Data Processing Agreement (DPA)
Legally binding data processing agreement executed pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) between EssenByte Solutions and the Tournament Organizer.
Preamble & Contracting Parties
This Data Processing Agreement ('DPA') governs the rights and obligations of the parties regarding personal data processing operations executed in the context of supplying and utilizing the cloud services of the ScoreEngine SaaS platform (scoreengine.online), entered into between:
1. EssenByte Solutions, acting as Data Processor (referred to hereinafter as the 'Processor' or the 'Provider'), contact email: [email protected] / [email protected],
and
2. The Client / Beneficiary (legal entity, association, sports club, federation, or individual event organizer) who created an account, purchased a license, or operates a ScoreEngine instance, acting as Data Controller (referred to hereinafter as the 'Controller' or the 'Client').
The Processor and the Controller are referred to individually as the 'Party' and collectively as the 'Parties'.
This DPA constitutes a mandatory and inseparable annex to the Terms of Service (ToS), available at: scoreengine.online/legal/terms-of-service, or, where applicable, to the Master Services Agreement (MSA): scoreengine.online/legal/msa.
Subject Matter, Purpose & Duration of Processing
Article 1. Subject Matter of the Agreement
Article 2. Purpose and Duration of Processing
Instructions & Obligations of the Data Processor
Article 3. Processing on Documented Instructions
Article 4. Confidentiality of Authorized Personnel
Article 5. Assistance Provided to the Controller
Technical & Organizational Security Measures (TOMs)
Article 6. Implementation of Security Measures
Technological Sub-processors (Sub-contractors)
Article 7. General Authorization of Sub-processors
Article 8. Notification of Changes & Right to Object
Article 9. International Data Transfers
High-Risk Data Framework & Exclusive Controller Liability
Article 10. Sensitive Data, National IDs, Passports & Visas
Article 11. Indemnification of the Processor
Security Breach Notification Protocol
Article 12. Incident Notification to Controller
Audits & Compliance Verification
Article 13. Audit Conditions & Procedures
Passive Retention, Data Return & Irreversible Deletion
Article 14. Service Conclusion & Deletion Procedure
Contractual Liability & Final Provisions
Article 15. Liability Cap
Article 16. Amendments, Governing Law & Jurisdiction
Description of Personal Data Processing
Technical & Organizational Measures (TOMs)
1. Physical & Logical Access Control: Biometric-secured cloud data centers with 24/7 surveillance (provided by cloud partners); Multi-Factor Authentication (2FA) enforced on production administrative environments.
2. Cryptography: TLS 1.3 standard for all data in transit and AES-256 encryption for data at rest (databases and backups).
3. Multi-Tenant Segregation: Software architecture strictly barring cross-instance database queries between distinct clients.
4. Backup & Disaster Recovery: Daily geographically redundant backups, periodically tested to ensure business continuity.
5. Logging & Continuous Telemetry: Audited security event logs monitoring unauthorized access attempts and network anomalies.