Data Processing Agreement
Effective: · Version: 2026.04
1. Definitions
Capitalised terms not defined here have the meanings given in the GDPR (Regulation (EU) 2016/679) or UK GDPR. "Customer" means the entity using the TeamStores.AI Service. "TeamStores.AI" means TeamStores.AI Sport, Inc. "Personal Data" means any information that identifies, or could be used to identify, a natural person.
2. Scope
This DPA applies whenever TeamStores.AI Processes Personal Data on behalf of Customer in connection with the Service. It is incorporated by reference into the Terms of Service.
3. Roles of the parties
Customer is the Controller of Customer Personal Data. TeamStores.AI is the Processor. For Personal Data we collect about Customer's own end users for security, billing, or product analytics purposes, TeamStores.AI may act as an independent Controller; that processing is governed by our Privacy Policy.
4. Customer instructions
TeamStores.AI will Process Personal Data only on documented instructions from Customer, including with regard to transfers, unless required to do so by applicable law.
5. Data-subject rights
TeamStores.AI will provide reasonable assistance to enable Customer to respond to data-subject requests. Where appropriate, our self-service privacy dashboard at /me/privacy allows individuals to exercise access, deletion, and portability rights without involving Customer.
6. Sub-processors
Customer authorises TeamStores.AI to engage the sub-processors listed in our public subprocessor catalog. TeamStores.AI will provide notice of new sub-processors via the catalog and will impose data-protection terms substantially equivalent to this DPA on each sub-processor.
7. Security measures
TeamStores.AI implements technical and organisational measures appropriate to the risks, including encryption at rest and in transit, access controls and MFA, audit logging, vulnerability management, and a written incident-response plan. See our security posture page for the current control set.
8. Breach notification
TeamStores.AI will notify Customer without undue delay (and in any event within 72 hours where feasible) after becoming aware of a Personal Data breach, providing the information necessary for Customer to comply with its own notification obligations.
9. Deletion & return of data
Upon termination of the Service, TeamStores.AI will, at Customer's option, delete or return all Personal Data in its possession within 30 days, save where retention is required by law.
10. Audit
Customer may request, no more than once per twelve-month period, a copy of TeamStores.AI's most recent third-party security attestation (SOC 2 Type II or equivalent) and reasonable additional information needed to demonstrate compliance.
11. International transfers
Where Personal Data is transferred outside of the EEA, UK, or Switzerland to a country without an adequacy decision, the transfer relies on the EU Standard Contractual Clauses (and the UK Addendum, where applicable), incorporated by reference into this DPA.
12. Liability
Each party's liability arising out of or in connection with this DPA is subject to the aggregate liability cap set forth in the underlying Terms of Service.
13. Governing law
This DPA is governed by the laws of the State of Delaware, USA, except to the extent that mandatory data-protection law in another jurisdiction applies.