09Legal
Data processing.
When you hold a roster on the platform, you decide what happens to your athletes' data and we carry it out. This is the agreement that makes that split enforceable — required by Article 28(3), and written to be read.
Last updated 2026-08-29
This agreement applies where you use the Veliard platform to hold data about people you coach. It forms part of the terms of service and takes effect when you create a roster and add someone to it.
09.1Parties, scope and precedence
- Controller
- You — the coach, gym, team or club holding the roster
- Processor
- Veliard Ltd, reg. HE493832, Anastasiou Sioukri 1, Themis Court, 4th Floor, Office 402, 3105 Limassol, Cyprus
- Applies to
- Personal data we process on your behalf about the athletes on your roster
- Does not apply to
- Data we process as controller in our own right — your account, your billing, security logs, product diagnostics. That is covered by the platform privacy policy, not by this agreement.
Where this agreement and the terms of service conflict on the processing of athlete data, this agreement prevails. Where you have signed a separate negotiated DPA with us, that one prevails over this.
09.2What is processed
- Subject matter
- Providing the Veliard training platform, so that you can programme, assign and review training
- Duration
- For as long as your roster exists, plus the deletion window in 09.11
- Nature and purpose
- Storage, organisation, retrieval, transmission and display of athlete training data; backup; and the technical support you ask us for
- Categories of data subject
- The athletes you add to your roster, including minors where you have the authority described in09.4
- Categories of personal data
- Identity and contact data; training content — exercises, loads, sets, repetitions, tempo, RPE, maxima, notes; bodyweight; the programme you assign; and technical data generated in use
- Special category data
- Where you or the athlete record injury, restriction, medical or physiological entries, these are Article 9 data. We process them only as part of providing the platform, and only where a lawful basis under 09.4 exists.
09.3Instructions
We process athlete data only on your documented instructions, including on transfers to a third country, unless EU or member state law requires otherwise — in which case we tell you before processing, unless that law forbids us to on important grounds of public interest.
Your instructions are: these terms, this agreement, and what you do through the platform’s own functions. Configuring, editing, exporting or deleting through the interface is an instruction, and does not require a separate written request.
If we consider an instruction infringes the GDPR or other EU or member state data protection law, we tell you immediately and may suspend that instruction until it is resolved.
We do not use athlete data for our own purposes. We do not sell it, do not use it for advertising, and do not train machine learning models on it. Where we derive aggregate statistics to improve the product, they are aggregated and anonymised so that no individual is identifiable, and the test we apply is whether re-identification is reasonably possible — not merely whether a name has been removed.
09.4Your obligations as controller
You are the controller, and some things only you can do. You warrant that:
- You have a lawful basis under Article 6 for putting each athlete’s data on the platform, and you can evidence it.
- You have given each athlete the information Articles 13 and 14 require — including that Veliard Ltd processes their data on your behalf, and that this agreement governs it.
- Where injury, restriction, medical or physiological data is recorded, you hold the athlete’s explicit consent under Article 9(2)(a), or another Article 9 condition, and you can evidence it.
- Where an athlete is below the age of digital consent where they live, you hold the consent or authorisation of the holder of parental responsibility, and you can evidence it.
- Your instructions to us, and the data you upload, do not breach any law or any obligation you owe the athlete.
- You keep your own record of processing under Article 30 — ours does not discharge yours.
We will not police these, and we are not in a position to: we cannot see whether a parent consented. That is why they are your warranties, and why 08.12 of the terms of service makes you indemnify us for claims arising from their breach.
09.5Confidentiality
Everyone we authorise to process athlete data is bound by an enforceable duty of confidentiality — by contract for employees and contractors, by professional obligation where that applies — and that duty survives the end of their engagement. Access is granted on need, reviewed, and withdrawn when the need ends.
09.6Security measures
We implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the cost of implementation, and the risk to the people whose data it is. These are commitments, not aspirations:
- Encryption. TLS in transit; encryption at rest for the database, backups and object storage.
- Access control. Role-based access to production, multi-factor authentication required, individual accounts with no shared credentials, access reviewed at least ⟨quarterly⟩.
- Tenant separation. One coach cannot read another’s roster. Separation is enforced in the data layer, so an interface bug cannot expose it.
- Credentials. Passwords stored only as salted hashes from a memory-hard function. Never stored or logged recoverably.
- Logging. Administrative and production access is logged, and the logs are retained ⟨12 months⟩ and protected from alteration by the people they record.
- Resilience. Automated backups, encrypted, with restoration tested at least ⟨annually⟩ rather than assumed to work.
- Development. Code review before merge, dependency scanning, and no production personal data in development or test environments.
- Vulnerability management. Security patches applied on a defined schedule by severity; ⟨periodic⟩ penetration testing.
