Last updated: 22 August 2026(version 2026-08-22)
This Addendum forms part of the Club Terms of Service and records the terms required by Article 28(3) of the UK GDPR. Where it conflicts with the Club Terms of Service on a data protection matter, this Addendum wins.
Where a clause exists because a specific provision of the UK GDPR requires it, that provision is named.
"UK GDPR" and "Data Protection Law" mean the UK General Data Protection Regulation and the Data Protection Act 2018, together with any legislation replacing or amending them. "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the UK GDPR.
"Club Data" means the personal data described in Annex 1, which the Club instructs Longroom to process on its behalf.
"Longroom" means Tim Hoare, a sole trader trading as Longroom, of 9 Ingram Road, London N2 9QA, as in the Club Terms of Service.
"Sub-processor" means a processor engaged by Longroom to process Club Data.
Other capitalised terms have the meanings given in the Club Terms of Service.
There are two categories of personal data in the Service, and the parties' roles differ between them.
The cricket records synced from Play-Cricket, described in Annex 1, are processed by Longroom on the Club's behalf and on its instructions. The Club decides that the sync should happen, supplies the Play-Cricket API token that makes it possible, holds the agreement with the ECB under which the data is available, and has its own relationship with the people the data is about. Longroom decides none of those things: it runs the sync the Club asked for and serves the results back to the Club's Members.
The Club is the controller of Club Data. Longroom is a processor of it. The rest of this Addendum sets out Longroom's obligations in that role.
A Member's name, email address, sign-in identifiers, conversations with the assistant, usage records, error logs and notification tokens are not processed on the Club's instructions. A Member creates an account with Longroom directly, Longroom decides what is collected and why, and Longroom answers to that Member for it.
Longroom is the controller of that data. It is described in the Privacy Policy, and this Addendum does not apply to it. The Club is not responsible for it, and cannot instruct Longroom about it.
One thing that can look like an instruction is not one. A Member's account exists at the Club's discretion: that is a rule Longroom sets as controller and tells Members in the Member Terms of Use, and it is why the Club's administrators can suspend or remove a Member from the app. When they do, the Club is deciding who is in the Club; what then happens to the account — a suspended account is kept, a removed one is deleted — is Longroom's own rule, applied to its own data. Any note an administrator records against a suspension or a bar is personal data about that Member, which Longroom holds as controller and which the Member can ask Longroom for; the Club should keep such notes factual and about the Member.
The two categories meet in one place. A Member's question to the assistant is Longroom's data as controller, but the answer is derived from the Club's data. Where content derived from Club Data is stored inside a conversation, Longroom treats that content as Club Data and applies this Addendum to it. Where the Club exercises a right under this Addendum over Club Data, such as deletion at the end of the agreement, Longroom applies it to that derived content too.
Neither party is a joint controller with the other. Each is separately responsible for the category it controls.
The ECB operates Play-Cricket and is a controller of the data held in it, independently of both parties. Nothing in this Addendum affects the ECB's role or the Club's agreement with it.
The Club:
The obligations in this clause are the ones Article 28(3) requires.
Longroom will process Club Data only on the Club's documented instructions, including in relation to transfers outside the UK, unless UK law requires otherwise. If UK law does require otherwise, Longroom will tell the Club before processing, unless the law forbids it from doing so.
The Club's documented instructions are: this Addendum, the Club Terms of Service, the configuration the Club sets in the Service, and any further written instruction the Club gives. The ordinary operation of the Service, meaning syncing from Play-Cricket, storing, indexing, serving statistics to Members, answering Members' questions and taking backups, is instructed by this Addendum.
Longroom will tell the Club immediately if, in its opinion, an instruction infringes Data Protection Law.
Longroom does not use Club Data for its own purposes. In particular it does not sell it, does not use it to market to anyone, and does not use one club's data to serve another club. Aggregate operational counts that identify nobody, such as how many questions were asked in a month and how long answers take, are used to run and improve the Service.
Longroom does not use Club Data to train or fine-tune any machine learning model, and will not do so unless the Club instructs it in writing. Anthropic, the only sub-processor that receives Club Data as an input to a model, does not train on it either; Annex 3 records that.
Longroom is currently operated by one individual, Tim Hoare, who is bound by the confidentiality obligations in this Addendum and the Club Terms of Service. Any person Longroom later authorises to process Club Data will be bound by a written confidentiality undertaking of at least equivalent effect before being given access.
Longroom will implement appropriate technical and organisational measures to protect Club Data, taking account of the state of the art, the cost of implementation, and the nature, scope and risks of the processing. The measures in place are set out in Annex 2.
The Club gives general authorisation to Longroom to engage the Sub-processors listed in Annex 3.
If Longroom intends to add or replace a Sub-processor for Club Data, it will give the Club's administrators at least 30 days' notice by email. If the Club reasonably objects on data protection grounds within that period, the parties will discuss it in good faith; if no resolution is reached, the Club may terminate the Club Terms of Service without penalty and receive a pro-rata refund of any period paid for and not used.
