Draft — not in force
This text has not been reviewed by a lawyer and is published so the sign-up experience can be tested. It does not bind anyone, and it will be replaced before LeagueBinder is offered to leagues outside our own. Version 2026-08-08.draft.2.
Still to be settled: date, error monitoring vendor, hosting / database vendor, legal entity name, payment processor, subprocessor url, transactional email vendor.
Data Processing Addendum
LeagueBinder Data Processing Addendum
DRAFT — NOT REVIEWED BY COUNSEL. NOT FOR PUBLICATION.
Version: 0.1 (draft) Effective Date: [DATE]
This is the structurally most important document in the set. It establishes that the league — not LeagueBinder — is the owner of the personal information in the Service and therefore carries the primary duty to notify individuals and regulators in the event of a breach.
This Data Processing Addendum ("DPA") supplements the LeagueBinder Terms of Service (the "Agreement") between [LEGAL ENTITY NAME] ("Provider") and the customer organization ("Customer"). Capitalized terms not defined here have the meanings given in the Agreement. If this DPA conflicts with the Agreement, this DPA controls as to the subject matter here.
1. Definitions
"Personal Information" means information that identifies, relates to, describes, or could reasonably be linked with a particular individual or household, as defined under Applicable Data Protection Law.
"Applicable Data Protection Law" means United States federal and state laws governing privacy, data protection, and data security that apply to the processing of Personal Information under the Agreement, including state breach notification statutes and state comprehensive privacy statutes to the extent applicable.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Information in Provider's possession or control. It does not include unsuccessful attempts, pings, port scans, or similar events that do not compromise Customer Personal Information.
"Subprocessor" means a third party engaged by Provider to process Customer Personal Information.
"Customer Personal Information" means Personal Information contained in Customer Data.
2. Roles of the Parties
2.1 Allocation. As between the parties, Customer is the business, controller, and owner of Customer Personal Information, and Provider is the service provider and processor, acting only on Customer's documented instructions.
2.2 Customer's responsibilities. Customer determines the purposes and means of processing. Customer is responsible for: the lawfulness of its collection and use of Customer Personal Information; providing all required notices to, and obtaining all required consents from, individuals — including parents and legal guardians of minors; responding to individual rights requests; and determining its own retention obligations.
2.3 Provider's undertakings. Provider will process Customer Personal Information only: (a) to provide, maintain, secure, and support the Service; (b) on Customer's documented instructions, including through use of the Service's features; and (c) as required by law, in which case Provider will notify Customer first unless legally prohibited.
2.4 Restrictions. Provider will not: sell Customer Personal Information; share it for cross-context behavioral advertising; retain, use, or disclose it for any purpose other than performing the Service; retain, use, or disclose it outside the direct business relationship between the parties; use it to train machine learning or artificial intelligence models; or combine it with information received from other sources, except as necessary to perform a business purpose permitted by Applicable Data Protection Law.
2.5 Certification. Provider certifies that it understands and will comply with the restrictions in §2.4.
2.6 Notice of inability to comply. Provider will notify Customer promptly if it determines it can no longer meet its obligations under Applicable Data Protection Law.
3. Details of Processing
The subject matter, nature, purpose, duration, categories of data, and categories of individuals are set out in Annex I.
4. Confidentiality and Personnel
Provider will ensure that personnel and contractors authorized to process Customer Personal Information are bound by written confidentiality obligations, receive access on a least-privilege basis, and have access revoked promptly when no longer required.
5. Security Measures
5.1 Provider will implement and maintain the technical and organizational measures described in Annex II, designed to protect Customer Personal Information against Security Incidents.
5.2 Provider maintains a written information security program.
5.3 Provider may update its security measures, provided it does not materially reduce the overall level of protection during the subscription term.
5.4 Customer's role. Customer is responsible for configuring the Service appropriately, managing user access, enabling multi-factor authentication where available, promptly removing departing users, and refraining from uploading the categories of data restricted under the Agreement.
6. Security Incidents
6.1 Provider's obligation — notify Customer. Provider will notify Customer of a Security Incident without undue delay and in any event within forty-eight (48) hours of confirming it. Notice will be given to the administrative contacts on the account.
