Data Processing Agreement
Last updated · September 2026 · Standard-form DPA · Article 28 UK GDPR
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Grantive Ltd ("Processor") and the golf club or members' club that has subscribed to Fairway ("Controller"). It governs the processing of personal data that the Controller entrusts to the Processor when using the Fairway service.
This standard DPA applies automatically to every Fairway subscription. Clubs with their own DPA templates or specific procurement requirements can email
[email protected] — we're happy to redline your version instead.
1. Definitions
Terms not defined here have the meaning given in UK GDPR. "Personal Data," "Data Subject," "Processing," "Data Controller" and "Data Processor" carry their statutory meanings. "Sub-processor" means any third party engaged by the Processor to process Personal Data on the Controller's behalf.
2. Subject-matter, nature and purpose
The Processor processes Personal Data solely to provide the Fairway service to the Controller under the Terms of Service. This includes hosting member profiles, tee-time bookings, competition entries, scorecards, notice-board posts, member-to-member messages, guest bookings, event registrations, lesson bookings, and related club activity.
3. Categories of Data Subjects and Personal Data
- Data Subjects: the Controller's members, guests booked via the Controller, and members' contacts (invited playing partners).
- Personal Data: identity data (name, email, phone, membership category, member number, optional handicap, optional date of birth, optional gender, optional avatar photo), activity data (bookings, scores, sign-ups, messages), engagement metadata (last-active time, push token, preferences).
4. Duration
The Processor processes Personal Data for the duration of the Terms of Service and, thereafter, for the retention periods set out in the Privacy Policy (member data retained 30 days after account deletion for backup rollover; billing records held six years for HMRC compliance).
5. Obligations of the Processor
The Processor will:
- Process Personal Data only on the documented instructions of the Controller, including with respect to any transfer of Personal Data outside the UK or EEA (or notify the Controller before doing so where required by law).
- Ensure that persons authorised to process the Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organisational measures set out in Schedule A ("Security Measures") to meet the requirements of Art. 32 UK GDPR.
- Assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to Data Subject requests under Chapter III UK GDPR.
- Assist the Controller in ensuring compliance with obligations under Arts. 32-36 UK GDPR (security, breach notification, DPIA, prior consultation).
- At the choice of the Controller, delete or return all Personal Data to the Controller after the end of provision of services relating to processing, and delete existing copies unless UK law requires storage.
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 UK GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Inspections take place at the Controller's cost, with reasonable notice, no more than once per year (except following a security incident), and subject to the Processor's confidentiality and security requirements.
6. Sub-processors
The Controller consents to the Processor engaging the sub-processors listed in the Privacy Policy (Railway, Stripe, Cloudflare, Resend, Apple, Google). The Processor will give the Controller at least 30 days' notice of any intended addition or replacement of sub-processors, giving the Controller the opportunity to object. If the Controller reasonably objects on data-protection grounds, the Processor will use commercially reasonable efforts to make available an alternative or, failing that, the Controller may terminate the affected part of the service without penalty.
Each sub-processor is bound by a written agreement imposing the same data-protection obligations as those set out in this DPA (Art. 28(4) UK GDPR).
7. Security incident notification
The Processor will notify the Controller without undue delay — and in any event within 72 hours — of becoming aware of a Personal Data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address the breach.
8. International transfers
Personal Data is stored in the UK / EEA region of Railway's infrastructure. Where a sub-processor (Stripe, Cloudflare, Apple, Google) is an international provider, transfers rely on the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses supplemented by the UK Addendum.
9. Liability
Liability under this DPA is subject to the limitation of liability in the Terms of Service, save that nothing in this DPA limits either party's liability for breach of statutory data-protection obligations to Data Subjects.
10. Order of precedence
In the event of conflict between this DPA and the Terms of Service, this DPA takes precedence in respect of the processing of Personal Data.
11. Governing law & jurisdiction
This DPA is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales.
Schedule A — Security Measures
- Encryption in transit: TLS 1.2 or higher on every connection, HSTS enforced on public hosts.
- Encryption at rest: production database and rolling backups encrypted at rest by Railway.
- Password storage: bcrypt with salt for member and admin passwords; passwords are never stored or logged in plain text.
- Access control: per-tenant scoping enforced at every database query; short-lived bearer tokens with idle- and absolute-timeout for admin sessions; role-based scopes on the admin API.
- Rate limiting: authentication endpoints rate-limited to prevent credential-stuffing; guest booking rate-limited to prevent scraping.
- Application hardening: content-security-policy headers, Stripe webhook signature verification, HTML sanitisation on user-supplied rich text.
- Backups: rolling 30-day encrypted backups.
- Audit logging: admin actions logged with actor, target, and timestamp; retained 90 days.
- Personnel: access to production restricted to named engineers under a written confidentiality obligation; access is reviewed quarterly.
Schedule B — Sub-processors (as at Last updated)
- Railway — application hosting and Postgres database (UK / EEA region).
- Stripe Payments Europe, Limited — subscription and payment processing.
- Cloudflare, Inc. — DDoS protection, custom-domain serving, asset CDN.
- Resend — transactional email delivery.
- Apple Inc. — push-notification delivery (APNS) — payload only, no personal data.
- Google LLC — push-notification delivery (FCM) — payload only, no personal data.
Contact for DPA queries
Data-protection queries and audit requests: [email protected]. We aim to respond within two working days.