Data Processing Agreement
For clubs, companies and other business customers
Luduslabs Ltd · trading as Foremates
Version: October 2026
This Data Processing Agreement (“DPA”) forms part of the Foremates Terms and Conditions, Order Form or other agreement under which Luduslabs Ltd provides Foremates services to a business customer (the “Agreement”).
On this page
- 1. Scope and status
- 2. Definitions
- 3. Roles and instructions
- 4. Compliance with Data Protection Laws
- 5. Confidentiality
- 6. Security
- 7. Personal Data Breach
- 8. Data-subject requests
- 9. DPIAs and regulator assistance
- 10. Subprocessors
- 11. International transfers
- 12. Audit and compliance information
- 13. Return and deletion
- 14. Liability and precedence
- 15. Term
- Schedule 1 — Processing details
- Schedule 2 — Technical and organisational measures
- Schedule 3 — International transfer terms
- Schedule 4 — Contact details
1. Scope and status
This DPA applies where Luduslabs Ltd (“Foremates”, “Processor”) processes Personal Data on behalf of the customer (“Customer”, “Controller”) in connection with the Foremates services.
It is intended to satisfy applicable controller-to-processor contract requirements, including Article 28 UK GDPR and, where applicable, Article 28 EU GDPR.
For data that Foremates processes for its own independent purposes, such as its own account security, billing administration or legal compliance, Foremates may act as a separate controller and the Foremates Privacy Policy applies.
2. Definitions
“Data Protection Laws” means all data-protection and privacy laws applicable to the processing under the Agreement, including where relevant the UK GDPR, Data Protection Act 2018 as amended, Data (Use and Access) Act 2025, EU GDPR and applicable national implementing laws.
“Customer Personal Data” means Personal Data processed by Foremates on behalf of Customer under the Agreement.
“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing” and “Personal Data Breach” have the meanings given by applicable Data Protection Laws.
“Subprocessor” means a third party appointed by Foremates to process Customer Personal Data on Foremates’ behalf.
“Restricted Transfer” means a transfer of Personal Data that requires a transfer mechanism under applicable Data Protection Laws.
3. Roles and instructions
Customer is the Controller and Foremates is the Processor for Customer Personal Data, except where the parties expressly agree otherwise.
Foremates will process Customer Personal Data only:
- on Customer’s documented instructions;
- as necessary to provide, secure, support and improve the contracted services in accordance with those instructions; or
- where required by applicable law, in which case Foremates will inform Customer before processing unless the law prohibits notice.
The Agreement, Order Form, use of configured Foremates features and documented support instructions constitute Customer’s instructions.
If Foremates believes an instruction infringes applicable Data Protection Laws, Foremates will notify Customer and may suspend the affected processing until the parties resolve the issue.
4. Compliance with Data Protection Laws
Each party will comply with the Data Protection Laws applicable to its role.
Customer is responsible for:
- having an appropriate lawful basis for Customer Personal Data;
- providing required notices to players, members, guests, staff and other Data Subjects;
- ensuring its instructions are lawful;
- determining appropriate retention periods for data it controls; and
- responding to Data Subjects and regulators as Controller, with Foremates’ assistance where required.
Foremates will make available information reasonably necessary to demonstrate compliance with this DPA.
5. Confidentiality
Foremates will ensure that personnel authorised to process Customer Personal Data are subject to confidentiality obligations and receive appropriate privacy and security guidance.
Access to Customer Personal Data is limited to personnel and contractors who need access for legitimate service, support, security or legal purposes.
6. Security
Taking into account the state of the art, implementation cost, nature and scope of processing and relevant risks, Foremates will maintain appropriate technical and organisational measures designed to protect Customer Personal Data.
Current baseline measures are described in Schedule 2.
Foremates may update its security measures provided the overall level of protection is not materially reduced during the term.
Customer is responsible for configuring its own users, permissions, devices, authentication practices and exports securely.
7. Personal Data Breach
Foremates will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
Where feasible, Foremates will provide initial notice within 48 hours after awareness, followed by further information as it becomes available.
