including logging and abuse prevention), compliance with legal obligations, and the preparation of aggregated statistics about use of the Platform that cannot be traced back to an individual. These processing activities are described in Pro Season's privacy statement. Pro Season does not use Customer Data for commercial purposes, does not sell or licence it, and does not use it to build profiles of Players outside the Customer's instructions.
Part 4: Categories of data subjects and personal data
4.1 Categories of data subjects
The data subjects are:
- Players, including minor Players. The Customer acknowledges that a significant proportion of data subjects may be minors (under the age of 18, and in some cases under the age of 16), and represents that it applies heightened care in its processing of data relating to minors, consistent with the guidance of the European Data Protection Board and the applicable national supervisory authority;
- parents or legal guardians of minor Players, to the extent their contact data is entered by the Customer;
- coaches, team managers, and other club staff who use the Platform as authorised users of the Customer.
4.2 Categories of personal data
The following categories of personal data are processed under this Agreement:
Identity data. Name, date of birth (optional), photo, position, contact details.
Club history. Teams, seasons, group assignment, transfers within the Customer.
Development data. Scores and free-text notes on competency categories as configured by the Customer, learning goals, coach commentary.
Attendance data. Presence at training and matches.
Contact data of parents or legal guardians. Name, email address, phone number, relationship to the Player, to the extent entered by the Customer.
Images. Photos and videos of Players entered by the Customer for club use, as further described in Pro Season's privacy policy.
Billing and payer data (only where club invoicing is used). Name, email and billing address of the payer (usually a parent or legal guardian), the relationship to the Player, invoice lines and amounts, payment status and payment date, and the customer or transaction reference at the payment provider. Pro Season does not receive or store full card or bank account details; those are processed solely by the payment provider. For its own statutory purposes (including fraud prevention and identifying the Customer as a merchant) the payment provider acts as an independent controller, not as a sub-processor of Pro Season.
Technical metadata. Timestamps of creation and modification; user identifiers of who created or modified a record; access logs recording which user viewed which record and when.
4.3 Special categories
This Agreement does not authorise the processing of special categories of personal data within the meaning of Article 9 GDPR (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data, health data, or data concerning a natural person's sex life or sexual orientation). If the competency model configured by the Customer contains categories that could lead to the recording of health-related information (for example, relating to an injury or medical limitation), the Customer is responsible for removing or adjusting those categories before the Platform is used for that purpose.
Part 5: Obligations of Pro Season (Processor)
5.1 Processing on instructions only
Pro Season processes Customer Data only on the documented instructions of the Customer, including with regard to transfers of personal data to a third country or an international organisation. This Agreement, the quote, and the applicable product documentation constitute the Customer's documented instructions. Use of the Platform's features by the Customer's authorised users also constitutes an instruction from the Customer.
Pro Season processes Customer Data outside those instructions only where required to do so by Union or Member State law. In that case Pro Season informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
Pro Season informs the Customer immediately if, in its opinion, an instruction would infringe the GDPR or other applicable Union or Member State data protection law. Pro Season may suspend performance of that instruction until the Customer confirms or amends it.
5.2 Confidentiality
Pro Season ensures that all persons authorised to process Customer Data are bound by a contractual or statutory duty of confidentiality.
5.3 Technical and organisational security measures
Pro Season implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These measures include, at minimum:
Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent); access control based on the principle of least privilege, implemented through role-based permissions enforced at the database level using Row Level Security policies; multi-factor authentication for administrative access to the platform infrastructure; regular security testing and vulnerability management; and physical security controls at the data centre level as provided by the applicable sub-processor.
Pro Season reviews these measures periodically and updates them in response to changes in the threat landscape, applicable standards, and the nature of the data processed.
5.4 Sub-processors
The Customer gives Pro Season general written authorisation to engage sub-processors for infrastructure and operational services, within the meaning of Article 28(2) GDPR. The current list of sub-processors relevant to this Agreement is set out in Annex A.
