Data Processing Addendum

Effective date: August 10, 2026.

Scope

This addendum applies when Big Balls Sports Data (the "Processor") processes personal data on behalf of a customer (the "Controller") in connection with the API and developer platform. It forms part of, and is governed by, our Terms of Service.

Roles

The sports data the API returns (scores, odds, lineups, stats) is not personal data and falls outside this addendum. Where you operate a product on top of our API that processes personal data about your own end users, you are the Controller and we are the Processor of that data only to the extent it transits our systems (e.g. authentication metadata).

Sub-processors

We engage the following categories of sub-processor to deliver the service:

  • · Cloud hosting and database provider
  • · Payment processing (subscription billing)
  • · Transactional email delivery
  • · Customer authentication via OAuth identity providers
  • · Error reporting and operational telemetry

A current named list, with vendor, processing purpose, and data-residency region, is available on request from [email protected]. We will notify Controllers of new sub-processors at least 30 days before they take effect.

Security

Data in transit is encrypted with TLS 1.2 or later. Data at rest is encrypted at the storage layer. Access to production data is limited to a short list of named engineers and is logged. API keys are stored as one-way hashes; the plain-text value is shown to the developer once at creation time.

Data subject requests

Where end users of your product exercise rights of access, rectification, deletion, or portability against you, you can self-serve most operations through the developer dashboard. For requests that the dashboard can't satisfy we'll cooperate on a reasonable-effort basis; email [email protected].

Contact

Questions, signed addenda, or breach-notification routing go to [email protected].