Data Processing Agreement (DPA)
Last updated: [2026-08-27]
Version: 1.0
This Data Processing Agreement (“DPA”) forms part of the Terms of Service for Competely and applies where a Customer uses Competely to process personal data for which the Customer acts as data controller.
1. Parties
This DPA is entered into between:
Data Controller
The Customer, organiser, company, organisation or other legal entity using Competely to create, manage or run competitions, events, participant registrations, lead collection or result management.
In this DPA, the data controller is also referred to as the “Customer” or “Controller”.
Data Processor
Didgeridoo Event & Aktivitet AB
Company registration number: 556875-2231
Elverslösavägen 29
395 90 Kalmar
Sweden
Didgeridoo Event & Aktivitet AB provides the Competely service.
In this DPA, Didgeridoo Event & Aktivitet AB is also referred to as “Didgeridoo”, “Competely”, “we”, “us” or the “Processor”.
2. Background and purpose
The Customer uses Competely to create and manage competitions, events, participant registrations, competition results, leaderboards and, where applicable, exports of event data or leads.
Where the Customer collects or otherwise processes personal data relating to Participants, teams, contact persons or other individuals through Competely, the Customer will normally act as data controller.
Didgeridoo Event & Aktivitet AB processes such personal data on behalf of the Customer as data processor.
The purpose of this DPA is to govern such processing in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), and other applicable data protection law.
3. Scope of this DPA
This DPA applies to all processing of personal data carried out by Didgeridoo Event & Aktivitet AB on behalf of the Customer through Competely.
This DPA does not apply to personal data for which Didgeridoo Event & Aktivitet AB independently determines the purposes and means of processing and therefore acts as data controller.
This includes, for example, processing relating to:
- Customer accounts;
- subscriptions;
- billing;
- payments;
- Customer support;
- service communications;
- security relating to our own service administration; and
- management of the Customer relationship.
Such processing is described in Competely’s Privacy Policy.
4. Responsibilities of the Customer
The Customer is responsible for ensuring that its processing of personal data through Competely complies with applicable data protection law.
In particular, the Customer is responsible for:
- having an appropriate legal basis for the processing;
- providing Participants and other data subjects with legally required privacy information;
- collecting only personal data that is necessary for the relevant event or competition;
- ensuring that personal data entered into Competely is appropriate and relevant for the intended purpose;
- ensuring that its instructions to Competely comply with applicable law;
- avoiding the collection of special categories of personal data unless there is an appropriate legal basis and all required safeguards are in place;
- handling personal data exported from Competely lawfully and securely; and
- providing documented instructions to the Processor regarding the processing.
The Customer’s documented instructions consist of:
- this DPA;
- the Competely Terms of Service;
- the Customer’s configuration, settings and actions within Competely; and
- any additional written instructions expressly agreed between the parties.
The Customer warrants that it is entitled to instruct the Processor to process the personal data covered by this DPA.
5. Responsibilities of the Processor
Didgeridoo Event & Aktivitet AB will process personal data only on documented instructions from the Customer, unless processing is required by applicable EU or Member State law.
Where we are legally required to process personal data other than on the Customer’s instructions, we will inform the Customer of that legal requirement before processing, unless the applicable law prohibits us from doing so.
Didgeridoo Event & Aktivitet AB will:
- process personal data only for the purpose of providing and supporting Competely in accordance with the Customer’s documented instructions;
- not process Customer personal data for our own independent purposes;
- ensure that persons authorised to process personal data are subject to confidentiality obligations;
- implement appropriate technical and organisational security measures;
- assist the Customer with requests from data subjects where required under applicable law;
- assist the Customer with its obligations relating to security of processing, personal data breaches, data protection impact assessments and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to us;
- notify the Customer of personal data breaches as described in this DPA;
- provide information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR;
- allow for and contribute to audits as described in this DPA; and
- delete or return personal data when processing ends, in accordance with this DPA.
6. Subject matter, nature and purpose of the processing
The subject matter of the processing is the operation and provision of Competely on behalf of the Customer.
Processing may include:
- collection and storage of Participant data;
- registration, calculation and display of competition results;
- creation and display of leaderboards;
- administration of competitions, activities, teams and Participants;
- collection of data requested by the Customer;
- export of event data, competition results or leads;
- authentication and access control;
- technical operation;
- troubleshooting and support;
- security monitoring;
- logging; and
- backup and recovery.