Before engaging a new sub-processor or replacing an existing one, Pro Season informs the Customer in writing. The Customer has the right to object to a new sub-processor within fourteen (14) days of receiving notice, on reasonable grounds relating to data protection. If the Customer objects and the Parties cannot resolve the objection, either Party may terminate this Agreement in accordance with Part 14.
Pro Season imposes on each sub-processor, by contract, the same data protection obligations as those set out in this Agreement, in particular the obligation to implement appropriate technical and organisational measures. Where a sub-processor fails to fulfil its data protection obligations, Pro Season remains fully liable to the Customer for the performance of that sub-processor's obligations, in accordance with Article 28(4) GDPR.
5.5 Assistance with data subject rights
Pro Season provides the Customer with reasonable technical assistance to enable the Customer to respond to requests from data subjects exercising their rights under Articles 15 to 22 GDPR (access, rectification, erasure, restriction, portability, and objection). Pro Season does not respond directly to data subjects on behalf of the Customer unless the Customer has explicitly instructed it to do so.
5.6 Assistance with security and compliance obligations
Pro Season assists the Customer in complying with the obligations in Articles 32 to 36 GDPR, including: notification of personal data breaches to supervisory authorities; communication of breaches to data subjects; and the conduct of data protection impact assessments.
5.7 Personal data breach notification
In the event of a personal data breach affecting Customer Data, Pro Season notifies the Customer without undue delay and, in any event, within seventy- two (72) hours of becoming aware of the breach. The notification includes, to the extent available at the time: a description of the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences of the breach; and the measures taken or proposed to address it. Pro Season documents all breaches and makes that documentation available to the Customer on request.
5.8 Records of processing activities
Pro Season maintains a record of processing activities under this Agreement in accordance with Article 30(2) GDPR.
5.9 Audit and inspection
Pro Season makes available to the Customer all information reasonably necessary to demonstrate compliance with this Agreement and contributes to audits or inspections conducted by the Customer or its appointed representative. The Customer gives reasonable advance notice of any audit and agrees to keep confidential any information obtained during the audit that constitutes Pro Season's trade secrets or security architecture details.
Part 6: Obligations of the Customer (Controller)
6.1 Lawful basis
The Customer is responsible for establishing and maintaining a valid lawful basis for the processing of Customer Data under Article 6 GDPR, including, where applicable, data relating to minor Players.
6.2 Transparency obligations
The Customer is responsible for informing data subjects, including the parents or guardians of minor data subjects where required, about the processing of their personal data. This includes making available a privacy notice that covers the Customer's own processing, consistent with Articles 13 and 14 GDPR. Pro Season provides a privacy policy for its own processing and can, on request, provide support in drafting the Customer's own privacy communications, but is not responsible for their content.
6.3 Instructions to users
The Customer is responsible for ensuring that its coaches, team managers, and other club staff use the Platform in accordance with these contractual terms and with applicable data protection law. The Customer ensures that its users are informed of the prohibition on entering special categories of data (see 4.3), and of the obligation to use the Platform only for the purposes described in Part 3.
6.4 Competency model
The Customer is responsible for the content of any competency model it configures within the Platform. The Customer confirms that the competency model does not include questions or categories that lead to the recording of special category data.
6.5 Minors
The Customer acknowledges that it will process data relating to minors and represents that it has assessed the risks associated with such processing, applied the additional safeguards required by the GDPR and applicable national law, and documented this assessment.
6.6 Lawful basis for international data flows
If the Customer operates outside the European Economic Area, or transfers Customer Data or derived data outside the EEA, the Customer is responsible for ensuring that an adequate transfer mechanism is in place in accordance with Chapter V GDPR. The Customer informs Pro Season of any such transfer scenarios before they arise.
6.7 Sharing by the Customer with third parties
If the Customer itself shares Customer Data with a third party outside the Platform (for example with a scout, another organisation, or a parent requesting an export), the Customer is itself responsible for the lawfulness of that sharing. Pro Season is not a party to this, except for the technical execution of an export instructed by the Customer, as described in Part 10.
