Data Processing Agreement
The rules Tempo works under when it handles your athletes' data for you. This is part of the Terms of Service — you do not need to sign it separately.
Version 2026-07-30
We are still finalising who operates Tempo
The company name, registered address, contact address for data requests and the country whose law applies are not settled yet. Everywhere one of them belongs, this document shows a marker like Not yet filled in: [LEGAL ENTITY NAME] instead of a guess. Everything else here describes what Tempo actually does today. If you need any of the missing details before they are published, ask your Tempo contact.
1. Who this is between, and why it exists
This agreement is between you — the coach or team using Tempo — and Not yet filled in: [LEGAL ENTITY NAME] of Not yet filled in: [REGISTERED ADDRESS], registered in Not yet filled in: [COUNTRY OF REGISTRATION].
You are the controllerof your athletes' data: you decide what is collected and why. We are your processor: we hold it and act on it to run Tempo for you. Data-protection law requires a written contract between those two roles. This is it, and it takes effect the moment you start using Tempo. It applies for as long as we hold your athletes' data.
Where we act as controller in our own right — your coach account, our billing records, and keeping the AI working properly — the Privacy Policy applies instead of this document.
2. What we process for you
3. We act on your instructions
We process your athletes' data only to run Tempo for you, and only as this agreement, the Terms and your use of the app direct. We do not use it for our own purposes, we do not sell it, and we do not use it to train an AI model.
If the law forces us to do something else with it, we will tell you before we do, unless that same law forbids us from telling you. If we think an instruction from you would break data-protection law, we will say so.
Everyone at Tempo who can reach your athletes' data is bound to keep it confidential.
4. How we keep it safe
The measures we actually have in place today, not a wish list:
- Hard separation between teams.Every table is scoped to one organisation and the database enforces it on every query. A query that reached another team's rows would be refused by the database itself, not just by the app.
- Private file storage.Every uploaded file — health documents, attachments, raw wearable files, methodology documents — sits in a private store with no public link. Access goes through short-lived signed URLs issued by the server.
- Encryption in transit for everything, and encryption at restfor the third-party keys we have to store — AES-256-GCM with a fresh random value per secret, so one key cannot be read with another.
- An access log for health documents.Every AI read of an athlete's health document is written to an audit trail before the content is returned. If the log entry cannot be written, the read does not happen.
- Logs that carry no content. Our error logs record where something failed and nothing else. No message text, no health data, no file contents, no request bodies. This is enforced by the logging code itself.
- A hard cut-off for the most sensitive data. Blood-test and DNA content is never sent to any AI provider, whatever consents or settings are in place. It is blocked in two independent places in the code.
We do not hold a security certification and we are not claiming one. If you need evidence for your own compliance file, ask and we will show you what we have.
5. The companies we use
You agree to us using the companies below. Each one only receives what its job needs.
One AI provider is active at a time; the other is not called. If we add or replace a company on this list, we will tell you before it starts processing your athletes' data, so you have a chance to object.
Where we are not finished. The law expects us to have a written data-processing contract with each company above that imposes the same duties we owe you. That work runs alongside settling the operator details at the top of this page and is not complete. Specifically, we have notsigned a zero-retention or data-processing agreement with either AI provider — they operate under their ordinary commercial terms, which do not train on the data but may retain requests briefly. We are telling you because you are the controller and you need to know it before you rely on us.
6. Helping you answer your athletes
If an athlete asks you for a copy of their data, or asks you to correct or delete it, the app already does most of the work: every athlete can download their own data and delete their own account from their profile, without needing you or us.
Where a request cannot be handled by those controls, tell us and we will help within a reasonable time and at no charge. If an athlete comes to us directly, we will not answer for you — we will pass it to you and tell the athlete we have.
One gap you should know about: a head coach who owns an organisation cannot currently delete their own account from the app. It asks them to transfer ownership first, and that control has not been built yet. Ask us and we will do it by hand.
7. If something goes wrong
If we become aware of a breach affecting your athletes' data, we will tell you without undue delay, with what we know: what happened, who is affected, what the likely consequences are, and what we are doing about it. Telling your athletes and telling the regulator is your call to make — you are the controller — and we will give you what you need to make it.
We will also help if you have to carry out a data protection impact assessment or consult a regulator, to the extent the answers are ours to give.
8. Data leaving the country
The companies in clause 5 operate internationally, so your athletes' data is processed outside your country and outside the EU. The transfer safeguards for that are being put in place with the operator details, and we are not going to describe them as done before they are. If you need to know where a particular piece of data sits, ask and we will tell you what we actually know.
9. Deletion when we are finished
When you stop using Tempo, or when you ask us to, we delete your athletes' data — or return it to you first if you ask. We keep only what the law makes us keep, such as financial records, and that stays protected by this agreement for as long as we hold it.
What that means in practice today:
- An athlete deleting their own accountis immediate and total: their record and everything hanging off it — training, intake, consents, messages, billing, health documents and the files themselves — go at once, and their login is removed. There is no recovery window.
- An assistant coach deleting their own account removes their membership and their login immediately.
- Closing a whole organisation is a manual request today. Ask us, and we do it by hand and confirm in writing when it is done.
- Health documents are deleted immediately on closure. They are never held for the 30-day window that applies to the rest.
What does not exist yet.There is no self-service way to transfer ownership of a team or to delete an organisation. Both are being built. Until they ship, the head coach's own account deletion and whole-organisation deletion are manual requests to us. This paragraph will be replaced when they land — the date at the top of the page will change with it.
10. Checking up on us
You can ask us for the information you need to show that we are meeting these obligations, and we will give you what we have. If that is not enough for your circumstances, we will agree a sensible way for you or an auditor to check — with reasonable notice, no more than once a year unless something has actually gone wrong, and without either of us seeing another team's data.
11. How this fits with the Terms
This agreement is part of the Terms of Service. Where the two disagree about your athletes' personal data, this one wins. Everything else — payment, liability, ending the agreement — is governed by the Terms.
This agreement is governed by the law of Not yet filled in: [GOVERNING LAW], the same as the Terms.
12. Contact
Data-protection questions go to Not yet filled in: [CONTACT EMAIL], or to Not yet filled in: [REGISTERED ADDRESS]. Until those are published, use your Tempo contact.