01Parties & definitions
This Data Processing Agreement ("DPA") is between The Mother Goose Group Ltd, trading as WRDRB™ (Company No. 17250953) ("Processor", "we") and the organisation with a WRDRB account ("Controller", "you"), together with these Terms of Service. It applies from the date you create a paid-tier account and for as long as we process personal data on your behalf.
"UK GDPR", "personal data", "processing", "controller", "processor" and "data subject" have the meanings given in the UK General Data Protection Regulation and the Data Protection Act 2018. "Personal Data Breach" has the meaning given in UK GDPR Article 4(12).
02Scope & roles
You are the Controller of the personal data you enter into WRDRB about your staff, players, members or volunteers ("Customer Personal Data") — you decide who's on your roster, what's collected about them, and why. We are the Processor: we process Customer Personal Data only to provide the platform, strictly on your documented instructions as set out in this DPA and our Terms.
This DPA does not apply to data where WRDRB is itself the controller (your own account/billing details as an organisation) — that's covered by our Privacy Policy.
03Processing on your instructions
We will process Customer Personal Data only:
- To provide, maintain and support the WRDRB platform as described in our Terms of Service
- In accordance with your documented instructions — which include the instructions built into how the platform works (e.g. what an admin enters, edits or deletes) and any further written instructions you give us
- As required by UK law, in which case we'll tell you before processing, unless the law prohibits this
If we believe an instruction infringes UK GDPR or other data protection law, we'll tell you and may suspend that specific processing until it's resolved.
04Confidentiality
We ensure that anyone we authorise to process Customer Personal Data (employees, contractors) is subject to a duty of confidentiality, whether contractual or statutory, and is trained appropriately for their role.
05Security
We implement appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing, and against accidental loss, destruction or damage, having regard to the state of the art, cost, and the nature, scope and purposes of processing. Details are set out in Annex 3.
06Sub-processors
You give us general authorisation to engage the sub-processors listed in Annex 2 to help us provide the platform. Before engaging a new sub-processor, or replacing one, we'll give you at least 14 days' notice by email. If you reasonably object on data protection grounds within that period, we'll work with you to address the concern; if we can't resolve it, either party may terminate the affected service.
We remain fully liable to you for any sub-processor's performance of their data protection obligations, and we impose obligations on each sub-processor equivalent to those in this DPA.
07International transfers
Our core database and email infrastructure are hosted in the EU/UK. Where any sub-processor transfers Customer Personal Data outside the UK or EEA, we ensure an appropriate safeguard is in place — Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision — before the transfer occurs.
08Assisting with data subject rights
Since you're the Controller, individuals should generally approach you directly to exercise their rights (access, rectification, erasure, etc.). Where the platform lets you handle these directly (e.g. editing or deleting a staff record yourself), you can act immediately without needing us. Where you need our help — for example, a full data export or permanent deletion beyond what the interface supports — we'll provide reasonable assistance within a reasonable timeframe, taking into account the nature of the request.
If an individual contacts us directly about their data, we'll tell you promptly and won't respond substantively without your instruction, unless legally required to.
09Assisting with compliance
We'll provide reasonable assistance, taking into account the information available to us, to help you comply with your own UK GDPR obligations, including:
- Data protection impact assessments, where processing via WRDRB is likely to result in high risk to individuals
- Prior consultation with the ICO, if required as a result of a DPIA
- Maintaining your records of processing activities, by providing information about how we process Customer Personal Data on your behalf
10Personal data breaches
If we become aware of a Personal Data Breach affecting Customer Personal Data, we will notify you without undue delay, and in any event within 48 hours of becoming aware, so you can meet your own 72-hour notification duty to the ICO where applicable. Our notification will include, as far as we're able at the time:
- The nature of the breach, including categories and approximate number of data subjects and records affected
- Likely consequences of the breach
- Measures taken or proposed to address it and mitigate harm
We'll cooperate with you and provide reasonable further information as it becomes available. Notifying you does not mean we accept fault or liability for the breach.
11Children's data
Where your roster includes individuals under 18 (common for grassroots and academy clubs), we apply additional safeguards to that data specifically — see §4 of our Privacy Policy. We never use it for marketing or any purpose beyond kit/uniform administration, and access remains scoped to your organisation's authorised admins only.
As Controller, you remain responsible for establishing a lawful basis for processing a minor's data (including, where relevant, parental/guardian awareness or consent under your own club's membership terms) and for entering only what's necessary for kit administration.
12Audits
We'll make available to you information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. Given the practicalities of a shared multi-tenant platform, we ask that audits be scheduled with reasonable notice (at least 14 days), conducted during business hours, and — where a report from an independent third-party audit or security review is available — that this is accepted in place of an on-site audit where it reasonably addresses your concerns.
13Deletion & return of data
On termination of your account, at your choice we will either delete or return all Customer Personal Data, and delete existing copies, within 30 days — unless UK law requires us to retain it, in which case we'll continue to protect it and process it only for that retention purpose. You can export your data at any time while your account is active.
14Liability
Each party's liability under this DPA is subject to the limitation of liability set out in our Terms of Service. Nothing in this DPA relieves either party of its own direct obligations and liabilities under UK GDPR.
15Term & general
This DPA takes effect on the date you create a paid-tier account and continues for as long as we process Customer Personal Data on your behalf. It's governed by the laws of England and Wales, consistent with our Terms of Service. If there's a conflict between this DPA and the Terms on data protection matters, this DPA prevails.
Details of processing
| Subject matter | Provision of the WRDRB kit/uniform management platform |
|---|---|
| Duration | For the term of the Customer's subscription, plus the deletion/export period described in §13 |
| Nature & purpose | Storage, organisation, retrieval, issuing/return tracking, and reporting of kit and uniform records against named individuals |
| Categories of data subjects | The Controller's staff, players, members, volunteers and administrators — including, where applicable, minors under 18 |
| Categories of personal data | Name, email, role/department, clothing sizes, kit issued/returned history, requests, policy acknowledgements, login/audit activity |
| Special category data | None collected by design. The Controller should not enter special category data (health, religion, ethnicity etc.) into free-text fields. |
Authorised sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU/UK |
| Stripe | Payment processing | UK/EU, with onward transfer safeguards |
| Resend | Transactional email | EU (Ireland) |
| Netlify | Application hosting | Global CDN, transfer safeguards apply |
| Tawk.to | Live chat support | Transfer safeguards apply |
Current sub-processor changes are notified per §6. An up-to-date list is always available at this page.
Technical & organisational security measures
- Tenant isolation: row-level security enforced at the database layer, so one organisation cannot access another's data even in the event of an application-layer fault
- Access control: role-based access within each organisation (admin vs. staff/member); WRDRB personnel access to production data is limited to what's needed for support and maintenance
- Encryption: data encrypted in transit (TLS/HTTPS) and at rest
- Authentication: passwords hashed, never stored in plain text; multi-admin access via token-based invites
- Audit logging: key actions (issuing, returns, admin changes) are logged and retained per our retention schedule
- Payment data: card data handled entirely by Stripe; never stored on WRDRB systems
- Backups: automated backups maintained by our infrastructure provider
- Breach response: documented internal process for detecting, assessing and notifying Personal Data Breaches per §10