Who this agreement is between
- The club: the archery club whose organiser accepts this agreement in the TargetAce organiser console, on the club's behalf. For its course bookings the club is the controller.
- Us: Last Candle Studios, 38 Carmuirs Drive, Motherwell, North Lanarkshire, ML1 5US, [email protected], who make TargetAce. For the club's course bookings we are the processor.
This agreement is the contract that UK GDPR Article 28 requires between a controller and a processor. It sits alongside our terms of service (targetace.app/terms). Where they differ about course bookings, this agreement wins.
What it covers and for how long
- Subject matter: bookings for the club's beginners' courses and have-a-go sessions that people make on targetace.app through TargetAce course bookings, with or without a TargetAce account.
- Duration: from when the club accepts it until we have deleted or anonymised all of the club's course booking data as section 9 describes. It ends early if the club stops using course bookings and asks us to delete its booking data, or if either side ends it by email (bookings already taken are then handled as section 9 says).
What we do with the data, and why
We process booking data only to run course bookings for the club:
- showing the club's course page and its booking form, and taking bookings, including waiting lists;
- storing bookings and showing them to the club's organisers in the organiser console, with the register (who came to each session) and who completed the course;
- sending emails on the club's behalf: booking confirmations with a private link to see, change or cancel the booking, waiting-list places, cancellations (with the club's note), and, if the club chooses, an invitation to join the club after the course;
- exports the club's organisers download (Club Plus);
- keeping and then deleting the data as section 9 says;
- keeping the service secure, working and supported.
We don't use booking data for anything else: no marketing, no selling or sharing it, no profiling, and no training of AI models.
The data and the people it's about
- People: the person who books and pays (the payer), each participant, and a parent or guardian named for participants under 18.
- Data the booking form always asks for: the payer's name and email address; each participant's name and age in years (not a date of birth); a parent or guardian's name for anyone under 18.
- Data the club chooses to ask for: answers to the club's own questions. These can include health or access information (special category data) if the club asks for it.
- Records: which of the club's statements (for example its terms, insurance, consent or photography wording) were agreed to, the exact wording, and when; the register; "course completed"; the club's notes when it cancels a booking; and, if the payer was signed in, a link to their TargetAce account.
- Children: participants can be children. Bookings for under-18s are made by an adult, and participants' names are never shown on public pages.
The club's responsibilities
The club:
- decides what its booking form asks and is responsible for having a lawful basis for collecting and using it (and a condition for any health information it asks for);
- writes its own wording (terms, insurance, consent, photography, medical) and questions, and makes sure they're accurate and lawful;
- asks only for what it needs to run the course safely, especially about health, and doesn't use free-text questions to collect more than it needs;
- tells the people booking what it does with their information (for example in its own privacy notice or its form's wording);
- deals with requests from people about their data (access, correction, deletion and so on), with our help as section 8 says;
- keeps the console sign-in and any exports it downloads secure, and lets only its organisers see bookings;
- tells us promptly if any instruction it gives us needs to change.
Our duties as processor
We:
- process booking data only on the club's documented instructions: this agreement, and what the club sets up in the organiser console (its form, its course details, cancelling bookings, the register, exports and invitations). If we think an instruction breaks data protection law, we'll tell the club. If the law requires us to process data in another way, we'll tell the club first unless the law forbids it;
- make sure everyone at Last Candle Studios who can access booking data is bound to keep it confidential;
- keep it secure with appropriate technical and organisational measures, including: encrypted connections (HTTPS); booking data visible only to the club's organisers; the "manage your booking" link's secret stored only in hashed form; limits on repeated bookings; access to servers limited to us; and backups kept for 14 days;
- don't use another processor (a sub-processor) without the club's general authorisation under section 7;
- help the club meet its obligations as section 8 says;
- delete or anonymise the data as section 9 says;
- give the club the information it reasonably needs to show compliance, and allow audits as section 10 says.
Sub-processors
The club gives its general authorisation for us to use these sub-processors:
- netcup GmbH: hosts TargetAce Live and targetace.app (Vienna, Austria).
- Cloudflare: network security and delivery of targetace.app.
- Amazon Web Services (Amazon SES): sends the booking emails (EU-West-2, London).
We'll tell the club at least 30 days before we add or replace a sub-processor for course bookings, by email to the club's organisers or a notice in the organiser console. The club can object; if we can't resolve it, the club can stop using course bookings and ask us to delete its booking data. Each sub-processor is bound by data protection terms that give at least the same protection as this agreement, and we remain responsible for them. Where a sub-processor handles data outside the UK, it uses recognised safeguards for international transfers.
Helping the club
- People's requests: the club can see, export (Club Plus) and cancel bookings in the organiser console, and payers can correct names and ages with their manage link. If someone contacts us about a booking, we'll pass the request to the club without undue delay and won't answer it ourselves unless the club asks us to. We'll help with any request the club can't handle with those tools.
- Breaches: if we become aware of a personal data breach affecting the club's booking data, we'll tell the club without undue delay, by email to its organisers, with what we know (what happened, the data and people affected, the likely consequences, and what we're doing about it), and keep the club updated.
- Assessments: we'll give reasonable help with the club's data protection impact assessments and any consultation with the Information Commissioner's Office about course bookings.
Deleting the data
- 90 days after the course's last session we delete the payer's email address, the parent or guardian's name, the answers to the club's own questions (including any health or access information), the club's cancellation notes, the link to the payer's TargetAce account and the "manage your booking" link.
- We keep the register for 3 years after the course's last session: each participant's name and age at booking, the payer's name, which sessions they came to, whether they completed the course, the course dates, and the exact wording of the club's statements each booking agreed to, with when. This is the record a club may need for insurance or a claim.
- For participants under 18 at booking, we keep the register until 3 years after the course or until they turn 21, whichever is later. As we only store an age, we take the latest date they could turn 21 (the booking date, plus 21 minus their age, plus one year).
- After that the register is anonymised: names and ages are removed, and only counts remain (places, attendance and courses completed).
- The club can export its bookings at any time with Club Plus, or ask us by email for a copy or for earlier deletion. If the club or the course is deleted in TargetAce, its bookings are deleted with it.
- Deleted data can remain in server backups for up to 14 days.
Audits
On reasonable request, we'll give the club the information it needs to show that we meet this agreement. If that isn't enough, the club (or an auditor it appoints who is bound to confidentiality) can audit our compliance, with at least 30 days' notice, at its own cost, no more than once a year unless there has been a breach, and in a way that doesn't affect other clubs' data or the service.
General
- Each side is responsible for its own compliance with data protection law. Our liability under this agreement is as set out in our terms of service, except where the law doesn't allow that.
- We may update this agreement, for example to add sub-processors (section 7) or follow changes in the law. A new version applies once an organiser accepts it; until then the club can't open bookings or take new ones.
- This agreement is governed by Scots law, and the Scottish courts have jurisdiction.