Legal

Data Processing Addendum

Draft Data Processing Addendum for Customers that control operational team data.

Status
DRAFT
Version
2026-08-draft-1
Language
English
Last updated
2026-08-18
Effective date
Not effective — draft
Draft only — review and approval required by a qualified Swiss IT/SaaS lawyer before publication, signature, pilot use, paid use, or legal reliance.

1. Parties and status

The proposed parties are Janis Zarins, operator of MyTeamTravel, and the Customer identified in the applicable Workspace agreement. This DPA is not effective while DRAFT and requires qualified legal review and valid agreement.

2. Roles

The Customer is proposed as controller for instructed Club/member/travel operations and MyTeamTravel as processor for that scope. MyTeamTravel may be an independent controller for account security, abuse prevention, provider administration and legal obligations. Final allocation requires review.

3. Subject matter and duration

Processing supports account, Club/team and TravelPlan operation for the term of the service plus agreed return/deletion and legally required retention periods.

4. Purposes and instructions

Instructions arise from the agreement, configured features and authorised Customer actions. MyTeamTravel will process instructed data only to provide, secure and support the service unless law requires otherwise.

5. Data subjects and categories

  • Admins, Managers, Coaches, Staff, Players, minors, Parents/Family, drivers, Persons in Charge, invitees and support contacts.
  • Identity/contact, memberships/roles/relationships, addresses/locations, TravelPlans/timing, selections/carpools, notes, acknowledgements, notifications, exports, driver access, audit/security and subscription/promo data.

6. Confidentiality

Persons authorised to process Customer data must be bound by appropriate confidentiality and access restrictions.

7. Security measures

  • Password hashing and verified-email authentication.
  • Role, active-membership, Club/team and subscription checks.
  • Server-side provider keys; hashed/signed tokens in security-sensitive flows where implemented.
  • Encryption in transit through deployed HTTPS and provider controls, subject to deployment verification.
  • Audit records, expiry/revocation checks, backups and incident handling subject to final TOM review.

8. Providers and subprocessors

The draft list includes Vercel, Supabase/PostgreSQL and Resend, subject to contractual verification. Google Maps Platform is separately listed pending role classification. A notice/objection process for changes must be agreed.

9. International transfers

The primary database project is configured in Zurich, but provider support/subprocessors may process elsewhere. Appropriate safeguards and transfer mechanisms must be verified.

10. Rights assistance

MyTeamTravel will provide reasonable assistance for access, correction, deletion, restriction, portability or objection requests, taking account of processing nature and Customer instructions.

11. Incidents and DPIA assistance

MyTeamTravel will notify the Customer without undue delay after confirming a relevant personal-data breach, provide available facts and assist with legal notifications and DPIA/authority consultation where required. Exact deadlines require agreement.

12. Return and deletion

Current Club offboarding uses a 30-day recovery period and soft deletion. Complete export, physical purge and verified backup rotation are not yet technical guarantees. Final return/deletion instructions, exceptions and evidence must be agreed.

13. Audit and government requests

Reasonable evidence and audit cooperation, confidentiality, cost, frequency and security restrictions require final terms. Government requests will be assessed and the Customer notified where legally permitted.

14. Liability and precedence

Liability, caps, conflict with Customer Terms and order of precedence are open lawyer-review items.

Annex — technical and organisational measures

  • Access control and least-privilege role scoping.
  • Credential hashing, verification, token expiry/revocation and secure server secrets.
  • Application logging, incident procedure and provider monitoring.
  • Data minimisation in user read models and exports.
  • Soft-deletion recovery and protected finalizer, with physical-purge gap recorded.
  • Change control, tests and environment separation.

Legal contact

janis@myteamtravel.app

The English and German versions are parallel drafts. Language precedence in case of conflict remains open for lawyer review.