Skip to main content
Draft for legal review. This page is a working draft prepared before launch and is being reviewed by a data-protection adviser (open question Q8). It is not yet the final text.

Data processing agreement

This agreement applies when CheerDeck processes personal data on behalf of an event producer or a club (the "customer"). It is accepted when a workspace or club is created, and each acceptance is recorded with who accepted it, when and which version.

Version 2026-09 · Parties: CheerDeck (processor) and the producer or club named in the acceptance record (controller).

1. Subject matter, duration, nature and purpose

  • Subject matter: providing the CheerDeck competition platform.
  • Duration: for as long as the customer uses CheerDeck, and until deletion or return under section 10.
  • Nature and purpose: storing, organising, displaying and transmitting data so the customer can run registration, payments, scheduling, judging, results, communications and event-day operations.

2. Types of personal data and data subjects

  • Clubs: athletes (names, dates of birth, sex, team membership, consents and waivers, and medical notes only with explicit consent), guardians and emergency contacts, club staff (names, contact details, safeguarding checks).
  • Producers: entry rosters received from clubs, coaches on entries, judges and event staff, scores and comments, event-day incidents and safeguarding records, ticket buyers, people who register interest.
  • Special category data (health) and children’s data are included and receive the protections in section 5.

3. Instructions

CheerDeck processes customer personal data only on the customer’s documented instructions — this agreement, the terms of service and the customer’s use of the product’s settings — unless UK law requires otherwise, in which case CheerDeck tells the customer first unless the law forbids it. CheerDeck will tell the customer if it believes an instruction breaks data protection law.

4. Confidentiality

Everyone at CheerDeck who can access customer personal data is bound by confidentiality. CheerDeck’s support access to a producer workspace requires two-step verification and a recorded reason, lasts 60 minutes, is audited, and never includes medical records, safeguarding records or athlete master records.

5. Security (Article 32)

  • Tenant isolation enforced by row-level security on every table, tested automatically.
  • All writes through permission-checked functions; secret keys held only on CheerDeck’s servers.
  • Medical notes: separate storage, access limited to the event medic during the event days, every view logged, automatic deletion afterwards.
  • Encryption in transit; encrypted backups kept for 30 days; a monthly automated restore drill.
  • An append-only audit log of changes, releases, payments, role changes and support access.

6. Sub-processors

The customer authorises the sub-processors on the sub-processor list. CheerDeck gives at least 14 days’ notice of any addition or replacement; the customer may object on reasonable data-protection grounds, and if the objection cannot be resolved may end the service. CheerDeck imposes data-protection terms on each sub-processor no less protective than these and remains responsible for them.

7. International transfers

Customer data is stored in the UK. Where a sub-processor may access it from outside the UK, the transfer relies on UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework, or the UK International Data Transfer Addendum, as listed per sub-processor.

8. Assisting the customer

CheerDeck helps the customer respond to data subjects’ requests (the product includes athlete export and erasure, account export and deletion, and a request log with a 30-day clock), and with security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing.

9. Personal data breaches

CheerDeck notifies the customer without undue delay after becoming aware of a personal data breach affecting customer data, with the information the customer needs to meet its own 72-hour duty to report to the ICO where required.

10. Deletion or return

When the service ends, CheerDeck returns customer personal data in a machine-readable export on request and deletes it within 90 days, except where UK law requires it to be kept (for example financial records for 6 years). Backups expire within 30 days.

11. Audits

CheerDeck makes available the information needed to show compliance with this agreement — including its security review record and DPIA — and allows for and contributes to audits by the customer or an auditor it appoints, on reasonable notice and subject to confidentiality.

12. Retention

Retention periods run as automatic jobs set out in the privacy notice; the customer may shorten some of them in its settings (for example medical copies after 7–30 days).

Last updated 26 September 2026.