The purpose of the processing is to enable the Customer to create, manage and run competitions, activities and events using Competely.
Further processing instructions are set out in Appendix 1.
7. Categories of data subjects
The personal data processed under this DPA may relate to:
- Participants in competitions or events;
- team members;
- team leaders;
- Customer representatives;
- Customer administrators;
- individuals appearing in uploaded images or other event material; and
- individuals whose information is entered into customised questions or fields configured by the Customer.
8. Categories of personal data
Depending on how the Customer configures Competely, personal data processed under this DPA may include:
- name;
- team name or team number;
- company or organisation;
- email address;
- telephone number;
- nationality;
- answers to customised questions;
- competition results;
- rankings;
- scores;
- images or other uploaded media;
- timestamps relating to registration and result submission;
- IP address;
- device information; and
- technical log information to the extent necessary for operation and security.
The Customer must not use Competely to collect special categories of personal data, national identification numbers, health information, religious or philosophical beliefs, political opinions, trade union membership, biometric data used for identification, or other particularly sensitive personal data unless such processing has been expressly agreed with Didgeridoo Event & Aktivitet AB and is lawful under applicable data protection law.
9. Duration of processing
Personal data will be processed for as long as the Customer uses Competely and for as long as the data is required to provide the Service in accordance with the Customer’s instructions.
Upon termination of the relevant services or upon a valid instruction from the Customer, personal data will be handled in accordance with Section 17 of this DPA.
Personal data may remain temporarily in backups after deletion from active systems until the relevant backups are rotated, overwritten or securely deleted in accordance with our backup procedures.
During such period, the data will remain protected and will not be restored or otherwise processed except where necessary for disaster recovery, security or compliance with applicable law.
10. Security measures
Didgeridoo Event & Aktivitet AB will implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access or other unlawful processing.
The measures will take into account:
- the state of the art;
- implementation costs;
- the nature, scope, context and purposes of processing; and
- the risks to the rights and freedoms of individuals.
Measures may include, where appropriate:
- access controls;
- administrator authentication;
- restricted access to personal data;
- encrypted transmission;
- logging of relevant security events;
- backup and recovery procedures;
- incident response procedures;
- secure development and maintenance practices;
- use of established infrastructure providers; and
- regular security updates and technical maintenance.
Further information about security measures is set out in Appendix 3.
11. Confidentiality
Didgeridoo Event & Aktivitet AB will ensure that employees, contractors, consultants and other persons authorised to process Customer personal data are subject to appropriate confidentiality obligations.
Personal data will not be disclosed to unauthorised persons unless instructed by the Customer or required by applicable law.
12. Subprocessors
The Customer grants Didgeridoo Event & Aktivitet AB general written authorisation to engage subprocessors where necessary to provide Competely.
Subprocessors may be used for services such as:
- hosting and infrastructure;
- database services;
- authentication;
- storage;
- email delivery;
- support;
- logging;
- security;
- error reporting; and
- technical monitoring.
Current subprocessors are listed in Appendix 2 or in an up-to-date subprocessor list made available by Competely.
Didgeridoo Event & Aktivitet AB will enter into appropriate contractual arrangements with subprocessors that impose data protection obligations that provide a level of protection substantially equivalent to the obligations applicable to Didgeridoo Event & Aktivitet AB under this DPA, to the extent required by Article 28 GDPR.
Didgeridoo Event & Aktivitet AB will inform the Customer of intended additions or replacements of subprocessors before the relevant change takes effect, thereby giving the Customer a reasonable opportunity to object.
The Customer may object to a new or replacement subprocessor where it has reasonable and documented grounds relating to data protection.
The parties will attempt in good faith to resolve such an objection.
If a reasonable solution cannot be reached, the Customer may discontinue the affected part of the Service or terminate the affected Service in accordance with the applicable Terms of Service.
Didgeridoo Event & Aktivitet AB remains responsible to the Customer for the performance of its subprocessors’ data protection obligations to the extent required under applicable law.
13. International transfers
Didgeridoo Event & Aktivitet AB will ensure that transfers of personal data outside the EU/EEA are carried out in accordance with applicable data protection law and the Customer’s documented instructions.
Where personal data is transferred to a country outside the EU/EEA that has not been recognised by the European Commission as providing an adequate level of protection, an appropriate transfer mechanism will be used.
