AAU Club Manager

Data Processing Agreement

Between the Organisation (Data Controller) and the Platform Operator (Data Processor)

Version 1.0 - Draft for legal review. This Agreement forms part of the Terms of Service accepted when an Organisation registers on the AAU Club Manager platform and applies to all Personal Data the Organisation processes through the Platform. Defined terms follow the Personal Data Protection Act 2010 (Malaysia) as amended ("PDPA").

1. Parties and roles

1.1 "Controller" means the club, academy, society or other organisation that registered the Platform account (the "Organisation"). The Controller determines the purposes and means of processing the Personal Data of its members, participants, parents/guardians, coaches and staff ("Organisation Data").

1.2 "Processor" means the operator of the Platform (legal name, registration number and address as published on the Platform's privacy settings page).

1.3 The Processor is itself the Controller of, and this Agreement does not apply to, Platform Account Data: the Organisation administrator's login account, subscription and invoicing records between the Processor and the Organisation, support communications, and the affiliate programme. That processing is described in the Platform Privacy Notice.

2. Subject matter, duration, nature and purpose

Item Description
Subject matter Provision of the Platform as a hosted software service for membership, enrolment, attendance, billing, assessment, tournament, certificate and communication management
Duration The term of the Organisation's subscription, plus the deletion / return period in clause 11
Nature of processing Storage, structuring, retrieval, display, transmission (email, push notification), generation of documents (invoices, receipts, certificates), automated reminders, deletion / anonymisation
Purpose To enable the Organisation to run its membership operations; the Processor processes Organisation Data only on the documented instructions of the Controller as embodied in the Platform's features and configuration
Categories of data subjects Members, participants (many of whom are children under 18), parents and guardians, coaches, staff, committee members, tournament participants, website contact-form senders
Categories of personal data Identity and contact details; date of birth, gender, nationality; IC/passport numbers and images; addresses; school details; guardian and emergency contacts; sensitive personal data (medical conditions, allergies, blood type) where the Controller chooses to collect it; enrolment, attendance and geolocation check-in records; assessments and coach notes; billing and payment records; uploaded documents and photographs; communications

3. Processor obligations

The Processor shall:

3.1 process Organisation Data only on the Controller's documented instructions, including instructions given through the Platform's configuration, unless required by Malaysian law, in which case the Processor will inform the Controller before processing unless the law prohibits it;

3.2 ensure that persons authorised to process Organisation Data are bound by confidentiality obligations and receive appropriate training;

3.3 implement and maintain the technical and organisational security measures in Schedule 1 in accordance with section 9 of the PDPA and the Personal Data Protection Standard 2015 (Security Standard), and not reduce their overall level of protection during the term;

3.4 not engage a sub-processor without the general authorisation in clause 6 and the notification procedure there;

3.5 taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures to respond to data subject requests (access, correction, withdrawal of consent, cessation of direct marketing, data portability) - the Platform's Privacy Centre and data request console are the primary means;

3.6 assist the Controller in meeting its obligations regarding security, data breach notification and any data protection impact assessment, taking into account the information available to the Processor;

3.7 at the Controller's election, delete or return Organisation Data at the end of the services in accordance with clause 11;

3.8 make available the information necessary to demonstrate compliance with this Agreement and allow for and contribute to audits under clause 9;

3.9 inform the Controller immediately if, in the Processor's opinion, an instruction infringes the PDPA.

4. Controller obligations

The Controller shall:

4.1 ensure it has a lawful basis under the PDPA for every category of Organisation Data it collects, including explicit consent under section 40 for sensitive personal data (health information) and parental or guardian consent for data subjects under 18;

4.2 provide data subjects with a privacy notice under section 7 of the PDPA (in English and Bahasa Malaysia) covering its own processing - the Platform provides a page for the Controller's supplementary notice and a platform-level notice describing the Processor's role;

4.3 collect only Personal Data that is necessary for its purposes (data minimisation) and configure optional fields accordingly;

4.4 grant Platform access to its administrators, coaches and staff on a least-privilege basis and remove access promptly when it is no longer needed;

4.5 respond to data subject requests routed to it through the Platform within the statutory 21 days;

4.6 comply with its own obligations regarding data breach notification, DPO appointment and registration as a data controller where applicable.

5. Confidentiality

Each party shall keep the other party's confidential information, including Organisation Data, confidential and use it only for the purposes of this Agreement, except as required by law.

6. Sub-processors

6.1 The Controller gives general authorisation for the Processor to engage the sub-processors listed in the Platform's public Sub-processor Register (available at /privacy/notice/#third-parties and in the Processor's compliance documentation).

6.2 The Processor shall notify the Controller (by email to the Organisation administrator and by updating the Register) at least 30 days before adding or replacing a sub-processor that processes Organisation Data. The Controller may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected services without penalty.

6.3 The Processor shall impose data protection obligations on each sub-processor that are no less protective than those in this Agreement and remains liable to the Controller for the sub-processor's performance.

