Legal·Version 1.2 · 13 September 2026·Sub-processors·Privacy
Thwok · Trust & data protection

Data protection pack for academies

How Thwok handles your pupils' and parents' personal data, what moves onto the platform when you onboard, who is responsible for what, and the agreement that governs it. Written for academy owners, welfare officers and anyone acting as your data protection lead.

Prepared forFlying Shuttles Badminton Academy
Prepared bySIMPLIFY HCS LIMITED, trading as Thwok
Version1.2 · 13 September 2026
StatusIssued for academy review and solicitor sign-off
What changed in version 1.2. Issued 13 September 2026 and supersedes 1.1. One change of fact: the named data protection contact and signatory for SIMPLIFY HCS LIMITED is now Nagini Vallamkonda (Section 2, clause 10 and the sign-off). No commitment changes.
What changed in version 1.1. Issued the same day as 1.0 and supersedes it. Four changes, all additions or corrections of fact, none of which reduces a commitment: the company number, registered office and ICO registration number are now stated (Section 2 and the clause 10 parties); the suppression list is now kept permanently rather than for 12 months, because an objection does not expire (Section 7); bringing your coaching staff across is now described, with the lawful basis for holding a DBS expiry date (Sections 4 and 5); and the email and SMS sub-processors are named, including the fact that no invitation-SMS provider is engaged yet (Section 6).
How to read this pack. Sections 1–3 are the short version: what you need to know and do. Sections 4–9 explain the detail a data protection lead will want to check. Section 10 is the Academy Data Processing Agreement — the legal document that binds Thwok to everything else in this pack. Sections 11–13 are templates you can use with parents. Words in amber are values still to be confirmed. As at version 1.1 only two remain: the invitation-SMS provider, which has not been chosen, and the fields in the Section 11 and 12 templates that you fill in yourself.

Contents

  1. The short version
  2. Who we are
  3. Who is responsible for what
  4. What data moves, and why we're allowed to
  5. How onboarding works, step by step
  6. Where the data lives and who else touches it
  7. How long we keep things
  8. How we protect it
  9. Children, rights requests, complaints and breaches
  10. Academy Data Processing Agreement
  11. Template: notice to parents before migration
  12. Template: guardian consent & medical information
  13. Parent FAQ
  14. Checklists and sign-off

1. The short version

Your academy already holds personal data about every pupil and parent — names, dates of birth, phone numbers, emergency contacts, medical notes, photo permissions. Today that lives in spreadsheets, paper forms and WhatsApp. Moving it onto Thwok does not change who is responsible for it: you remain the data controller, and Thwok becomes your data processor, acting only on your instructions under a written agreement (Section 10). That is exactly the same legal relationship you would have with a payroll provider or a hosted email service.

UK GDPR does not require you to collect fresh consent from every parent to move their data to a new supplier. What it does require is that the move is lawful, transparent, secure and minimal. This pack shows how each of those is met.

What you need to do

  1. Read this pack and sign the Data Processing Agreement (Section 10).
  2. Send parents the migration notice (Section 11) at least 7 days before we import — email, WhatsApp or a printed note in the sports hall all count.
  3. Export your register using the template we give you, upload it through the secure link, and delete any copies you don't need.
  4. Add one line to your own privacy notice naming Thwok as a processor (wording supplied in Section 11).

What Thwok commits to

  • Data is stored in the UK (Google Cloud London region) and never sold or used for advertising.
  • Parents claim their child's record themselves; nothing is visible to other families and no child appears in search or public pages, ever.
  • Records that no parent claims within 60 days are deleted and you're told.
  • We only ever contact parents about the academy — never marketing without a separate opt-in.
  • We tell you about any security incident affecting your data within 24 hours of confirming it.
  • You can export or delete everything at any time; leaving Thwok is one click, not a negotiation.

2. Who we are

Legal entitySIMPLIFY HCS LIMITED, a company registered in England and Wales, trading as Thwok (thwok.app)
Company number13667511 — incorporated 2021 in England and Wales
Registered office4 Henley Gardens, Pinner, HA5 2DE, England
ICO registrationZB235652 — Tier 1 fee paid. Thwok is registered with the Information Commissioner's Office as a controller for its own platform data and pays the data protection fee.
Data protection contactNagini Vallamkonda, Founder and data protection lead · privacy@thwok.app
Thwok is not required to appoint a statutory Data Protection Officer (it is not a public authority and its core activity is not large-scale monitoring or special category processing). A named lead with the founder's authority is the appropriate arrangement for a business of this size, and this pack has been prepared to a DPO standard.
Applicable lawUK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025; the Privacy and Electronic Communications Regulations 2003 (PECR); the ICO Age Appropriate Design Code (the "Children's Code").
Professional backgroundThwok's founder holds Digital Clinical Safety Officer (DCSO) certification and has built NHS-facing compliance software. The safeguarding, data-minimisation and audit-trail patterns in this pack are carried over from that work.

