TERMS & CONDITIONS

Effective Aug 1st 2026

These terms govern your use of ProAgenda. They replace all previous versions. Schedule 1 is our Data Processing Agreement and forms part of these terms.

ProAgenda is a registered trading name of Golf Financial Services B.V., a company registered in the Netherlands with the Chamber of Commerce under number 34130467, at Jan van Krimpenweg 9e, 2031 CE Haarlem, the Netherlands. In these terms "ProAgenda", "we" and "us" mean that company, and the contract is with it.

These terms apply to any business, organisation or venue that subscribes to ProAgenda ("you", "the Customer") — including coaching academies, sports clubs, studios, salons, practices, schools and similar. ProAgenda is a business service. If you are an individual who books an appointment because a business you use runs on ProAgenda, these terms do not apply to you; see our Privacy Notice for Clients.


1. Definitions

Platform — the ProAgenda software, websites, mobile applications and related services.

Customer Data — all data you or your users enter into or generate through the Platform, including client records, bookings, appointment and session notes, video content and transaction records.

Clients — the individuals you serve, or who book appointments or sessions through your ProAgenda booking page.

Subscription — your paid access to the Platform and any products you have added to it.


2. Your account

2.1 You must provide accurate registration information and keep it current.

2.2 You are responsible for all activity under your account and for keeping login credentials secure. Multi-factor authentication is not currently available; we will notify you when it is.

2.3 You are responsible for the users you create within your account, including staff and administrators, and for what they do on the Platform.

2.4 Notify us promptly at info@proagenda.com if you believe your account has been accessed without authorisation.


3. Free trial

3.1 We offer a one-month free trial without requiring payment details.

3.2 At the end of the trial your account closes unless you choose a subscription and pay. We do not charge you automatically at the end of a trial.

3.3 Data entered during a trial is retained for 30 days after the trial ends, after which we may delete it. Ask us before that date if you need an export.


4. Subscription, term and renewal

4.1 Subscriptions run for either one month or twelve months, depending on the plan you choose, from the date of registration or of adding a product.

4.2 Your subscription renews automatically for a further period of the same length unless you give notice of cancellation before the end of the current period.

4.3 You may cancel at any time with effect from the end of your current period. You may also terminate early, but we do not refund the remainder of a period.

4.4 You are responsible for adding or removing products before a renewal takes effect. We do not refund unused products within a period that has begun.

4.5 Cancel through your account or by writing to info@proagenda.com. We will confirm cancellation in writing; if you do not receive confirmation, assume the cancellation has not been processed and contact us.


5. Fees and payment

5.1 Fees are as published at [/pricing] or as separately agreed, and exclude VAT and other applicable taxes unless stated.

5.2 Payment is due at the start of each subscription period.

5.3 If payment is not received, access to the Platform is suspended after 3 days. We will notify you before suspension and will restore access promptly once payment is made. Your data is not affected by suspension.

5.4 A suspended account remains in place and its data is retained in accordance with clause 12. We will tell you before we delete anything.

5.5 We may change our fees. We will give at least 60 days' written notice, and the change takes effect at your next renewal. If you do not accept the new fees you may cancel with effect from the end of your current period.


6. Acceptable use

6.1 You may not use the Platform to store or transmit anything unlawful, infringing or harmful, or to attempt to gain unauthorised access to the Platform or to another customer's data.

6.2 You may not resell or provide the Platform to third parties as a service in your own right without our written agreement. Using it to serve your own Clients is exactly what it is for.

6.3 We may suspend access where we reasonably believe there is a serious breach of this clause or a security risk. We will tell you why and, where we can, give you an opportunity to put it right first.


7. Customer Data and data protection

7.1 Customer Data is yours. We claim no ownership of it. We do not sell it, and we do not use it to train machine learning models.

7.2 In relation to Customer Data you are the data controller and we are your processor. Schedule 1 governs that processing. Where Schedule 1 conflicts with these terms in relation to personal data, Schedule 1 prevails.

7.3 You are responsible for having a lawful basis for the personal data you record, for informing your Clients what you hold and why, and for obtaining any consent required — including from a parent or guardian where a Client is under 18, and for any video recording.

7.4 We are the controller for your own account and billing data. See our Privacy Notice for Businesses and Organisations.

7.5 If your organisation requires a separately signed data processing agreement, we will provide one on request, identical in substance to Schedule 1.