Such mechanisms may include:
- the European Commission’s Standard Contractual Clauses;
- another legally recognised safeguard under Chapter V GDPR; or
- another lawful transfer mechanism available under applicable data protection law.
Where required, supplementary safeguards will be implemented taking into account the circumstances of the transfer.
14. Data subject rights
Taking into account the nature of the processing, Didgeridoo Event & Aktivitet AB will assist the Customer, through appropriate technical and organisational measures insofar as reasonably possible, in fulfilling the Customer’s obligations to respond to requests from data subjects.
Such requests may relate to:
- access;
- rectification;
- erasure;
- restriction of processing;
- objection;
- data portability; and
- other applicable rights under data protection law.
Where a data subject contacts Didgeridoo Event & Aktivitet AB directly regarding personal data for which the Customer is the Controller, we will not independently respond to the substantive request unless required by law.
Where appropriate, we will refer the individual to the Customer or forward the request to the Customer.
15. Personal data breaches
Didgeridoo Event & Aktivitet AB will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on behalf of the Customer.
To the extent that the relevant information is available to us, the notification will include information regarding:
- the nature of the personal data breach;
- the categories and approximate number of affected data subjects, where known;
- the categories and approximate number of affected personal data records, where known;
- the likely consequences of the breach;
- measures taken or proposed to address the breach and mitigate its possible adverse effects; and
- a contact point for further information.
Where all information is not available at the same time, it may be provided in phases without undue further delay.
Didgeridoo Event & Aktivitet AB will reasonably assist the Customer with investigating and responding to the incident.
The Customer, as Controller, is responsible for determining whether the breach must be notified to a supervisory authority or communicated to affected data subjects, except where applicable law provides otherwise.
16. Compliance information and audits
Didgeridoo Event & Aktivitet AB will make available to the Customer information reasonably necessary to demonstrate compliance with the obligations applicable to processors under Article 28 GDPR and this DPA.
Where such information is not sufficient for the Customer to reasonably verify compliance, the Customer may request an audit.
Audits must:
- be requested in writing;
- normally be carried out with reasonable advance notice;
- take place during normal business hours where applicable;
- be limited to matters relevant to processing under this DPA;
- avoid unreasonable disruption to Competely’s operations; and
- be conducted in a manner that protects the security, confidentiality, personal data and commercially sensitive information of Didgeridoo Event & Aktivitet AB and other Customers.
Where appropriate, an audit may initially be satisfied through available documentation, certifications, reports or written responses.
The Customer may conduct an audit itself or appoint an independent auditor that is not a direct competitor of Didgeridoo Event & Aktivitet AB and is subject to appropriate confidentiality obligations.
Reasonable assistance relating to ordinary compliance enquiries is included in the Service.
Where an audit requested by the Customer requires substantial work beyond ordinary compliance obligations, Didgeridoo Event & Aktivitet AB may charge reasonable costs for that additional work, provided that such charges do not prevent the Customer from exercising its rights under applicable data protection law.
We will not charge additional fees for an audit where the audit is reasonably required as a result of a material breach of this DPA by Didgeridoo Event & Aktivitet AB.
17. Return and deletion of personal data
Upon termination of the processing services, Didgeridoo Event & Aktivitet AB will, at the Customer’s choice, delete or return the personal data processed on the Customer’s behalf and delete remaining copies, unless applicable EU or Member State law requires continued storage.
The Customer may be able to export certain data directly through the functionality available in Competely.
Where the Customer chooses return of the data, the Customer should export or otherwise request the relevant data before account deletion where reasonably required by the technical design of the Service.
Personal data may remain temporarily in backups after deletion from active systems until such backups are rotated, overwritten or deleted according to our backup procedures.
Any personal data retained in backups will remain subject to this DPA and will not be used for any other purpose.
18. Unlawful instructions
If Didgeridoo Event & Aktivitet AB considers that an instruction from the Customer infringes the GDPR or other applicable data protection law, we will inform the Customer without undue delay unless prohibited from doing so by law.
We may suspend the execution of the relevant instruction until the Customer confirms, modifies or withdraws the instruction.
Nothing in this DPA requires Didgeridoo Event & Aktivitet AB to carry out processing that would violate applicable law.
19. Assistance requiring additional work
Reasonable assistance necessary for compliance with this DPA is included as part of the Service.
