Data Protection
For clubs, associations, organisers and public bodies that use Ludoya: who is responsible for your members' and guests' data, what we keep and for how long, where it is stored, who else processes it, and the agreement that covers all of it.
Who we are
Ludoya is run by Tenkai Workshop S.L., NIF B56364086, Avinguda de la Vall d'Aran 12, 43206 Reus (Tarragona), Spain. For anything about personal data, write to app@ludoya.com. We have not appointed a data protection officer.
Who is responsible for what
When your club uses Ludoya to run its membership and events, your club is the controller of its members' and guests' data, and Ludoya is its processor: we store and process that data on your behalf and only to provide the service. That covers your join forms, your roster, your event forms, attendance and dues.
For people's own Ludoya accounts (their profile, collection, plays and messages), Ludoya is the controller, under our privacy policy.
For example: the phone number a member typed into your event's sign-up form is your club's data, handled for you. The games that same member logged on their own profile are theirs, under their own account.
People without an account
People can come to your events without registering: someone saves them a seat, or they sign up at the door with just a name and an email. We keep what was given: their name, their email address and their answers to your event's form.
If they never finish creating an account, we delete those details 30 days after their last event. When we have their email address, we send them one reminder about 10 days after the event with the exact date, and a reminder always gives at least 14 days. Their name stays on the event's attendee list and on the plays and results they took part in, with nothing linking it to them. If they sign up with the same email address before the date, their seats and plays move to their new account.
Members of your club are not deleted this way: they stay on your roster for as long as they are members. When a club is deleted, its members and roster, and the answers given to its forms, go with it. Its past events, who attended them and the plays stay, because they are also part of other people's history, but without the answers.
What we do with the data
We use your club's data only to provide the service you use: memberships, events, forms, attendance, lending and dues. We do not sell it, and we never pass it to advertisers or data brokers.
We may compile anonymous statistics from activity on Ludoya, such as how often a game is played in a region, and use them in our own reports or with partners such as publishers. They are built so that no person or small group can be identified.
Where the data lives
Our servers and database are with OVH in France (Roubaix), and uploaded images and our backups are with OVH in Paris. Some of the services listed below process data outside the EU; for each one, the table says under what legal basis.
Services that process data for us
These services process personal data on our instructions and only for the purpose listed. We tell every club by email at least 30 days before we add or replace one, and a club that objects can end the agreement.
| Service | What it does for us | Where | Basis for transfers outside the EU |
|---|---|---|---|
| OVH | Our servers, database, uploaded images and backups | France (Roubaix; images and backups in Paris) | None: the data stays in the EU |
| SMTP2GO | Sending every email Ludoya sends | Data centres in the EU, the United States and Australia | SMTP2GO's data processing agreement |
| Stripe | Payments: subscriptions, tickets and membership dues | United States | EU–US Data Privacy Framework |
| Sign-in with Google, maps, places and address lookup, and push notifications on Android | United States | EU–US Data Privacy Framework | |
| Apple | Push notifications on iPhone and iPad | United States | Standard contractual clauses |
| OpenAI | AI features: the game assistant, matching and describing games, and the chat bot a club can add to its Telegram or Discord group, which can pass an event's attendee names when someone asks it about that event | United States | Standard contractual clauses |
| Cloudflare | Domain names and the network in front of our servers | Worldwide network | EU–US Data Privacy Framework and standard contractual clauses |
| PostHog | Product analytics: which features are used and where people get stuck | EU (Frankfurt) | None: the data stays in the EU |
A club can also connect Telegram, Discord to its own groups. Those services receive what the club chooses to send to its channels and act under their own terms, not on our behalf.
Security
- Passwords are stored hashed, never in readable form.
- Every connection to Ludoya is encrypted.
- Access to the servers and the database is limited to the operator, and every club's data is only reachable through the permissions of its own admins.
- The database is backed up continuously, with a full copy every week, to a separate location.
- If a breach affects a club's data, we tell the club without undue delay.
Data processing agreement
This agreement applies to every organisation that uses Ludoya to manage members or events, as part of our terms of service. Signing it is optional and gives you a paper copy: print it, fill in your details, sign it and send it to app@ludoya.com, and we will send it back countersigned. The Spanish version prevails.
