Data Processing Agreement (DPA)
Last updated: 15 June 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between SentinelHQ Ltd ("Processor", "we") and the customer organisation ("Controller", "you") using the CountyConsent Service. It governs the processing of personal data carried out by us on your behalf.
1. Roles
You are the data controller and SentinelHQ Ltd is the data processor in respect of personal data processed through the Service, including personal data relating to junior golfers, parents/guardians and your staff.
2. Scope and purpose of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of junior safeguarding and consent management software |
| Duration | For the term of the subscription and any agreed retention period |
| Nature and purpose | Storage, organisation, retrieval and transmission of consent and safeguarding data |
| Type of personal data | Names, dates of birth, contact details, parental consent responses, and related safeguarding information |
| Categories of data subjects | Junior golfers (children), parents/guardians, club/county staff |
3. Our obligations as processor
We will:
- Process personal data only on your documented instructions, including via the Service's features, unless required by law;
- Ensure persons authorised to process the data are bound by confidentiality;
- Implement appropriate technical and organisational security measures (including encryption in transit, access controls, row-level security and audit logging);
- Assist you, taking into account the nature of processing, in responding to data subject rights requests;
- Assist you with your obligations regarding security, breach notification and data protection impact assessments;
- Notify you without undue delay on becoming aware of a personal data breach;
- At your choice, delete or return all personal data at the end of the provision of services, and delete existing copies unless legally required to retain them;
- Make available information necessary to demonstrate compliance and allow for audits.
4. Children's data
We acknowledge that the Service processes the personal data of children. We will handle such data with particular care, consistent with the UK GDPR and the ICO's Age Appropriate Design Code. You remain responsible for obtaining valid parental consent and for the lawful basis of processing children's data.
5. Subprocessors
You authorise us to engage the following subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database and hosting | Ireland (eu-west-1) |
| Vercel | Application hosting | London (lhr1) |
| Resend | Transactional email | United States |
| Stripe | Payment processing | United States / global |
We will inform you of any intended changes to subprocessors and give you the opportunity to object. We remain responsible for our subprocessors' compliance.
6. International transfers
Where personal data is transferred outside the UK, we will ensure an appropriate safeguard is in place (UK adequacy regulations or the UK International Data Transfer Agreement / Addendum to the EU SCCs).
7. Security
We maintain a documented set of technical and organisational measures appropriate to the risk, reviewed periodically. Details are available on request.
8. Breach notification
We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting your data, providing the information you need to meet your own notification obligations.
9. Liability and term
This DPA is governed by the same liability provisions, term and governing law as the Terms of Service. In the event of conflict between this DPA and the Terms regarding data protection, this DPA prevails.
10. Contact
Data protection contact: SentinelHQ Ltd — hello@sentinelhq.co.uk.