The Padel Professor Club ApS · CVR 42183369 · Elmegårdsvej 5, 8361 Hasselager, Denmark
This End-User License Agreement (the "Agreement") is entered into between you (the "User") and:
The Padel Professor Club ApS("we", "us" or the "Company"), and governs your use of the Point by Point platform, available at pointbypoint.dk and associated domains, including any mobile or web applications provided by the Company (collectively, the "Service").
By creating an account or using the Service, you accept this Agreement. If you do not accept it, you may not use the Service. If you use the Service as a consumer, nothing in this Agreement limits the rights you have under mandatory Danish or EU consumer protection law; in case of conflict, your mandatory rights prevail.
The Service is a sports club and league management platform that provides, among other things, event management, match registration, rating and leaderboard functionality, member profiles and related club administration tools for padel, tennis and similar racket sports.
Subject to this Agreement, we grant you a limited, non-exclusive, non-transferable, revocable license to access and use the Service for its intended purpose. You may not copy, modify, distribute, sell, lease, reverse engineer or attempt to extract the source code of the Service, except to the extent such restrictions are prohibited by mandatory law.
You agree not to:
You retain ownership of content you submit to the Service (e.g. profile photos and profile information). You grant us a non-exclusive license to store, display and process such content solely for the purpose of operating and providing the Service. You are responsible for having the necessary rights to the content you upload.
Certain parts of the Service may require payment (e.g. event participation fees or club subscriptions). Prices, including VAT where applicable, are stated before purchase. Payments are processed by third-party payment providers (currently Stripe); we do not store your card details. If you are a consumer, your statutory right of withdrawal is described in section 8, and rules for recurring subscriptions in section 9.
If you are a consumer and purchase services from us at a distance, you have a statutory right to withdraw from the purchase within 14 days without giving any reason, cf. the Danish Consumer Contracts Act (forbrugeraftaleloven). The withdrawal period expires 14 days after the day the agreement was concluded. To exercise the right, you must notify us by an unambiguous statement (e.g. e-mail to [email protected]) before the period expires; you may, but are not required to, use the standard withdrawal form annexed to the Act. If you withdraw, we will refund all payments received from you for the purchase without undue delay and no later than 14 days after we receive your notice, using the same means of payment you used.
Important exceptions:
If you purchase an ongoing (recurring) subscription as a consumer, you may terminate it with one month's notice to the end of a month once 5 months have passed since the agreement was concluded, cf. section 28 of the Danish Consumer Contracts Act. Termination can be effected through your account or by e-mail to [email protected]. Any prepaid amounts covering the period after termination takes effect will be refunded.
The Service integrates with third-party services, including booking systems, payment providers and accounting systems. We are not responsible for the availability or content of third-party services, which are subject to their own terms.
The Service, including software, design, trademarks and content provided by us, is owned by the Company or its licensors and is protected by applicable intellectual property law. No rights are transferred to you other than the limited license set out in this Agreement.
We strive to keep the Service available at all times but do not guarantee uninterrupted or error-free operation. We may update, change or discontinue features of the Service, and we may perform maintenance that temporarily limits availability. We will use reasonable efforts to inform users of material changes.
The Service is provided "as is" and "as available". To the maximum extent permitted by law, we disclaim all warranties, express or implied. We are not liable for indirect losses, including loss of data, profits or goodwill. Our total aggregate liability under this Agreement is limited to the amount you have paid for the Service during the 12 months preceding the claim.
The limitations in this section do not apply to: (i) liability for death or personal injury; (ii) liability under mandatory product liability rules; (iii) loss caused by our gross negligence or wilful misconduct; or (iv) any other liability that cannot be excluded or limited under mandatory law. If you are a consumer, nothing in this section limits your mandatory statutory rights.
You may stop using the Service and request deletion of your account at any time. We may suspend or terminate your access if you materially breach this Agreement. Sections that by their nature should survive termination (including intellectual property, disclaimers and limitation of liability) will survive.
