Legal centre

Data Processing Addendum

This Addendum applies where LeanPlay processes personal data on behalf of a club, academy or agency and forms part of the Terms of Use in respect of that processing. It is concluded pursuant to Article 28(3) GDPR.

Version 1.0 — last updated 30 August 2026

1.Roles and subject matter

The business User is the controller and LeanPlay is the processor in respect of personal data uploaded or generated by that User in its own recruitment or representation activity. LeanPlay remains an independent controller for account administration, security, billing and platform-wide compliance.

The subject matter is the provision of the Services; the duration is the term of the underlying contract; the nature and purpose are hosting, storage, structured retrieval, analytics and controlled disclosure; the categories of data subject are players, guardians, agents and club personnel; and the categories of data are those listed in the Privacy Policy.

2.Processor obligations

LeanPlay shall:

  • process personal data only on the documented instructions of the controller, including as to international transfers, unless required otherwise by Union or member state law, in which case it will inform the controller unless that law prohibits it;
  • ensure that persons authorised to process the data are bound by confidentiality;
  • implement the technical and organisational measures required by Article 32;
  • assist the controller, by appropriate measures, in responding to data subject requests and in complying with Articles 32 to 36, including data protection impact assessments and prior consultation;
  • notify the controller without undue delay after becoming aware of a personal data breach, with sufficient information to enable the controller to meet its own notification obligations;
  • at the controller's election, delete or return all personal data at the end of the provision of services, save where storage is required by law; and
  • make available all information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the controller or an auditor mandated by it.

3.Sub-processors

The controller grants general written authorisation for the engagement of sub-processors. LeanPlay maintains a current sub-processor register comprising hosting, database, email, payment and identity-verification providers, and will give at least thirty (30) days' prior notice of any intended addition or replacement. The controller may object on reasonable, documented data protection grounds, in which case the parties shall negotiate in good faith and, failing resolution, the controller may terminate the affected service without penalty.

LeanPlay imposes on each sub-processor obligations no less protective than those in this Addendum and remains fully liable for the performance of each sub-processor's obligations.

4.International transfers

Transfers of personal data outside the European Economic Area are made pursuant to an adequacy decision or, failing that, Module Two or Module Three of the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), which are incorporated into this Addendum by reference and completed as follows: the optional docking clause applies; the governing law and forum are those of the member state of the controller's establishment; and the appendices are populated by the descriptions in this Addendum and the Privacy Policy.

5.Security measures

Measures include encryption in transit (TLS 1.2 or above) and at rest, role-based and least-privilege access control, multi-factor authentication for administrative access, environment segregation, immutable audit logging of document access, key management, backup with tested restoration, vulnerability management and periodic independent penetration testing. LeanPlay may update measures provided that the level of protection is not degraded.

6.Liability and precedence

Each party's liability under this Addendum is subject to the limitations in the Terms of Use, save to the extent such limitation is prohibited by Article 82 GDPR. In the event of conflict, the Standard Contractual Clauses prevail over this Addendum, and this Addendum prevails over the Terms of Use in respect of processing of controller personal data.

Where a translation of this document is provided, the English-language version prevails in the event of a conflict.