Data Processing Agreement
Version 1.0 · Effective date: [date of publication]
Status: Approved by Lia (Legal) for the pilot. To be reviewed by an Ontario lawyer before general commercial launch.
This DPA is part of the Subscription and Service Agreement between the Customer (the club or team) and [Legal entity name], operating as ClarityLedger Sports ("ClarityLedger").
1. Roles
- The Customer controls the personal information of its members, guardians and athletes and decides why it is collected.
- ClarityLedger processes that information only on behalf of the Customer, to provide the service. Under PIPEDA, the Customer remains accountable for information it transfers to ClarityLedger for processing.
2. Scope of processing
| Item | Detail |
|---|---|
| People | club owners, treasurers, coaches, parent representatives, guardians, athletes (minimal data) |
| Data | contact data, roles, minimal athlete data, financial records, receipt images, bank statement lines, messages to the assistant, consent records |
| Out of scope | health, medical, allergy, date of birth, photos of athletes, location, SIN, bank and card numbers |
| Purpose | bookkeeping, reporting, reminders, statements, AI assistant, security, support |
| Duration | the term of the Agreement, plus the retention periods in the Privacy Policy |
3. ClarityLedger commitments
ClarityLedger will:
- process Customer data only on the Customer's documented instructions (the Agreement, the settings chosen in the app and written requests);
- not sell Customer data, not use it for advertising, and not use it to train public AI models;
- make sure staff and contractors with access are bound by confidentiality;
- apply the security measures in section 5;
- use sub-processors only as set out in section 6;
- help the Customer answer access, correction and deletion requests within 30 days;
- notify the Customer without undue delay (target: within 72 hours) after learning of a breach of security safeguards involving Customer data, give the facts known, and help the Customer assess real risk of significant harm and notify people and the Office of the Privacy Commissioner of Canada if needed;
- at the end of the Agreement, let the Customer export its data for 30 days, then delete or anonymize it, except where the law requires us to keep it;
- give the Customer the information reasonably needed to show compliance with this DPA, once a year or after an incident.
4. Customer commitments
The Customer will:
- have a lawful basis and any needed consent to give the data to ClarityLedger;
- tell its families that it uses ClarityLedger for club finances (a sample notice is in the Consent Texts document);
- only add adults to accounts and groups;
- not upload data that is out of scope;
- keep role access current.
5. Security measures
Encryption in transit (TLS); role-based access; row level security in the database, scoped by club; confidential fields restricted to club owner and treasurer; audit log of create, update and delete on finance records; minimum data by design; automated security scans after each release; secrets stored in a secure vault; protection against CSV formula injection in imports and exports.
6. Sub-processors
Current main sub-processors: Lovable Cloud / Supabase (hosting and database), AI model providers through Lovable AI (OCR and assistant), Meta WhatsApp Business Platform (messaging), app email sending service (statements and reminders), Zoho Mail Canada (company email), and a payment processor for club subscriptions when enabled. ClarityLedger will keep a current list on the Privacy page and give 30 days' notice of a new main sub-processor. The Customer may object for a reasonable privacy reason; if we cannot solve it, the Customer may cancel without penalty.
7. Transfers outside Canada
Some sub-processors process data in the United States or other countries. ClarityLedger requires them by contract to give a comparable level of protection. The Customer should tell its families that data may be processed outside Canada (included in the sample notice).
8. Order of priority
If this DPA conflicts with the Agreement on the topic of personal information, this DPA wins.