- Deletion. Documented, automated deletion paths — not a manual query someone has to remember to run.
We may change a measure, provided the level of security is not reduced. Material reductions are notified in advance.
09.7Sub-processors
You give general authorisation for us to engage sub-processors. The current list is maintained in the platform privacy policy, and each is engaged under a written contract imposing the same obligations as this agreement — in particular the security measures in 09.6.
We give you at least 30 days’ notice before adding or replacing a sub-processor. If you object on reasonable data protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate the affected part of the service and receive a refund of the unused part of what you paid.
We remain fully liable to you for a sub-processor’s performance of its data protection obligations. Their failure is our failure.
09.8Requests from data subjects
The platform gives you the functions to answer an athlete’s request yourself — access, export, correction and deletion are all available to you in the interface, which is the fastest route and does not need us.
Where an athlete comes to us instead, we do not answer on your behalf. We tell them we act on your instructions, tell them who you are so they know whom to ask, and pass the request to you without undue delay. Taking account of the nature of the processing, we assist you by appropriate technical and organisational measures in meeting your obligation to respond.
One exception, and it is deliberate: an athlete’s own account — their credentials, devices and sessions — is ours as controller, and we will delete it at their request without asking you. That does not delete the training record you hold in your roster, which stays yours to decide.
09.9Personal data breach
We notify you of a personal data breach affecting athlete data without undue delay after becoming aware of it, and in any event within 24 hours, so that you can meet your own 72-hour deadline under Article 33.
The notification describes, so far as we know it at the time:
- The nature of the breach, including the categories and approximate number of data subjects and records concerned.
- The likely consequences.
- The measures taken or proposed to address it and mitigate its effects.
- A contact point for more information.
Where we cannot provide all of it at once we provide it in phases, without further undue delay. We do not notify your athletes or a supervisory authority on your behalf unless you instruct us to — that decision is the controller’s.
09.10Impact assessments and prior consultation
Taking account of the nature of processing and the information available to us, we assist you in meeting Articles 32 to 36 — security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
In practice that means giving you the information about our processing, sub-processors and security measures that a DPIA needs. You are likely to need one: training data about athletes, potentially including minors and Article 9 entries, on a platform used systematically is a combination that meets several of the Article 35(3) and Article 29 Working Party criteria.
09.11Return and deletion
At the end of the service you choose, at your option, whether we return or delete the athlete data. The platform provides export in a structured, commonly used, machine-readable format, and you can take it at any time without asking us.
Unless you tell us otherwise, we delete athlete data 30 days after the service ends, giving you that window to export. Deletion propagates to backups as they expire on their own schedule rather than by editing them; until then the data is inert and restorable only as part of a whole-system recovery.
We keep data beyond that only where EU or member state law requires it, and if that happens we tell you what and why.
09.12Audits and information
We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance we satisfy this with documentation: our security measures, sub-processor list, and any third-party audit report or certification we hold — none currently held. Where that is genuinely insufficient for your obligations, you may audit on reasonable notice, no more than once a year unless a supervisory authority requires it or we have had a breach affecting your data, during business hours, without unreasonable disruption, and subject to confidentiality. Each party bears its own costs, unless the audit finds a material breach on our side, in which case we bear yours.
09.13International transfers
Athlete data is hosted in an EU region, and we keep processing inside the EEA where we can.
Where a sub-processor processes athlete data outside the EEA, the transfer relies on an adequacy decision or on the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 — Module Three, processor to processor, since you are the controller — with a transfer impact assessment on file and supplementary measures where the assessment calls for them. Where you are established outside the EEA and we transfer to you, Module Four applies.
For US sub-processors we verify that the specific entity is certified under the EU–US Data Privacy Framework and remains on the list, rather than treating the Framework as covering a group, and we keep Standard Contractual Clauses in place as a fallback. By entering this agreement you mandate us to conclude Standard Contractual Clauses with sub-processors in your name where that is the mechanism required.
09.14Liability, term and changes
Each party is liable for its own compliance. Under Article 82(2), a processor is liable for damage caused by processing where it has not complied with obligations directed specifically at processors, or where it has acted outside or contrary to lawful instructions — and we do not attempt to contract out of that. A data processing agreement allocates responsibility between us; it does not transfer our statutory liability to you or yours to us.
Subject to that, the limitations in 08.12 of the terms of serviceapply to claims under this agreement, and the two are read together rather than as separate caps.
This agreement runs for as long as we process athlete data for you. We may update it where the law or the service changes, on at least 30 days’ notice; if an update materially reduces your protection you may terminate before it takes effect. Provisions that by their nature should survive termination — confidentiality, deletion, liability — do.
Need a signed copy, or a negotiated DPA?
Write to us