Skip to content

The provider's identification details (marked [PLACEHOLDER]) are still to be completed. The rest of the text is in force.

Data processing agreement

Last updated: 8 October 2026

Contents

1. Parties and purpose

This data processing agreement ("the agreement") forms part of the SmashBook Terms and conditions. It is entered into by the club that accepts those terms ("the club"), as controller, and [PLACEHOLDER: nombre y apellidos del titular] (tax ID [PLACEHOLDER: NIF], [PLACEHOLDER: domicilio completo]), owner of SmashBook ("SmashBook"), as processor, under Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

It covers the personal data of the club's customers, members, students and other data subjects that SmashBook processes on behalf of the club when providing the service. It does not cover the data of dashboard users or the club's billing data, which SmashBook processes as controller under the Privacy policy.

2. Duration

The agreement lasts as long as the club's SmashBook subscription. When it ends, the section "End of processing: return and deletion" applies.

3. Nature and purpose of the processing

SmashBook processes the data only to provide the contracted service:

  • hosting and managing customer, member and student records;
  • managing bookings, classes, fees and payments (payments through the club's Stripe account);
  • sending and receiving the club's WhatsApp messages and transactional emails;
  • replying to customers with the artificial intelligence assistant, according to the club's settings;
  • automatic transcription of customers' voice notes, so the assistant can understand them (the audio is not kept; only the text, like any other message);
  • providing technical support and maintaining the security, backups and logs needed to run the service.

Operations: collection, recording, storage, consultation, alteration, disclosure to the listed sub-processors, export and erasure.

4. Data and data subjects

Data subjects: the club's customers, members, students and players, and people who write to its WhatsApp.

Data: identification and contact data (name, phone, email); bookings, classes and fees; payments (amount and status; card data is processed by Stripe); preferences (sport, level, interests); communication permissions (date, channel and text version); and WhatsApp conversation content.

The service is not intended for special categories of data (Art. 9 GDPR): the club must not enter them in notes, conversations or the assistant's knowledge base. If the club processes minors' data, it is responsible for obtaining their parents' or guardians' consent where required.

5. SmashBook's obligations

As processor, SmashBook undertakes to:

  • process the data only on the club's documented instructions: the terms, this agreement and the settings the club makes in the dashboard, unless required to process them by Union or Member State law; in that case, SmashBook will inform the club of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. If SmashBook considers an instruction infringes data protection law, it will immediately inform the club;
  • not use the data for its own purposes or disclose it to third parties, except to authorised sub-processors or where required by law;
  • ensure that persons authorised to process the data have committed to confidentiality;
  • apply the measures in the "Security" section (Art. 32 GDPR);
  • help the club respond to data subject requests and meet its obligations on security, breach notification, impact assessments and prior consultation (Arts. 32 to 36 GDPR), taking into account the nature of the processing and the information available to it;
  • make available to the club the information needed to demonstrate compliance with this agreement and allow audits (section "Information and audits");
  • keep a record of processing activities as processor (Art. 30(2) GDPR).

6. The club's obligations

As controller, the club undertakes to:

  • have a legal basis for each processing activity and inform its customers (with the club privacy page generated by SmashBook or its own policy);
  • have its customers' permission for the WhatsApp messages that require it;
  • give lawful instructions and keep its controller details up to date in the dashboard;
  • manage its staff's access to the dashboard.

7. Sub-processors

The club authorises SmashBook to engage these sub-processors:

  • Supabase, Inc.: database, authentication and storage. Servers in the European Union (Frankfurt, Germany).
  • Vercel Inc.: hosting of the website, dashboard and server functions, network and AI Gateway. Global infrastructure.
  • OpenAI OpCo, LLC and Google LLC, via Vercel AI Gateway (sub-processors of Vercel Inc.): AI models and audio transcription. They may process data in the United States.
  • Anthropic, PBC, via Vercel AI Gateway (sub-processor of Vercel Inc.): language models for the assistant. It may process data in the United States. The service only allows the Gateway to route to these three AI providers (not to others, such as Amazon Bedrock, Google Vertex AI or Microsoft Azure).
  • Plus Five Five, Inc. (Resend): transactional email (notices to the club and, if the club enables it, to its customers). United States.
  • Meta Platforms Ireland Ltd.: WhatsApp Business Platform, to send and receive the club's WhatsApp messages. European Union and United States.
  • Stripe Payments Europe, Limited: customer payments through the club's Stripe account. For payment data, Stripe also acts as an independent controller. European Union and United States.

SmashBook imposes on each sub-processor data protection obligations equivalent to those in this agreement and remains liable to the club for their compliance.

SmashBook will notify the club by email of any new or replacement sub-processor at least 15 days in advance. The club may object on reasonable data protection grounds and, if no solution is found, terminate the agreement without penalty before the change takes effect.

8. International transfers

The main database is in the European Union. Some sub-processors may process data outside the European Economic Area, mainly in the United States. Those transfers rely on the EU-US Data Privacy Framework where the provider is certified and, in any case, on the European Commission's standard contractual clauses, with any supplementary measures required.

9. Security

SmashBook applies technical and organisational measures appropriate to the risk, including:

  • encrypted communications (HTTPS/TLS) and encryption at rest of the database by the hosting provider;
  • separation of each club's data with row-level security policies in the database;
  • dashboard access with username and password and role-based permissions (owner, admin, staff);
  • third-party credentials (such as WhatsApp tokens) stored encrypted;
  • backups by the database provider;
  • activity log of relevant changes;
  • SmashBook staff access limited to what is needed for support and maintenance.

10. Personal data breaches

SmashBook will notify the club by email, without undue delay and in any event within 48 hours of becoming aware of it, of any breach of the security of personal data processed on behalf of the club, with the information available at that time (nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences and measures taken or proposed), and will supplement it as further information becomes available, so that the club can notify the supervisory authority within the 72-hour period of Article 33 GDPR where required.

Notifying the supervisory authority and, where applicable, the data subjects is the responsibility of the club as controller.

11. Data subject rights

The dashboard lets the club export and erase a customer's data, and customers can request it via WhatsApp. If a data subject contacts SmashBook directly, SmashBook will forward the request to the club without delay and will not respond to it itself unless instructed by the club.

12. End of processing: return and deletion

Before the end, the club can export its data from the dashboard. When the agreement ends, SmashBook will delete the personal data processed on behalf of the club within 90 days at most, unless a law requires it to be kept (in which case it will keep it blocked only for that period). The database provider's backups are overwritten in their rotation cycle, at most 7 days later, and until then are used only to restore the service.

At the club's request, SmashBook will confirm the deletion in writing.

13. Information and audits

SmashBook will provide the club, on reasonable written request to info@smashbookapp.com, with the information needed to demonstrate compliance with this agreement. Audits or inspections will be agreed with reasonable notice, at the club's expense, and must not affect the security or confidentiality of other clubs. SmashBook may first offer its providers' documentation or certifications; if these are not sufficient, the club, or an auditor it appoints who is bound by confidentiality, may carry out the audit.

14. Liability and governing law

Liability, changes and governing law are governed by the Terms and conditions. On data protection matters, if there is a conflict, this agreement prevails.

Data processing agreement | SmashBook