Version 1.0, draft for solicitor review, 11 October 2026. Effective the day it is published.
This agreement is between the club, organiser or association that uses Whole Team ("the club") and Whole Team Ltd (company number SC902475, 5 South Charlotte Street, Edinburgh EH2 4AN; ICO registration ZC248423) ("we"). It forms part of Part B of the Whole Team terms of service. The person who sets up the club accepts it for the club when they tick to agree. It meets Article 28 of the UK GDPR.
1. Who is responsible for what
- The club is the controller of the information it puts into Whole Team about its members, their
children and its events: who is in the club, teams, availability, selections, payments it asks for, its coach register, its messages and its website.
- We are the processor of that information. We use it only to run Whole Team for the club, on the
club's instructions, which are these terms, this agreement and what the club does in the app.
- We are a controller in our own right for some things: people's accounts and sign-in, safety and
security records, preventing misuse, our own legal and tax records, and support. The privacy notice covers those.
2. What the processing is
| Subject matter | Running the Whole Team service for the club |
|---|---|
| Duration | While the club uses Whole Team, then as section 9 says |
| Nature and purpose | Storing, organising, showing, sending and deleting information so the club can run its teams, events, messages, payments and website |
| People | The club's adult members, parents and guardians, coaches and volunteers, players including children, and people who contact the club |
| Information | Names, contact details, dates of birth, team and role, availability and attendance, minutes played, messages, photos the club allows, payment records (not card numbers), coach check references and dates, medical or consent notes a guardian chooses to add |
| Special category | Only health notes a guardian adds for their own child's safety. The club must not use Whole Team to collect any other special category information |
3. The club's part
The club confirms it has a lawful basis for what it asks members for, gives its members any privacy information that is its to give, enters only what the service needs, and gives roles that see children's information only to people it has checked.
4. Our part
We will:
- process the club's information only on its documented instructions, unless the law requires otherwise,
and tell the club if we think an instruction breaks the law;
- make sure everyone who works on Whole Team is bound to keep it confidential;
- keep it secure, as section 5 says;
- help the club answer requests from its members (access, correction, erasure, objection), using the
tools in the app where we can;
- help the club with security, breach reporting and any data protection impact assessment, as far as the
information we hold allows;
- give the club the information it reasonably needs to show we meet this agreement, and allow a
reasonable audit on 30 days' notice, at the club's cost, no more than once a year unless there has been a breach.
5. Security
We take appropriate technical and organisational measures, including: encryption in transit and at rest; encrypted backups; access limited by role inside the app; staff access only when needed, recorded, and for a club's own data only with the club's permission through the support access request; sign-in by one-time code; and regular review. The data protection impact assessment describes these in more detail.
6. Sub-processors
The club agrees that we may use the sub-processors listed at wholeteam.co.uk/privacy/processors. Each is bound by a written contract giving at least the same protection as this agreement. We will tell the club in the app or by email at least 14 days before we add or replace one. The club may object on reasonable data protection grounds. If we can't resolve it, the club may stop using Whole Team and export its data.
7. Where the information is kept
The main database, file storage, email and backups are in the United Kingdom. Where a sub-processor is outside the UK, we rely on UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or the UK International Data Transfer Agreement or Addendum, as the processors list states.
8. Breaches
If we become aware of a personal data breach affecting the club's information, we will tell the club's admins without undue delay and within 48 hours, with what we know, what we are doing, and who to contact. We will keep the club updated and help it decide whether to tell the ICO or its members.
9. When the club leaves
The club can export its information at any time. When it closes its account, we delete or anonymise the club's information in line with the retention policy, except where the law needs us to keep it (for example payment records for six years). Backups roll off within 30 days.
10. Liability and law
Liability under this agreement is as set out in the terms of service. This agreement is governed by the law of Scotland and the courts there. If anything in it conflicts with the terms of service, this agreement wins on data protection.
Contact
privacy@wholeteam.co.uk - Whole Team Ltd, 5 South Charlotte Street, Edinburgh EH2 4AN