The notice will include, to the extent known:
- the nature of the breach;
- categories of affected data and Data Subjects;
- likely consequences;
- measures taken or proposed; and
- a contact point for follow-up.
Foremates’ notice does not constitute an admission of fault or liability.
Customer is responsible for regulatory and Data Subject notifications required of the Controller, and Foremates will provide reasonable assistance.
8. Data-subject requests
Taking into account the nature of processing, Foremates will provide reasonable technical and organisational assistance to help Customer respond to valid requests to exercise Data Subject rights.
If Foremates receives a request clearly relating to Customer Personal Data controlled by Customer, Foremates may direct the requester to Customer and will not substantively respond on Customer’s behalf unless instructed or legally required.
Reasonable assistance is included as part of the Service where it can be provided through standard functionality or normal support. Material bespoke work may be chargeable if agreed in advance and permitted by law.
9. DPIAs and regulator assistance
Foremates will provide reasonable information and assistance required for:
- data-protection impact assessments;
- prior consultation with a regulator where legally required; and
- enquiries from a competent data-protection authority relating to Foremates’ processing of Customer Personal Data.
Customer remains responsible for determining whether a DPIA or consultation is required for Customer’s use of the Service.
10. Subprocessors
Customer grants Foremates general written authorisation to use Subprocessors.
Foremates will:
- maintain a current Subprocessor List;
- impose data-protection obligations on Subprocessors that are no less protective in substance than the relevant obligations in this DPA, as required by law;
- remain responsible for the performance of its Subprocessors to the extent required by applicable law; and
- provide notice of a new Subprocessor where reasonably practicable before that Subprocessor begins processing Customer Personal Data.
Customer may object to a new Subprocessor on reasonable data-protection grounds by notifying Foremates promptly after notice. The parties will work in good faith to find a commercially reasonable solution. If no reasonable solution is available, either party may terminate the affected service without penalty for the unused prepaid portion relating to that affected service.
11. International transfers
Foremates may process Customer Personal Data in the United Kingdom and in countries where authorised Subprocessors operate.
Where a Restricted Transfer occurs, the parties will use an applicable lawful transfer mechanism, including where relevant:
- an adequacy decision or adequacy regulations;
- the European Commission Standard Contractual Clauses dated 4 June 2021 (“EU SCCs”);
- the UK International Data Transfer Agreement (“IDTA”); or
- the UK International Data Transfer Addendum to the EU SCCs (“UK Addendum”).
The transfer terms in Schedule 3 apply where legally required.
Foremates will reasonably cooperate with transfer-risk assessments and supplementary measures required by applicable law.
12. Audit and compliance information
Foremates will provide Customer with information reasonably necessary to demonstrate compliance with applicable processor obligations.
Where available, Foremates may satisfy audit requests through current policies, security documentation, third-party reports, questionnaires or certifications.
Customer may conduct or appoint an independent auditor to conduct an audit where required by Data Protection Laws, subject to:
- reasonable prior notice;
- confidentiality obligations;
- measures to avoid disruption or access to other customers’ data;
- no more than one routine audit in any 12-month period unless a regulator, confirmed breach or material compliance concern reasonably requires more; and
- Customer bearing its audit costs unless a material breach by Foremates is identified.
On-site access will be limited to circumstances where remote information is not reasonably sufficient.
13. Return and deletion
At the end of the services, Customer may request return or export of Customer Personal Data using available product functionality or a reasonably agreed method.
After termination or a valid deletion instruction, Foremates will delete or return Customer Personal Data within a commercially reasonable period, ordinarily within 30 days for active systems, unless applicable law requires retention.
Protected backup copies may remain until overwritten under Foremates’ backup lifecycle, during which they remain subject to this DPA and are not used for ordinary processing.
14. Liability and precedence
Liability under this DPA is subject to the liability provisions in the Agreement unless applicable Data Protection Laws require otherwise.
If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails.
If incorporated EU SCCs, the UK Addendum or IDTA conflict with this DPA, the mandatory transfer terms prevail to the extent of that conflict.
