Skip to content
Legal center

Data Processing Addendum

Documented processing instructions, privacy roles, safeguards, subprocessors, rights requests, incidents, deletion, and audits.

Effective
2026-08-24
Version
2026.08
Audience
Leagues and organizations contracting for BagTag services

1. Scope and incorporation

This DPA forms part of an agreement under which BagTag processes personal data for a customer. It applies only to processing covered by privacy law and does not change the independent roles a party has for its own accounts, security, legal duties, employment, payments, external sites, or direct relationships.

2. Definitions and roles

Customer is the league or organization determining the documented purpose; BagTag is the processor, service provider, or contractor for that processing. Personal data, processing, controller, processor, sale, sharing, and similar terms have the meanings in applicable law. Each party is independently responsible where it determines purposes and means.

3. Processing details

  • Subject matter: youth-sports recognition, family verification, rewards, optional media, organization workspaces, support, reporting, and security.
  • Duration: the service term plus the documented export, deletion, backup, dispute, and legal-retention period.
  • People: adult family contacts, youth players, league staff, sponsor and partner staff, applicants, authorized officers, and public visitors.
  • Data: identifiers, contact information, team/game/award context, reward and redemption, optional content and permissions, organization/application data, device/network context, and audit/security records.
  • Purposes: provide, secure, support, measure, and legally administer the contracted service.

4. Customer instructions

BagTag processes customer personal data only on documented instructions in the agreement, configuration, authorized actions, and lawful support requests, unless law requires otherwise. BagTag will inform the customer if an instruction appears unlawful unless prohibited. The customer will not instruct BagTag to create child accounts, share claim emails with sponsors, use content beyond recorded permissions, or perform unlawful marketing or profiling.

5. Confidentiality and access

BagTag restricts access to personnel and contractors with a need to know, binds them to confidentiality, trains them for their role, and logs sensitive administrative actions where appropriate. Customer applies least privilege to its own members and is responsible for their instructions.

6. Security measures

Measures evolve with risk and technology and will not materially reduce overall protection during the term.

  • Encryption of sensitive family fields and transport encryption.
  • Keyed blind indexes and hashed bearer tokens.
  • Tenant and role authorization, session protection, and rate limiting.
  • Audit logging, monitoring, vulnerability and dependency review, backups, and recovery procedures.
  • Controlled provider credentials, media moderation states, and private administrative routes.
  • Incident response, access removal, and retention jobs.

7. Subprocessors

Customer gives general authorization for the subprocessors listed in the current Subprocessor List. BagTag remains responsible for their processing to the extent required by law and contract, uses appropriate written safeguards, and will provide notice of a material new category or provider where the agreement requires it. Customer may object on reasonable data-protection grounds within the stated notice period.

8. Rights requests

BagTag provides workflows and reasonable assistance for verified access, correction, deletion, media withdrawal, portability, objection, restriction, authorized-agent, appeal, and opt-out requests required by applicable law. Customer remains responsible for instructions and communications for processing it controls. A party receiving a request will route it without unnecessary disclosure.

9. Youth data

Customer directs adult-only flows, supplies required notices, determines whether COPPA or other youth law applies, obtains any required parental authority, minimizes data, and ensures optional content is not required for the reward. BagTag will not use customer youth data for targeted advertising, sale, unrelated profiling, or model training under this DPA.

10. Security incidents

BagTag will notify the customer's designated contact without undue delay after confirming a personal-data breach affecting customer data, provide information reasonably available about nature, scope, likely consequences, containment, and remediation, and cooperate with required notices. Notification is not an admission of fault. Customer promptly reports compromise of its users, devices, links, PINs, exports, or instructions.

11. Return, deletion, and retention

At termination or a valid instruction, BagTag will provide available exports and delete or pseudonymize customer personal data within the documented operational period, except where law, safety, fraud, consent proof, audit integrity, dispute, or enforcement requires retention. Provider copies and backups are removed under their technical schedules. Retained data remains protected and limited to the exception.

12. Assessments and audits

BagTag will make current security and compliance information reasonably available, answer proportionate questionnaires, and support a legally required assessment. An onsite or third-party audit requires reasonable notice, confidentiality, minimal disruption, scope tied to customer data, no exposure of other tenants, and customer payment of extraordinary costs unless a material BagTag breach caused the audit.

13. Transfers and conflict

BagTag will use a lawful transfer mechanism where covered personal data is transferred internationally. Mandatory privacy law controls over inconsistent contract text. Otherwise, the signed services agreement controls commercial issues and this DPA controls covered data-processing issues.

These documents describe the current BagTag service. A signed order or negotiated agreement may add terms for a particular organization. If you need this document in another format, use the accessibility contact in the legal center.