Splays Data Processing Agreement (DPA)
Last updated: 26 July 2026
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Splays Terms of Service (the "Agreement") between:
- Splays Digital Ltd, company number 17357759, registered in England & Wales at 4-6 Swaby's Yard, Walkergate, Beverley, East Yorkshire, HU17 9BZ ("Splays", the "Processor"); and
- the club, venue or organisation identified in the Order Form (the "Customer", the "Controller").
It sets out the terms on which Splays processes personal data on behalf of the Customer in connection with the Service. It is designed to satisfy Article 28 of the UK GDPR. Where this DPA conflicts with the rest of the Agreement on data protection matters, this DPA prevails.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR and the Data Protection Act 2018 ("Data Protection Laws"). "UK GDPR" means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland.
For clarity, this DPA governs only the personal data for which the Customer is the controller and Splays is the processor (principally kiosk visitor sign-up data). It does not cover club administrator account data, for which Splays is itself the controller under its Privacy Policy.
2. Roles of the parties
2.1 The Customer is the controller and Splays is the processor in respect of the personal data described in Annex 1 (the "Controller Personal Data").
2.2 The Customer is responsible for ensuring it has a lawful basis (including, where relevant, valid consent) to collect the Controller Personal Data and to instruct Splays to process it, and for providing an appropriate privacy notice to data subjects at the point of collection.
3. Subject-matter and duration of processing
3.1 Subject-matter. Splays' processing of the Controller Personal Data as part of providing the Service.
3.2 Duration. Processing continues for the term of the Agreement, and until the Controller Personal Data is deleted or returned in accordance with clause 11.
4. Nature and purpose of processing
4.1 The nature of the processing is the collection, storage, organisation, retrieval, display and deletion of the Controller Personal Data by automated means, using Splays' hosted platform.
4.2 The purpose of the processing is to enable the Customer to:
- (a) display the Customer's chosen content on its screens; and
- (b) collect optional visitor sign-ups / lead capture at the kiosk (for example, a member or visitor giving a name, email address and marketing consent to join the club's mailing list or obtain WiFi access),
so that the Customer can contact those individuals in accordance with its own privacy notice.
5. Types of personal data and categories of data subject
5.1 Types of personal data and categories of data subject are set out in Annex 1. In summary:
- Types of personal data: member/visitor name, email address and marketing consent flag; and, in the limited context where Splays acts as processor for the Customer, any administrator contact details the Customer supplies to configure the Service.
- Categories of data subject: the Customer's club members, visitors to the clubhouse, and staff.
5.2 No special category data is required by, or should be entered into, the Service. The Customer must not use the Service to process special category data or children's data without a documented agreement with Splays.
6. The Customer's instructions
6.1 Splays will process the Controller Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case Splays will, where lawful, inform the Customer first).
6.2 The Agreement, this DPA, the Order Form and the Customer's use of the Service's features constitute the Customer's complete and documented instructions. Any additional instruction must be agreed in writing.
6.3 Splays will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
7. Processor obligations
Splays will:
7.1 Confidentiality. Ensure that persons authorised to process the Controller Personal Data are bound by confidentiality obligations and process it only as instructed.
7.2 Security. Implement and maintain the technical and organisational measures described in Annex 3, appropriate to the risk, in accordance with Article 32 of the UK GDPR.
7.3 Sub-processors. Engage sub-processors only in accordance with clause 8.
7.4 Assistance with data-subject rights. Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection and withdrawal of consent). Where a data subject contacts Splays directly about Controller Personal Data, Splays will promptly forward the request to the Customer and will not respond substantively itself unless the Customer instructs it to.
7.5 Assistance with compliance. Taking into account the information available to it, assist the Customer in ensuring compliance with its obligations under Articles 32–36 of the UK GDPR, including security of processing, personal data breach notification (clause 9), data protection impact assessments (DPIAs) and prior consultation with the supervisory authority.
7.6 Records. Maintain records of its processing activities carried out on behalf of the Customer, as required by Article 30(2).
