Effective 20 September 2026
Data processing agreement
This agreement applies whenever a club (the controller) uses MediaVault to process personal data, and PLACEHOLDER — registered company name (the processor) processes it on the club's behalf. It is part of the terms of service and reflects GDPR article 28.
Draft: company details in this document are placeholders and must be completed before publication.
01Subject matter and duration
| Item | Detail |
|---|---|
| Subject matter | Hosting, analysing and distributing the controller's match media and roster |
| Duration | The term of the controller's account, plus the 30-day export and deletion period |
| Nature and purpose | Storage; generation of renditions; face detection and matching against the controller's roster; sponsor-logo, caption and tag generation; search indexing; delivery to athletes, partners and galleries; notifications; optional creative drafts |
| Categories of data | Identity data (names, shirt numbers, email addresses), images and video of identifiable people, capture time and location, biometric face templates, access and activity records |
| Categories of data subject | The controller's players and staff (including minors), photographers, sponsor and partner contacts, and members of the public who appear in match media |
02What the processor commits to
- Process personal data only on the controller's documented instructions, which are given through the product's settings and features, unless EU or member-state law requires otherwise, in which case the processor informs the controller before processing.
- Ensure that people authorised to process the data are bound by confidentiality.
- Apply the security measures in section 5.
- Engage sub-processors only as set out in section 4.
- Help the controller respond to data-subject requests, including by forwarding requests received directly and by providing the “not me” dismissal control to athletes.
- Assist the controller with security, breach notification, data-protection impact assessments and consultations with the supervisory authority, taking into account the nature of the processing.
- Delete or return all personal data at the end of the service, as the controller chooses, and delete remaining copies unless law requires storage.
- Make available the information needed to demonstrate compliance and allow audits, on reasonable notice and no more than once a year unless a breach or a supervisory authority requires otherwise.
- Notify the controller without undue delay, and in any case within 48 hours, after becoming aware of a personal-data breach affecting the controller's data.
03Sub-processors
The controller authorises the following sub-processors. We give 30 days' notice by email before adding or replacing one; the controller may object on reasonable data-protection grounds, in which case either party may terminate the affected service.
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway Corp. | Application hosting, database | EU |
| Tigris Data, Inc. | Object storage | Global, S3-compatible |
| Amazon Web Services EMEA SARL | Rekognition (face matching), SES (email) | eu-west-1 |
| Google Ireland Ltd. | Gemini API for captions, tags, logo detection, embeddings | EU/US under SCCs |
| OpenAI Ireland Ltd. | Creative studio chat and image drafts (only when used) | US under SCCs |
04Security measures
- Tenant isolation enforced in a single shared access layer on every query.
- Encryption in transit (TLS 1.2+) and at rest at the hosting and storage providers.
- Secrets (passwords, share tokens, API keys) stored only as hashes.
- Least-privilege, scoped, expiring API keys; instant revocation.
- Biometric templates held per controller in a dedicated collection; deleted on removal of the person or reference photo.
- Rate limiting on authentication and public endpoints; audit records of gallery access.
- No advertising or analytics trackers; self-hosted fonts; no use of Cloudflare.
05Controller obligations
- Have a lawful basis for all processing it instructs, including explicit consent for biometric processing of each registered person and guardian consent for minors, and keep records of it.
- Inform data subjects about the processing, including how to dismiss a match and how to exercise their rights.
- Keep its own account, roles and API keys secure, and remove access when people leave.
06International transfers
Where a sub-processor processes data outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses (2021/914) or an adequacy decision, with supplementary measures where needed.
07Contact
Data-protection matters under this agreement: privacy@mvt.sh.
PLACEHOLDER — registered company name · PLACEHOLDER — CIF · PLACEHOLDER — registered address, city, postcode, Spain
Questions about this document: hello@mvt.sh