Fairway · by Grantive

Data Processing Agreement

Last updated · September 2026 · Standard-form DPA · Article 28 UK GDPR

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Grantive Ltd ("Processor") and the golf club or members' club that has subscribed to Fairway ("Controller"). It governs the processing of personal data that the Controller entrusts to the Processor when using the Fairway service.

This standard DPA applies automatically to every Fairway subscription. Clubs with their own DPA templates or specific procurement requirements can email [email protected] — we're happy to redline your version instead.

1. Definitions

Terms not defined here have the meaning given in UK GDPR. "Personal Data," "Data Subject," "Processing," "Data Controller" and "Data Processor" carry their statutory meanings. "Sub-processor" means any third party engaged by the Processor to process Personal Data on the Controller's behalf.

2. Subject-matter, nature and purpose

The Processor processes Personal Data solely to provide the Fairway service to the Controller under the Terms of Service. This includes hosting member profiles, tee-time bookings, competition entries, scorecards, notice-board posts, member-to-member messages, guest bookings, event registrations, lesson bookings, and related club activity.

3. Categories of Data Subjects and Personal Data

4. Duration

The Processor processes Personal Data for the duration of the Terms of Service and, thereafter, for the retention periods set out in the Privacy Policy (member data retained 30 days after account deletion for backup rollover; billing records held six years for HMRC compliance).

5. Obligations of the Processor

The Processor will:

  1. Process Personal Data only on the documented instructions of the Controller, including with respect to any transfer of Personal Data outside the UK or EEA (or notify the Controller before doing so where required by law).
  2. Ensure that persons authorised to process the Personal Data are bound by confidentiality obligations.
  3. Implement appropriate technical and organisational measures set out in Schedule A ("Security Measures") to meet the requirements of Art. 32 UK GDPR.
  4. Assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to Data Subject requests under Chapter III UK GDPR.
  5. Assist the Controller in ensuring compliance with obligations under Arts. 32-36 UK GDPR (security, breach notification, DPIA, prior consultation).
  6. At the choice of the Controller, delete or return all Personal Data to the Controller after the end of provision of services relating to processing, and delete existing copies unless UK law requires storage.
  7. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 UK GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Inspections take place at the Controller's cost, with reasonable notice, no more than once per year (except following a security incident), and subject to the Processor's confidentiality and security requirements.

6. Sub-processors

The Controller consents to the Processor engaging the sub-processors listed in the Privacy Policy (Railway, Stripe, Cloudflare, Resend, Apple, Google). The Processor will give the Controller at least 30 days' notice of any intended addition or replacement of sub-processors, giving the Controller the opportunity to object. If the Controller reasonably objects on data-protection grounds, the Processor will use commercially reasonable efforts to make available an alternative or, failing that, the Controller may terminate the affected part of the service without penalty.

Each sub-processor is bound by a written agreement imposing the same data-protection obligations as those set out in this DPA (Art. 28(4) UK GDPR).

7. Security incident notification

The Processor will notify the Controller without undue delay — and in any event within 72 hours — of becoming aware of a Personal Data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address the breach.

8. International transfers

Personal Data is stored in the UK / EEA region of Railway's infrastructure. Where a sub-processor (Stripe, Cloudflare, Apple, Google) is an international provider, transfers rely on the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses supplemented by the UK Addendum.

9. Liability

Liability under this DPA is subject to the limitation of liability in the Terms of Service, save that nothing in this DPA limits either party's liability for breach of statutory data-protection obligations to Data Subjects.

10. Order of precedence

In the event of conflict between this DPA and the Terms of Service, this DPA takes precedence in respect of the processing of Personal Data.

11. Governing law & jurisdiction

This DPA is governed by the laws of England and Wales and subject to the exclusive jurisdiction of the courts of England and Wales.


Schedule A — Security Measures

Schedule B — Sub-processors (as at Last updated)

Contact for DPA queries

Data-protection queries and audit requests: [email protected]. We aim to respond within two working days.

Grantive Ltd · Registered in England & Wales · Company no. 17070259 · Registered office: 82a James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE
Questions about this page? Email [email protected]
Privacy · Terms · Data Processing Agreement · fairwaybygrantive.com