Parties
The controller (the organisation)
Name:
Tax ID (NIF):
Address:
Contact email:
The processor
Tenkai Workshop S.L. (Ludoya)
Tax ID (NIF): B56364086
Address: Avinguda de la Vall d'Aran 12, 43206 Reus (Tarragona), Spain
Contact email: app@ludoya.com
Standard contractual clauses
The parties agree to the standard contractual clauses between controllers and processors adopted by the European Commission in Implementing Decision (EU) 2021/915, reproduced below in their official wording, with the options selected in the next section and Annexes I to IV completed after them.
ANNEX
Standard contractual clauses
SECTION I
Clause 1
Purpose and scope
(a) | The purpose of these Standard Contractual Clauses (the Clauses) is to ensure compliance with [choose relevant option: OPTION 1: Article 28(3) and (4) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)] / [OPTION 2: Article 29(3) and (4) of Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC]. |
(b) | The controllers and processors listed in Annex I have agreed to these Clauses in order to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 and/or Article 29(3) and (4) of Regulation (EU) 2018/1725. |
(c) | These Clauses apply to the processing of personal data as specified in Annex II. |
(d) | Annexes I to IV are an integral part of the Clauses. |
(e) | These Clauses are without prejudice to obligations to which the controller is subject by virtue of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. |
(f) | These Clauses do not by themselves ensure compliance with obligations related to international transfers in accordance with Chapter V of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. |
Clause 2
Invariability of the Clauses
(a) | The Parties undertake not to modify the Clauses, except for adding information to the Annexes or updating information in them. |
(b) | This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a broader contract, or from adding other clauses or additional safeguards provided that they do not directly or indirectly contradict the Clauses or detract from the fundamental rights or freedoms of data subjects. |
Clause 3
Interpretation
(a) | Where these Clauses use the terms defined in Regulation (EU) 2016/679 or Regulation (EU) 2018/1725 respectively, those terms shall have the same meaning as in that Regulation. |
(b) | These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679 or Regulation (EU) 2018/1725 respectively. |
(c) | These Clauses shall not be interpreted in a way that runs counter to the rights and obligations provided for in Regulation (EU) 2016/679 / Regulation (EU) 2018/1725 or in a way that prejudices the fundamental rights or freedoms of the data subjects. |
Clause 4
Hierarchy
In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties existing at the time when these Clauses are agreed or entered into thereafter, these Clauses shall prevail.
Clause 5 - Optional
Docking clause
(a) | Any entity that is not a Party to these Clauses may, with the agreement of all the Parties, accede to these Clauses at any time as a controller or a processor by completing the Annexes and signing Annex I. |
(b) | Once the Annexes in (a) are completed and signed, the acceding entity shall be treated as a Party to these Clauses and have the rights and obligations of a controller or a processor, in accordance with its designation in Annex I. |
(c) | The acceding entity shall have no rights or obligations resulting from these Clauses from the period prior to becoming a Party. |
SECTION II
OBLIGATIONS OF THE PARTIES
Clause 6
Description of processing(s)
The details of the processing operations, in particular the categories of personal data and the purposes of processing for which the personal data is processed on behalf of the controller, are specified in Annex II.
Clause7
Obligations of the Parties
7.1. Instructions
(a) | The processor shall process personal data only on documented instructions from the controller, unless required to do so by Union or Member State law to which the processor is subject. In this case, the processor shall inform the controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. Subsequent instructions may also be given by the controller throughout the duration of the processing of personal data. These instructions shall always be documented. |
(b) | The processor shall immediately inform the controller if, in the processor’s opinion, instructions given by the controller infringe Regulation (EU) 2016/679 / Regulation (EU) 2018/1725 or the applicable Union or Member State data protection provisions. |
7.2. Purpose limitation
The processor shall process the personal data only for the specific purpose(s) of the processing, as set out in Annex II, unless it receives further instructions from the controller.
7.3. Duration of the processing of personal data
Processing by the processor shall only take place for the duration specified in Annex II.