7.7 Audits. Make available to the Customer the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections conducted by the Customer or an auditor it mandates. Audits will be on reasonable prior written notice, no more than once per year (save where required by a supervisory authority or following a personal data breach), during business hours, and subject to confidentiality, so as not to disrupt Splays' operations or the security of other customers' data.
7.8 Deletion or return. Delete or return the Controller Personal Data on termination in accordance with clause 11.
8. Sub-processors
8.1 The Customer provides general written authorisation for Splays to engage the sub-processors listed in Annex 2 to process the Controller Personal Data.
8.2 Splays will impose on each sub-processor, by written contract, the same data protection obligations as set out in this DPA (in particular sufficient guarantees to implement appropriate Article 32 measures) — a "flow-down" of terms. Splays remains fully liable to the Customer for the performance of each sub-processor's obligations.
8.3 Splays will give the Customer prior notice of any intended addition or replacement of a sub-processor, giving the Customer a reasonable opportunity to object on reasonable data protection grounds. If the parties cannot resolve a reasonable objection, the Customer may terminate the affected part of the Service.
9. Personal data breach notification
9.1 Splays will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Controller Personal Data, targeting notification within 48–72 hours of becoming aware.
9.2 The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Splays will provide further information in phases as it becomes available.
9.3 Splays will reasonably assist the Customer in meeting the Customer's own obligations to notify the supervisory authority (the ICO) and affected data subjects where required. The Customer, as controller, is responsible for any such regulatory or data-subject notification.
10. International transfers
10.1 UK hosting. The Controller Personal Data — the application, its database and uploaded media — is hosted and processed in the United Kingdom on Microsoft Azure (UK South and UK West regions).
10.2 Permitted processing in the EEA. The Customer instructs and authorises Splays to process limited Controller Personal Data in the European Economic Area solely for the sub-processors and purposes identified as such in Annex 2 — currently the sending of service emails (for example secure sign-in links) via Microsoft Azure Communication Services. The EEA benefits from UK adequacy regulations made under the Data Protection Act 2018, so no additional transfer mechanism is required for such transfers.
10.3 Splays will not transfer the Controller Personal Data outside the United Kingdom or the EEA without the Customer's prior documented instruction.
10.4 If a transfer outside the UK and the EEA ever becomes necessary, Splays will ensure an appropriate transfer mechanism is in place (for example the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses) before the transfer takes place, and will inform the Customer.
10.5 For completeness, the services listed in Annex 2 as involving no personal data (for example map imagery and weather data, which are requested by geographic coordinates only) do not constitute transfers of Controller Personal Data.
11. Deletion or return of data
11.1 On expiry or termination of the Agreement, Splays will, at the Customer's choice, delete or return all Controller Personal Data, and delete existing copies, unless UK law requires continued storage.
11.2 The Customer may export the Controller Personal Data through the Service, or request its return, within 30 days of termination. After that period, and subject to clause 11.1, Splays will delete the Controller Personal Data from active systems, with residual copies in backups purged on the ordinary backup-rotation cycle.
11.3 Member sign-up data is retained per the Customer's instruction while the Agreement is in force, and is exported or deleted on request and on the Customer's exit.
12. Liability
The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
13. Governing law
This DPA is governed by the laws of England & Wales, and the parties submit to the exclusive jurisdiction of the courts of England & Wales.