We may amend this Agreement from time to time. Material changes will be notified via the Service or by e-mail at least 30 days before they take effect. If you do not accept a material change, you may terminate your account with effect from the date the change takes effect; until then, the previous version applies to you. Changes never deprive consumers of rights under mandatory law. The current version is always available on this page, and previous dated versions can be requested at [email protected].
This Agreement is governed by Danish law, without regard to its conflict-of-law rules.
Questions about this Agreement can be directed to [email protected].
This policy describes how personal data is processed in connection with the Point by Point platform (the "Service"), operated by:
The Padel Professor Club ApSWe act in two distinct roles:
Sources: we receive personal data directly from you, from your club (e.g. when a club administrator registers you for a league or event), and — where your club has enabled a booking integration — from the club's booking system (e.g. MATCHi AB), which transmits booking and participation data to the Service on the club's behalf.
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the Service: accounts, events, ratings, leaderboards, club administration | Art. 6(1)(b) — performance of a contract |
| Processing payments and issuing invoices/receipts | Art. 6(1)(b) and Art. 6(1)(c) — legal obligation |
| Bookkeeping and accounting records | Art. 6(1)(c) — the Danish Bookkeeping Act (retention for 5 years from the end of the financial year) |
| Service operation, security, error diagnostics and abuse prevention | Art. 6(1)(f) — legitimate interest in a secure and stable service |
| Optional features, e.g. profile photos | Art. 6(1)(a) — consent, which can be withdrawn at any time |
| Service communications (e.g. event notifications, password resets, and — if you have enabled them — mobile push notifications, which you can turn off at any time in your device settings) | Art. 6(1)(b) and Art. 6(1)(f) |
We do not use automated decision-making that produces legal or similarly significant effects for you within the meaning of GDPR Article 22. Player ratings are calculated automatically but affect only sporting placement within the Service.
We share personal data only as necessary to operate the Service, with the following categories of recipients:
Booking systems (e.g. MATCHi AB) are engaged by your club, not by us; we receive data from them on the club's behalf and do not transmit your data to them. Our data processors act only on documented instructions under data processing agreements pursuant to GDPR Article 28.
We primarily use data centres within the EU/EEA. Where a provider processes personal data outside the EU/EEA (e.g. certain services provided by DigitalOcean, Stripe or Expo from the United States), the transfer is based on an adequacy decision under GDPR Article 45 (including the EU–U.S. Data Privacy Framework) or the EU Commission's Standard Contractual Clauses under Article 46.
The Service may be used by children, for example through a club's youth programmes. In accordance with the Danish Data Protection Act (databeskyttelsesloven § 6(3)):
Under the GDPR you have the right to:
To exercise your rights, contact us at [email protected]. We will respond without undue delay and at the latest within one month. Where we act as data processor for your club, we will forward your request to the club and assist it in responding.
If you are dissatisfied with our processing of your personal data, you can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark — www.datatilsynet.dk.
The Service uses strictly necessary cookies for login sessions, security (CSRF protection) and basic functionality. We do not use cookies for marketing or cross-site tracking. Should this change, we will update this policy and obtain the required consent beforehand.
We may update this Privacy Policy from time to time. The current version is always available on this page, material changes will be communicated via the Service, and previous dated versions can be requested at [email protected].
This Data Processing Agreement ("DPA") applies where a customer of The Padel Professor Club ApS — typically a sports club or similar organisation (the "Controller") — uses the Point by Point platform (the "Service") to process personal data about its members, players and staff, and The Padel Professor Club ApS, CVR no. 42183369, Elmegårdsvej 5, 8361 Hasselager, Denmark (the "Processor") processes such personal data on the Controller's behalf.
This DPA is entered into pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and forms an integral part of the agreement between the Controller and the Processor regarding the Service (the "Main Agreement"). Material changes to this DPA are notified to Controllers with reasonable notice, and previous dated versions — or a signed copy — can be requested at [email protected].
