Data Processing Agreement
Last updated: February 2026
1. Definitions
For the purposes of this Data Processing Agreement (“DPA”), the following definitions apply:
- “Controller” means the entity that determines the purposes and means of processing personal data (i.e., the customer organisation using AMES).
- “Processor” means AMES Solutions Ltd, which processes personal data on behalf of the Controller.
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Processing” means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
- “Sub-processor” means any third party appointed by the Processor to process personal data on behalf of the Controller.
- “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of personal data.
2. Scope and Purpose
This DPA applies to all personal data processed by AMES Solutions Ltd (“the Processor”) on behalf of the customer organisation (“the Controller”) in connection with the provision of the AMES activity management platform. The Processor shall process personal data only on documented instructions from the Controller and solely for the purpose of delivering the agreed services, including member management, scheduling, communications, and payment processing.
3. Data Processing Details
The following details apply to the processing carried out under this DPA:
Types of Personal Data
- Contact information (names, email addresses, phone numbers, postal addresses)
- Dates of birth and age-related information
- Medical and health information relevant to activities
- Payment and billing information (processed via PCI-compliant third parties)
- Attendance records, booking history, and enrolment data
- Communications content (emails and messages sent through the platform)
Categories of Data Subjects
- Members and participants of activity programmes
- Parents, guardians, and emergency contacts of participants
- Staff, instructors, and administrators
Purpose of Processing
To provide the AMES platform services, including but not limited to: member registration and management, class scheduling and booking, payment processing and invoicing, automated and manual communications, reporting and analytics, and compliance record-keeping.
4. Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller, unless required by law.
- Ensure that persons authorised to process personal data have committed themselves to confidentiality.
- Implement appropriate technical and organisational security measures, including encryption at rest and in transit, access controls, regular security testing, and incident response procedures.
- Not engage a sub-processor without prior written authorisation from the Controller. A current list of sub-processors is available on request.
- Assist the Controller in ensuring compliance with obligations under Articles 32 to 36 of the UK GDPR, taking into account the nature of processing and the information available to the Processor.
- At the choice of the Controller, delete or return all personal data upon termination of the service, and delete existing copies unless storage is required by applicable law.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by the Controller or an appointed auditor.
5. Data Subject Rights
The Processor shall assist the Controller in responding to requests from data subjects exercising their rights under the UK GDPR, including the right of access, rectification, erasure, restriction of processing, data portability, and the right to object. The Processor shall promptly notify the Controller of any data subject request received directly and shall not respond to such requests without the Controller's prior written instructions, unless required by law.
6. Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach. The notification shall include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences of the breach, and the measures taken or proposed to address the breach and mitigate its effects.
7. International Transfers
Personal data processed under this DPA is stored and processed within the United Kingdom and European Union by default. The Processor shall not transfer personal data to a country outside the UK or EU without the prior written consent of the Controller and without ensuring that appropriate safeguards are in place, in accordance with Chapter V of the UK GDPR. Where sub-processors are located outside the UK/EU, the Processor shall ensure appropriate transfer mechanisms are in place (such as Standard Contractual Clauses or adequacy decisions).
8. Term and Termination
This DPA shall remain in effect for the duration of the Controller's use of the AMES platform. Upon termination or expiry of the service agreement:
- The Processor shall, at the Controller's election, return or delete all personal data within 30 days.
- The Controller may request a data export in a commonly used, machine-readable format prior to deletion.
- The Processor may retain personal data only where required by applicable law, and shall inform the Controller of any such requirement.
9. Contact
For questions about this Data Processing Agreement, please contact our Data Protection Officer at privacy@amessolutions.io.
