1. Scope and Application
This Data Processing Addendum ("DPA") supplements the MUNAUGHT Terms & Conditions where MUNAUGHT processes personal data on behalf of a business customer, sports federation, or enterprise client in the course of providing software or hosting services.
2. Roles of the Parties
Depending on the service structure and applicable data protection law:
- The Customer acts as the Data Fiduciary / Data Controller regarding personal data uploaded into the system.
- MUNAUGHT acts as the Data Processor / Service Provider processing data solely on behalf of and according to documented customer instructions.
3. Purpose and Scope of Processing
MUNAUGHT processes personal data strictly as necessary to execute contracted services, provision hosting, maintain system uptime, prevent cybersecurity breaches, and comply with applicable statutory mandates.
4. Confidentiality of Personnel
MUNAUGHT ensures that all personnel authorized to access customer personal data have committed themselves to confidentiality obligations.
5. Subprocessors
MUNAUGHT engages trusted subprocessors (cloud data centers, payment gateways, upstream domain registries, email relays) to provide infrastructure components. Subprocessors are bound by data protection obligations consistent with this DPA.
6. Security Incident Notification
In the event of a confirmed security incident impacting customer personal data, MUNAUGHT will notify the affected customer without undue delay and provide relevant information to assist in regulatory compliance.
7. Data Deletion and Return
Upon contract termination, MUNAUGHT will delete or return customer data upon request, subject to mandatory statutory retention periods under applicable law.