Table of Contents
Legal Hub/Privacy & Data Protection/Data Processing Agreement
GDPR ARTICLE 28 MANDATE // DPAVERSION 1.0.0

Data Processing Agreement (DPA)

Legally binding data processing agreement executed pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) between EssenByte Solutions and the Tournament Organizer.

Effective Date: 22.08.2026
Last Revised: 22.08.2026
Legal Entity: EssenByte Solutions
PREAMBLE

Preamble & Contracting Parties

This Data Processing Agreement ('DPA') governs the rights and obligations of the parties regarding personal data processing operations executed in the context of supplying and utilizing the cloud services of the ScoreEngine SaaS platform (scoreengine.online), entered into between:

1. EssenByte Solutions, acting as Data Processor (referred to hereinafter as the 'Processor' or the 'Provider'), contact email: [email protected] / [email protected],

and

2. The Client / Beneficiary (legal entity, association, sports club, federation, or individual event organizer) who created an account, purchased a license, or operates a ScoreEngine instance, acting as Data Controller (referred to hereinafter as the 'Controller' or the 'Client').

The Processor and the Controller are referred to individually as the 'Party' and collectively as the 'Parties'.

This DPA constitutes a mandatory and inseparable annex to the Terms of Service (ToS), available at: scoreengine.online/legal/terms-of-service, or, where applicable, to the Master Services Agreement (MSA): scoreengine.online/legal/msa.

CHAPTER I

Subject Matter, Purpose & Duration of Processing

Article 1. Subject Matter of the Agreement

(1)
The subject matter of this DPA is the establishment of technical, legal, and organizational conditions under which the Processor processes personal data on behalf of and under the instructions of the Controller, through the logically isolated software instances of the ScoreEngine platform.
(2)
The Processor shall perform solely technical processing operations (storage, organization, structuring, retrieval, leaderboard display, programmatic transmission, and deletion) strictly necessary for providing the contracted SaaS services.

Article 2. Purpose and Duration of Processing

(1)
Purpose of processing: Providing technical support and cloud infrastructure necessary for competition management, competitor registration, refereeing, scoring algorithm calculation, and public leaderboard display configured by the Controller.
(2)
Duration of processing: Data processing commences upon activation of the event instance and continues throughout the active validity term of the main contract, plus the designated passive retention period (ranging from 1 month to a maximum of 1 calendar year), pursuant to the agreed commercial package.
CHAPTER II

Instructions & Obligations of the Data Processor

Article 3. Processing on Documented Instructions

(1)
The Processor undertakes to process personal data exclusively on documented written instructions from the Controller, including regarding data transfers, unless required to do so by European Union or Romanian statutory law. In such case, the Processor shall notify the Controller prior to processing, unless prohibited by law on important grounds of public interest.
(2)
Configuration of instance parameters, registration forms, and scoring rules via the ScoreEngine administrative console constitutes direct documented instructions from the Controller.
(3)
The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes Regulation (EU) 2016/679 or other applicable data protection provisions.

Article 4. Confidentiality of Authorized Personnel

(1)
The Processor warrants that all persons authorized to process personal data under its direct authority (employees, technical collaborators, system administrators) are bound by strict confidentiality agreements or statutory confidentiality obligations.
(2)
Access by Processor personnel to Controller instance databases is strictly limited on a need-to-know basis and permitted exclusively for technical support or critical maintenance.

Article 5. Assistance Provided to the Controller

(1)
Response to Data Subject Requests: Taking into account the nature of the processing, the Processor shall assist the Controller through appropriate technical measures (including native export and direct deletion functions in the management portal) to enable the Controller to respond to requests exercising rights under GDPR Articles 15–22.
(2)
Data Protection Impact Assessments (DPIA) & Prior Consultation: The Processor shall provide the Controller, upon reasonable request and subject to cost reimbursement if exceeding standard assistance, technical documentation required to conduct DPIAs under GDPR Articles 35 and 36.
CHAPTER III

Technical & Organizational Security Measures (TOMs)

