1. Scope and incorporation
This DPA forms part of an agreement under which BagTag processes personal data for a customer. It applies only to processing covered by privacy law and does not change the independent roles a party has for its own accounts, security, legal duties, employment, payments, external sites, or direct relationships.
2. Definitions and roles
Customer is the league or organization determining the documented purpose; BagTag is the processor, service provider, or contractor for that processing. Personal data, processing, controller, processor, sale, sharing, and similar terms have the meanings in applicable law. Each party is independently responsible where it determines purposes and means.
3. Processing details
- Subject matter: youth-sports recognition, family verification, rewards, optional media, organization workspaces, support, reporting, and security.
- Duration: the service term plus the documented export, deletion, backup, dispute, and legal-retention period.
- People: adult family contacts, youth players, league staff, sponsor and partner staff, applicants, authorized officers, and public visitors.
- Data: identifiers, contact information, team/game/award context, reward and redemption, optional content and permissions, organization/application data, device/network context, and audit/security records.
- Purposes: provide, secure, support, measure, and legally administer the contracted service.
4. Customer instructions
BagTag processes customer personal data only on documented instructions in the agreement, configuration, authorized actions, and lawful support requests, unless law requires otherwise. BagTag will inform the customer if an instruction appears unlawful unless prohibited. The customer will not instruct BagTag to create child accounts, share claim emails with sponsors, use content beyond recorded permissions, or perform unlawful marketing or profiling.
5. Confidentiality and access
BagTag restricts access to personnel and contractors with a need to know, binds them to confidentiality, trains them for their role, and logs sensitive administrative actions where appropriate. Customer applies least privilege to its own members and is responsible for their instructions.
6. Security measures
Measures evolve with risk and technology and will not materially reduce overall protection during the term.
- Encryption of sensitive family fields and transport encryption.
- Keyed blind indexes and hashed bearer tokens.
- Tenant and role authorization, session protection, and rate limiting.
- Audit logging, monitoring, vulnerability and dependency review, backups, and recovery procedures.
- Controlled provider credentials, media moderation states, and private administrative routes.
- Incident response, access removal, and retention jobs.
7. Subprocessors
Customer gives general authorization for the subprocessors listed in the current Subprocessor List. BagTag remains responsible for their processing to the extent required by law and contract, uses appropriate written safeguards, and will provide notice of a material new category or provider where the agreement requires it. Customer may object on reasonable data-protection grounds within the stated notice period.
8. Rights requests
BagTag provides workflows and reasonable assistance for verified access, correction, deletion, media withdrawal, portability, objection, restriction, authorized-agent, appeal, and opt-out requests required by applicable law. Customer remains responsible for instructions and communications for processing it controls. A party receiving a request will route it without unnecessary disclosure.
9. Youth data
Customer directs adult-only flows, supplies required notices, determines whether COPPA or other youth law applies, obtains any required parental authority, minimizes data, and ensures optional content is not required for the reward. BagTag will not use customer youth data for targeted advertising, sale, unrelated profiling, or model training under this DPA.
10. Security incidents
BagTag will notify the customer's designated contact without undue delay after confirming a personal-data breach affecting customer data, provide information reasonably available about nature, scope, likely consequences, containment, and remediation, and cooperate with required notices. Notification is not an admission of fault. Customer promptly reports compromise of its users, devices, links, PINs, exports, or instructions.
11. Return, deletion, and retention
At termination or a valid instruction, BagTag will provide available exports and delete or pseudonymize customer personal data within the documented operational period, except where law, safety, fraud, consent proof, audit integrity, dispute, or enforcement requires retention. Provider copies and backups are removed under their technical schedules. Retained data remains protected and limited to the exception.
12. Assessments and audits
BagTag will make current security and compliance information reasonably available, answer proportionate questionnaires, and support a legally required assessment. An onsite or third-party audit requires reasonable notice, confidentiality, minimal disruption, scope tied to customer data, no exposure of other tenants, and customer payment of extraordinary costs unless a material BagTag breach caused the audit.
13. Transfers and conflict
BagTag will use a lawful transfer mechanism where covered personal data is transferred internationally. Mandatory privacy law controls over inconsistent contract text. Otherwise, the signed services agreement controls commercial issues and this DPA controls covered data-processing issues.