The Processor processes personal data as necessary to provide the Service, i.e. hosting, storage, display and processing of data related to club administration, event management, match registration, ratings, leaderboards, payments and related functionality.
| Element | Description |
|---|---|
| Duration | The term of the Main Agreement, plus the period until deletion/return of data under section 10. |
| Categories of data subjects | The Controller's members, players (including minors, where registered by the Controller), coaches, administrators and staff. |
| Categories of personal data | Name, contact details (e-mail, phone), username, profile photo, club membership, skill level, event participation, attendance, match results and rating history, payment transaction references. |
| Special categories of data | None. The Service is not intended for processing special categories of personal data (GDPR Art. 9), and the Controller shall not submit such data. |
Where the Controller registers minors, the Controller is responsible for ensuring a valid legal basis, including consent from holders of parental responsibility where required (cf. the Danish Data Protection Act § 6(3)).
The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required by EU or Danish law. The functionality of the Service and the Main Agreement constitute the Controller's general instructions. The Processor shall inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
The Processor implements appropriate technical and organisational measures pursuant to GDPR Article 32, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing. Measures include:
The Processor may update these measures from time to time, provided that the overall level of security is not materially reduced.
The Controller grants the Processor general authorisation to engage sub-processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object on reasonable grounds within 14 days. If the parties cannot resolve a justified objection, the Controller may terminate the part of the Service affected by the intended change, without penalty for the remaining term. The Processor imposes the same data protection obligations on sub-processors as set out in this DPA and remains fully liable to the Controller for the sub-processors' performance. Current sub-processors:
| Sub-processor | Service | Location |
|---|---|---|
| DigitalOcean, LLC | Application and database hosting | EU data centres; US parent company (DPF / SCCs) |
| Stripe Payments Europe Ltd. / Stripe, Inc. | Payment processing | Ireland / US (DPF / SCCs) |
| Visma e-conomic A/S | Invoicing and accounting | Denmark |
| Expo (650 Industries, Inc.) | Mobile push notification delivery | US (DPF / SCCs) |
For clarity: booking systems engaged by the Controller (e.g. MATCHi AB) are the Controller's own providers, not sub-processors of the Processor. The Processor receives data from such systems on the Controller's instruction. Stripe additionally processes certain payment data as an independent data controller (e.g. for fraud prevention and financial-regulatory compliance); such processing falls outside this DPA.
Personal data is primarily processed within the EU/EEA. Where processing by a sub-processor involves a transfer to a third country, the Processor ensures a valid transfer basis under GDPR Chapter V, such as an adequacy decision (including the EU–U.S. Data Privacy Framework) or the EU Commission's Standard Contractual Clauses.
Taking into account the nature of the processing, the Processor assists the Controller, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the Controller's obligations to respond to data subjects' requests (GDPR Chapter III) and in ensuring compliance with the Controller's obligations pursuant to GDPR Articles 32–36 (security, breach notification, impact assessments and prior consultation).
The Processor shall notify the Controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach affecting the Controller's personal data, and shall provide the information reasonably required for the Controller to fulfil its notification obligations under GDPR Articles 33 and 34. The notification shall, to the extent known, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
Upon termination of the Main Agreement, the Processor shall, at the Controller's choice, delete or return all personal data processed on the Controller's behalf and delete existing copies, unless EU or Danish law requires continued storage (e.g. bookkeeping records). Absent instructions, data is deleted no later than 90 days after termination.
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in GDPR Article 28 and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, with reasonable prior notice and no more than once per year unless a supervisory authority requires otherwise or a breach has occurred. The Controller bears its own costs and the Processor's reasonable documented costs of such audits.
Liability under this DPA follows the liability provisions of the Main Agreement and GDPR Article 82. This DPA is governed by Danish law, and disputes are subject to the venue agreed in the Main Agreement.