Part 7: Sub-processors
The following sub-processors are engaged by Pro Season in the performance of this Agreement at the date of this version. This list constitutes Annex A to this Agreement.
Supabase, Inc. Role: database infrastructure, authentication, and file storage services Location of data processing: European Union (EU-West region) Transfer mechanism: processing within the EEA; Supabase is a US-based company operating EU infrastructure under EU Standard Contractual Clauses Reference: Supabase Data Processing Agreement available at https://supabase.com/legal/dpa
Stripe Technology Europe, Limited Role: payment processing, including club invoicing to Players or their parents where the Customer uses that functionality Location: Ireland / European Union, with transfer to the United States Transfer mechanism: EU Standard Contractual Clauses and/or EU-US Data Privacy Framework, where applicable Note: for its own statutory purposes Stripe is an independent controller (see section 4.2)
Microsoft Corporation (Microsoft 365 / Graph) Role: transactional email and notifications Location: EU data centres where available Transfer mechanism: Microsoft product terms and EU Standard Contractual Clauses
Vercel Inc. Role: hosting of the web applications Location: United States / edge network Transfer mechanism: EU Standard Contractual Clauses
Firma (e-sign provider) Role: electronic signing of proposals and contracts Location: according to Firma’s processor terms Transfer mechanism: Firma DPA / Standard Contractual Clauses
Pro Season updates this Annex when sub-processors are added or changed, in accordance with section 5.4 of this Agreement.
Part 8: Rights of data subjects
8.1 Handling of requests
If a data subject exercises their rights under the GDPR directly towards Pro Season, Pro Season informs the Customer within five (5) business days and provides reasonable technical assistance to enable the Customer to respond. The Customer is responsible for deciding how to respond and for communicating directly with the data subject.
8.2 Erasure
If the Customer receives a valid erasure request under Article 17 GDPR relating to Customer Data, it may instruct Pro Season to permanently delete the relevant data. Pro Season carries out such deletion within seven (7) business days of receiving the instruction.
8.3 Access requests
If the Customer receives an access request from a data subject, Pro Season provides the Customer with a structured export of the relevant Customer Data, to the extent technically feasible.
Part 9: Retention periods and deletion
9.1 Standard retention
Customer Data (platform data) is retained for as long as the main agreement between the Parties continues, plus twelve (12) months thereafter, unless: (a) the Customer requests earlier deletion of specific data; (b) the Customer instructs a shorter retention period; or (c) a shorter period follows from Pro Season's privacy policy.
Club invoicing data (invoices and payer details of parents or players) is technically retained for a maximum of seven (7) years, or shorter on the Customer's instruction.
9.2 Data relating to minors
For Customer Data relating to Players who were minors at the time of recording, the same retention approach applies as for adult Players. On withdrawal of consent for imagery of minors, Pro Season deletes or blocks that imagery within fourteen (14) days after instruction or automated detection of the withdrawal. The Customer must exercise particular caution in retaining sensitive free-text notes about minors for longer than necessary for the purpose for which they were recorded.
9.3 Export and derived copies
The Customer is responsible for managing the retention of any Customer Data or derived data that it exports from the Platform. Data exported from the Platform is outside the scope of Pro Season's automated retention mechanisms and falls under the Customer's own data retention obligations. Pro Season offers the Customer an export option before the end of the retention period.
9.4 Technical implementation
Pro Season implements deletion through a process that removes data that has exceeded the applicable retention period, or upon the Customer's instruction. Deleted data cannot be recovered from the production database. Residual copies in rolling backups disappear within a maximum of ninety (90) days with the backup cycle. Deletion logs are retained for twelve (12) months after deletion for compliance and audit purposes.
Part 10: Third-party sharing, scouting, and the player-passport demarcation
This Part sets out how this Agreement relates to the product principle that the Player owns their own player passport (see Pro Season's privacy policy, chapter 5), and to possible future sharing with scouts or third parties.
