Data Processing Agreement

Between: Compteam (the "Processor") and the branch admin registering a branch (the "Controller")

Last updated: June 2026


This Data Processing Agreement ("DPA") forms part of the Terms of Service between Compteam and the Controller. It governs the processing of personal data by Compteam on behalf of the Controller in accordance with Article 28 of the GDPR.

1. Subject matter and duration

Compteam processes personal data of the Controller's athlete members for the duration of the Controller's active subscription and for any legally required retention period thereafter.

2. Nature and purpose of processing

Compteam processes member data to provide the core gym management functions: athlete profiles, belt promotions, competition records, membership billing, SEPA mandates, training attendance, and related operations as described in the platform's feature set.

Where the Controller has enabled AI features (Blue Belt plan or above), Compteam also processes data to provide:

  • AI Companion chat — branch staff may query athlete and operational data via an AI assistant. Athlete names are pseudonymised server-side before transmission to the AI sub-processor and restored in the response; real names are only transmitted if the staff member explicitly requests a named athlete.
  • Proactive club briefing (Purple Belt plan / ambassador branches) — on first dashboard load per session, an automated summary of the branch's operational state is generated. Only the following data is transmitted to the AI sub-processor: branch operational metadata (name, location, billing/accreditation status), first name and last-name initial of athletes with pending approvals or trials ending within 30 days, and anonymised counts for billing and payroll items. Full last names, contact details, payment data, and all other personal data are not transmitted.

3. Categories of data subjects and data

  • Data subjects: The Controller's athlete members, parents/guardians of minor athletes.
  • Categories of data: Name, date of birth, email address, postal address, phone number, gender, training history, belt and stripe history, competition results, membership status, payment references (IBAN, SEPA mandate IDs), weight records, photos.

4. Obligations of the Processor (Compteam)

Compteam shall:

  • Process personal data only on documented instructions from the Controller
  • Ensure that persons authorised to process the data are bound by confidentiality
  • Implement appropriate technical and organisational security measures (encryption at rest and in transit, access controls, audit logging)
  • Assist the Controller in fulfilling data subject rights requests (access, rectification, erasure, portability) — tools available in the platform's admin interface
  • Delete or return all personal data upon termination of the service, unless retention is required by law
  • Make available all information necessary to demonstrate compliance and allow audits upon reasonable notice

5. Sub-processors

Compteam engages the following sub-processors:

Sub-processorLocationRole
Supabase Inc.EU (Frankfurt, Germany)Database hosting and authentication
Stripe Inc.EU/USPayment processing, SEPA mandate management
ResendUSTransactional and service email delivery
Anthropic / Google / OpenRouterUSAI Companion chat and proactive club briefing, where enabled by the Controller (Blue Belt plan or above). Data minimisation applied: see §2 for detail on what is transmitted.

Compteam will notify the Controller of any intended changes to sub-processors with at least 14 days' notice, giving the Controller the opportunity to object.

6. International transfers

Transfers of personal data to US sub-processors (Stripe, Resend, and — where the AI assistant is enabled — Anthropic, Google, or OpenRouter) are governed by the EU–US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs) where applicable. These safeguards are recognised under LQPD Articles 42–45. No other personal data is transferred outside Andorra/the EEA.

7. Security

Compteam implements industry-standard security measures including:

  • TLS encryption for all data in transit
  • Encryption at rest provided by the hosting infrastructure (Supabase on AWS)
  • Application-level encryption for sensitive payment fields (IBAN)
  • Role-based access controls
  • Consent audit records (append-only log of accepted documents per athlete)

8. Data subject rights

The Controller is responsible for responding to data subjects. Compteam provides tooling to support:

  • Data export (CSV export from the admin interface)
  • Account erasure (admin can erase a member account; personal data is removed, anonymised financial records are retained)

9. Acceptance

This DPA is accepted automatically when a branch admin completes registration on the Compteam platform. A signed copy is available upon written request to info@compteam.io.