Where the Customer requests substantial additional work beyond the ordinary operation of Competely or our normal obligations under this DPA, such as:
- customised manual exports;
- extensive investigations unrelated to a breach by Didgeridoo Event & Aktivitet AB;
- bespoke audit procedures;
- specialised reports; or
- substantial manual assistance,
Didgeridoo Event & Aktivitet AB may charge reasonable fees for such work.
Any such fees will not limit obligations that the Processor is required to perform without restriction under applicable data protection law.
20. Term
This DPA remains in effect for as long as Didgeridoo Event & Aktivitet AB processes personal data on behalf of the Customer in connection with Competely.
Relevant provisions of this DPA will continue to apply for as long as personal data remains in the possession or control of Didgeridoo Event & Aktivitet AB or its subprocessors.
21. Relationship with other terms
This DPA forms part of the agreement governing the Customer’s use of Competely.
In the event of a conflict between this DPA and the Competely Terms of Service, this DPA will take precedence in matters relating to the processing of personal data where the Customer acts as Controller and Didgeridoo Event & Aktivitet AB acts as Processor.
22. Governing law and disputes
This DPA is governed by Swedish law.
Disputes relating to this DPA will be handled in accordance with the dispute provisions in the Competely Terms of Service, unless otherwise required by mandatory law.
Appendix 1 – Processing Instructions
1. Purpose
Personal data may be processed for the purpose of providing Competely and enabling the Customer to create, manage and run competitions, events, participant registrations, result reporting, leaderboards, event-data exports and related support.
2. Processing operations
Didgeridoo Event & Aktivitet AB may perform the following processing operations on behalf of the Customer:
- collect data through the Customer’s use and configuration of the Service;
- receive data submitted by Participants;
- store personal data;
- organise and structure personal data;
- display personal data in administrative interfaces, Participant interfaces and leaderboards in accordance with the Customer’s settings;
- calculate, structure and compile competition results;
- make data available for export by the Customer;
- delete personal data;
- create backups;
- log technical events necessary for operation and security; and
- access personal data where reasonably necessary for troubleshooting and support.
3. Categories of personal data
Processing may include:
- name;
- team name or team number;
- company or organisation;
- email address;
- telephone number;
- nationality;
- answers to customised questions;
- results;
- rankings;
- scores;
- images or other media;
- timestamps; and
- technical logs and related device or network information where required for operation and security.
4. Categories of data subjects
Processing may relate to:
- event Participants;
- competition Participants;
- team leaders;
- team members;
- Customer administrators;
- Customer contact persons; and
- individuals appearing in uploaded content.
5. Duration
Processing will continue for as long as the Customer uses Competely and for as long as the personal data is required to provide the Service, unless the Customer validly instructs earlier deletion or continued storage is required by applicable law.
Appendix 2 – Subprocessors
Didgeridoo Event & Aktivitet AB currently uses the following subprocessors in connection with the processing covered by this DPA:
Supabase
Purpose: Hosting infrastructure, database, authentication, storage and real-time functionality.
Location of processing: [CONFIRM SUPABASE PROJECT REGION AND RELEVANT PROCESSING LOCATIONS]
Role: Provides core technical infrastructure used to operate Competely and may process Customer personal data on behalf of Didgeridoo Event & Aktivitet AB.
Additional subprocessors
Didgeridoo Event & Aktivitet AB may use additional subprocessors for services such as email delivery, support, error reporting, logging, security monitoring or technical infrastructure where those providers process personal data covered by this DPA.
An up-to-date list of subprocessors will be made available to Customers, either through the Competely website, within the Service or upon request.
Appendix 3 – Technical and Organisational Security Measures
Didgeridoo Event & Aktivitet AB maintains technical and organisational measures appropriate to the risks associated with the processing carried out through Competely.
Measures may include, where applicable:
- restricted access to personal data based on authorised roles and business need;
- access and permission management;
- authentication for administrators;
- encrypted communications in transit;
- secure development and maintenance practices;
- procedures for applying security updates;
- incident response procedures;
- backup and recovery procedures;
- use of established infrastructure and technology providers;
- logging of relevant technical and security events;
- procedures for deleting personal data when it is no longer required;
- confidentiality obligations for persons with authorised access; and
- internal procedures governing access, support and handling of personal data.
These measures may be updated as Competely develops and as technology and risks change, provided that the overall level of protection is not materially reduced.