8. Clients and payments between you and your Clients

8.1 Clients do not pay ProAgenda. They pay you.

8.2 Where a Client pays through the Platform — for a booking, package, credit, voucher or membership — we facilitate that payment through our payment provider, but the contract for the appointment, session or service is between you and the Client. We are not a party to it.

8.3 You are responsible for what you sell to your Clients, for your own cancellation and refund policy, for delivering what has been paid for, and for resolving disputes with Clients. We will provide transaction records to help you do so.

8.4 You are responsible for your own tax obligations on payments you receive.

8.5 Payment processing is subject to the terms of our payment provider, which apply to you directly in addition to these terms.


9. Video content (where you use it)

9.1 Video is an optional feature. Where you use it, you and your users decide what to record and upload, and you are responsible for that content and for having the necessary permissions from the people in it.

9.2 Video is encoded, stored and delivered by our video provider. You should understand three things about how it currently works:

  • Video is delivered over links that are shown only to authenticated users and contain unguessable identifiers, but the links themselves carry no expiry and cannot be withdrawn. Anyone who obtains a link can view that video.
  • Deleting a record does not currently delete the underlying video file. If you need video permanently removed, contact us and we will arrange it with our provider.
  • We are implementing automatic video deletion during 2026 and are evaluating a change that would allow expiring links.

9.3 We state these limitations because they are relevant to your own obligations as controller, particularly for video of Clients under 18.


10. Availability, support and changes to the Platform

10.1 We do not currently offer a contractual availability commitment. We aim to keep the Platform available at all times and have had no significant unplanned outages, but we do not guarantee uninterrupted access.

10.2 We may carry out maintenance, and will give notice of planned maintenance likely to affect you.

10.3 Support is provided by email at info@proagenda.com during Dutch business hours.

10.4 We may change or improve the Platform. We will not materially reduce core functionality you rely on without at least 60 days' notice; if we do and it matters to you, you may cancel with effect from the end of your current period.


11. Intellectual property

11.1 The Platform, and all intellectual property in it, belongs to us. These terms grant you a non-exclusive, non-transferable right to use it for the duration of your Subscription.

11.2 Your content, branding and Customer Data remain yours. Where you use a branded mobile application, you grant us the limited right to use your name and logo for the purpose of providing it.

11.3 We may name you as a customer and use your logo on our website and materials, unless you tell us not to.

11.4 If you give us feedback or suggestions, we may use them without obligation to you.


12. Termination and what happens to your data

12.1 Either party may terminate in accordance with clause 4. We may terminate immediately on written notice for material breach that is not remedied within 30 days, or for non-payment under clause 5.

12.2 On termination your access to the Platform ends.

12.3 You may request a full export of your Customer Data within 30 days of termination. We will provide structured data in CSV or Excel format, and video files, within 10 working days of your request.

12.4 We retain your Customer Data for 12 months after your account becomes inactive. Many of our customers operate seasonally and suspend and reactivate their accounts across a year. Retaining data for this period means you can return without losing your records.

12.5 After 12 months of inactivity we delete your Customer Data from production systems. Residual copies in backups are overwritten within our seven-day backup cycle. We confirm deletion in writing on request.

12.6 You may ask us to delete your data sooner at any point, and we will do so within 30 days of your written request. If you do not want your data retained for the seasonal period, tell us.

12.7 We retain invoices and payment records for seven years, as Dutch law requires, irrespective of clause 12.5.


13. Warranties and disclaimers

13.1 We warrant that we will provide the Platform with reasonable skill and care, and in accordance with these terms and Schedule 1.

13.2 Beyond that, the Platform is provided as it is. We do not warrant that it will be uninterrupted, error-free, or fit for a particular purpose you have not told us about.

13.3 We are not responsible for the content of media, video, audio or text that you or your users place on the Platform.

13.4 We are not responsible for third-party integrations you choose to connect, or for their availability or acts.


14. Liability

14.1 Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot be limited under Dutch law.

14.2 Neither party is liable for indirect or consequential loss, loss of profit, loss of anticipated savings, loss of goodwill, or loss of business opportunity.

14.3 Subject to 14.1, our total liability arising out of or in connection with these terms in any twelve-month period is limited to the fees paid by you in the twelve months preceding the event / €15.000, whichever is greater.