6.2 Contents. Notice will include, to the extent known and as it becomes known: the nature of the incident, the categories and approximate volume of information involved, the likely consequences, measures taken or proposed, and a contact for further information. Provider will provide updates as the investigation progresses.
6.3 Assistance. Provider will provide reasonable cooperation and information to assist Customer in investigating, mitigating, and responding to the incident, including producing access and audit logs for a specified period.
6.4 Customer's obligation — notify individuals and regulators. Customer is responsible for determining whether notification to affected individuals, state attorneys general, consumer reporting agencies, or other authorities is required, and for making all such notifications. As the owner of the information, Customer is best positioned to identify affected individuals and to determine the requirements of the states in which they reside. Provider will not notify Customer's individuals or regulators on Customer's behalf without Customer's written request.
6.5 Coordination. Neither party will make a public statement identifying the other in connection with a Security Incident without prior consultation, except where required by law.
6.6 No admission. Notification under this section is not an acknowledgment of fault or liability.
[DRAFTING NOTE — SEE COVER MEMO §3(F): counsel to confirm this allocation holds across the breach statutes of the states where customers are likely located.]
7. Subprocessors
7.1 Authorization. Customer generally authorizes Provider to engage Subprocessors. The current list is at [SUBPROCESSOR URL] and in Annex III.
7.2 Obligations. Provider will impose on each Subprocessor data protection obligations substantially as protective as those in this DPA, and remains responsible for each Subprocessor's performance.
7.3 Changes. Provider will give at least [thirty (30)] days' notice before adding or replacing a Subprocessor, by email to account administrators or by a subscribable update to the Subprocessor page.
7.4 Objection. Customer may object on reasonable data protection grounds within the notice period. The parties will discuss in good faith. If no resolution is reached, Customer may terminate the affected Service on written notice and receive a pro-rata refund of prepaid, unused fees.
8. Individual Rights Requests
8.1 The Service provides functionality allowing Customer to access, export, correct, and delete Customer Personal Information.
8.2 If Provider receives a request from an individual concerning Customer Personal Information, Provider will not respond substantively, and will promptly refer the individual to Customer and inform Customer of the request.
8.3 Provider will provide reasonable assistance to Customer in responding, taking into account the nature of the processing and the information available to Provider.
9. Audit and Assurance
9.1 On reasonable written request, not more than once per twelve (12) months, Provider will make available information reasonably necessary to demonstrate compliance with this DPA, including a completed security questionnaire and a description of its security measures.
9.2 Given the scale of Provider's operations, Customer's audit right is satisfied by the documentation described in §9.1. On-site audits are not provided. [DRAFTING NOTE: some institutional customers will push back. Counsel to advise on a fallback — e.g. an annual third-party assessment once revenue supports one.]
10. Deletion and Return
10.1 During the subscription term and for 30 days after termination, Customer may export Customer Personal Information using the Service's export functionality.
10.2 After that period, Provider will delete Customer Personal Information from active systems within [thirty (30)] days.
10.2A Expired free trials. Where a free trial ends without a subscription, the account is suspended and Customer Personal Information is retained in suspended status for one hundred eighty (90) days to permit reactivation. Customer's administrators may sign in to a limited, export-only mode during that period to download their data. Suspended data remains subject to all security measures in Annex II and is not accessed by Provider except for security, backup, or support purposes. At the end of the 90-day period, Provider will permanently delete it. [DRAFTING NOTE: 180 days of retention without an active commercial relationship is a deliberate business decision reflecting the seasonal decision cycle of volunteer boards. Counsel should be aware that it enlarges the data held at any given time.]
10.3 Copies residing in encrypted backups are deleted on the ordinary backup rotation cycle, within 90 days of termination. Until deleted, backup copies remain protected by the measures in Annex II and are not accessed except for disaster recovery.
10.4 Provider may retain Customer Personal Information where required by law, and will continue to protect it for as long as retained.
10.5 On written request, Provider will confirm deletion.
11. Limitation of Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.
12. Term
This DPA takes effect when Customer accepts the Agreement and continues until Provider ceases processing Customer Personal Information.
