Data Processing Agreement (DPA) — annex to the Terms of Sale
Version françaiseLast updated: 14 September 2026
Draft for review by a lawyer — not contractually binding while this banner is displayed; bracketed items [TO CONFIRM: …] and [TO BE SET: …] remain to be settled.
This Data Processing Agreement (“DPA”) is an annex to the GolfSpec Terms of Sale, entered into between the subscribing shop (the “Shop”) and GolfSpec [TO CONFIRM: company name, legal form, registration number, registered office] (“GolfSpec”) under Article 28 GDPR. It describes only the processing, measures and features in place on 14 September 2026, the date of the technical inventory it is based on.
1. Subject matter and duration
The DPA forms an integral part of the Terms of Sale and prevails over them on data-protection matters. It applies during the subscription, trial included, and then until the purge: after termination or an account-deletion request, the data remain accessible for 30 days before automatic deletion (section 12); encrypted backups then expire within 90 days at most.
2. Roles of the parties
- The Shop is the controller for the data of its end customers, its staff and its supplier contacts: it determines the purposes, ensures lawfulness, informs data subjects and collects any required consent.
- GolfSpec is the processor: it processes these data solely to provide the Service, on the Shop’s documented instructions, with no use for its own purposes.
- GolfSpec is the controller for its contractual relationship with the Shop (account, billing via Stripe, support, alerts, error logging): see the privacy policy. [TO CONFIRM with the lawyer: qualification for the Shop’s staff accounts.]
3. Annex 1 — Description of the processing
Purposes, on the Shop’s instructions: fitting; workshop; after-sales with suppliers; online booking; customer messaging (portal); deposits, pre-authorisations and payments via Stripe Connect; AI assistance (analysis, summary, assistant, drafts); automatic reminders; accounting export.
Data subjects: the Shop’s end customers (including prospects booking online and walk-in workshop customers); the Shop’s staff; suppliers’ sales contacts (after-sales).
Categories of data:
- Identity and contact details: surname, first name, e-mail, telephone, home club, external CRM identifiers, free-text notes by the Shop; no date of birth or postal address.
- Playing data: handicap index, handedness, frequency, skill level, swing speeds, goals, current bag.
- Body measurements: height, wrist-to-floor distance, arm length.
- Fitting interview, including declared physical constraints and free-text comments, which may contain health data (Article 9 GDPR): the Shop warrants a valid legal basis, in practice the data subject’s explicit consent, and enters only what is strictly necessary. [TO CONFIRM with the lawyer: wording of the consent and warning in the interface.]
- Launch-monitor data, shot by shot (up to 100 shots per club tested); imported TrackMan reports; recommendations and quotes (specifications, fitter’s notes, prices, order status).
- Workshop: description, internal notes, measurements, before/after and step photos, timing, technician, immutable log. After-sales: product, warranty, proof of purchase, photos, exchanges with the supplier.
- Handwritten signatures (fitting and workshop), stored as images in the database.
- Messaging: messages, attachments, templates, AI drafts. Bookings: type, date, fitter, contact details entered, booking token.
- Payments: amount, method, reference (cheque, transfer, Stripe identifier), invoices; date and IP of acceptance of the Shop’s terms during an online payment; no card data.
- Satisfaction: rating, verbatim comments, click-through to the Google review. Notifications: staff push tokens (browser, iOS), the customer’s e-mail for the portal. E-mail log: recipient, subject, delivery status, with no tracking pixel or click tracking.
Duration: the subscription, then 30 days before purge (section 12).
4. Documented instructions
The Shop’s instructions are the Terms of Sale, this DPA and its settings in the interface (AI drafts and instructions, connected CRM, TrackMan import, reminders, online booking, roles and sites). GolfSpec does not process the data for any other purpose and flags any instruction that appears to infringe the GDPR; additional instructions in writing to [TO CONFIRM: data-protection contact address].
5. Confidentiality of personnel
Persons authorised to access production are bound to confidentiality by contract or by law; GolfSpec’s access to the Shop’s data is limited to support, maintenance and security. [TO CONFIRM: persons with production access and signed confidentiality undertaking.]