14.4 Subject to 14.1, our total liability for breach of Schedule 1 or of applicable data protection law is limited to € 25.000 in any twelve-month period. This is a separate cap and does not reduce the cap in 14.3.

14.5 You are responsible for the lawfulness of the personal data you record and the instructions you give us, and for any claim arising from those.

14.6 Each party must take reasonable steps to mitigate its loss.


15. Confidentiality

15.1 Each party will keep the other's confidential information confidential and use it only for the purposes of these terms.

15.2 This does not apply to information that is public through no fault of the receiving party, was already known to it, or must be disclosed by law.


16. Changes to these terms

16.1 We may amend these terms, including Schedule 1. We will notify you in writing at least 30 days before a change takes effect. For a change to Schedule 1 that materially affects your rights as controller, we will give at least 60 days' notice.

16.2 If you do not accept a change, tell us in writing within the notice period. The previous terms continue to apply to you until the end of your current subscription period, after which the change applies or you may cancel.

16.3 We will not apply a change retrospectively.


17. Force majeure

Neither party is liable for failure to perform caused by events beyond its reasonable control, provided it notifies the other and takes reasonable steps to mitigate. Payment obligations are not excused.


18. General

18.1 You may not assign these terms without our written consent. We may assign them to a successor in connection with a merger or sale of our business, on notice to you.

18.2 If a provision is found unenforceable, the rest remains in force.

18.3 These terms, including Schedule 1, and the order you place together form the whole agreement between us on this subject.

18.4 Failure to enforce a right is not a waiver of it.


19. Governing law and jurisdiction

19.1 These terms are governed by the laws of the Netherlands.

19.2 Disputes are subject to the exclusive jurisdiction of the competent courts in the Netherlands.

19.3 Clause 19.1 does not affect the application of data protection law to the processing of personal data, including the EU GDPR and the UK GDPR, which apply irrespective of the governing law of these terms.


20. Contact

Golf Financial Services B.V., trading as ProAgenda Jan van Krimpenweg 9e, 2031 CE Haarlem, the Netherlands info@proagenda.com · KvK 34130467 EU +31 20 449 6099 · UK +44 1753 913045 · US +1 832 534 0478

---

Schedule 1 — Data Processing Agreement

This Schedule is made under Article 28 of the EU General Data Protection Regulation and, where applicable, the UK GDPR. It forms part of the Terms and Conditions above and is accepted when you register.

In this Schedule you are the controller and ProAgenda, a registered trading name of Golf Financial Services B.V. (KvK 34130467), is the processor. Protected Data means personal data we process on your behalf in connection with the Platform.

If your organisation requires a separately signed agreement, we will provide one identical in substance to this Schedule.


S1. Status and scope

S1.1 In relation to Protected Data you are the controller and we are the processor.

S1.2 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex A.

S1.3 You are responsible for ensuring that you have a lawful basis for the processing, that necessary notices have been given and consents obtained, and that your instructions to us comply with data protection law.


S2. Processing on your instructions

S2.1 We process Protected Data only on your documented instructions, including as set out in these terms, and for no other purpose.

S2.2 We will inform you without delay if, in our opinion, an instruction infringes data protection law, and may suspend that instruction until it is amended or confirmed.

S2.3 We will not transfer Protected Data outside the European Economic Area except as set out in Annex C or as you authorise in writing. Where such a transfer occurs we will ensure an appropriate transfer mechanism is in place under Chapter V of the GDPR.


S3. Confidentiality and personnel

S3.1 Access to Protected Data is limited to personnel who require it to provide the Platform.

S3.2 Those personnel are subject to a duty of confidentiality and receive appropriate data protection training.


S4. Security

S4.1 We implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing.

S4.2 The measures in place are set out in Annex B, which states the position accurately including where a measure is not yet implemented. We will not reduce the overall level of protection during the term.

S4.3 Annex B also sets out measures we have committed to implement, with target periods.


S5. Sub-processors

S5.1 You give us general written authorisation to engage the sub-processors listed in Annex C.

S5.2 We will give you at least 30 days' written notice before engaging any additional or replacement sub-processor. You may object on reasonable data protection grounds within that period. If the objection cannot be resolved in good faith, you may terminate in respect of the affected services without penalty.

S5.3 We impose data protection obligations on each sub-processor by written contract that are no less protective than those in this Schedule, and we remain fully liable to you for their performance.


