CourtNetworks Data Processing Addendum
Version: 1.0
Effective date: 26 September 2026
1. When this DPA applies
This Data Processing Addendum ("DPA") applies where UbD Products Ltd, through CourtNetworks, processes personal data on behalf of a person or organisation that acts as controller.
It forms part of the CourtNetworks Organisation and Organiser Terms or another agreement that expressly incorporates it.
It does not apply to personal data for which UbD Products Ltd independently acts as controller.
2. Parties
Processor: UbD Products Ltd, company number 17445762, registered in England and Wales, trading through CourtNetworks.
Controller: the person or organisation that determines the purposes and essential means of the relevant processing and has accepted an agreement incorporating this DPA.
A person accepting on behalf of an organisation confirms they have authority to bind it.
3. Data-protection law
"Data Protection Law" means applicable UK data-protection and privacy law, including the UK GDPR and Data Protection Act 2018.
"Controller Personal Data" means personal data processed by UbD Products Ltd on behalf of the Controller.
"Sub-processor" means another processor engaged by UbD Products Ltd to process Controller Personal Data.
4. Processing instructions
The Controller's documented instructions include its configuration and authorised use of CourtNetworks, written requests consistent with the service, and the agreements governing its use of CourtNetworks.
We will process Controller Personal Data only on documented instructions unless applicable law requires otherwise.
If we believe an instruction infringes Data Protection Law, we will inform the Controller unless the law prevents us from doing so.
5. Our processor commitments
Where we act as processor, we will:
- process Controller Personal Data only on documented instructions, unless law requires otherwise;
- ensure authorised personnel are subject to appropriate confidentiality obligations;
- maintain technical and organisational measures appropriate to the risk;
- use Sub-processors in accordance with section 6;
- provide reasonable assistance with data-subject rights where required;
- provide reasonable assistance with applicable security, breach and data-protection obligations;
- notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller Personal Data;
- deal with Controller Personal Data at the end of processing as described below; and
- provide information reasonably necessary to demonstrate compliance and cooperate with proportionate audits.
6. Sub-processors
The Controller gives general authorisation for us to use Sub-processors to provide CourtNetworks.
The current list is published at:
https://courtnetworks.com/sub-processors
Where a provider acts as a Sub-processor, we will put appropriate data-protection obligations in place.
Where we intend to appoint or replace a Sub-processor that will materially process Controller Personal Data, we will provide reasonable notice through an appropriate channel.
The Controller may raise a reasonable data-protection objection by contacting privacy@courtnetworks.com.
We remain responsible for the obligations that Data Protection Law requires us to pass down to Sub-processors.
7. International transfers
We will not make a restricted transfer of Controller Personal Data unless it is permitted by Data Protection Law.
Where a safeguard is required, we will use or rely on an appropriate lawful transfer mechanism.
8. Security
We maintain technical and organisational measures appropriate to the nature and risk of the processing.
The Controller is responsible for controlling its authorised users, protecting its own accounts and devices, and removing access when it is no longer required.
9. Deletion and return
When the Controller stops using the relevant service, Controller Personal Data processed solely on its behalf will be deleted or returned as required by applicable law and lawful instructions, subject to reasonable technical deletion cycles and backup retention.
This does not require us to delete information that:
- we are legally required to retain; or
- we independently control for a separate lawful purpose.
10. Data-subject requests
If we receive a request clearly relating to Controller Personal Data processed only on behalf of the Controller, we may refer the requester to the Controller or notify the Controller unless law requires otherwise.
The Controller remains responsible for requests relating to processing for which it is controller.
11. Personal-data breaches
If we become aware of a personal-data breach affecting Controller Personal Data, we will notify the Controller without undue delay and provide information reasonably available to us that the Controller needs to meet its legal obligations.
The Controller is responsible for deciding whether it must notify the ICO, another regulator or affected individuals where it is controller.
12. Audits and compliance information
On reasonable written request, we will provide information reasonably necessary to demonstrate compliance with applicable processor obligations.
Where an audit is reasonably required, the parties will agree a proportionate scope, timing and method. Documentary or remote review should normally be used first.
Any inspection must avoid unnecessary access to another customer's information, confidential information or security-sensitive material and must not unreasonably disrupt CourtNetworks.
13. Assistance and costs
We will provide the assistance required of a processor by Data Protection Law.
Where a request requires substantial work beyond what is reasonably included in the normal service, the parties may agree reasonable arrangements for that work, provided this does not remove a legal obligation that we must fulfil.
14. Duration and priority
This DPA applies for as long as we process Controller Personal Data on the Controller's behalf.
If this DPA conflicts with another CourtNetworks term on a processor data-protection matter, this DPA takes priority unless the parties have expressly agreed another compliant arrangement.
15. Processing details
Subject matter and duration
Provision of CourtNetworks and related organisation, activity, communication and administration functions for the period in which the Controller uses those functions and any lawful technical or retention period afterwards.
Nature and purpose
Processing may include collecting, storing, organising, displaying, transmitting, communicating, securing, exporting, deleting or anonymising personal data as needed to provide CourtNetworks on the Controller's behalf.
Categories of data subjects
Depending on use, data subjects may include participants, prospective participants, organisers, organisation representatives, parents, guardians, children, authorised profile managers and other people whose information the Controller lawfully processes through CourtNetworks.
Types of personal data
Depending on use, personal data may include identity and contact information, participation and activity information, sporting records, communications, guardian or management relationships, notification information, and related technical or audit information.
CourtNetworks standard organiser functions are not intended to require special-category personal data unless a feature expressly supports that processing.
16. Controller responsibilities
The Controller is responsible for:
- having an appropriate lawful basis;
- providing required privacy information;
- using information obtained through CourtNetworks lawfully;
- controlling who receives authorised access;
- responding to rights requests relating to its processing;
- applying appropriate safeguards where needed; and
- giving lawful instructions.
17. Contact
UbD Products Ltd
privacy@courtnetworks.com