Article 6. Implementation of Security Measures

(1)
In accordance with GDPR Article 32, the Processor implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
•
Multi-Tenant Logical Isolation: Strict database and storage volume segregation for each event instance.
•
In-Transit Encryption: Encryption of all data streams via cutting-edge HTTPS / TLS 1.3 cryptographic protocols.
•
At-Rest Encryption: Storage volumes, databases, and backup archives encrypted using industry-standard AES-256 algorithms.
•
System Integrity & Resilience: Multi-tier cloud redundancy and availability pursuant to the Service Level Agreement (SLA): scoreengine.online/legal/sla.
•
Access Control & Auditing: Secure authentication via SSO with 2FA enforcement and immutable audit log tracing.
(2)
Comprehensive compliance measures are detailed in the Security & Compliance Page: scoreengine.online/legal/security-compliance.
CHAPTER IV

Technological Sub-processors (Sub-contractors)

Article 7. General Authorization of Sub-processors

(1)
The Controller grants general written authorization to the Processor to engage technological sub-processors (cloud hosting providers, EU data centers, CDN routing, anti-DDoS mitigation, transactional email services).
(2)
Main categories of sub-processors include: EEA-located cloud data center facilities; edge security and cyber attack mitigation providers (e.g. Cloudflare); and transactional email delivery networks for system alerts.
(3)
The Processor imposes upon each sub-processor, via written agreement, the same data protection obligations as set forth in this DPA. Where a sub-processor fails to fulfill its obligations, the Processor remains fully liable to the Controller for the performance of said obligations.

Article 8. Notification of Changes & Right to Object

(1)
The Processor shall notify the Controller of any intended changes concerning the addition or replacement of sub-processors.
(2)
The Controller has the right to state justified objections on data protection grounds within 10 calendar days of notification. Where the parties cannot reach an agreed technical solution, the Controller is entitled to terminate instance use without retroactive penalty.

Article 9. International Data Transfers

(1)
Data processed within ScoreEngine is stored and processed primarily in data centers located within the European Union / European Economic Area.
(2)
Any data transfers outside the EEA are conducted strictly pursuant to European Commission adequacy decisions, Standard Contractual Clauses (SCCs - Implementing Decision (EU) 2021/914), or the EU-US Data Privacy Framework.
CHAPTER V

High-Risk Data Framework & Exclusive Controller Liability

Article 10. Sensitive Data, National IDs, Passports & Visas

(1)
Where the Controller configures custom forms collecting special categories of data or high-risk identifiers (including National Identification Numbers, passport copies/numbers, identity cards, sports medical certificates, or embassy visa documents): the Controller bears exclusive and absolute legal liability for valid legal bases (GDPR Articles 6 & 9), explicit consent collection where required, and full data subject notices; the Processor acts strictly as a passive technical hosting and storage provider; and the Processor does not inspect, verify authenticity, filter, or use sensitive data for any independent purpose.

Article 11. Indemnification of the Processor

(1)
The Controller warrants that all data entered into the instance has been obtained in strict compliance with applicable legal norms.
(2)
The Controller shall fully defend, indemnify, and hold harmless the Processor (EssenByte Solutions) against any administrative fines imposed by supervisory authorities (including ANSPDCP), legal costs, attorney fees, and third-party damages arising from the Controller's breach of its statutory Data Controller obligations.
CHAPTER VI

Security Breach Notification Protocol

Article 12. Incident Notification to Controller

(1)
In the event the Processor becomes aware of a confirmed security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data processed for the Controller (Personal Data Breach), the Processor shall notify the Controller without undue delay (and at the latest within 48 hours of technical confirmation).
(2)
The notification shall include, to the extent available: description of the nature of the breach and estimated number of affected individuals; contact details of the Data Protection Officer (DPO); description of likely consequences; and remedial measures adopted or proposed to mitigate negative effects.
(3)
External security reports are processed via the Responsible Disclosure Policy (scoreengine.online/legal/responsible-disclosure) and Bug Bounty Policy (scoreengine.online/legal/bug-bounty-policy).
CHAPTER VII