Longroom will impose on each Sub-processor, by written contract, data protection obligations materially equivalent to those in this Addendum, and remains fully liable to the Club for a Sub-processor's failure to meet them.
If a person exercises a right under Chapter III of the UK GDPR, meaning access, rectification, erasure, restriction, portability or objection, in relation to Club Data:
The Service already provides export and deletion for a Member's own data, which handles most requests without either party having to do anything.
Assistance under this clause is provided at no charge, unless a request is manifestly unfounded, excessive or repetitive, in which case Longroom may charge its reasonable costs after telling the Club what they will be.
Complaints are a separate duty from rights requests. Since 19 June 2026 a controller must provide a route for data protection complaints, acknowledge one within 30 days, investigate it and communicate the outcome. That duty falls on the Club for Club Data. Where a complaint about Club Data reaches Longroom, Longroom will pass it to the Club's administrators without undue delay and within 5 working days, on the same basis as a rights request, and will provide the information the Club needs to investigate it. Longroom operates its own complaints route for the data it controls, described in the Privacy Policy.
Longroom will provide reasonable assistance to the Club with its obligations under Articles 32 to 36, taking account of the nature of the processing and the information available to Longroom. In particular:
Personal data breaches. Longroom will notify the Club's administrators of a personal data breach affecting Club Data without undue delay after becoming aware of it, and in any event within 24 hours of becoming aware. The notification will describe, so far as Longroom knows at the time: what happened, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Longroom will keep the Club updated as more becomes known.
The 24-hour commitment exists so that the Club can meet its own 72-hour obligation to the ICO under Article 33. The Club, as controller, decides whether to notify the ICO or affected individuals; Longroom will not do so on the Club's behalf.
The limits of detection. That clock starts when Longroom becomes aware of a breach. Longroom monitors for operational failure such as a broken sync or a token that no longer works, and it logs authentication events — sign-ins, failed sign-ins, refresh-token replay and administrator actions — and alerts its operator on the patterns that suggest unauthorised access, as described in Annex 2. Detection is still bounded: most of those alerts are raised by a nightly check rather than in real time, there is no 24/7 monitoring, and an access that presents valid credentials and triggers none of the alerted patterns may not be detected promptly or at all. The Club should weigh the notification commitment against those limits.
Impact assessments. Longroom will provide the information the Club reasonably needs for a data protection impact assessment or prior consultation under Articles 35 and 36.
On the end of the Club Terms of Service, at the Club's choice, Longroom will delete or return all Club Data, and delete existing copies, unless UK law requires it to be retained.
In practice:
Where Longroom must retain something because the law requires it, such as a record needed for tax or to establish or defend a legal claim, it will tell the Club what and why, and will process it for no other purpose.
Longroom will make available to the Club all information reasonably necessary to demonstrate compliance with this Addendum and with Article 28, and will allow and contribute to audits and inspections by the Club or an auditor it appoints.
Given the size of the Service, that will normally be satisfied by Longroom answering the Club's written questions and providing the documents it holds. The Club may also, on 30 days' notice, not more than once in any 12 months unless there has been a breach affecting Club Data or the ICO requires it, carry out a fuller audit. An audit must be during business hours, must not unreasonably disrupt the Service, must respect other clubs' confidentiality, and is at the Club's cost, except where it reveals material non-compliance, when Longroom bears the reasonable cost.
Club Data is stored in the United Kingdom or the European Economic Area.
Two transfers outside that area are inherent in the Service, and by agreeing to this Addendum the Club instructs Longroom to make them:
For Anthropic, Longroom relies on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, which is incorporated into Anthropic's data processing addendum and applies to Longroom's use of the API. For Google and Apple, Longroom relies on the safeguards recorded in Annex 3. Longroom will maintain an appropriate safeguard under Article 46 for as long as each transfer continues, and will tell the Club if a mechanism changes.
Longroom will not transfer Club Data outside the UK or EEA other than as described here without the Club's prior written instruction.
Each party's liability under this Addendum is subject to the limits in clause 10 of the Club Terms of Service, including the cap in clause 10.3. This Addendum does not displace that cap, and the precedence rule at the top of this Addendum does not operate to disapply it.
Nothing in either document limits or excludes either party's own liability to a data subject under Article 82 of the UK GDPR. Article 82 gives data subjects rights directly against a controller and against a processor, and no agreement between the parties can affect them.
Regulatory fines are each party's own. A fine or other penalty imposed on a party by the Information Commissioner is that party's to bear. Neither party indemnifies the other against its own fine, and any claim by one party against the other in respect of a fine is subject to the cap in clause 10.3 like any other claim. Neither party gives an uncapped regulatory indemnity.
This Addendum takes effect when the Club Terms of Service do, and continues for as long as Longroom processes Club Data.
