Data Processing Agreement
Version 1.1 · Effective 28 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Torq360 LLC, a Wyoming limited liability company ("Processor", "Torq360"), and the club, school or organization that uses the BeltRise platform (the "Controller", "you"). It governs Torq360's processing of personal data on your behalf.
1. Roles
For the member, student, guardian and staff records you enter into BeltRise ("Controller Personal Data"), you are the controller and Torq360 is the processor. You determine the purposes and means of processing; Torq360 processes only on your documented instructions, which include your use of the Service and this DPA. If Torq360 is required by law to process otherwise, it will inform you unless legally prohibited.
2. Subject matter, duration, nature and purpose
Subject matter: provision of the BeltRise platform. Duration: the term of your account plus the retention period below. Nature and purpose: hosting, storing and organizing member records so you can run your club (membership, attendance, grading, scheduling, communications, safeguarding, and, where enabled, fees). Full details are set out in Annex I.
3. Categories of data and data subjects
Types of data: identity and contact details; guardian and emergency contacts; dates of birth; grading, attendance and activity; membership, license and insurance details; and, where you record it, special-category data (health/medical and safeguarding information) and children's data, and member photographs. Data subjects: your members (including children), their guardians, and your staff. See Annex I.
4. Torq360's obligations
Torq360 will: (a) process Controller Personal Data only on your documented instructions, including for transfers, unless required otherwise by law; (b) ensure persons authorized to process the data are under an obligation of confidentiality; (c) implement appropriate technical and organizational security measures (Section 5); (d) respect the conditions in Section 6 for engaging sub-processors; (e) assist you, taking into account the nature of processing, to respond to data-subject rights requests; (f) assist you with security, breach notification and, where applicable, data-protection impact assessments; (g) at your choice, delete or return all Controller Personal Data at the end of the services and delete existing copies unless retention is required by law (Section 8); and (h) make available information reasonably necessary to demonstrate compliance with this DPA. Torq360 does not use Controller Personal Data to train AI models.
5. Security measures
Torq360 maintains measures appropriate to the risk, including: access controls and least-privilege administrative access; row-level security isolating each club's data from other clubs; encryption of data in transit and at rest; regular backups; storage on reputable cloud infrastructure; and restricted, logged access to production systems. You are responsible for the security of your own account credentials and for the access you grant to users within your club. Further detail is set out in Annex II.
6. Sub-processors
You authorize Torq360 to engage the sub-processors listed below to process Controller Personal Data. Torq360 imposes data-protection obligations on each sub-processor consistent with this DPA and remains responsible for their performance. Torq360 will maintain the list and give you reasonable notice of any intended addition or replacement so you may object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage (hosting of Controller Personal Data) | United States |
| Cloudflare | Application hosting, content delivery, security | United States / global edge |
| Stripe | Payment processing (card data handled by Stripe; full card numbers not stored by Torq360) | United States |
| Anthropic | AI features (e.g. drafting a syllabus; in-app assistant). Data is not used to train models | United States |
Objection remedy. If you object to a new or replacement sub-processor on reasonable data-protection grounds and Torq360 cannot, within a reasonable time, provide an alternative or a change that resolves your objection, you may terminate the affected part of the Service and receive a pro-rata refund of any prepaid fees for the terminated portion of the then-current term.
7. Breach notification
Torq360 will notify you without undue delay and in any event within 48 hours after becoming aware of a personal-data breach affecting Controller Personal Data, and will provide information reasonably available to help you meet your own notification obligations. Notification is not an acknowledgement of fault.
8. Return and deletion
On termination of your account you may export your Controller Personal Data for 30 days. After that period Torq360 will delete or de-identify the data (backups roll off on their normal cycle shortly thereafter), except where retention is required by law. On written request during the term, Torq360 will delete or return specified data where it can reasonably do so consistent with the operation of the Service.
9. International transfers
Torq360 and its sub-processors are located in the United States and may process data there and in other countries. Where Controller Personal Data of individuals in the EU/EEA is transferred to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Module Two: controller-to-processor), completed with the details in Annexes I and II. Where such data relates to individuals in the UK, the parties incorporate the UK International Data Transfer Addendum (IDTA Addendum) to those Clauses. In the event of a conflict, the Clauses and Addendum prevail on the subject of restricted transfers.
10. Audit
Torq360 will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once per year (or as required by a supervisory authority), allow for and contribute to reasonable audits, subject to confidentiality and to protecting the security of other customers' data.
11. Your obligations
You confirm that you have a lawful basis for the Controller Personal Data you process using BeltRise and that you have obtained any consents required by applicable law, including parental or guardian consent for children's data before it is entered into or enabled in the Service, and that your instructions comply with applicable law.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, including the aggregate liability cap set out there.
13. Term and precedence
This DPA takes effect when you accept the Terms of Service and continues while Torq360 processes Controller Personal Data. If there is a conflict between this DPA and the Terms of Service on the subject of data protection, this DPA prevails.
14. Contact
[email protected]. Torq360 LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, USA.
Annex I: Details of processing
- Data exporter (Controller): the Customer club/organization (name and address as on its account).
- Data importer (Processor): Torq360 LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, USA.
- Subject matter & duration: provision of the BeltRise platform for the term of the account plus the retention period in Section 8.
- Nature & purpose: hosting and processing member/club records to run the club (membership, attendance, grading, scheduling, communications, safeguarding, fees where enabled).
- Categories of data subjects: members (including children), guardians, staff.
- Categories of personal data: identity and contact details; guardian/emergency contacts; dates of birth; grading/attendance/activity; membership/license/insurance details; photographs.
- Special-category data: health/medical and safeguarding information, where the Controller records it; children's data.
- Frequency: continuous, for the duration of the account.
Annex II: Technical and organizational security measures
Access controls and least-privilege administrative access; row-level security isolating each club's data; encryption in transit and at rest; regular backups; storage on reputable cloud infrastructure (see Section 6 sub-processors); restricted and logged access to production systems; confidentiality obligations on authorized personnel; and support for breach notification and data-subject requests.
A signable/countersigned PDF of this DPA (with Annexes completed for the specific Customer) is available on request for clubs, schools, federations or authorities that require one. Contact [email protected].
