Data Processing Agreement
Last updated: 19 August 2026
This data processing agreement (the "Agreement") governs Driblo's processing of personal data on behalf of a club. It forms part of Driblo's Terms of Service and is entered into when the club accepts them. No signature is required; Article 28(9) of the GDPR provides that the agreement shall be in writing, including in electronic form.
1. The parties and the subject matter
The controller is the club on whose behalf the Terms of Service were accepted, as identified in the club's account with Driblo. That club is referred to below as "the Club".
The processor is:
Driblo FCCVR no. 33324138Astridsminde 168960 Randers SØDenmarkThe Agreement governs Driblo's processing of personal data on the Club's behalf in connection with providing the Driblo platform, including the website and the Driblo Player and Driblo Coach apps (the "Service"). It is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679.
The Club is the controller for the data processed in connection with the Club's use of the Service. Driblo is the controller for the relationship between Driblo and the individual user — account, email address, sign-in, security logs and notification tokens — and that processing falls outside this Agreement. Section 1 of the privacy policy describes the same division.
2. Definitions
Terms defined in the GDPR have the same meaning here. In addition:
- Personal data: any information relating to an identified or identifiable natural person that Driblo processes on the Club's behalf
- Data subjects: the people whose personal data is processed through the Service — players with and without an account, coaches, team leaders and club administrators
- Sub-processor: a supplier Driblo uses to carry out part of the processing on the Club's behalf
3. The Club's responsibilities
The Club is responsible for the processing having a lawful basis, and in particular for:
- determining the purposes of the processing
- deciding which people are created in the Service and what is recorded about them
- having a lawful basis for the processing and informing the data subjects about it
- involving a parent or guardian where the rules require it for a member under 18
- ensuring that coaches only record health data about players who have consented in the Service
- the lawfulness of the instructions given to Driblo
4. Driblo's processing
Driblo processes personal data only:
- to provide, operate, maintain and secure the Service
- in accordance with this Agreement and its annexes
- on documented instructions from the Club
- where processing is required by EU or Danish law, in which case Driblo informs the Club beforehand unless the law forbids it
Driblo does not use personal data for its own purposes. The data is not used to train AI models, for marketing or for profiling, and it is not sold.
5. Instructions
The Club's instructions consist of this Agreement, Annex 1, and the Club's use of the Service's features. Subsequent instructions shall be given in writing.
If Driblo considers an instruction to infringe data protection law, Driblo informs the Club. Driblo is not obliged to carry out an instruction that is manifestly unlawful before the matter has been resolved.
6. Confidentiality
Driblo ensures that anyone authorised to process personal data is bound by confidentiality, and that access is limited to what each person's tasks require. The obligation continues after the engagement ends.
7. Security
Driblo implements appropriate technical and organisational measures so that the level of security matches the risk of the processing, in accordance with Article 32. The measures are set out in Annex 3 and are maintained at least to the extent described.
Driblo reviews on an ongoing basis whether the measures remain sufficient and may implement further measures.
8. Health data
The Service may be used to record injuries, which constitute health data and therefore a special category under Article 9.
- Such data may only be processed if the Club has a valid basis under Article 9
- The Service requires the individual player to have given her own consent before an injury can be recorded about her
- Driblo does not use health data for purposes other than those the Club has instructed
- Access to the data is restricted in the software itself, as described in Annex 3
9. Sub-processors
The Club gives Driblo general authorisation to use sub-processors. The currently approved ones are listed in Annex 2.
- Driblo imposes on every sub-processor data protection obligations at least equivalent to this Agreement
- Driblo is liable to the Club for a sub-processor's processing to the same extent as for its own
Driblo informs the Club at least 30 days before a sub-processor is added or replaced. Within that period the Club may object to the change in writing. If the parties cannot find a solution, the Club may terminate the Service without notice and without payment for the remaining period.
10. Transfers to third countries
Personal data is not transferred to a country outside the EU/EEA unless the conditions in Chapter V of the Regulation are met. Where a sub-processor is established in a third country, Driblo ensures a valid transfer mechanism. The sub-processors' locations and transfer mechanisms are set out in Annex 2.