3. Who is responsible for what

Data protection law has three roles. A controller decides why and how personal data is used. A processor acts on a controller's documented instructions. Where two organisations decide together, they are joint controllers. The table below is the role map for every activity that touches academy data. It is deliberately explicit because ambiguity here is the first thing a regulator looks for.

ActivityAcademyThwokNotes
Your register: pupils, guardians, emergency contacts, medical notes, attendance, term enrolments, fees owedControllerProcessorYou decide what is collected and why. We store and process it only to run your academy on Thwok.
The bulk import of your existing registerControllerProcessorYou instruct the import by uploading the file. We do not add to, enrich or cross-reference it.
Inviting existing parents to claim their child's recordControllerProcessorInvitations are sent in the academy's name, on your instruction. These are service messages, not marketing.
The parent's Thwok account (login, profile, notification settings, consent records)—ControllerCreated when the parent accepts our terms. Governed by Thwok's Privacy Notice.
Payments (card details, transaction history)—Controller with Stripe as independent controller for card processingThwok never sees full card numbers. Stripe is regulated by the FCA and PCI-DSS certified.
Safeguarding concerns raised through the platformControllerProcessor (academy matters) / Controller (platform matters)Concerns about academy sessions are forwarded to your welfare officer within 4 working hours. Concerns about the platform itself are handled by Thwok.
Verifying your staff's credentials (DBS, safeguarding, first aid, qualifications)ControllerProcessorVerification of staff credentials is the academy's processing, as controller. Thwok processes the uploaded certificate and the academy's check record on the academy's instruction only, and gives no verdict of its own.
Aggregated, anonymised platform statistics (e.g. "how many academies use waitlists")—ControllerNever at child level; never published below a minimum group size of 20.
Marketing to parentsDoes not happen without a separate, unticked, revocable opt-in held by Thwok. The academy register is never used as a marketing list.
Why this matters to you. Because you are the controller of the register, the obligations to tell parents what is happening, to honour their rights, and to have a lawful basis sit with you — and this pack gives you the wording and the process for each. Because Thwok is your processor, we are contractually bound (Section 10) to act only on your instructions, to keep the data secure, to help you with rights requests and breaches, and to delete or return everything when you leave.

4. What data moves, and why we're allowed to

Only what is needed to run the academy on Thwok moves. The import template has exactly these columns and rejects anything else. Each row below states the lawful basis you rely on as controller, which is also the basis on which Thwok processes as your processor.

DataWhoseWhy it's neededLawful basis (Art. 6) and, where relevant, condition (Art. 9)
Child's first name, surname, date of birthPupilIdentify the pupil, place them in the right age group, apply DBS/ratio rulesContract (6(1)(b)) — performance of the coaching contract with the guardian
Guardian's name, mobile number, emailGuardianSend the invitation, confirm the place, session changes, cancellations, receiptsContract (6(1)(b))
Second guardian / emergency contact name and phoneThird partyReach someone if the guardian can't be reached during a sessionLegitimate interests (6(1)(f)) — the child's safety; balancing test recorded in Section 9
Medical notes relevant to physical activity (e.g. asthma, allergies, an inhaler in the bag)PupilCoaches can respond appropriately in an emergencyContract (6(1)(b)) plus explicit consent of the guardian (9(2)(a)) — captured on the Section 12 form. In a genuine emergency, vital interests (9(2)(c)) also applies.
Photo/video permission (yes/no)Pupil / guardianEnforce your existing permissions on the platformConsent (6(1)(a)) — imported as a flag; the underlying permission is re-confirmed by the guardian when they claim the record
Current group, term enrolment, session dayPupilRecreate your timetable so parents see the right sessionsContract (6(1)(b))
Coach or staff member's name, mobile, email, role, and the expiry date of their DBS certificateAcademy staffGive each coach their own login, put them on the right sessions, and stop an out-of-date DBS being rostered onto a junior sessionContract (6(1)(b)) or legitimate interests (6(1)(f)) — whichever the academy relies on for that person — and, for the DBS expiry date, legal obligation and substantial public interest in safeguarding (9(2)(g), DPA 2018 Sch. 1 Pt. 2 para. 18). Thwok holds the date only; never the certificate, the certificate number or the disclosure content.
Outstanding balance (optional)GuardianCarry forward what's owed so parents aren't double-chargedContract (6(1)(b))

What we ask you not to send

Free-text notes about a child or family, safeguarding case notes, previous incident reports, religion, ethnicity, benefits status, school names, or photographs. None of these are needed to onboard, and the import will reject unrecognised columns. If a medical note contains more than a coach needs to know on court, shorten it. You can always add detail later inside the platform, where it is encrypted and access-logged.

Why fresh consent is not the basis

Consent is the wrong basis for most of this data. A parent cannot meaningfully "refuse" to give their child's name to the academy that coaches them, and consent that can't be refused isn't valid consent. The coaching contract already justifies the core data; the migration is simply the academy choosing a new tool to perform that contract. What parents are entitled to is transparency — being told clearly, in advance, what is changing — which is what the Section 11 notice provides. Explicit consent is used only where the law requires it: medical information (special category data) and images of children.

Children's data and the Children's Code

Under UK law a child can consent to online services from age 13, but Thwok is designed so that this never has to be tested. Children under 13 do not have Thwok accounts at all: the pupil is a record held by a guardian, and it is the guardian who holds the account, accepts the terms and controls every setting. Pupils aged 13–17 may be given a limited account by their guardian, provisioned and controlled by the guardian, with no public profile, no messaging with strangers, and no location features. Because the service is nevertheless likely to be used by children, Thwok applies the ICO Children's Code: privacy settings default to the highest level, no nudge techniques, no profiling for advertising, no geolocation, and children never appear in search results, share cards, leaderboards or public event pages.

5. How onboarding works, step by step

The migration is designed so that the parent, not the academy or Thwok, is the one who activates their child's record. Until they do, the record is dormant, invisible and time-limited.

  1. Agreement signed. You sign the Data Processing Agreement (Section 10). Nothing is uploaded before this.
  2. Parents told. You send the Section 11 notice to all current families at least 7 days before upload, through whatever channel you normally use. Keep a copy and the date — that is your transparency evidence.
  3. Staff brought over. Your coaches come across the same way and at the same time, on their own template: name, mobile, email, role and DBS expiry date. They are adults, so there is no guardian step — each coach gets their own invitation, sets up their own passwordless login, and sees only the sessions you assign them. Send us the DBS expiry date, never the certificate.
  4. Register exported. You fill the import template (CSV or Google Sheet; we supply it). One row per pupil. The template validates dates, phone formats and rejects unknown columns before you upload.
  5. Secure upload. You upload through a one-time, expiring link in your Thwok academy dashboard — never by email or WhatsApp. The file goes straight to an encrypted, access-restricted bucket in the London region. The raw file is deleted automatically within 24 hours of processing.
  6. Pending records created. Each row becomes a pending pupil record linked to a hashed version of the guardian's phone number. Pending records are not searchable, not visible to coaches beyond name and group, and not linked to any Thwok account.
  7. Invitations sent in your name. Each guardian receives one message — email and/or SMS, in the academy's name — saying that Flying Shuttles has moved to Thwok and inviting them to claim their child's place. The message states where their number came from, links to the Privacy Notice, and offers a one-tap "this isn't me / remove my details" route that works without an account. This is a service message about an existing relationship, not marketing.
  8. Guardian claims the record. The guardian verifies their phone by one-time code, reviews the child's details, corrects anything wrong, confirms or updates medical notes and photo permission (Section 12), and accepts Thwok's Guardian Terms and Privacy Notice with an unticked checkbox. The consent record stores the document versions, timestamp and method. Only now does a Thwok account exist.
  9. Reminders, bounded. Unclaimed invitations get at most two reminders (day 7 and day 21). Anyone who taps "remove my details" is suppressed immediately and permanently for that academy.
  10. Unclaimed records deleted. Any record not claimed within 60 days is permanently deleted, and you receive a list of the pupil names (no other data) so you can follow up offline if you want to.
  11. Confirmation to you. You receive an import report: rows received, records claimed, records removed at the parent's request, records deleted as unclaimed. That report is your Article 30 record for the migration.
No WhatsApp group imports for academies. Thwok offers WhatsApp chat import for adult social clubs. It is not used for academies, because chat exports contain children's data and third-party conversations that the academy has no basis to hand over. Academy onboarding uses the structured register only.

6. Where the data lives and who else touches it

Thwok is built on Google Cloud (Firebase) in the London region (europe-west2). Academy data is stored, backed up and processed in the UK. The following sub-processors are engaged under written contracts that impose the same obligations Thwok owes you. You will be given 30 days' notice of any addition, with the right to object.

Sub-processorWhat they do for usData involvedLocationTransfer safeguard
Google Cloud / Firebase (Google Cloud EMEA Ltd)Database, authentication, file storage, serverless functions, hostingAll platform dataUK — London (europe-west2). Authentication metadata may be processed in the EU/US per Google's regional configuration.Google Cloud Data Processing Addendum; UK Addendum to the EU SCCs for any non-UK processing; ISO 27001, SOC 2
Stripe Payments Europe Ltd / Stripe Payments UK LtdCard payments, payouts to the academyGuardian name, email, card (tokenised — never held by Thwok), transaction amountsEU/UK, with US processing under Stripe's DPAStripe DPA with UK Addendum; PCI-DSS Level 1; FCA-authorised
Anthropic (Claude)Drafts replies to parent enquiries and summarises free text for staff review — a person approves every output before it is usedEnquiry text only; no pupil register data, no medical notes; inputs are not used to train models and are not retained beyond the requestUSAnthropic Commercial Terms and DPA with UK Addendum / IDTA; zero-retention configuration
Zoho Corporation B.V.Delivers invitations, confirmations and receipts by email (SMTP)Name, email address, message contentEU — Netherlands (smtp.zoho.eu)Zoho Data Processing Addendum with UK Addendum to the EU SCCs; ISO 27001, SOC 2
Google Cloud / Firebase AuthenticationSends the one-time codes that verify a guardian's phoneMobile number, six-digit codeProcessed by Google under its regional configurationCovered by the Google Cloud Data Processing Addendum above
[Invitation SMS provider — not yet engaged]Would send the invitation text message in the academy's name. No provider is engaged today, so invitations are sent by email only until one is. Engaging one is a change to this list and the Academy will receive 30 days' notice with a right to object (clause 6).Mobile number, message contentTo be confirmedTo be confirmed

International transfers: where a sub-processor processes personal data outside the UK, Thwok relies on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment on file, as required following the ICO's 2026 transfer guidance and the Data (Use and Access) Act 2025 "data protection test". The current list is maintained at thwok.app/legal/sub-processors.

What never happens

  • No data is sold, rented or shared with advertisers or data brokers.
  • No analytics SDK receives a child's name, date of birth or medical data. Product analytics are event-level and pseudonymised.
  • No child's data is used to train any machine-learning model, ours or anyone else's.
  • No academy's data is visible to another academy, club or venue.

7. How long we keep things

DataRetentionWhy
Raw import fileDeleted within 24 hours of processing (lifecycle rule as backstop)Minimisation; only structured records survive
Pending (unclaimed) pupil records and invitations60 days, then deletedNo relationship established; the academy is told which names were removed
Suppression list ("remove my details")Hashed phone/email, kept permanentlyAn objection does not expire. The record is a one-way hash with no contact details in it, so keeping it indefinitely is the least intrusive way to be certain the person is never contacted for this academy again. Deleting it after a fixed period would mean a later import could reach them a second time.
Active pupil record, enrolments, attendanceWhile enrolled, then 12 months after the last enrolment ends, then deleted or anonymisedAllows re-enrolment after a gap year; matches typical sports-body guidance
Medical notesDeleted 90 days after the last enrolment ends, or immediately on guardian requestSpecial category data — shortest workable period
Consent records (terms, privacy, medical, photo)6 years after the relationship endsEvidence of compliance (limitation period)
Payment and fee records6 years from end of the tax yearHMRC and accounting requirements
Safeguarding recordsRetained per the academy's safeguarding policy and applicable statutory guidance — the academy instructs; Thwok holdsStatutory inquiries and the child's future welfare
Guardian account after deletion requestDeleted within 30 days; financial records retained as above in a form unlinked from the accountRight to erasure, balanced against legal obligations
On termination of the Academy AgreementFull export offered; all academy data deleted within 30 days of your instruction, backups purged within a further 35 daysSection 10, clause 12

8. How we protect it

Technical measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256) for all data, including backups.
  • Medical notes and emergency contacts are stored in a separate, more tightly controlled collection with field-level access rules.
  • Every read and write goes through server-side security rules: a coach sees only the pupils in their own sessions; an academy admin sees only their academy; a parent sees only their own children.
  • Guardian phone numbers are the identity anchor and are stored hashed with a secret key for matching; plaintext is held only where needed to send a message.
  • All data changes are written through an audit log; medical-note access is logged by user and time.
  • Passwordless sign-in (one-time code / magic link) — nothing for parents to reuse or leak.
  • Automated daily backups in the London region, tested restores, 35-day point-in-time recovery.
  • Dependency scanning and secret scanning on every code change; production access requires hardware-key MFA.

Organisational measures

  • Production data access is limited to the founder; there are no contractors with standing access. Any future staff are DBS-checked where their role touches children's data and trained before access.
  • Support is done through admin tooling with the same access rules as the product, not through raw database access.
  • A written incident response procedure (Section 9) with a 24-hour notification commitment to academies.
  • A Data Protection Impact Assessment covering children's data, medical data, messaging and AI-assisted features, reviewed before each major feature ships (summary in Section 9).
  • Sub-processors reviewed annually; DPAs on file.
  • Records of processing maintained under Article 30.
  • Per-academy export and delete functions so that leaving is always possible without asking us.

Independent assurance: Thwok is an early-stage company and does not yet hold its own ISO 27001 or Cyber Essentials certification. Its infrastructure providers (Google Cloud, Stripe) are ISO 27001 and SOC 2 certified. Thwok intends to obtain Cyber Essentials within 12 months of the date of this pack and will notify academies when achieved.

9. Children, rights requests, complaints and breaches

Rights requests from parents (and older pupils)

Parents can exercise every UK GDPR right about their child's data — access, rectification, erasure, restriction, portability and objection. A pupil aged 13 or over may also exercise rights in their own name where they have the maturity to understand them; Thwok will involve the guardian unless doing so would be against the child's interests. You are responsible for responding as controller; Thwok is responsible for making that easy:

  • Most requests need no request at all: guardians can view, correct, export and delete their child's data from their own account.
  • A request that arrives at Thwok about academy data is forwarded to your nominated contact within 2 working days, and we do not respond on your behalf unless you ask us to.
  • Where you need help — a full export, a search across attendance history, deletion with a legal-hold exception — we provide it within 5 working days so you can meet the statutory one-month deadline. Since 5 February 2026 you may pause that clock while waiting for identity confirmation or clarification from the requester, and you need only carry out a reasonable and proportionate search.

Complaints

Since 19 June 2026 every controller must have a way for people to complain about how their data is handled, acknowledge within 30 days and respond without undue delay. Thwok operates such a route for its own controller activities at privacy@thwok.app and, on request, provides academies with a simple complaints log template. Anyone unhappy with the outcome may complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).

If something goes wrong: breach procedure

  1. Detect and contain. Access revoked, credentials rotated, affected systems isolated. Target: within 4 hours of detection.
  2. Assess. What data, whose, how many, likely consequences. Children's or medical data automatically counts as "likely to result in a risk", so assume notification is needed.
  3. Tell you. Written notification to your nominated contact within 24 hours of confirming a breach affecting your data, with what we know, what we've done and what we recommend — followed by updates as the picture develops. This is well inside the "without undue delay" the law requires of a processor.
  4. Support your ICO decision. As controller you decide whether to notify the ICO (72 hours from becoming aware) and affected parents. We give you the facts and draft wording; we do not notify parents about academy data without your instruction.
  5. Learn. Written post-incident review shared with you within 14 days.

Legitimate interests assessment — emergency contacts

Emergency contacts are third parties who have not signed anything. Holding their name and phone number is justified by the legitimate interest in a child's safety during a session: the purpose is real and specific; the data is the minimum needed (name, number, relationship); the contact would reasonably expect it, having been nominated by the parent for exactly this; the impact is minimal, as the number is used only in an emergency, never for messaging or marketing, and is deleted with the pupil record. The balance favours processing. The guardian is asked to confirm the person is aware they have been nominated.

Data Protection Impact Assessment — summary

A full DPIA is held by Thwok and available to academies on request. Its conclusions for the academy product are:

RiskAssessmentControls
Children's data exposed to other usersHigh impact, low likelihoodChildren are records, not accounts; never in search, share cards, leaderboards or public pages; per-role security rules tested on every release
Medical data accessed beyond needHigh impact, low likelihoodSeparate collection, field-level rules, access logging, 90-day post-enrolment deletion
Migration reaches the wrong personMedium impact, medium likelihood (stale numbers)Phone OTP before any record is shown; "not me" route; 60-day auto-delete of unclaimed records
Invitations treated as unsolicited marketingMedium impact, low likelihoodSent in the academy's name about an existing relationship; capped at one invite and two reminders; immediate suppression
AI-assisted features process pupil dataMedium impact, low likelihoodModel receives enquiry text only, never the register; human approves every output; zero-retention contract; no training on inputs
Automated decisions affecting a child (e.g. arrears suspension)Medium impactNever enforced at the door; disclosed ladder; human review on request; suspension of a child's place requires an academy admin's confirmation
Photos and video of childrenHigh impactPer-use guardian consent; guardian-only visibility by default; never indexed; withdrawable at any time with removal
Loss of availability (Thwok ceases trading)Medium impactAcademy can export everything at any time; deletion on termination; no lock-in of register data

10. Academy Data Processing Agreement

This Agreement forms part of, and is incorporated into, the Thwok Academy Agreement between the parties. It sets out the terms required by Article 28(3) UK GDPR. Defined terms have the meanings given in UK GDPR. To be reviewed by the parties' legal advisers before signature.

Parties. (1) [Flying Shuttles Badminton Academy — legal name, entity type and address] (the "Academy", the Controller) and (2) SIMPLIFY HCS LIMITED, company number 13667511, of 4 Henley Gardens, Pinner, HA5 2DE, trading as Thwok ("Thwok", the Processor).

1.Subject matter and duration. Thwok processes Academy Personal Data for the purpose of providing the Thwok academy management platform (enrolment, timetabling, registers, communications with guardians, fee collection and safeguarding workflows) for as long as the Academy Agreement is in force and for the deletion period in clause 12.
2.Nature and purpose of processing. Storage, organisation, retrieval, transmission to guardians and coaches authorised by the Academy, and deletion. Categories of data subjects: pupils (children aged 4–17), their parents and guardians, emergency contacts, and Academy staff and coaches. Categories of personal data: identity and contact details, date of birth, group and enrolment data, attendance, fee and payment status, consent flags, and — as special category data — medical information relevant to physical activity, provided with the guardian's explicit consent.
3.Documented instructions. Thwok shall process Academy Personal Data only on the Academy's documented instructions, which are: the Academy Agreement, this Agreement, the configuration the Academy sets in the platform, and the actions of the Academy's authorised users. Thwok shall inform the Academy immediately if, in its opinion, an instruction infringes data protection law. Thwok shall not process Academy Personal Data for its own purposes except as permitted in clause 14.
4.Confidentiality. Thwok shall ensure that every person authorised to process Academy Personal Data is bound by a written duty of confidentiality and has received appropriate training, and that access is limited to those who need it to perform the services.
5.Security. Thwok shall implement and maintain the technical and organisational measures described in Section 8 of the Data Protection Pack, and shall not materially reduce their overall level of protection during the term. Thwok shall keep those measures under review in light of the state of the art and the risks to children's data in particular.
6.Sub-processors. The Academy gives general authorisation to the sub-processors listed in Section 6 of the Data Protection Pack. Thwok shall give the Academy at least 30 days' written notice of any intended addition or replacement, during which the Academy may object on reasonable grounds; if the objection cannot be resolved, the Academy may terminate the Academy Agreement without penalty and clause 12 applies. Thwok shall impose on each sub-processor, by written contract, data protection obligations no less protective than this Agreement, and remains fully liable to the Academy for the sub-processor's performance.
7.International transfers. Thwok shall store Academy Personal Data in the United Kingdom and shall not transfer it outside the United Kingdom except to a sub-processor listed under clause 6, and then only under the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another mechanism valid under Chapter V UK GDPR, with a transfer risk assessment on file.
8.Assistance with data subject rights. Taking into account the nature of the processing, Thwok shall assist the Academy by appropriate technical and organisational measures — including self-service access, rectification, export and deletion tools for guardians — to respond to requests to exercise data subject rights. Thwok shall forward to the Academy within 2 working days any such request it receives that concerns Academy Personal Data, and shall not respond to it except on the Academy's instruction. Where the Academy requires further assistance, Thwok shall provide it within 5 working days.
9.Assistance with security, breach notification and DPIAs. Thwok shall assist the Academy in meeting its obligations under Articles 32 to 36 UK GDPR. Thwok shall notify the Academy without undue delay, and in any event within 24 hours of confirming, any personal data breach affecting Academy Personal Data, providing the information the Academy needs to meet its own notification obligations, and shall provide updates as further information becomes available. Thwok shall make its DPIA available to the Academy on request.
10.Children's data. Thwok shall (a) not create an account for any pupil under 13; (b) provision any account for a pupil aged 13–17 only at a guardian's instruction and under the guardian's control; (c) never display a pupil in public or cross-academy search, listings, share cards, leaderboards or event pages; (d) not publish any image or recording in which a pupil is identifiable without a current, specific consent record from the guardian; (e) apply the ICO Age Appropriate Design Code standards to all surfaces a pupil may use; and (f) not use Academy Personal Data for profiling, advertising or the training of any machine-learning model.
11.Safeguarding. Thwok shall forward any safeguarding concern relating to Academy sessions, staff or pupils to the Academy's nominated welfare officer within 4 working hours of receipt, retaining a record of the concern and the forwarding. Nothing in this Agreement prevents either party from disclosing information to the police, a local authority or another statutory body where required by law or necessary to protect a child.
12.Return and deletion. At any time during the term, and on termination, the Academy may export all Academy Personal Data in a structured, commonly used, machine-readable format through the platform. Within 30 days of termination or of the Academy's instruction, Thwok shall delete all Academy Personal Data, and shall purge it from backups within a further 35 days, except to the extent that UK law requires retention (in which case Thwok shall retain only what is required, in isolation, and only for so long as required). Thwok shall confirm deletion in writing on request.
13.Audit and information. Thwok shall make available to the Academy all information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, including this Pack, its records of processing, sub-processor contracts (redacted for commercial terms) and any third-party certifications or audit reports it holds. Where these are insufficient, the Academy or an auditor it mandates (not a competitor of Thwok, and bound by confidentiality) may audit Thwok's compliance once in any 12-month period on 30 days' notice, or at any time following a personal data breach, during business hours and without unreasonable disruption.
14.Thwok as controller. The Academy acknowledges that Thwok is an independent controller of: guardian and staff account data (login credentials, notification and consent settings); payment transaction records; and aggregated, anonymised statistics that cannot identify any pupil, guardian or academy. Thwok processes such data under its Privacy Notice. Thwok shall not use Academy Personal Data to market to guardians unless the guardian has given Thwok a separate, specific and revocable opt-in.
15.Academy obligations. The Academy warrants that it has a lawful basis for the Academy Personal Data it provides, that it has given guardians the information required by Articles 13 and 14 UK GDPR (including by the notice in Section 11 of the Pack) before instructing the migration, that it has obtained explicit consent for any medical information it provides, and that it will provide only the data fields specified in the import template.
16.Liability. Each party is liable for damage caused by its own processing in breach of UK GDPR or this Agreement, in accordance with Article 82 UK GDPR. The limitations and exclusions of liability in the Academy Agreement apply to this Agreement, save that nothing limits either party's liability for breach of clause 10 or for a fine or claim arising from its own wilful default.
17.General. This Agreement prevails over any conflicting term of the Academy Agreement in relation to personal data. It is governed by the laws of England and Wales. Changes in law that require amendment shall be made by agreement, and Thwok shall propose amendments in good time.
For the AcademyName · Role · Signature · Date
For SIMPLIFY HCS LIMITED (Thwok)Nagini Vallamkonda · Director · Signature · Date

11. Template: notice to parents before migration

Send this to every current family at least 7 days before the import, by whatever channel you normally use. Edit the amber parts; keep the substance. The final paragraph is the line to add to your own privacy notice.

Subject: Flying Shuttles is moving to Thwok — what it means for you

Dear parents and carers,

From [date] we're running Flying Shuttles on Thwok, a badminton academy platform, instead of spreadsheets and WhatsApp. You'll be able to see your child's sessions, pay for the term, update medical and emergency details, and hear about cancellations — all in one place.

What happens to your details. We'll transfer the information we already hold for your child and you — name, date of birth, your contact details, emergency contact, any medical notes you gave us, and your photo permission — to Thwok so that your child's place is ready. Thwok stores it in the UK, uses it only to run our academy, and is bound by a contract with us. Nothing about your child will ever be visible to other families or searchable online.

What you need to do. Around [date] you'll receive a message from Flying Shuttles via Thwok inviting you to confirm your child's place. It takes about a minute: verify your phone number, check the details, confirm the medical and photo permissions, and accept Thwok's terms. If you don't claim the place within 60 days, Thwok deletes the record and we'll get in touch the old way.

If you'd rather we didn't. Tell us before [date] and we'll leave your details out of the transfer and carry on with you offline. If you get a message you weren't expecting, tap "this isn't me" and it stops.

Thwok's privacy notice is at thwok.app/privacy and their data protection pack for academies — the full detail of how they look after children's data — is at thwok.app/legal/academies. Any questions, ask [name] at [academy contact].

Thanks,
[Name], Flying Shuttles Badminton Academy

Line for your own privacy notice

"We use Thwok (SIMPLIFY HCS LIMITED) to manage enrolments, registers, communications and payments. Thwok processes pupil and parent data on our behalf under a written agreement, stores it in the UK, and does not use it for any other purpose. Details: thwok.app/legal/academies."

12. Template: guardian consent & medical information

This is the screen a guardian completes when claiming a record (and the paper equivalent for anyone who prefers it). Each consent is separate, unticked, specific and withdrawable — which is what makes it valid. Thwok records the version, timestamp and method for each.

About your child — name, date of birth, group. Please check these are right.

Emergency contact — name, relationship, phone. ☐ I confirm this person knows they've been nominated.

Medical information (optional but important). Is there anything a coach should know to keep your child safe on court — for example asthma, allergies, epilepsy, a condition affecting exercise, or medication they carry?
[free text, 300 characters]
☐ I give my explicit consent for Flying Shuttles and Thwok to record this information and share it with the coaches running my child's sessions, so they can respond in an emergency. I understand I can change or remove it at any time and it will be deleted 90 days after my child's last enrolment ends.

Photos and video.
☐ Coaches may take photos or short clips of my child during sessions for my eyes only (progress and skills feedback, visible only in my account).
☐ My child may appear in academy group photos shared with other Flying Shuttles families.
☐ My child may appear in Flying Shuttles' public promotion (website, social media), never named.
Each of these is separate. Leaving all three unticked is completely fine. You can change your mind at any time and we'll take the content down.

Messages. We'll always contact you about your child's sessions, payments and safety — that's part of running the academy.
☐ Thwok may also message me about other badminton activities near me (optional; you can stop this any time).

☐ I am the parent or legal guardian of this child. I have read Thwok's Guardian Terms and Privacy Notice.

13. Parent FAQ

Do I have to use Thwok? The academy has chosen it as the way it runs bookings and communications, so it's how you'll see sessions and pay. If you have a real difficulty with it, speak to the academy — they can keep you on a manual arrangement.

Can other parents see my child? No. Only you, the academy's admin and the coaches running your child's sessions can see your child's record. Children never appear in search, on public pages or in any leaderboard.

Where is the data stored? In the UK, on Google Cloud's London region, encrypted.

Will Thwok send me marketing? Not unless you tick a separate box asking for it. Messages about your child's sessions and payments aren't marketing — they're the service.

Who can see the medical notes? You, the academy's admin and the coaches on your child's sessions. Every time someone opens them it's logged.

What if I want everything deleted? You can delete your child's record and your account from the app. Payment records that the law says must be kept are retained for six years in a form that isn't linked to your account.

Does Thwok use AI? Thwok uses an AI model to help draft replies to enquiries and to summarise text for staff, and a person checks every output. Your child's record and medical notes are never sent to it, and nothing you write is used to train it.

Who do I complain to? The academy first (they are responsible for your child's data), or Thwok at privacy@thwok.app. If you're not satisfied, the Information Commissioner's Office at ico.org.uk.

14. Checklists and sign-off

Academy — before upload

  • Data Processing Agreement (Section 10) signed by both parties
  • Nominated data protection contact and welfare officer given to Thwok
  • Section 11 notice sent to all families; date and copy kept
  • Own privacy notice updated with the Thwok line
  • Families who opted out removed from the export
  • Export completed in the template; medical notes trimmed to what a coach needs; no extra columns
  • Upload made through the secure link only; local copies deleted or moved to your normal secure storage

Thwok — before and after import

  • Signed DPA on file; academy contacts recorded
  • Entity details, ICO number and sub-processor placeholders completed in this pack
  • Import template validation and column rejection tested
  • Raw-file 24-hour deletion and 60-day unclaimed purge verified in staging
  • Invitation wording, "not me" route and reminder cap reviewed
  • Guardian consent screen matches Section 12 exactly; versions recorded
  • Import report delivered to the academy; Article 30 record updated

Acknowledgement

By signing below the Academy confirms it has received and reviewed this Data Protection Pack, version 1.0, and that its contents form the basis on which it instructs Thwok to migrate and process its pupil and guardian data.

For the AcademyName · Role · Signature · Date
For ThwokNagini Vallamkonda · Director, SIMPLIFY HCS LIMITED · Signature · Date

Thwok Data Protection Pack for Academies · Version 1.2 · 13 September 2026 · © SIMPLIFY HCS LIMITED trading as Thwok. This pack describes Thwok's practices in good faith and to a data protection officer's standard; it is not legal advice to the Academy, which should take its own advice on its obligations as controller. Current versions of Thwok's legal documents are published at thwok.app/legal. Law referenced is current as at the version date, including the Data (Use and Access) Act 2025 (main provisions in force 5 February 2026; complaints duty 19 June 2026).

SIMPLIFY HCS LIMITED trading as Thwok · Company 13667511 · ICO ZB235652 · 4 Henley Gardens, Pinner, HA5 2DE, England · privacy@thwok.app