Annex 1 — Details of processing
| Item | Detail |
|---|---|
| Subject-matter | Processing of Controller Personal Data as part of providing the Splays interactive-screen and kiosk service. |
| Duration | For the term of the Agreement, plus the deletion/return period in clause 11. |
| Nature of processing | Collection, storage, organisation, retrieval, display and deletion by automated means on Splays' hosted platform. |
| Purpose | Displaying the Customer's content on screens, and collecting optional visitor sign-ups / lead capture at the kiosk. |
| Types of personal data | Member / visitor name; email address; marketing consent flag. Where applicable, club administrator contact details supplied by the Customer to configure the Service. No special category data. |
| Categories of data subject | Club members; visitors to the clubhouse; staff. |
| Frequency | Continuous, for the duration of the Agreement. |
Annex 2 — Authorised sub-processors
| Sub-processor | Service provided | Location of processing | Personal data involved |
|---|---|---|---|
| Microsoft Azure (Microsoft Corporation / Microsoft Ltd) | Application hosting (App Service), database (Azure Database for PostgreSQL), media storage (Azure Storage) and authentication (Microsoft Entra ID) | United Kingdom — UK South and UK West | Yes — all Controller Personal Data is stored and processed here, with UK data residency |
| Microsoft Azure Communication Services (Microsoft Corporation / Microsoft Ltd) | Sending service emails on the Customer's behalf — for example secure sign-in links issued to administrators | European Union (ACS data location: Europe) | Yes — limited to the recipient's name and email address, and the content of the message. Covered by UK adequacy; see clause 10.2 |
| Microsoft Azure Maps (Microsoft Corporation / Microsoft Ltd) | Aerial imagery for the golf course guide, requested by geographic coordinates through a server-side proxy | Ireland (North Europe) | No personal data — only map coordinates are sent. The kiosk does not contact the service directly |
| Google LLC (Google Fonts) | Serving the brand typeface on the splays.co.uk marketing website | United States | No Controller Personal Data. A website visitor's IP address is visible to Google as part of the font request. Not used on the kiosk or in the admin area's data paths |
| Open-Meteo | Weather forecast data displayed on screens, requested by geographic coordinates | European Union | No personal data — only coordinates are sent; no data subject information is transferred |
| Payment processor — e.g. Stripe (future — not yet engaged) | Card payment processing, when card billing is introduced | To be confirmed at the time of engagement | (Future) billing/contact details of the Customer's account. Will be added here with prior notice under clause 8.3 before any personal data is shared |
Splays will keep this list current and give prior notice of changes in accordance with clause 8.3.
Annex 3 — Technical and organisational security measures (Article 32)
Splays maintains the following measures, appropriate to the risk. These reflect controls currently in place on the live platform:
- Access control — administrator sign-in via Microsoft (Entra) single sign-on. Admin APIs reject anonymous callers (return 401). Any non-production development login is not registered in production.
- Tenant isolation. Each club's data is scoped by
club_idand logically separated, verified by a dedicated isolation test suite. - Encryption in transit. All traffic is protected using HTTPS/TLS. HTTPS is enforced on all hosts, and the marketing site sends HSTS.
- Security headers and CSRF protection.
nosniff, a strict referrer policy (strict-origin-when-cross-origin), a restrictive Permissions-Policy (camera, microphone, geolocation, payment and USB denied), clickjacking protection viaframe-ancestors, removal of theX-Powered-Byheader, a staged Content-Security-Policy, and a same-origin CSRF guard on cookie-authenticated writes. - Secure session cookies. Session cookies are set
httpOnlyandsecurein production. - Input validation and resilience. All content writes are validated at the boundary (invalid input is rejected), with an async error wrapper and process backstops so the platform survives bad requests.
- Rate limiting. Applied to public endpoints (member sign-up, device pairing, heartbeat) to reduce abuse.
- Secrets management. No secrets are exposed in the browser bundle; all secrets are held server-side.
- UK-hosted infrastructure. Application, database and media storage run in UK Azure regions (UK South / UK West), with backups and point-in-time restore provided by the Azure managed PostgreSQL service. Supporting services processing outside the UK are limited to those identified in Annex 2.
- Minified builds. No source maps are published; the client bundle is minified with no readable source served.
These measures are reviewed and updated as the Service develops; Splays may substitute equivalent or stronger measures over time.
Signatures
Signed for and on behalf of the parties as part of the Agreement / Order Form.
| Processor | Controller | |
|---|---|---|
| Organisation | Splays Digital Ltd | [CUSTOMER / CLUB NAME] |
| Name | ||
| Position | ||
| Date |