11. Assistance to the Club
Taking into account the nature of the processing and the information available to it, Driblo assists the Club in meeting its obligations, including:
- requests from data subjects for access, rectification, erasure, restriction, portability and objection
- the security of the processing
- notification of a personal data breach
- data protection impact assessments and any prior consultation with the supervisory authority
12. Requests from data subjects
If a data subject approaches Driblo directly about data processed on the Club's behalf, Driblo informs the Club without undue delay. Driblo does not decide on the request itself unless the Club has instructed it to, and assists the Club in answering.
13. Personal data breaches
If Driblo becomes aware of a breach concerning personal data processed on the Club's behalf, Driblo informs the Club without undue delay and no later than 48 hours after the breach is established. The notification includes, to the extent the information is available:
- the nature of the breach
- which types of personal data and categories of data subjects are affected
- the likely consequences
- the measures taken or planned
Driblo cooperates with the Club on handling the breach and on any notification to the supervisory authority. It is the Club, as controller, that notifies the authority.
14. Documentation and audit
Driblo makes available the information necessary to demonstrate that the obligations in Article 28 and in this Agreement are met. Verification is carried out in the first instance by:
- reviewing Annex 3 and Driblo's other documentation
- Driblo answering the Club's questionnaire
- any audit reports or certifications held by Driblo or Driblo's sub-processors
Where that is not sufficient, the Club may require a closer inspection. Such an inspection takes place at most once a year, on at least 30 days' written notice, during normal working hours, and at the Club's expense — unless it establishes a material breach, in which case Driblo bears the cost. Inspections are conducted with regard to the confidentiality and security of Driblo's other customers.
15. Retention and deletion
Driblo does not retain personal data for longer than is necessary to provide the Service or for longer than instructed by the Club. The retention periods are set out in Annex 1.
On termination Driblo deletes or returns, at the Club's choice, the personal data processed on the Club's behalf, and deletes existing copies, unless EU or Danish law requires continued storage. Any such requirement is communicated to the Club unless the law prevents it.
A user may delete her own account at any time. What the user has created for the Club — training sessions, exercises, playing styles and match data — stays with the Club without the user's name on it. This follows from Driblo's role as controller for the account relationship and is not processing that requires the Club's instruction.
16. Duration, changes and termination
The Agreement takes effect when the Club accepts the Terms of Service and applies for as long as Driblo processes personal data on the Club's behalf.
Driblo may amend the Agreement where necessary to comply with the law or to reflect changes to the Service. Material changes are notified at least 30 days before they take effect, and during that period the Club may terminate the Service if it does not wish to accept them.
The provisions on confidentiality, deletion and return, and any statutory retention requirements, continue to apply after termination.
17. Governing law and jurisdiction
The Agreement is governed by Danish law. Disputes are settled according to Danish rules on jurisdiction.
Annex 1 — Processing instruction
Purpose
Personal data is processed solely to provide the Service to the Club and its members: planning and running training sessions and matches, selecting squads and writing game plans, following player development, recording injuries for players who have consented, and giving each user access to the data they are entitled to see.
Data subjects
- players with an account
- players without an account — a club can create a player as a placeholder before she has an account. She is a real person, and the data about her is personal data even though she cannot sign in herself
- coaches and team leaders
- club administrators
- other people the Club creates as users of the Service
Categories of personal data
- Identification and contact: name, display name, email address, phone number, profile photo, address, postcode, city, country, nationality and language choice
- Date of birth and gender: on the user profile for players with an account, and on the club membership for placeholder players
- Club and team membership: role in the club, coaching role, team assignment, membership period and access permissions
- Sports data: jersey number, playing positions, primary position, preferred foot, height and weight
- Activity data: participation in training sessions and matches, declines, squad selection, starting eleven and bench, match data and match events
- Development data: development plans with title, description, goals, dates and status, and documents and videos the Club attaches to a player's plan
- Health data — special category: injury type chosen from a fixed list, start date, end date, the coach's comment, and who created the record. Plus each player's consent status
- Technical data: authentication sessions, device information, a notification token per app install with platform and language, and a record of which notifications have been sent
- AI-related data: conversations with the assistant Libero, which only coaches and club administrators can reach, and a log of which feature sent something to a provider and when — without content
Processing activities
Collection, recording, storage, display, alteration, search, organisation, transfer to the sub-processors listed in Annex 2, and deletion.
