Data Processing Agreement
Last updated: August 11, 2026 · One-page pilot DPA
1. Parties
- Controller: the academy / club using PlayerDev OS (“Academy”).
- Processor: Player Development OS (“PlayerDev OS”, “we”).
2. Subject matter
We process Academy personal data solely to provide the PlayerDev OS service: roster, evaluations, goals, session notes/transcripts, AI suggestions pending coach approval, reports, invites, and related audit/consent logs.
3. Duration
Processing lasts for the pilot or paid subscription term, plus the time needed to delete or return data after termination (see §8).
4. Nature and purpose
- Host and secure Academy data.
- Enable staff roles and access controls.
- Structure coach notes via LLM API when the coach uses that feature.
- Generate player development reports for Academy use.
- Send transactional emails (magic link, invites, consent confirms).
5. Types of data / data subjects
Staff (owners, directors, coaches); players (often minors); guardians when consent is required. Categories include identity/contact, birth year, sport attributes, development scores/comments, transcripts, and consent events.
6. Academy instructions
We process only on documented instructions from the Academy, which include:
- Using the product features as configured by Academy staff.
- These Terms / DPA / Privacy Policy.
- Written requests to hello@playerdevos.com (access, correction, deletion).
The Academy warrants it has a lawful basis (including parental consent where required) to instruct us to process player data.
7. Our obligations
- Confidentiality and access limited to people who need it to operate the service.
- Security measures appropriate to the risk, including tenant isolation and database row-level security as we ship the product.
- Never use player data to train AI models (ours or the LLM provider’s training sets). Configure APIs to disable training/retention where available.
- Assist with data-subject requests within our SLA (manual ≤ 30 business days in early pilots).
- Notify the Academy without undue delay of a personal-data breach affecting Academy data that we become aware of.
8. Subprocessors
Academy authorizes these subprocessors (and successors providing equivalent services):
- Vercel (hosting)
- Supabase — US East (database, auth, storage)
- Resend (email)
- OpenAI (note structuring API)
Material changes will be reflected on this page or notified to pilot contacts.
9. Deletion / return
On written request after pilot/subscription end, or on a verified deletion request, we will delete or return Academy personal data within 30 business days, except data we must keep for legal/audit reasons (e.g. consent event history for a limited period). MVP: no audio files to delete.
10. International transfers
Primary storage is intended in the United States (Supabase us-east-1). By using the service the Academy instructs that transfer for hosting the product.