7. Cross-border transfers

7.1 The Controller acknowledges that the sub-processors in the Register process Organisation Data outside Malaysia (principally in the United States and on global content-delivery networks) and authorises those transfers as necessary for the performance of this Agreement (PDPA section 129(3)).

7.2 The Processor shall ensure each such transfer is covered by a written contract with the sub-processor requiring protection of the data, shall carry out and keep a record of a transfer impact assessment where required by the Commissioner's Guideline on Cross-Border Personal Data Transfer, and shall inform the Controller of any material change in the destination country's protection.

8. Personal data breach

8.1 The Processor shall notify the Controller without undue delay and in any event within 48 hours after becoming aware of a personal data breach affecting Organisation Data, providing at least: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases.

8.2 The Controller, as data controller, is responsible for notifying the Personal Data Protection Commissioner (as soon as practicable and within 72 hours where the breach causes or is likely to cause significant harm) and affected data subjects (within 7 days of the Commissioner notification) in accordance with section 12B of the PDPA and the Data Breach Notification Regulations and Guideline. The Processor shall provide all reasonable assistance, and shall notify the Commissioner itself where the breach also concerns data for which the Processor is controller.

8.3 The Processor maintains a breach register and response procedure (Data Breach Response Policy).

9. Audit and cooperation

9.1 The Processor shall on request, no more than once per year unless a breach has occurred, provide the Controller with a written description of its security measures, the results of its automated security and tenant-isolation tests, and relevant third-party attestations of its hosting providers.

9.2 Where the Controller reasonably requires an audit beyond documentation, the parties shall agree the scope, timing, confidentiality and cost in advance; the audit shall not compromise the security or confidentiality of other Organisations' data.

10. Data subject rights

10.1 The Processor shall promptly route to the Controller any data subject request it receives that concerns Organisation Data, through the Platform's data request console, and shall not respond to such a request itself except as the Controller instructs or the law requires.

10.2 The Processor provides self-service tools (data export, consent management, correction of own profile) that the Controller may rely on to satisfy requests.

11. Deletion and return of data

11.1 On termination or expiry of the subscription the Controller may, within 30 days, export Organisation Data using the Platform's export functions.

11.2 After that period the Processor shall delete or anonymise Organisation Data within 90 days, except: (a) financial records the Processor must keep under the Income Tax Act 1967 and Companies Act 2016 (7 years), which are retained with identifying bill-to details redacted after that period; (b) backups, which are overwritten on the hosting provider's rotation schedule; (c) data the Processor is required by law to retain.

11.3 The Processor shall confirm deletion in writing on request.

12. Liability and indemnity

Each party's liability under this Agreement is subject to the limitations in the Terms of Service, save that nothing limits liability for a party's own breach of the PDPA that cannot be limited by law. Each party shall indemnify the other against penalties and third-party claims arising from that party's breach of its obligations under this Agreement.

13. Term and termination

This Agreement applies for as long as the Processor processes Organisation Data. Clauses 5, 11 and 12 survive termination.

14. Governing law

This Agreement is governed by the laws of Malaysia.


Schedule 1 - Technical and organisational measures

Area Measure
Tenant isolation Every query that returns Organisation Data is scoped to the requesting user's Organisation; exports fail closed when no Organisation scope can be determined; automated cross-tenant tests run in CI
Access control Role-based access (Super Admin, Club Admin, Coach, Staff, Parent, Trainee, Member, Affiliate); least privilege - coaches never see identity documents, medical details, or payment records; superadmin "manage as" access is audit-logged
Authentication Email + password (Django PBKDF2 hashing, minimum 8 characters, common-password and similarity validators); optional Google sign-in with PKCE; rate-limited login and password reset per IP and per account; email verification; 2-week session with HttpOnly, Secure, SameSite cookies; users can see and revoke their sessions
Encryption in transit TLS 1.2+ enforced (HSTS, preload)
Encryption at rest Hosting provider disk encryption; application-level Fernet encryption of payment-gateway credentials and temporary passwords; identity documents and payment proofs stored as private CDN assets delivered only via short-lived signed URLs after a permission check
Audit logging Login/logout/failed login, exports, file access, impersonation, consent changes, data subject request handling, anonymisation, retention runs, admin actions; retained 12 months
Data minimisation Optional profile fields; AI assistant payloads exclude dates of birth; email logs exclude recipient addresses
Retention Automated daily retention job with configurable periods (geolocation 90 days, tokens 30 days, audit log 12 months, invoices 7 years then redacted)
Breach management Breach register with 72-hour / 7-day deadline tracking; documented response procedure
Backups Hosting provider automated database backups; restore tested at least annually (Controller may request evidence)
Development practices Production data is never used in development or test environments; test suites use synthetic data; dependencies pinned and reviewed for vulnerabilities
Personnel Staff and contractors bound by confidentiality; production access limited to named administrators