S6. Data subject rights

S6.1 Taking into account the nature of the processing, we will assist you in responding to requests from data subjects exercising rights of access, rectification, erasure, restriction, portability and objection.

S6.2 If we receive a request directly from a data subject relating to Protected Data, we will not respond substantively but will notify you within two working days.

S6.3 We will action a written request from you for the erasure of Protected Data within five working days and confirm completion in writing.

S6.4 Two current limitations affect how you should handle such requests:

  • Deletion of a record by a user other than the account holder removes the record from the Platform but retains it in our database. A request under S6.3 is required to achieve permanent erasure.
  • Deletion does not currently delete the underlying video file held by our video sub-processor. Removal of stored video is available on request to us and we will arrange it with the provider. Automatic deletion is committed for delivery during 2026 (Annex B, Part 2).

S6.5 On your written request we will provide an export of Protected Data in a structured, commonly used and machine-readable format within 10 working days.


S7. Personal data breaches

S7.1 We will notify you of any personal data breach affecting Protected Data without undue delay, and in any event within 24 hours of becoming aware of it.

S7.2 The notification will include, to the extent known: the nature of the breach; the categories and approximate number of data subjects and records concerned; whether special category data or data relating to persons under 18 is involved; the likely consequences; the measures taken or proposed; and our point of contact. Where full information is not available at the time, we will provide it in phases without further undue delay.

S7.3 We will not notify a supervisory authority or any data subject of a breach affecting Protected Data without your prior written consent, unless required by law.

S7.4 We will cooperate with you and take reasonable steps as you direct to assist in investigation, mitigation and remediation, and will provide a written post-incident report.

S7.5 We maintain a documented incident response procedure and a register of personal data breaches, including those assessed as not requiring notification, as Article 33(5) requires. Both are available to you on request.

S7.6 Our hosting sub-processor has committed to notifying us of an incident in its environment within 24 hours, so the notification chain is consistent.


S8. Assistance, audit and records

S8.1 We will assist you in ensuring compliance with Articles 32 to 36, including data protection impact assessments and prior consultation with a supervisory authority.

S8.2 We will make available all information reasonably necessary to demonstrate compliance with this Schedule.

S8.3 You may audit our compliance, or appoint an independent auditor to do so, on at least 30 days' written notice, no more than once in any 12-month period (except following a personal data breach), during normal business hours and subject to reasonable confidentiality undertakings. Each party bears its own costs.


S9. Children's data

S9.1 The parties acknowledge that Protected Data may include personal data relating to individuals under the age of 18.

S9.2 You are responsible for determining the lawful basis for that processing and for obtaining and recording any consent or authorisation required from a parent or guardian, including for the recording, storage and analysis of video.

S9.3 We process such data only on your instructions and apply the measures in Annex B to it.


S10. Special category data

S10.1 The parties acknowledge that free-text client notes and video content may contain information relating to a data subject's health — for example injuries, physical limitations, rehabilitation, allergies, skin or scalp conditions, or medical history relevant to a service — which constitutes special category personal data under Article 9.

S10.2 You are responsible for identifying an Article 9 condition for that processing. We apply the security measures in Annex B to such data and use it only to provide the Platform.


S11. Deletion and return on termination

S11.1 On expiry or termination, at your election we will return Protected Data to you in the format described at S6.5, or delete it.

S11.2 You may request an export within 30 days of termination. Protected Data is then retained for 12 months from the date the account becomes inactive, to allow for seasonal reactivation, after which it is deleted from production systems. On your earlier written instruction we will delete it within 30 days of that instruction.

S11.3 Copies present in backups are overwritten in the ordinary course of our seven-day rolling backup cycle. Backups are used solely for disaster recovery and are not used to restore individual records.

S11.4 We may retain Protected Data to the extent required by law, and will retain it only for the period required and continue to protect it in accordance with this Schedule.

S11.5 We will certify deletion in writing on request.


S12. Liability and general

S12.1 Liability under this Schedule is subject to clause 14 of the Terms and Conditions.

S12.2 This Schedule takes effect on registration and continues for so long as we process Protected Data.

S12.3 This Schedule is governed by the laws of the Netherlands, subject to clause 19.3.


