Data processing agreement
A coach who films a squad is the controller of that video. We are the processor. Article 28 GDPR requires a written contract between the two, with specific terms in it. This page is that contract.
It is already in force for every account that accepted the terms of service. There is nothing to sign and nothing to request.
1.Who this agreement is between
This agreement applies when you use Tencoline to process personal data that you are the controller of. That is the case for a coach, club, academy, team or federation that uploads video of other people.
- Controller
- You, the account holder or the organisation you act for.
- Processor
- Tencoline, Moosacher Str. 89, 80808 München, Germany.
It takes effect when you accept the terms of service, which incorporate it. You do not have to sign anything separately. If your organisation requires a signed copy, write to legal@tencoline.com and we will provide one on these terms.
If you upload only video of yourself, you do not need this page. You are the data subject, we are the controller, and the privacy policy is the document that applies.
2.Subject matter and duration
We process personal data on your behalf so that you can store, watch, mark, analyse and share tennis video. The processing lasts as long as your account does. It ends when the account is deleted, or when this agreement is terminated, whichever is first.
3.What is processed, and about whom
Nature and purpose
Storage, format conversion, automatic shot recognition, statistics, highlight cutting, and controlled sharing. Nothing else.
Types of personal data
- Video and audio recordings of people on and around a court.
- The image, voice and movement of those people, as recorded.
- Names or labels you attach to a player, a mark or a comment.
- Account data of the users you give access to: email address, and the record of when they watched what.
Categories of data subject
- Your players, including players under 18.
- Opponents, hitting partners and coaches who appear in the recording.
- Other people who happen to be filmed beside the court.
- The staff and members you give an account or a share link to.
Special category data. A video can reveal a health condition — an injury, a disability, a way of moving. That would make it Article 9 data. You decide whether to upload such a recording and you need the explicit consent of the person for it. We do not analyse video for health information and we do not derive any. See why the shot analysis is not biometric data.
4.We act only on your instructions
We process personal data only on your documented instructions, including for transfers to a third country. Your instructions are: these terms, the settings you choose in the application, and anything you ask us in writing.
If EU or German law obliges us to process data beyond your instructions, we will tell you before we do, unless that law forbids the notice on grounds of important public interest.
We will tell you if we believe an instruction of yours breaches data protection law. We may suspend that instruction until it is resolved.
5.Confidentiality
Everybody we authorise to process this data is bound to confidentiality, by contract or by statute, and that duty outlives their engagement with us. Access is limited to the people who need it to run and support the service, and access to a customer video is limited to what a specific support request requires.
6.Security of processing (Art. 32)
We apply these measures, and keep them under review:
- Encryption in transit for every connection, with HTTPS.
- Passwords stored only as bcrypt hashes.
- Session cookies that a script cannot read and another site cannot send.
- Server-side authorisation on every request for a video, checked against the account making it, never against what the browser claims.
- Rate limiting and automatic blocking of repeated failed sign-ins.
- Separate administrator roles, checked on the server.
- Backups, so data survives a hardware failure.
- Logging that lets us reconstruct who did what after an incident.
The current measures are described in more detail in the privacy policy. We may change them, and we will not lower the level of protection.
7.Subprocessors
You give general written authorisation for us to engage subprocessors. The current list is at /subprocessors, with what each one does and where.
We will announce a new subprocessor, or a replacement, at least 30 days before it starts processing. Ask at privacy@tencoline.com to be told by email when the list changes. You may object on reasonable data protection grounds within those 30 days. If we cannot resolve the objection, you may terminate the affected service without penalty.
Every subprocessor is bound by the same obligations as this agreement. We stay fully liable to you for what they do.
8.Helping you answer data subjects
A data subject who asks you for access, correction, deletion, restriction, portability or objection is your request to answer, not ours. Where the application does not already let you do it yourself, we will help.
If a data subject contacts us directly about data you control, we will not answer for you. We will pass the request to you without undue delay and tell the person we have done so.
We will also help you meet Articles 32 to 36: security, breach notification, and a data protection impact assessment where you need one. We provide this help for the information we hold, and we charge nothing for a reasonable volume of it.
9.Data breaches
We will tell you without undue delay and within 48 hours of becoming aware of a personal data breach affecting data we process for you. We will describe what happened, which categories of data and roughly how many records are involved, what the likely consequences are, and what we are doing about it. If we do not have all of that at first, we will send what we have and follow it up. Notifying your supervisory authority within 72 hours under Art. 33 stays your obligation, and we will give you what you need to do it.
10.Deletion and return
When the service ends, we will delete the personal data we process for you, or return it, as you choose. Tell us which within 30 days of the end. After that we delete it. Backups are overwritten on their own cycle, and data in a backup is not restored into service. We keep only what EU or German law requires us to keep, and only for as long as that law requires.
11.Information and audits
We will give you the information you need to show that these obligations are met, and allow an audit or inspection by you or an auditor you appoint. Give us 30 days' notice, once in any twelve months, or after a breach. An audit must not compromise the confidentiality or security of another customer's data. We may charge our reasonable costs for an audit beyond the yearly one.
12.International transfers
Data is stored in Germany. Two optional services can transfer data outside the EU: analytics, which is off unless a visitor accepts it, and a frame check that is off by default. Both are covered by the European Commission's Standard Contractual Clauses. The subprocessor list names the safeguard for each. If a safeguard is invalidated, we will suspend the transfer or find another basis for it.
13.Precedence, and changes
Where this agreement and the terms of service conflict on the processing of personal data, this agreement wins.
We will tell affected controllers at least 30 days before changing this agreement, and we will not make a change that lowers the protection it gives.
Questions and signed-copy requests: legal@tencoline.com.