Status of this framework
This page summarizes the data processing terms Entekka expects to use for agency customers. It is not a countersigned DPA. Before production use, Entekka and the customer will agree a signed version that identifies the parties, processing details, selected configuration, and any required transfer terms.
In that signed DPA, the agency customer is the controller and Entekka is the processor for customer personal data placed in the Entekka workspace. Each party remains responsible for the obligations that apply to its role under the GDPR and Greek Law 4624/2019.
Processing details
The subject matter is the hosting and operation of an agency workspace for player, contact, club, request, deal, contract, document, reminder, and operational records. The duration is the customer's use of the service plus the agreed return, deletion, backup, and legal-retention period.
Data subjects may include agency personnel, players, guardians, club personnel, intermediaries, professional advisers, counterparties, and other contacts added by the customer. Data may include identity, contact, employment, representation, contract, financial, activity, document, and communication information. Medical, youth-player, or other special-category data requires an expressly documented purpose, legal basis, and safeguards from the controller.
Documented instructions
Entekka will process customer personal data only to provide, secure, support, and improve the contracted service, and otherwise on documented customer instructions, unless EU or Member State law requires different processing. Entekka will inform the customer where legally permitted if such a requirement applies.
Entekka will tell the customer if an instruction appears to infringe applicable data protection law. The customer is responsible for the lawfulness, transparency, accuracy, and scope of its instructions and source data.
Confidentiality and security
People authorized by Entekka to handle customer personal data will be bound by confidentiality duties. Measures are selected for the risk and documented during rollout. Current controls include Clerk-backed authentication, organization-aware route and API checks, restricted server credentials, provider access controls, and operational logging.
The customer remains responsible for member access, endpoint security, exports, and how information is shared after it leaves Entekka. The current security posture and certification status are described in the Security & Trust Centre.
Current subprocessors
- Clerk: identity, authentication, and organization membership.
- Supabase: hosted PostgreSQL database and file-storage infrastructure.
- Vercel: application hosting, delivery, aggregate analytics, and performance measurement.
The signed DPA will provide general authorization for these subprocessors and a process for notice of material additions or replacements. Entekka remains responsible for imposing appropriate data protection obligations on subprocessors. Hosting region and transfer details will be confirmed for the customer's selected production configuration.
Assistance and incidents
Taking account of the processing and information available, Entekka will reasonably help the customer respond to data-subject requests, security incidents, impact assessments, and supervisory-authority consultations. The customer remains responsible for the final response and legal assessment as controller.
Entekka will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data and will provide available information needed for the customer's assessment and notifications.
Return, deletion, and review
At the end of the service, Entekka will return or delete customer personal data as agreed, unless law requires retention. Residual backup copies will be protected and removed under the relevant provider schedule.
Entekka will make information reasonably necessary to demonstrate compliance with the signed DPA available to the customer. Audit scope, confidentiality, timing, frequency, and costs will be agreed so the review protects other customers and service security.
Request a signed DPA
Email alex@entekka.ai to review a signed DPA for your organization. The final document must be reviewed against the actual rollout configuration before production data is added.