Annex A — Details of Processing

Item Detail
Subject matter Provision of the ProAgenda coaching, booking and academy management platform
Duration The term of the Subscription, plus the periods described at S11
Nature and purpose Hosting, storage, organisation, retrieval, transmission and deletion of personal data for appointment and session scheduling, client management, service and session records, optional video analysis, memberships, packages and payment facilitation
Categories of data subject Our customers' staff, including coaches, instructors, practitioners and administrators; Clients, including individuals under 18; billing contacts
Types of personal data Name; email address; telephone number; address; username and hashed password; role and permissions; organisation affiliation; bookings, attendance and cancellations; client notes, assessments and progress records; video recordings and annotations where used; packages, credits, vouchers and memberships; transaction and billing records; IP address, log and usage data
Special category data Health data may be present within free-text client notes and video content — see S10
Children's data Personal data relating to Clients under 18 — see S9
Frequency of transfer Continuous, for the duration of the Subscription
Retention For the life of the account, plus 12 months from the date the account becomes inactive, subject to earlier deletion in accordance with S6 and S11

Annex B — Technical and Organisational Measures

Part 1 — Measures in place

Area Measure
Hosting Dedicated physical server in Equinix AM2 and AM7, Amsterdam, Netherlands, provided by Hypersolid, which holds ISO/IEC 27001:2022 (BSI certificate ISC 102)
Encryption in transit All user, application and API traffic over HTTPS/TLS. Connections to sub-processors over TLS
Encryption at rest Backups are encrypted at rest. Encryption of production storage is in progress (Part 2). No application-level database or field encryption
Access control Role-based access control. Staff-level restriction to assigned Clients and own schedule. Organisation-level permissions governing visibility and actions
Authentication Username and password. Multi-factor authentication is not currently available (Part 2)
Audit trail Change log recording amendments with acting user and timestamp, retained for the life of the account and visible directly to organisation administrators. Read-only access is not logged (Part 2)
Account management Organisation administrators can deactivate user accounts
Backups Daily, retained on a seven-day rolling cycle, encrypted at rest, stored in a separate Equinix facility from production. Restore process tested
Disaster recovery Restoration from backup onto replacement infrastructure. Recovery Point Objective 24 hours; Recovery Time Objective 24 hours, based on a tested restore
Video Stored by our video sub-processor in AWS eu-west-1 (Ireland) and delivered via a global content delivery network. Delivery URLs contain unguessable identifiers and are surfaced only to authenticated users, but carry no expiry and cannot be revoked (Part 2)
Incident response Documented procedure with a named incident lead and deputy, notification within 24 hours, and a breach register
Certifications ProAgenda holds no certification of its own. Our hosting provider's ISO/IEC 27001:2022 certificate is available on request

Part 2 — Committed measures

Measure Target
Encryption at rest enabled on production storage 2026
Video file deletion on erasure, including a backfill for records already erased During 2026
Documented and tested full-data export capability 2026
Transfer documentation for video content, and a documented transfer risk assessment for our United States sub-processors 2026
Signed, expiring video delivery links (requires a change to our storage and delivery architecture) Under evaluation
Multi-factor authentication, optional for all users with the ability for an organisation to enforce it To be confirmed
Access logging in addition to amendment logging To be confirmed
Configurable retention periods To be confirmed

Annex C — Approved Sub-processors

Sub-processor Entity and location Purpose Transfer basis
Hypersolid Netherlands (EEA) — Equinix AM2 and AM7, Amsterdam Server hosting, managed infrastructure, backups Within the EEA; no transfer mechanism required
Twilio SendGrid Twilio Inc., United States Transactional email EU Standard Contractual Clauses and the UK International Data Transfer Agreement, as incorporated in Twilio's Data Protection Addendum
Stripe Stripe Payments Europe, Limited, Ireland (EEA), with onward transfer to Stripe, LLC, United States Payment processing Adequacy for the EEA contracting entity. The onward US transfer relies on Stripe, LLC's Data Privacy Framework certification, with Standard Contractual Clauses and the UK Addendum as fallback
Bitmovin Bitmovin, Inc., United States; EEA representative Bitmovin GmbH, Austria Video encoding, storage and delivery. Storage in AWS eu-west-1 (Ireland); delivery via AWS CloudFront Being documented with the provider. Amazon Web Services acts as Bitmovin's sub-processor

Restriction on sensitive data: our email sub-processor's terms prohibit the submission of sensitive data. We therefore do not include health information, or information about a data subject's physical condition, in the content of emails sent through that service.