6. Annex 2 — Security measures
Measures in place:
- Encryption in transit (TLS) on all exchanges, database included; encryption at rest by the database host (Neon default); CRM integration credentials encrypted with AES-256-GCM; no Stripe Connect token stored.
- Passwords hashed with bcrypt (cost 12), 8 characters minimum, brute-force lockout (10 attempts / 15 min per e-mail and IP), reset link valid for 15 minutes, signed-token sessions.
- Multi-tenant isolation through PostgreSQL constraints (composite foreign keys) and an automated test; access control by role (administrator, manager, fitter) and by site; superadmin restricted to a list of e-mail addresses, closed by default.
- Rate limiting on authentication, the portal, booking, uploads, messaging and AI, failing closed on sensitive endpoints when unavailable; uploads limited to 10 MB and to allowed types.
- Encrypted backups (GPG, AES-256) daily, kept for 30 days (90 for the backup of the 1st of the month), completeness check, quarterly restore test; host PITR limited to 6 hours.
- Errors logged in Sentry (production) with alerts on scheduled-task failure; scheduled tasks protected by a secret; Stripe and Resend webhooks verified by signature with replay protection.
Known limitations:
- No two-factor authentication. [TO CONFIRM: 2FA roadmap.]
- Files (workshop photos, attachments, after-sales receipts, PDF cache) protected by non-guessable URLs that are neither signed nor time-limited; deterministic key for the PDF cache. [TO CONFIRM after fix: private access or signed URLs.]
- Sentry: personal-data filtering (masked e-mails, cookies and authentication headers removed) added after the inventory; session replays sampled and masked. [TO CONFIRM: actually deployed in production.]
- No named access log for customer records.
7. Annex 3 — Sub-processors
Sub-processors generally authorised by the Shop:
- Vercel Inc. — hosting, server functions, scheduled tasks, file storage (Blob) — London, United Kingdom (lhr1).
- Neon Inc. — PostgreSQL database — London, United Kingdom (AWS eu-west-2).
- Upstash — rate-limiting Redis (temporary keys, including IP, 15 minutes at most) — United States.
- Resend Inc. — transactional e-mails (via Amazon SES) and delivery receipts — [TO CONFIRM: region].
- Stripe — Stripe Connect for the Shop’s collections (the SaaS subscription falls under the GolfSpec–Shop relationship) — [TO CONFIRM: qualification, contracting entity and region].
- Google (Gemini API, gemini-2.5-flash) — AI features (section 9) — [TO CONFIRM: region and non-use for training].
- Apple (APNs) and Web Push services (Google FCM, Mozilla, Apple) — iOS and browser push notifications; only the endpoint identifier and the notification pass through — [TO CONFIRM: location].
- Sentry — error logging — [TO CONFIRM: region].
- GitHub (Microsoft) — encrypted database backups (key not held by GitHub) and continuous integration — United States.
- cron-job.org and Better Stack (forthcoming) — availability monitoring; no personal data. [TO CONFIRM: activation of Better Stack.]
- TrackMan — only when the Shop imports a report via a public link; the report contains the player’s name. [TO CONFIRM: Shop–TrackMan contractual framework.]
- Shopify or any CRM connected by the Shop — synchronisation of customer records, on its instruction and with its own credentials.
Any addition or replacement is notified to the account administrator with [TO CONFIRM: 30 days’] notice; the Shop may object in writing on legitimate grounds and, failing agreement, terminate without penalty before the change. GolfSpec imposes equivalent obligations on its sub-processors and remains liable for their performance.
8. Transfers outside the European Union
- United Kingdom (Vercel, Neon): European Commission adequacy decision [TO CONFIRM with the lawyer: validity and duration].
- United States (Upstash, GitHub and, depending on their region, Sentry, Google, Stripe, Resend, Apple): standard contractual clauses or Data Privacy Framework certification depending on the provider [TO CONFIRM: instrument applicable to each and signed DPAs].
No other transfer outside the European Union and the European Economic Area.
9. Artificial intelligence
The Service uses the Google Gemini API for structured analysis of a fitting, in-session directive and assistant, summary and reply drafts in messaging. Depending on the feature, requests contain: playing data, body measurements, home club, interview (including physical constraints and comments), per-club measurements, quoted items, the fitter’s free-text notes, catalogue, the Shop’s name and its AI instructions and, for drafts, the last eight messages exchanged with the customer.