15. Term
This DPA begins when Foremates first processes Customer Personal Data under the Agreement and continues until that processing ends and required deletion or return is complete.
Schedule 1 — Processing details
Subject matter
Provision of Foremates software and related services for golf clubs, companies, event organisers, societies and their users.
Duration
For the term of the Agreement and any limited post-termination period required for return, deletion, backups, legal compliance or dispute handling.
Nature and purpose
Hosting, organising, transmitting, displaying, analysing, securing and otherwise processing data to provide:
- account and access management;
- event and tournament setup;
- registrations and invitations;
- tee sheets, teams and player management;
- live scoring, leaderboards and results;
- communications and notifications;
- media and user content;
- support and troubleshooting;
- product security and fraud prevention;
- customer-requested reporting and analytics; and
- optional AI-enabled features where contracted and enabled.
Categories of Data Subjects
- Customer staff and administrators;
- club members;
- golfers and players;
- event guests and participants;
- society members;
- volunteers, contractors or other authorised users; and
- individuals whose information Customer lawfully submits to the Service.
Categories of Personal Data
Depending on enabled features:
- name and contact information;
- account identifiers and authentication metadata;
- golf profile, handicap or handicap-index information;
- event registration, attendance, team and tee-time details;
- scorecards, scores, statistics and competition results;
- user content, messages, photos and media;
- device, usage, diagnostic, IP and security information;
- payment-status and transaction-reference information;
- support communications; and
- prompt or instruction content submitted to enabled AI features.
Special-category data
Foremates is not designed for Customer to submit special-category data. Customer must not intentionally submit health, biometric, political, religious, sexual-life or other special-category data unless the parties have expressly agreed the use case and appropriate safeguards.
Processing frequency
Continuous or as initiated by authorised users during the term.
Schedule 2 — Technical and organisational measures
Foremates maintains measures appropriate to the Service and risk, including:
- HTTPS/TLS encryption for data in transit;
- encryption at rest where supported by the hosting provider;
- role-based access controls and least-privilege access;
- authentication and session controls;
- secure credential and secret management;
- separation of production access from ordinary business access where technically appropriate;
- logging, diagnostics and monitoring;
- dependency and security patching;
- controlled development and release practices;
- backup and recovery processes appropriate to the hosted service;
- incident-response procedures;
- access revocation for departing personnel;
- confidentiality obligations for authorised personnel;
- vendor and Subprocessor review proportionate to risk; and
- deletion and retention controls.
Customer acknowledges that specific technical controls evolve over time and may be described in more detail in security documentation provided under confidentiality.
Schedule 3 — International transfer terms
EU transfers
Where Customer Personal Data subject to EU GDPR is transferred to a recipient in a third country without an applicable adequacy decision and the EU SCCs are required:
- the EU SCCs are incorporated by reference;
- Module Two (Controller to Processor) applies where Customer is Controller and Foremates is Processor;
- Clause 7 docking applies;
- Clause 9 uses Option 2 general written authorisation with the notice period stated in this DPA;
- Clause 11 optional language does not apply unless the parties agree otherwise;
- the competent supervisory authority is determined under Clause 13;
- governing law for Clause 17 will be the law of an EU Member State that permits third-party beneficiary rights, selected by reference to the Customer’s establishment where possible, otherwise Ireland; and
- the courts under Clause 18 will correspond to the Clause 17 governing law.
UK transfers
Where the UK Addendum is required, the parties incorporate:
“Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.”
The information required by the Addendum tables is supplied by the Agreement, this DPA, the Order Form and the Subprocessor List. The parties select both importer and exporter as able to end the Addendum where the approved form permits that choice.
If the ICO replaces or updates the approved Addendum or IDTA, the parties intend to use the then-current lawful mechanism to the extent required.
Schedule 4 — Contact details
Processor
Luduslabs Ltd, trading as Foremates
Company number: 16312935
Registered office: 132 Kennel Lane, Billericay, England, CM11 2SU
Privacy contact: info@luduslabs.net
Controller
The Customer legal entity named in the applicable Order Form or Agreement.
Customer privacy contact: as notified to Foremates.