Legal

Data Processing Agreement

Contractual terms between Leagzr (processor) and league organizations (controllers) for processing player and league operational personal data.

Last updated: 2026-07-21

Draft for engineering review — counsel must approve before EU/UK launch.

Parties and scope

This Data Processing Agreement ("DPA") forms part of the agreement between Remonter Solutions Inc., operating Leagzr ("Processor"), and the league organization that accepts these Terms ("Controller", "League", or "you"). It applies when Processor processes personal data on behalf of Controller through the Leagzr platform.

By creating a league, subscribing to a paid plan, or otherwise using league management features that store player data, Controller accepts this DPA on behalf of its organization.

Roles

  • Controller determines the purposes and means of processing player registrations, waivers, schedules, communications, and published statistics.
  • Processor provides the hosted platform, stores data at Controller's direction, and implements security measures described herein.
  • Processor remains an independent controller for its own platform account, billing, and security logging data (see Privacy Policy).

Subject matter and duration

Processing continues for the term of Controller's use of the service and until personal data is deleted or returned per Controller instructions and our retention policies, subject to legal retention requirements.

Categories of data and data subjects

  • Data subjects: players, team staff, volunteers, and other participants Controller invites to the league.
  • Categories: identity and contact data, waiver records, registration and payment metadata, game statistics, photos, and other content Controller uploads.

Processor obligations

  1. Process personal data only on documented instructions from Controller, including these Terms, this DPA, and settings within the dashboard.
  2. Ensure personnel authorized to process data are bound by confidentiality.
  3. Implement appropriate technical and organizational measures (see Security).
  4. Assist Controller with data subject requests where feasible, using available platform tools or support channels.
  5. Notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data.
  6. Delete or return Controller personal data upon termination, except where retention is required by law.
  7. Make available information necessary to demonstrate compliance and allow audits as described below.

Subprocessors

Controller authorizes Processor to engage subprocessors listed in the Privacy Policy. Processor will impose data protection terms on subprocessors consistent with this DPA and remain liable for subprocessors' performance.

Security

Processor maintains measures appropriate to risk, including encryption in transit, access controls, tenant isolation, logging, and regular dependency updates. Details are available on request to enterprise customers.

International transfers

Where personal data is transferred outside the EEA/UK, Processor will implement appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

Audits

Upon reasonable written request, Processor will provide information to demonstrate compliance. On-site audits may be conducted no more than once per year with 30 days' notice, subject to confidentiality and security restrictions.

Liability

Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service, except where liability cannot be limited under applicable data protection law.

Contact and signed copies

For questions or a countersigned copy for your records, contact [email protected]. This online version constitutes the operative DPA unless a separate signed agreement is executed between the parties.