Annex I — Details of Processing
Subject matter. Provision of the LeagueBinder back-office platform for youth sports organization boards.
Duration. The subscription term, plus the retention and deletion periods in §10.
Nature and purpose. Hosting, storage, organization, retrieval, transmission, backup, security monitoring, and deletion of Customer Data, and provision of support.
Categories of individuals.
- Board members, officers, and volunteer administrators (Authorized Users)
- Coaches, team managers, and other volunteers
- Parents and legal guardians
- Players, including minors
Categories of Personal Information.
For Authorized Users, coaches, volunteers, and parents (adults):
- Identifiers: name, email address, postal address, telephone number
- Organizational role, term of service, team affiliation
- Account credentials and authentication metadata (Authorized Users only)
- Volunteer screening status and dates only (pass / fail / pending, completion date, expiry
date) — not reports or underlying documentation
For players who are minors — this is the complete list:
- First name
- Last name
- Year of birth (four digits; not a full date of birth)
No other Personal Information about minors is collected or stored. The Service does not collect or store a minor's full date of birth. It does not collect from or about minors: email addresses, telephone numbers, postal addresses, photographs, images, health or medical information, allergy or dietary information, emergency contact details, geolocation, or any government or financial identifier.
Other:
- Content of documents, meeting minutes, correspondence, and records uploaded by Customer
- Usage and audit log data
Categories expressly excluded by the Agreement. Social Security numbers; driver's license or other government identification numbers; financial account or payment card numbers; protected health information subject to HIPAA; background check reports and underlying screening documentation.
Sensitive information. Customer Personal Information includes information about minors. Customer is responsible for the lawful basis for its collection and for parental notice and consent where required.
Frequency. Continuous, for the duration of the subscription.
Location of processing. United States.
Annex II — Technical and Organizational Security Measures
Access control
- Role-based access controls within the Service; least-privilege by default
- Multi-factor authentication available to all users and enforceable for administrative roles
- Unique credentials per user; no shared accounts
- Prompt revocation of access on role change or departure
- Provider personnel access to production limited to named individuals, logged, and used only for
operational necessity
Tenant isolation
- Each Customer's data logically separated, enforced at the database layer through row-level
security
- Automated tests verifying that cross-tenant access fails
Encryption
- TLS for all data in transit
- Encryption at rest for databases, object storage, and backups
Logging and monitoring
- Append-only audit log capturing authentication events, permission changes, document access and
download, exports, deletions, and administrative actions
- Audit records not modifiable by Customer administrators through the application
- Alerting on anomalous activity including bulk export, unusual download volume, repeated failed
authentication, and new administrative grants
- Ability to produce a per-Customer access report for a specified date range
Resilience
- Automated encrypted backups
- Periodic automated restore testing with alerting on failure
- Documented recovery procedures
Secure development and operations
- Secrets held in a managed secrets store, not in source control
- Automated dependency and vulnerability scanning
- Production data not used in development, testing, seed data, or on personal devices
- Changes reviewed before deployment
Governance
- Written information security program
- Written incident response plan
- Written data inventory identifying where Personal Information is held
- Confidentiality obligations for all personnel and contractors
- Data minimization enforced contractually and, where feasible, in-product
[DRAFTING NOTE: every item here is a commitment. Remove anything not actually implemented before publication — an unmet security representation is worse than a modest one.]
Annex III — Subprocessors
Current as of [DATE]. Published and maintained at [SUBPROCESSOR URL].
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
[HOSTING / DATABASE VENDOR] | Application hosting, database, object storage | All Customer Data | United States |
[TRANSACTIONAL EMAIL VENDOR] | Account, notification, and support email | Names, email addresses, message content | United States |
[PAYMENT PROCESSOR] | Subscription billing | Billing contact and transaction data; no Customer Data | United States |
[ERROR MONITORING VENDOR] | Application error and performance monitoring | Technical metadata; configured to exclude Customer Data | United States |
[DRAFTING NOTE: keep this current. A stale subprocessor list is a common finding in due diligence and undercuts every other representation in this document.]