GolfSpec never inserts the customer’s name, e-mail or telephone into requests; they may appear if the fitter writes them in notes or if the customer mentions them in a message, of which the Shop informs its staff.
- Caps: 200 analyses per day per Shop, plus per-minute limits per feature.
- Each call is logged with the exact copy of the data sent and the response (FittingAnalysis). [TO BE SET: retention period.]
- AI drafts in messaging can be disabled in the settings (aiDraftEnabled) and are limited to certain plans; outputs are suggestions, the fitter remains the sole decision-maker, no decision with legal effect is automated.
- [TO CONFIRM: Google’s commitment to non-use for training, retention and region.]
10. Assistance to the controller
Data-subject rights: the Shop handles its end customers’ requests itself using the interface:
- access and portability: JSON export of the account (customers, fittings, appointments, conversations, goals, products), restricted to administrators, two per hour, without the workshop, after-sales, the e-mail log, attachments or AI logs [TO CONFIRM: completion of the export];
- rectification: from the fitting record, propagated to the customer record [TO CONFIRM: direct editing of the customer record];
- erasure: deletion of a fitting; messages soft-deleted; workshop tickets archived, not deleted; no individual customer-record deletion to date, GolfSpec carrying it out on the Shop’s written request [TO CONFIRM: procedure and development schedule].
GolfSpec assists the Shop within [TO CONFIRM: 10 working days] with any request it cannot fulfil alone, refers back to the Shop any person who contacts GolfSpec directly, and contributes, with the information available to it, to the Shop’s impact assessments.
Data breaches: notification to the Shop within [TO CONFIRM: 48 hours] of becoming aware (nature, categories and approximate number of data subjects and records, likely consequences, measures taken); notification to the CNIL and communication to data subjects are the Shop’s responsibility.
11. Audit
GolfSpec makes available the documentation demonstrating compliance with the DPA (technical inventory, sub-processors, restore procedures and tests) and answers in writing within [TO CONFIRM: 30 days]. An on-site audit or an audit by an independent third party is possible [TO CONFIRM: once a year, 30 days’ notice, at the Shop’s expense, under confidentiality], except in the event of an established breach or a supervisory-authority request.
12. Data at the end of the contract
- Before the end of the subscription, the Shop exports its data (JSON and CSV accounting export), with GolfSpec’s help on request.
- Account deletion is requested by an administrator (password confirmation); after 30 days, during which it can be cancelled and access is maintained, a daily task deletes all of the Shop’s data from the production database in cascade. [TO CONFIRM: deletion of the associated stored files.]
- Encrypted backups expire within 30 days (90 for the monthly backup) and are used only to restore the service after an incident.
13. Retention periods
Implemented periods: customer-portal tokens 90 days; magic and reset links 15 minutes; portal session cookie 24 hours; staff session 30 days; rate-limiting keys (including IP) 15 minutes at most; business content kept for as long as the account is active.
Periods to be defined: [TO BE SET: booking tokens (no expiry), IP of acceptance of terms, e-mail log (never purged), AI logs, inactive customers, satisfaction, archived workshop tickets and log, Vercel and Sentry technical logs]; the Shop may request shorter periods.
Accounting obligations: the purge at day 30 also deletes invoices and payments; the Shop, which alone bears accounting and tax retention duties, exports them before the end of the contract. [TO CONFIRM with the lawyer: separate retention of accounting records by GolfSpec.]
14. Liability
Each party is liable for damage caused by non-compliant processing under the conditions of Article 82 GDPR; GolfSpec’s liability follows the limitations of the Terms of Sale [TO CONFIRM: cap, for example 12 months’ subscription fees, and exclusions], except for gross negligence or wilful misconduct. The Shop indemnifies GolfSpec against any claim arising from a lack of legal basis, information or consent, in particular for health data.
15. Governing law and contact
French law; competent courts of Toulouse [TO CONFIRM with the lawyer: jurisdiction clause between professionals], after an attempt at amicable settlement. Data-protection contact: [TO CONFIRM: dedicated address and whether or not a DPO is appointed].
GolfSpec updates this DPA upon any significant change to the measures or sub-processors and informs the Shop.