CountyConsentCountyConsentLegal / Data Processing Agreement

Data Processing Agreement (DPA)

Last updated: 15 June 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between SentinelHQ Ltd ("Processor", "we") and the customer organisation ("Controller", "you") using the CountyConsent Service. It governs the processing of personal data carried out by us on your behalf.

1. Roles

You are the data controller and SentinelHQ Ltd is the data processor in respect of personal data processed through the Service, including personal data relating to junior golfers, parents/guardians and your staff.

2. Scope and purpose of processing

ItemDetail
Subject matterProvision of junior safeguarding and consent management software
DurationFor the term of the subscription and any agreed retention period
Nature and purposeStorage, organisation, retrieval and transmission of consent and safeguarding data
Type of personal dataNames, dates of birth, contact details, parental consent responses, and related safeguarding information
Categories of data subjectsJunior golfers (children), parents/guardians, club/county staff

3. Our obligations as processor

We will:

  • Process personal data only on your documented instructions, including via the Service's features, unless required by law;
  • Ensure persons authorised to process the data are bound by confidentiality;
  • Implement appropriate technical and organisational security measures (including encryption in transit, access controls, row-level security and audit logging);
  • Assist you, taking into account the nature of processing, in responding to data subject rights requests;
  • Assist you with your obligations regarding security, breach notification and data protection impact assessments;
  • Notify you without undue delay on becoming aware of a personal data breach;
  • At your choice, delete or return all personal data at the end of the provision of services, and delete existing copies unless legally required to retain them;
  • Make available information necessary to demonstrate compliance and allow for audits.

4. Children's data

We acknowledge that the Service processes the personal data of children. We will handle such data with particular care, consistent with the UK GDPR and the ICO's Age Appropriate Design Code. You remain responsible for obtaining valid parental consent and for the lawful basis of processing children's data.

5. Subprocessors

You authorise us to engage the following subprocessors:

SubprocessorPurposeLocation
SupabaseDatabase and hostingIreland (eu-west-1)
VercelApplication hostingLondon (lhr1)
ResendTransactional emailUnited States
StripePayment processingUnited States / global

We will inform you of any intended changes to subprocessors and give you the opportunity to object. We remain responsible for our subprocessors' compliance.

6. International transfers

Where personal data is transferred outside the UK, we will ensure an appropriate safeguard is in place (UK adequacy regulations or the UK International Data Transfer Agreement / Addendum to the EU SCCs).

7. Security

We maintain a documented set of technical and organisational measures appropriate to the risk, reviewed periodically. Details are available on request.

8. Breach notification

We will notify you without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting your data, providing the information you need to meet your own notification obligations.

9. Liability and term

This DPA is governed by the same liability provisions, term and governing law as the Terms of Service. In the event of conflict between this DPA and the Terms regarding data protection, this DPA prevails.

10. Contact

Data protection contact: SentinelHQ Ltd — hello@sentinelhq.co.uk.