Data processing agreement
The terms behind “we process it on your behalf.”
This agreement applies whenever an instructor records information about a client in myski.pro. It forms part of the Terms of Use.
Last updated August 18, 2026
This agreement has been drafted but not yet reviewed by counsel, and it cannot be executed until the operating entity is named. It is published so instructors can read the terms they will be asked to accept. See item 7 of the pre-launch review.
1. Parties, roles, and scope
This Data Processing Agreement (“DPA”) is between the instructor who holds a myski.pro account (“Controller”) and myski.pro (“Processor”). It is incorporated into the Terms of Use and applies for as long as the Processor holds personal data on the Controller’s behalf.
The Controller determines which clients to record, what to record about them, and how long to keep it. The Processor stores, syncs, and retrieves that data on the Controller’s documented instructions and for no independent purpose of its own.
Where an instructor is employed by a ski school and the school determines the purposes of processing, the school may be the Controller. In that case this DPA applies between the school and the Processor, and the instructor acts under the school’s authority.
For the instructor’s own account data — name, email, credentials, profile — the Processor acts as controller in its own right, and the Privacy Policy governs.
2. Subject matter, duration, nature and purpose
- Subject matter: recordkeeping for ski lesson instruction.
- Duration: the term of the Controller’s account, plus the retention periods in clause 10.
- Nature: storage, synchronisation, retrieval, backup, and Controller-directed transmission.
- Purpose: enabling the Controller to remember a client and carry lesson progress forward.
Categories of data subject: ski lesson clients, including minors; parents and guardians; co-instructors named on a lesson.
Types of personal data: name; exact age and optional date of birth; gender; mobile number; guardian name and mobile number; ability, goals, terrain and lift preferences, risk tolerance, personality and confidence notes, food preferences, equipment notes; lesson history including date, duration, terrain, drills, strengths, areas to improve, and next focus; free-text medical, allergy, dietary, and emergency notes; and photographs or video the Controller attaches.
3. Processor obligations
The Processor will:
- Process personal data only on the Controller’s documented instructions, including on international transfers, unless required otherwise by law — in which case it will inform the Controller first unless that law forbids it.
- Not sell personal data, share it for cross-context behavioural advertising, use it for advertising or profiling, or use it to train machine-learning models. These restrictions survive termination.
- Ensure that personnel authorised to process personal data are bound by confidentiality.
- Implement the security measures in clause 6.
- Assist the Controller with data subject requests (clause 8), breach notification (clause 9), and any data protection impact assessment or prior consultation the Controller must carry out.
- Make available the information needed to demonstrate compliance with this DPA, and allow for audits under clause 12.
- Delete or return personal data at the end of the relationship under clause 10.
The Processor will tell the Controller if, in its opinion, an instruction infringes applicable data protection law.
4. Special-category and children’s data
Medical, allergy, dietary, and emergency notes are special-category data under Article 9 of the GDPR and sensitive personal information under several US state laws. A large share of the data subjects are children.
The Controller warrants that before recording information about a minor it has the permission of a parent or guardian, together with any authority required by its employer, ski school, contract, and applicable law, and that it has established an Article 9 condition — ordinarily explicit consent — for any special-category data. The Controller will stop recording, and delete the record, if that permission is withdrawn.
The Processor will keep special-category data within the Controller’s account, exclude it from every sharing artifact the product generates, never use it for any purpose beyond providing the service, and flag it explicitly in any breach notice.
The Processor does not direct the service to children, does not market it to children, and does not permit children to hold accounts.
5. Sub-processors
The Controller gives general authorisation for the Processor to engage sub-processors on the terms of this clause. The current sub-processors are:
- Microsoft Azure — application hosting, database, and backup.
- Apple — app distribution and, where applicable, sign-in and receipt handling.
- No others. There are no analytics, advertising, attribution, crash-reporting, email, or support sub-processors.
The Processor will impose data protection obligations on each sub-processor no less protective than those in this DPA, and remains fully liable for their performance. It will give the Controller at least 30 days’ notice before adding or replacing a sub-processor, by updating this page and the Privacy Policy. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Controller may terminate and export its data.
6. Security measures
Taking account of the state of the art and the risk to data subjects, the Processor maintains:
- Passwords hashed with Argon2id; credentials never stored in readable form.
- Access tokens expiring in 15 minutes and refresh tokens in 30 days; tokens held in the iOS Keychain, excluded from device backup.
- Server-side authorisation on every request, scoped to the authenticated account, so one account’s records are unreachable from another’s session.
- Parameterised database access only, with no dynamic query construction.
- Encryption in transit over HTTPS, and encrypted database connections with certificate validation enforced in production.
- Share tokens of 32 random bytes, stored only as hashes, expiring within 24 hours, use-limited, revocable, and issuable only for a record the caller already owns.
- Regular backups, and restoration testing appropriate to the size of the service.
7. International transfers
Where personal data is transferred out of the EEA or the UK, the parties rely on the European Commission’s Standard Contractual Clauses, and the UK Addendum where the UK GDPR applies, together with the data protection terms of the hosting sub-processor. The Processor will carry out a transfer impact assessment where one is required.
8. Data subject requests
The Processor will not respond to a data subject request about the Controller’s records on its own initiative, except to confirm receipt and to direct the person to the Controller, unless legally required or instructed otherwise.
Taking account of the nature of the processing, the Processor will assist the Controller by appropriate technical and organisational measures in meeting requests to access, correct, delete, restrict, object, or port. Where a parent or guardian contacts the Processor directly, it will acknowledge within two business days, verify identity, guardianship, or authority as appropriate, and route the request to the Controller, completing verified requests within 30 days.
9. Personal data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s records, and in any event in time for the Controller to meet its own 72-hour obligation under Article 33 of the GDPR.
The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected, whether records about children or special-category data are involved, the likely consequences, and the measures taken or proposed. Where the Processor is itself a controller, it notifies the supervisory authority within 72 hours and affected individuals without undue delay where the risk is high.
10. Deletion and return
On deletion of an account, or on termination of the relationship, the Processor deletes the Controller’s personal data from the active service within 30 days, and normally within seconds of an authenticated deletion request. Backups are overwritten on a rolling basis within 90 days.
Before deleting, the Controller may export its records. The Processor may retain personal data where law requires, for as long as that requirement lasts, and will protect it accordingly. Retention periods for individual categories are set out in section 8 of the Privacy Policy.
Copies held offline on a device, exports the Controller made, and records already received by another instructor are outside the Processor’s control and are not retrieved automatically.
11. Records of processing
The Processor maintains a record of the processing carried out on behalf of the Controller, as required by Article 30(2) of the GDPR, and makes it available to a supervisory authority on request.
12. Audit
The Processor will make available the information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits conducted by the Controller or an auditor it mandates. Audits are limited to once per year unless a breach or a supervisory authority requires otherwise, must be requested with reasonable notice, must not unreasonably disrupt the service, and are subject to confidentiality.
13. Order of precedence and changes
If this DPA conflicts with the Terms of Use or the Privacy Policy on the processing of client records, this DPA prevails. Changes are published on this page with the date at the top updated, and material changes are notified in advance.
14. Contact
Questions about this agreement, and any notice given under it: brandonfoster@me.com.