7.4. Security of processing
(a) | The processor shall at least implement the technical and organisational measures specified in Annex III to ensure the security of the personal data. This includes protecting the data against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to the data (personal data breach). In assessing the appropriate level of security, the Parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks involved for the data subjects. |
(b) | The processor shall grant access to the personal data undergoing processing to members of its personnel only to the extent strictly necessary for implementing, managing and monitoring of the contract. The processor shall ensure that persons authorised to process the personal data received have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. |
7.5. Sensitive data
If the processing involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person’s sex life or sexual orientation, or data relating to criminal convictions and offences (“sensitive data”), the processor shall apply specific restrictions and/or additional safeguards.
7.6. Documentation and compliance
(a) | The Parties shall be able to demonstrate compliance with these Clauses. |
(b) | The processor shall deal promptly and adequately with inquiries from the controller about the processing of data in accordance with these Clauses. |
(c) | The processor shall make available to the controller all information necessary to demonstrate compliance with the obligations that are set out in these Clauses and stem directly from Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. At the controller’s request, the processor shall also permit and contribute to audits of the processing activities covered by these Clauses, at reasonable intervals or if there are indications of non-compliance. In deciding on a review or an audit, the controller may take into account relevant certifications held by the processor. |
(d) | The controller may choose to conduct the audit by itself or mandate an independent auditor. Audits may also include inspections at the premises or physical facilities of the processor and shall, where appropriate, be carried out with reasonable notice. |
(e) | The Parties shall make the information referred to in this Clause, including the results of any audits, available to the competent supervisory authority/ies on request. |
7.7. Use of sub-processors
(a) | OPTION 1: PRIOR SPECIFIC AUTHORISATION: The processor shall not subcontract any of its processing operations performed on behalf of the controller in accordance with these Clauses to a sub-processor, without the controller’s prior specific written authorisation. The processor shall submit the request for specific authorisation at least [SPECIFY TIME PERIOD] prior to the engagement of the sub-processor in question, together with the information necessary to enable the controller to decide on the authorisation. The list of sub-processors authorised by the controller can be found in Annex IV. The Parties shall keep Annex IV up to date. OPTION 2: GENERAL WRITTEN AUTHORISATION: The processor has the controller’s general authorisation for the engagement of sub-processors from an agreed list. The processor shall specifically inform in writing the controller of any intended changes of that list through the addition or replacement of sub-processors at least [SPECIFY TIME PERIOD] in advance, thereby giving the controller sufficient time to be able to object to such changes prior to the engagement of the concerned sub-processor(s). The processor shall provide the controller with the information necessary to enable the controller to exercise the right to object. |
(b) | Where the processor engages a sub-processor for carrying out specific processing activities (on behalf of the controller), it shall do so by way of a contract which imposes on the sub-processor, in substance, the same data protection obligations as the ones imposed on the data processor in accordance with these Clauses. The processor shall ensure that the sub-processor complies with the obligations to which the processor is subject pursuant to these Clauses and to Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. |
(c) | At the controller’s request, the processor shall provide a copy of such a sub-processor agreement and any subsequent amendments to the controller. To the extent necessary to protect business secret or other confidential information, including personal data, the processor may redact the text of the agreement prior to sharing the copy. |
(d) | The processor shall remain fully responsible to the controller for the performance of the sub-processor’s obligations in accordance with its contract with the processor. The processor shall notify the controller of any failure by the sub-processor to fulfil its contractual obligations. |
(e) | The processor shall agree a third party beneficiary clause with the sub-processor whereby - in the event the processor has factually disappeared, ceased to exist in law or has become insolvent - the controller shall have the right to terminate the sub-processor contract and to instruct the sub-processor to erase or return the personal data. |
7.8. International transfers
(a) | Any transfer of data to a third country or an international organisation by the processor shall be done only on the basis of documented instructions from the controller or in order to fulfil a specific requirement under Union or Member State law to which the processor is subject and shall take place in compliance with Chapter V of Regulation (EU) 2016/679 or Regulation (EU) 2018/1725. |