It is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
If a change in Data Protection Law, or guidance from the ICO, means this Addendum no longer meets what the law requires, the parties will agree in good faith the changes needed to make it do so.
Article 28(3) requires the subject-matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subject to be set out.
Subject-matter. Provision of the Longroom service to the Club: syncing the Club's Play-Cricket records, storing and organising them, and making statistics and answers about them available to the Club's Members.
Duration. For the term of the Club Terms of Service, plus the deletion periods in clause 4.7.
Nature of the processing. Collection by API from Play-Cricket; storage in a database dedicated to the Club; organisation, structuring and derivation of statistics; retrieval by database query, including queries composed by a language model; disclosure to the Club's Members through the Service, including in push notifications to Members who have turned them on; transmission to the sub-processors in Annex 3; backup; and erasure.
Purpose. Producing cricket statistics and answering questions about the Club's own cricket records, for the Club and its Members. No other purpose.
Categories of data subject.
Types of personal data.
What is deliberately not processed. The sync does not collect, store or use dates of birth, postal addresses, telephone numbers, email addresses, photographs, or guardian details for under-16s, although Play-Cricket holds them. Data collection is limited to what is needed to produce cricket statistics.
This is about Club Data. A Member's own email address is held by Longroom as controller, to create the account and to sign the Member in: it comes from the Member, not from Play-Cricket, it is not part of Club Data, and clause 2.2 governs it.
No special category data is knowingly processed as Club Data. If the Club were to introduce any, in a team name for example, it would be doing so outside the intended use of the Service. The one free-text field a Club administrator can write in the Service, the note against a Member's suspension or bar, is account data under clause 2.2 rather than Club Data; clause 2.2 asks the Club to keep it factual and about the Member, and a safeguarding note may nonetheless amount to criminal-offence data under Article 10, which is why it is disclosed to the Member and provided to them on request.
Club Data includes the names and performance records of players from other clubs. Those people are not the Club's members and have no relationship with Longroom.
The position taken is that this data is match-participation information already published by the ECB on Play-Cricket, that both parties process it for the narrow and expected purpose of recording the results of matches that were played, and that this is within the reasonable expectations of anyone who plays club cricket in a league whose scorecards are published. The Club, as controller, is responsible for satisfying itself that it has a lawful basis, most likely legitimate interests supported by a legitimate interests assessment, and that Article 14 is met or an exemption applies.
This position is recorded here rather than assumed.
Article 32. These are the measures in place.
Access control.
Separation of clubs.
Encryption.
Integrity.
Resilience and recovery.
Monitoring.
Organisational.
What Longroom does not have.
These measures are proportionate to a small service processing cricket scores that are already published. The Club should judge them against its own risk appetite rather than assume an enterprise posture.
Sub-processors of Club Data. These process personal data that the Club controls.
| Sub-processor | What it does | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting of the servers and databases; off-site backup storage | European Economic Area |
| Anthropic, PBC | Language model. Receives the text of a Member's question, the conversation so far, and data retrieved from the Club's database in order to answer it. Does not use it to train models. Anthropic applies its own retention period to API inputs, which the Club should review in Anthropic's published terms. | United States |
| Google LLC (Firebase Cloud Messaging) | Delivers push notifications to Members' mobile devices. Receives the device token, the text of each notification, which can name a player and what they did (a debut, a milestone), and the in-app link the notification opens, which can carry a Play-Cricket player identifier. Holds the message in order to deliver it. | United States |
| Apple Inc. (Apple Push Notification service) | Delivers those notifications to iPhones, downstream of Firebase. Receives the same. | United States |
Other recipients, where Longroom is the controller. Listed for completeness. They do not receive Club Data and are governed by the Privacy Policy rather than this Addendum.
| Recipient | What it does | Where |
|---|---|---|
| Stripe | Subscription billing; holds the Club's billing contact and card details | United States / Ireland |
| Resend | Delivers sign-in links and operational emails | United States |
| Google, Apple | Verify a Member's identity at sign-in | United States |
| Porkbun | Forwards email sent to our published contact addresses | United States |
Map tiles are not a recipient. The grounds map's imagery is served by Longroom from Longroom's own servers, which fetch and cache it from OpenStreetMap. A Member's browser makes no request to any map provider. OpenStreetMap receives requests from Longroom for map squares, and no personal data.
Transfers to the sub-processors and recipients above outside the UK rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on the UK extension to the EU-US Data Privacy Framework where the recipient is certified under it. For Google, the Firebase data processing terms apply, and Google is certified under that UK extension. Apple is the exception: the notification service is provided under the Apple Developer Program licence terms, Apple is not certified under the UK extension, and the safeguard for that transfer is under review — clause 4.4's notice applies to whatever resolves it.
Longroom will update this Annex when it changes, and will give notice under clause 4.4 before adding or replacing a Sub-processor of Club Data.