Duration and retention
Processing takes place for as long as the Club uses the Service. In addition the following periods apply, which are the same as those in section 10 of the privacy policy:
- Account data: while the account is active, and deleted immediately when the account is deleted
- Activity data: for the duration of the club membership
- Health data: until consent is withdrawn or the account is deleted
- Technical logs: 90 days
- Libero conversations: 12 months after the last message
- Record of AI transmissions: 12 months. Contains no content
- Notification tokens: on disconnection, on refusal by Apple or Google, or after 180 days without use
Annex 2 — Approved sub-processors
Each supplier is listed with its purpose, what it receives, where the processing takes place, and the basis for any transfer to a third country.
- Supabase — database, authentication and file storage. Receives all data in Annex 1. EU servers. US company; transfers are covered by Standard Contractual Clauses.
- Vercel — hosting and operational analytics. Receives traffic data and anonymised usage analytics. EU servers. US company; transfers are covered by Standard Contractual Clauses.
- Resend — outgoing email. Receives the email address and the contents of sign-in codes, invitations, confirmations, welcome messages and trial reminders. US company; transfers are covered by Standard Contractual Clauses.
- Anthropic — the assistant Libero, exercise import, match report reading and calendar import. Receives what is described in Annex 3 under AI features. US; transfers are covered by Standard Contractual Clauses.
- OpenAI — descriptions of animated match situations. Receives the situation text a coach has written. US; transfers are covered by Standard Contractual Clauses.
- Apple — notifications to iPhone and iPad. Receives the device token and the text of each notification, and only if the user turns notifications on. US; transfers are covered by Standard Contractual Clauses.
- Google — notifications to Android. Receives the same as Apple, on the same terms. US; transfers are covered by Standard Contractual Clauses.
A notification token identifies an app install rather than a person, and the notification text is the same sentence the user sees on her screen. Health data is never sent in a notification.
Annex 3 — Technical and organisational security measures
- Separation between clubs. Every table holding data from more than one club is protected by row-level security policies in the database. A query cannot return another club's rows whatever the application asks for — the separation is enforced in the database rather than in application code.
- Access control. Access follows the role in the club: club administrator, coach or player. A coach sees the teams she is assigned to. A player sees herself and what the Club has released to her — a game plan and a starting eleven are visible only once the coach publishes the match.
- Health data. Injuries live in a separate table with its own access policy: a player reads her own, and the Club's coaches and administrators read the Club's. A teammate can see that a player is out and that the reason is an injury — through a database function that returns a user and one of two words. Injury type, dates and comment are read inside the function and never leave it.
- AI features. There are exactly six places from which an AI model can be called, and none of them can do so without declaring the feature, the club, the coach and the kind of content. All structured content on its way to a model passes a filter that refuses — rather than scrubs — eight categories: health data, injuries, dates of birth, email addresses, phone numbers, coaches' notes, notes about a player, and preferred foot. These rules are enforced by an automated test that reads the source at every change and rejects a change that bypasses them.
- Files uploaded by a coach. Three features accept a file the coach has chosen — a match report, an exercise collection or a fixture list. The contents of a file cannot be filtered the same way, and those three features are therefore described in section 7 of the privacy policy.
- Phone apps. Neither app contains a key that can bypass the database's access policies. Where an app needs an action requiring elevated rights, it calls an endpoint on the server that first verifies the user's credentials. If a user chooses biometric sign-in, the key is kept in the phone's own secure keychain and never leaves the device.
- Notifications. A token is tied to an app install and is deleted as soon as Apple or Google refuses it, and in any case after 180 days without use. The unused ones are removed automatically every night.
- Deletion. An account can be deleted by the user herself and is deleted immediately. The deletion also covers files in storage, including profile photos and documents attached to a development plan. The database's foreign keys have been reviewed so a deletion cannot be blocked by an overlooked reference.
- Encryption and transport. All traffic goes over HTTPS/TLS. The database is encrypted at rest by the supplier, and backups are handled by the supplier.
- Changes to the code. Every change must pass type checking, static analysis and the security tests named above before it can enter the codebase. Changes to the database structure are made through versioned migrations.
- Driblo's own access. As the provider, Driblo has access to data across clubs. The access is limited to Driblo's administrator and support accounts and is used to run and support the service.