(b) | The controller agrees that where the processor engages a sub-processor in accordance with Clause 7.7. for carrying out specific processing activities (on behalf of the controller) and those processing activities involve a transfer of personal data within the meaning of Chapter V of Regulation (EU) 2016/679, the processor and the sub-processor can ensure compliance with Chapter V of Regulation (EU) 2016/679 by using standard contractual clauses adopted by the Commission in accordance with of Article 46(2) of Regulation (EU) 2016/679, provided the conditions for the use of those standard contractual clauses are met. |
Clause 8
Assistance to the controller
(a) | The processor shall promptly notify the controller of any request it has received from the data subject. It shall not respond to the request itself, unless authorised to do so by the controller. |
(b) | The processor shall assist the controller in fulfilling its obligations to respond to data subjects’ requests to exercise their rights, taking into account the nature of the processing. In fulfilling its obligations in accordance with (a) and (b), the processor shall comply with the controller’s instructions |
(c) | In addition to the processor’s obligation to assist the controller pursuant to Clause 8(b), the processor shall furthermore assist the controller in ensuring compliance with the following obligations, taking into account the nature of the data processing and the information available to the processor:
|
(d) | The Parties shall set out in Annex III the appropriate technical and organisational measures by which the processor is required to assist the controller in the application of this Clause as well as the scope and the extent of the assistance required. |
Clause 9
Notification of personal data breach
In the event of a personal data breach, the processor shall cooperate with and assist the controller for the controller to comply with its obligations under Articles 33 and 34 of Regulation (EU) 2016/679 or under Articles 34 and 35 of Regulation (EU) 2018/1725, where applicable, taking into account the nature of processing and the information available to the processor.
9.1 Data breach concerning data processed by the controller
In the event of a personal data breach concerning data processed by the controller, the processor shall assist the controller:
(a) | in notifying the personal data breach to the competent supervisory authority/ies, without undue delay after the controller has become aware of it, where relevant/(unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons); |
(b) | in obtaining the following information which, pursuant to [OPTION 1] Article 33(3) of Regulation (EU) 2016/679/ [OPTION 2] Article 34(3) of Regulation (EU) 2018/1725, shall be stated in the controller’s notification, and must at least include:
|
Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.
(c) | in complying, pursuant to [OPTION 1] Article 34 of Regulation (EU) 2016/679 / [OPTION 2] Article 35 of Regulation (EU) 2018/1725, with the obligation to communicate without undue delay the personal data breach to the data subject, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons. |
9.2 Data breach concerning data processed by the processor
In the event of a personal data breach concerning data processed by the processor, the processor shall notify the controller without undue delay after the processor having become aware of the breach. Such notification shall contain, at least:
(a) | a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned); |
(b) | the details of a contact point where more information concerning the personal data breach can be obtained; |
(c) | its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects. |
Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.
The Parties shall set out in Annex III all other elements to be provided by the processor when assisting the controller in the compliance with the controller’s obligations under [OPTION 1] Articles 33 and 34 of Regulation (EU) 2016/679 / [OPTION 2] Articles 34 and 35 of Regulation (EU) 2018/1725.
SECTION III
FINAL PROVISIONS
Clause 10
Non-compliance with the Clauses and termination
(a) | Without prejudice to any provisions of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725, in the event that the processor is in breach of its obligations under these Clauses, the controller may instruct the processor to suspend the processing of personal data until the latter complies with these Clauses or the contract is terminated. The processor shall promptly inform the controller in case it is unable to comply with these Clauses, for whatever reason. |
(b) | The controller shall be entitled to terminate the contract insofar as it concerns processing of personal data in accordance with these Clauses if:
|
(c) | The processor shall be entitled to terminate the contract insofar as it concerns processing of personal data under these Clauses where, after having informed the controller that its instructions infringe applicable legal requirements in accordance with Clause 7.1 (b), the controller insists on compliance with the instructions. |
(d) | Following termination of the contract, the processor shall, at the choice of the controller, delete all personal data processed on behalf of the controller and certify to the controller that it has done so, or, return all the personal data to the controller and delete existing copies unless Union or Member State law requires storage of the personal data. Until the data is deleted or returned, the processor shall continue to ensure compliance with these Clauses. |
Options selected
- Clauses 1(a), 8, 9.1 and 9.2: Option 1 (Regulation (EU) 2016/679, the General Data Protection Regulation).