10.1 No sharing without instruction or separate basis
Pro Season does not share Customer Data with a third party outside the Platform, except:
- on the Customer's explicit, written instruction;
- when the Player, or the parent or legal guardian of a minor Player, has given explicit consent or approval for sharing outside the Customer, through a mechanism that actually exists and is active at the time of sharing;
- when Pro Season is legally required to do so.
10.2 Scouting is not part of this Agreement
This Agreement does not authorise Pro Season to share Customer Data with a scout or a professional club for the purpose of talent identification. Should the Customer wish to cooperate in a future scouting pathway in which Customer Data is shared with a third party, this requires a separate, explicit instruction from the Customer and, where applicable, a separate legal basis and documentation held by the Customer. As of the date of this Agreement, Pro Season is working on a separate mechanism for this scenario; until that mechanism exists, no sharing with scouts takes place through the Platform.
This provision is separate from the existing, dedicated legal structure for Pro Season's scouting module, in which a professional club itself acts as controller for its own scouting observations of players who are not users of the Customer. That structure is covered by its own document (see the scope note at the top of this document) and is not the same as sharing of Customer Data from the Customer's own environment.
10.3 Termination of the relationship between a Player and the Customer
When the relationship between a Player and the Customer ends (for example on departure or transfer), the Customer may instruct Pro Season to export Customer Data about that Player for transfer, and subsequently delete or archive it, subject to the retention periods in Part 9 and any statutory retention obligations of the Customer.
Part 11: International transfers
If a sub-processor processes data outside the EEA, Pro Season ensures an appropriate transfer mechanism is in place, such as the EU Standard Contractual Clauses, consistent with Chapter V GDPR. The current state of transfer mechanisms per sub-processor is set out in Annex A.
Part 12: Liability and indemnification
12.1 Allocation of liability
Each Party is liable for damages caused by processing that infringes the GDPR to the extent attributable to that Party's breach of its obligations under this Agreement or applicable law.
12.2 Processor limitation
Pro Season's liability under this Agreement, to the extent permitted by law, is limited to the total fees paid by the Customer to Pro Season for the Platform in the twelve (12) months preceding the event giving rise to the claim. This limitation does not apply in cases of wilful misconduct or deliberate recklessness by Pro Season, nor to the extent mandatory law (including the GDPR) does not permit a limitation. Breaches of confidentiality obligations through wilful misconduct or deliberate recklessness fall under this exception.
12.3 Indemnification by the Customer
The Customer indemnifies and holds Pro Season harmless against claims by data subjects or supervisory authorities arising from: (a) the Customer's failure to maintain a valid lawful basis, (b) the Customer's users entering special categories of data in contravention of section 4.3, (c) the Customer's instructions that cause Pro Season to infringe applicable law, and (d) sharing of Customer Data by the Customer itself with third parties outside the Platform without a valid basis.
Part 13: Audit and inspection
See section 5.9. In addition: the Customer may request an audit from Pro Season a maximum of one (1) time per year, unless there is a specific reason for an interim audit (for example following a reported data breach).
Part 14: Termination and data deletion
14.1 Termination events
This Agreement terminates when the main agreement between the Parties terminates, or when the Parties agree in writing to terminate it.
14.2 Obligations on termination
After the effective date of termination there is a cooling-off period of thirty (30) days during which the Customer may still request or collect an export (section 14.4). Customer Data is not deleted during that cooling-off period.
No later than the end of the cooling-off period, the Customer chooses between deletion and return of the Customer Data (Article 28(3)(g) GDPR). If the Customer makes no choice, deletion applies.
Within thirty (30) days after the end of the cooling-off period, Pro Season permanently deletes all Customer Data from the production environment of the Platform, including access logs related to specific data subjects, except to the extent a statutory retention obligation applies. Copies held in secured backups are removed in the ordinary rotation of those backups, at the latest ninety (90) days after deletion from the production environment; in the meantime those backups are not accessible for regular use. Technical logs that do not contain personal data (system performance logs, aggregated statistics) may be retained by Pro Season for its own operational purposes.
14.3 Certification of deletion
Upon request from the Customer, Pro Season provides written confirmation that all Customer Data has been deleted in accordance with this clause.
14.4 Export before termination and during the cooling-off period
The Customer may request an export of its Customer Data prior to termination and during the cooling-off period referred to in section 14.2. Pro Season provides this export in a structured machine-readable format within ten (10) business days of the request. If delivery of an export requested in time runs beyond the cooling-off period, deletion is postponed accordingly for the data covered by that export.
Part 15: Governing law and dispute resolution
15.1 Governing law
This Agreement is governed by the laws of the Netherlands, without prejudice to the rights of data subjects under the GDPR as implemented by the law of the Member State in which the Customer is established.
15.2 Supervisory authority
The Parties acknowledge that the lead supervisory authority for Pro Season is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Nothing in this Agreement affects the rights of data subjects to lodge a complaint with any competent supervisory authority.
15.3 Dispute resolution
The Parties will seek to resolve any dispute arising from this Agreement through good-faith negotiation. If a dispute cannot be resolved within thirty (30) days, it will be submitted to the competent court in the Netherlands.
Part 16: Conclusion of the Agreement and signature
16.1 One signing moment
This Agreement is an appendix to Pro Season's quote. By signing or electronically accepting the quote, the Customer also enters into this data processing agreement. No separate signature of this document is required. The quote or the secured proposal page states which version of this Agreement the Customer accepts.
16.2 Electronic form
The Parties conclude this Agreement by electronic means. That is the written form required by Article 28(3) GDPR: Article 28(9) GDPR expressly recognises the electronic form as written.
Two equivalent methods:
(a) electronic signing of the quote via the signing channel (Firma or equivalent), with the accompanying signing evidence;
(b) express acceptance on the secured proposal page, by two separate, not pre-checked boxes (terms of service and this data processing agreement), with the evidence record of that acceptance.
Neither method is a qualified electronic signature within the meaning of Regulation (EU) No 910/2014. Both are an electronic agreement. Only one method is completed for any given quote.
16.3 Record and copy
Pro Season records, per customer, which version of this Agreement belongs to the accepted quote, together with the date of acceptance. The Customer receives this Agreement as an appendix to the quote, or after digital acceptance as a copy (PDF or another storable file) plus the website URL of the accepted version. The Customer may request a copy in which the party details and the date of acceptance have been filled in, for its own file or for a supervisory authority. Should the Customer nevertheless want a separately signed counterpart for its own reasons, Pro Season will cooperate, without this altering the agreement already in place.
Annex A: Sub-processors
See Part 7 of this Agreement for the current list of sub-processors.
Annex B: Technical and organisational measures (summary)
This Annex summarises the technical and organisational measures referred to in section 5.3. A more detailed description is available on request.
Access control: role-based access enforced at the database level using Row Level Security. Each user sees only the data they are authorised to access. The Customer's administrators have no access to other customers' data.
Encryption: data in transit encrypted using TLS 1.2 or higher. Data at rest encrypted using AES-256 or equivalent.
Authentication: multi-factor authentication available and required for administrator accounts. Password policies enforce minimum complexity.
Audit logging: all access to Customer Data is logged with the user identifier, timestamp, and record accessed. Security and audit logs are retained for a minimum of twelve (12) and a maximum of twenty-four (24) months and are available for inspection.
Retention enforcement: automated deletion runs on a scheduled basis. Deletion is permanent and irreversible. Residue in rolling backups is removed within a maximum of ninety (90) days.
Incident response: Pro Season maintains a documented incident response procedure. Breaches are escalated to the responsible person within four hours of detection. Notification to the Customer follows without undue delay and within seventy-two (72) hours at the latest.
Physical security: provided by Supabase infrastructure. Data centres hold ISO 27001 certification or equivalent.
Penetration testing: Pro Season periodically has security testing carried out or relies on the certifications and tests of its infrastructure partners. A summary is available on request.
End of the data processing agreement (version 1.0, 3 September 2026).
Version 1.0 · 3 September 2026 · Pro Season International B.V.