Data Processing Agreement
Last updated: 18 August 2026
This Agreement governs Troop's processing of personal data on behalf of your club. It forms part of the Terms of Service and applies automatically to every club using Troop — you do not need to sign a separate copy, though we will counter-sign one on request.
1. The parties and their roles
The Club (you) is the controller. You decide which children and members are enrolled, what information is collected about them, and why.
My Task Master Ltd, company number 16878946, Flat 93 March Court, Warwick Drive, London SW15 6LD, trading as Troop, is the processor. We process that data only on your documented instructions, which are given through your use of the software and through this Agreement.
For a narrow set of matters Troop decides for itself — account security, our own billing records, and this website — Troop is a controller in its own right. That processing is described in the Privacy Policy and is outside this Agreement.
2. Subject matter, duration, nature and purpose
- Subject matter and purpose — providing the Troop service: class scheduling and registers, bookings and waitlists, family and member records, communications with families, payment collection, and incident reporting.
- Nature of processing — collection, storage, structuring, retrieval, transmission to the recipients you direct, and erasure.
- Duration — for as long as your club has an account, plus the retention periods in §7.
3. Categories of data subject and personal data
Troop is built to hold as little about a child as the service can function on. The full inventory is:
- Children— first name, date of birth (for age banding), one free-text “essential information” field, answers to the registration questions your club defines, attendance, progress and award records, and — where your club enables them — consented photographs and accident or incident reports.
- Guardians and adult members — name, email address, telephone number, relationship to the child, and payment records. Card details are never held by Troop (see §5).
- Club staff — name, email address, role, and the qualification and vetting records your club chooses to store, such as DBS and first-aid expiry dates.
Special category data. Essential-information fields, registration answers flagged as medical or allergy-related, and accident and incident reports are health data under UK GDPR Article 9. Troop restricts them to your own staff for the classes concerned, never exports them in bulk, and holds no free-text medical history or safeguarding case-note module at all.
4. Your instructions, and our staff
We process personal data only on your documented instructions, including on international transfers, unless required otherwise by law — in which case we will tell you before processing, unless the law forbids it. We will tell you if we consider an instruction to infringe data protection law.
Everyone we authorise to process the data is bound by a duty of confidentiality that survives the end of their engagement.
5. Sub-processors
You give general authorisation for the sub-processors below. Each is bound by written terms no less protective than this Agreement.
- Supabase — database, authentication and file storage. Region: London (eu-west-2).
- Vercel — application hosting and request logs. Region: London (lhr1).
- Amazon Web Services (SES) — transactional email delivery. Region: London (eu-west-2).
- Stripe — payment processing. Card details go directly to Stripe and are never seen or stored by Troop. Payments use Stripe Connect direct charges, so your club is the merchant of record for its own transactions.
- Expo — delivery of push notifications to the mobile app, where your families use it.
We will give you at least 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, you may terminate the affected part of the service without penalty for the unused term.
Troop does not currently run any analytics or advertising service, and no analytics processor receives your families' data. If that changes it will be added under the notice period above and reflected in the Cookie Policy.
6. Security
Measures in place today, not aspirations:
- Encryption in transit (TLS) and at rest.
- Row-level security enforced in the database itself, so a club can only read its own records and a guardian only their own family's — the isolation does not depend on application code being correct.
- Role-based access: administrators, coaches and guardians each see a different, enforced subset.
- Card data never touches Troop's systems.
- Administrative access to production data is limited to Troop's named operator.
- Backups are performed by our database provider under its own retention schedule; we will confirm the current schedule in writing on request.
7. Personal data breaches
We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where we cannot provide all of it at once, we will provide it in phases without further undue delay.
Reporting to the ICO, and to affected families where required, remains the Club's decision as controller. We will give you the information and assistance you need to make it.
8. Assistance, audit, return and deletion
Data subject rights.Troop provides self-service export and deletion for a family's own data, and gives club administrators the tools to respond to access, rectification, erasure, restriction and portability requests. Where those tools are not enough, we will help you on request.
Impact assessments. We will give you reasonable assistance with data protection impact assessments and any prior consultation with the ICO.
Audit. We will make available the information needed to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, by you or an auditor you mandate, on reasonable notice and no more than once in any twelve months unless a breach or a regulator requires otherwise.
Return and deletion. On termination you may export your data. At your choice we will delete or return it, and delete existing copies, within 90 days, except where UK law requires retention — financial records are kept for six years for tax purposes, and invoice records are anonymised rather than deleted so that a club's accounts remain intact.
9. International transfers
All primary processing takes place in the United Kingdom: Supabase in London (eu-west-2), Vercel in London (lhr1), and AWS SES in London (eu-west-2). Where a sub-processor processes data outside the UK — Stripe and Expo operate globally — the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by an adequacy decision.
10. Contact
Data protection enquiries, audit requests and breach notifications: hello@mbo9.com. We aim to respond within five working days.
Questions about how a specific child's data is handled should go to your club first — as controller, they decide what is collected and why.