Audits & Compliance Verification

Article 13. Audit Conditions & Procedures

(1)
The Processor makes available to the Controller all information necessary to demonstrate compliance with obligations under GDPR Article 28, permitting audits and inspections conducted by the Controller or an independent mandated auditor.
(2)
Any on-site or technical audit shall be subject to: at least 30 days prior written notice; execution during normal business hours without disrupting operations or compromising other tenant data; execution of a Non-Disclosure Agreement (NDA) by the auditor; and full reimbursement of associated audit costs by the Controller.
(3)
Provision of independent security audit certificates or technical documentation published on the Security & Compliance Page (scoreengine.online/legal/security-compliance) constitutes primary fulfillment of this verification obligation.
CHAPTER VIII

Passive Retention, Data Return & Irreversible Deletion

Article 14. Service Conclusion & Deletion Procedure

(1)
Upon termination of services, the Controller is responsible for downloading and exporting its data, rankings, and participant lists using native ScoreEngine export functions (CSV / JSON formats).
(2)
Passive Retention Phase: Following expiration of the active term, the instance enters a secure archival state (Read-Only) for 1 month to a maximum of 1 calendar year.
(3)
Irreversible Purging: Upon conclusion of the passive retention term, the Processor shall definitively, completely, and irreversibly delete all personal data stored within the Controller's instance and remove all existing copies from production databases, unless Union or Member State law mandates continued storage.
CHAPTER IX

Contractual Liability & Final Provisions

Article 15. Liability Cap

(1)
The total aggregate liability of each Party arising out of or in connection with this DPA (including GDPR compliance warranties) is expressly capped at the total amount paid by the Controller in the 3 (three) calendar months preceding the incident, as stipulated in the Terms of Service (scoreengine.online/legal/terms-of-service) and Billing Policy (scoreengine.online/legal/billing-refund-policy).

Article 16. Amendments, Governing Law & Jurisdiction

(1)
Any modification to this DPA takes effect upon publication on the platform or direct written notice.
(2)
This Agreement is governed exclusively by the laws of Romania and European Union law.
(3)
Any dispute failing amicable settlement shall be submitted to the competent courts of Buzău Municipality, Romania.
MANDATORY DPA ANNEXES & TECHNICAL SPECIFICATIONS
ANNEX 1

Description of Personal Data Processing

•
Categories of Data Subjects: Legal representatives, tournament coordinators, and administrators of the Controller; athletes, competitors, and registered team members; referees, judges, technical delegates, and match officials; and public spectators monitoring live leaderboards.
•
Types of Personal Data: Identification data (Full name, birthdate, gender, age/weight division, affiliated sports club); Contact details (Email address, telephone number); Performance metrics (Scores, lap times, matches played, penalties, rankings); SSO authentication tokens (User ID, session tokens, email); and Optional special regime data (National ID, passport/ID series, visa documents – collected strictly on the initiative and exclusive liability of the Controller).
•
Processing Operations: Cloud hosting on logically segregated instances; Algorithmic calculation of results and tournament bracket generation; File exports upon Controller request; and Anonymization/purging at the conclusion of the instance lifecycle.
ANNEX 2

Technical & Organizational Measures (TOMs)

1. Physical & Logical Access Control: Biometric-secured cloud data centers with 24/7 surveillance (provided by cloud partners); Multi-Factor Authentication (2FA) enforced on production administrative environments.

2. Cryptography: TLS 1.3 standard for all data in transit and AES-256 encryption for data at rest (databases and backups).

3. Multi-Tenant Segregation: Software architecture strictly barring cross-instance database queries between distinct clients.

4. Backup & Disaster Recovery: Daily geographically redundant backups, periodically tested to ensure business continuity.

5. Logging & Continuous Telemetry: Audited security event logs monitoring unauthorized access attempts and network anomalies.

Have legal, DPA, or compliance inquiries?
Our compliance officer and legal counsel at EssenByte Solutions are available to review custom federation DPAs, enterprise MSAs, or answer regulatory questions.
Contact via Helpdesk →