Legal
Data Processing Agreement
We do not publish a standard DPA yet. If your club or organisation needs one, email hello@infacta.com and we will send you the current document to review and sign. This page sets out what it covers so you know what to expect.
When your club uses Infacta products, you decide who belongs to the club, what roles they hold and what data you enter about them. That makes your club the data controller, and Groupmail Ltd — trading as Infacta — the processor acting on your instructions. A Data Processing Agreement is the contract that records that relationship, as Article 28 of the GDPR requires.
Who needs one
Any club or organisation that is itself subject to the GDPR and holds personal data about its members in an Infacta product. Many small clubs never sign one; some — particularly those with a data-protection officer, a public-body funder or an insurer that asks — do. If you are unsure whether you need one, ask us.
You do not need a DPA for your own personal Infacta account. For that, we are the controller and our Privacy Policy applies.
What it covers
- Subject matter and duration — what we process for you, and for how long: as long as your club’s account is active.
- Nature and purpose — operating the account service and the products your club uses, and nothing else.
- Categories of data and data subjects — the names, email addresses, roles and product access of the people your club invites, and anything your club enters in a product.
- Our obligations as processor — acting only on your documented instructions, keeping our people bound to confidentiality, and applying the security measures described in our Privacy Policy.
- Sub-processors — the providers we use to run the service, and notice before that list changes.
- International transfers — where data is processed, and the safeguards used when anything leaves the EEA.
- Assistance — helping you answer a member’s data-subject request, and telling you without undue delay about a personal data breach affecting your data.
- Return and deletion — what happens to your club’s data when you stop using the service.
- Audit — how you can satisfy yourself that we are doing the above.
Where your data is processed
The account service runs its application and database in the European Union (Frankfurt, Germany), so personal data is processed in the EU by default.
Our transactional-email provider may process limited data outside the EEA/UK. Where that happens, we rely on the European Commission’s 2021 Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum.
Sub-processors
We use a small number of trusted providers to run the service — cloud hosting and database (in the EU) and transactional email delivery. They process data on our instructions under their own data-protection terms. The signed DPA names each one, and we will tell you before that list changes.
Requesting one
Email hello@infacta.com with your club’s full legal name, the country it is established in, and who will sign. We will send the document back for review. If your organisation has its own DPA template it would rather use, send it along and we will read it.