- Clause 5 (optional docking clause): not used.
- Clause 7.7(a): Option 2, general written authorisation, with a notice period of 30 days.
Annex I: List of parties
The parties are those named at the top of this agreement. The controller's signatory, role and date of signature appear in the signature block at the end.
Annex II: Description of the processing
- Data subjects: the controller's members, event attendees and guests, and people on its roster.
- Categories of personal data: identification and contact details (name, email address, phone number when the controller asks for it), attendance, answers to the controller's forms, membership and dues status.
- Sensitive data: none is needed for the service. The controller should not collect special categories of data (such as health data) through its forms; if it does, that is on its instructions and its responsibility.
- Nature and purpose: storing and processing the data to provide the service the controller uses on Ludoya: memberships, events, forms, attendance, lending and dues. The controller's instructions are its settings and actions in the product.
- Duration: for as long as the controller uses the service. The details of people without an account are deleted 30 days after their last event, as described on this page. When the controller leaves, it can export its data; its memberships, its roster and the answers to its forms are then deleted within 30 days, except what the law requires us to keep, such as invoices. Past events, attendance and plays are kept with participants' names only, as part of the other participants' own records.
Annex III: Technical and organisational measures
- Passwords are stored hashed, never in readable form.
- Every connection to Ludoya is encrypted.
- Access to the servers and the database is limited to the operator, and every club's data is only reachable through the permissions of its own admins.
- The database is backed up continuously, with a full copy every week, to a separate location.
- If a breach affects a club's data, we tell the club without undue delay.
Annex IV: List of sub-processors
| Service | What it does for us | Where | Basis for transfers outside the EU |
|---|---|---|---|
| OVH | Our servers, database, uploaded images and backups | France (Roubaix; images and backups in Paris) | None: the data stays in the EU |
| SMTP2GO | Sending every email Ludoya sends | Data centres in the EU, the United States and Australia | SMTP2GO's data processing agreement |
| Stripe | Payments: subscriptions, tickets and membership dues | United States | EU–US Data Privacy Framework |
| Sign-in with Google, maps, places and address lookup, and push notifications on Android | United States | EU–US Data Privacy Framework | |
| Apple | Push notifications on iPhone and iPad | United States | Standard contractual clauses |
| OpenAI | AI features: the game assistant, matching and describing games, and the chat bot a club can add to its Telegram or Discord group, which can pass an event's attendee names when someone asks it about that event | United States | Standard contractual clauses |
| Cloudflare | Domain names and the network in front of our servers | Worldwide network | EU–US Data Privacy Framework and standard contractual clauses |
| PostHog | Product analytics: which features are used and where people get stuck | EU (Frankfurt) | None: the data stays in the EU |
Additional clauses
As Clause 2 allows, the parties add the following. None of them contradicts the standard contractual clauses or limits the rights of the people whose data it is; if one ever did, the clauses prevail.
- Breaches. The processor aims to notify the controller of a personal data breach within 48 hours of becoming aware of it.
- Assistance. The product's own tools (exporting data, removing a member) are the first way to answer data subjects' requests. The processor may charge reasonable costs for assistance that goes beyond them and is manifestly excessive or repetitive.
- Audits. The information on this page is the first answer to any request under Clause 7.6. Audits are at the controller's cost and subject to confidentiality.
- Anonymous statistics. The processor may derive anonymous, aggregated statistics from the use of the service, which cannot identify any data subject or small group of data subjects, and may use them for its own purposes, including after this agreement ends.
- Liability. Between the parties, each party's liability under this agreement is limited to the amount the controller paid the processor in the 12 months before the claim, except where the law does not allow such a limit. This does not limit anyone's rights under Article 82 of the General Data Protection Regulation.
- Law and courts. This agreement is governed by Spanish law, and the courts of Tarragona have jurisdiction.
- Language. This agreement is available in several languages; the Spanish version prevails.
Signatures
The controller (the organisation)
Name of the signatory:
Role:
Date:
Signature:
The processor
Tenkai Workshop S.L.
Date:
Signature: