Data Processing Addendum
Effective date: August 10, 2026.
Scope
This addendum applies when Big Balls Sports Data (the "Processor") processes personal data on behalf of a customer (the "Controller") in connection with the API and developer platform. It forms part of, and is governed by, our Terms of Service.
Roles
The sports data the API returns (scores, odds, lineups, stats) is not personal data and falls outside this addendum. Where you operate a product on top of our API that processes personal data about your own end users, you are the Controller and we are the Processor of that data only to the extent it transits our systems (e.g. authentication metadata).
Sub-processors
We engage the following categories of sub-processor to deliver the service:
- · Cloud hosting and database provider
- · Payment processing (subscription billing)
- · Transactional email delivery
- · Customer authentication via OAuth identity providers
- · Error reporting and operational telemetry
A current named list, with vendor, processing purpose, and data-residency region, is available on request from [email protected]. We will notify Controllers of new sub-processors at least 30 days before they take effect.
Security
Data in transit is encrypted with TLS 1.2 or later. Data at rest is encrypted at the storage layer. Access to production data is limited to a short list of named engineers and is logged. API keys are stored as one-way hashes; the plain-text value is shown to the developer once at creation time.
Data subject requests
Where end users of your product exercise rights of access, rectification, deletion, or portability against you, you can self-serve most operations through the developer dashboard. For requests that the dashboard can't satisfy we'll cooperate on a reasonable-effort basis; email [email protected].
Contact
Questions, signed addenda, or breach-notification routing go to [email protected].