Data protection procedures

How data protection requests and security incidents are handled on Clubo — written so club admins and members can both follow it.

Last updated 2 September 2026

Who is responsible for what

Your club decides what member data it collects and why, so the club is the data controller for that data. Clubo Software Ltd runs the software the club uses, so we are the data processor acting on the club's instructions under our data processing agreement.

  • Club admins answer requests about their own members and are the first point of contact.
  • Clubo provides the tools to export, correct and erase data, and handles anything that affects the platform itself.

Your rights

  • Access — ask what personal data is held about you and get a copy.
  • Correction — have inaccurate details such as your name, contact details or date of birth fixed.
  • Erasure — ask for your data to be removed, subject to records we must keep (see below).
  • Portability — receive your data in a structured, machine-readable format.
  • Objection and restriction — object to a particular use of your data, or ask us to pause processing while a dispute is resolved.
  • Withdraw consent — turn off notifications, remove a saved card, or withdraw a consent you previously gave, at any time from your account.

How to make a request

  1. 1. Contact your club. Email or message a club admin. A request does not need special wording — any clear ask counts.
  2. 2. If the club does not respond, email hello@club-o.app and we will contact the club on your behalf, or act directly where we are able to.
  3. 3. Identity check. So data is not disclosed to the wrong person, we confirm the request comes from the account holder — normally by replying from the email address on the account. Where a request concerns a member under 18, we deal with the parent or guardian recorded on the account.
  4. 4. Response. We aim to respond within one calendar month. If the request is complex or there are several requests, this can be extended by up to two further months — we will tell you within the first month if that happens.

Requests are free. We only charge, or refuse, where a request is manifestly unfounded or excessive — and we will explain why if that ever applies.

What happens when data is erased

Erasure removes identifying details — name, contact details, date of birth, profile photo, notification devices and saved card links — and disables the sign-in. Some records are kept because there is a legal or financial reason to keep them:

  • Payment and fee records are retained for accounting and tax purposes, with the payer detached from the identifying profile.
  • Card details are never held by us — they stay with our payment provider.

A nightly retention sweep also removes data nobody needs any more: members who have left every team in a club beyond the club's retention window are anonymised automatically, expired invites and short-lived security records are deleted, and if a club cancels, its member data is purged after a 90-day grace period.

Security incidents and breaches

We follow the same steps every time, in this order:

  1. 1. Detect. Incidents reach us through automated error monitoring and job alerts, reports from clubs or members, or notifications from one of our sub-processors.
  2. 2. Contain. We stop the exposure first — revoking sessions or keys, disabling the affected feature, or taking the affected part of the service offline.
  3. 3. Assess. We establish what data was involved, how many people are affected and the likely harm.
  4. 4. Notify. Where a breach is likely to result in a risk to people's rights and freedoms, it is reported to the Information Commissioner's Office within 72 hours of becoming aware of it. Affected clubs are told without undue delay so they can meet their own obligations, and members are told directly where the risk to them is high.
  5. 5. Remediate. We fix the root cause, record the incident and what was done, and review whether the same class of problem can happen elsewhere.

If you think data has been exposed, email hello@club-o.app with as much detail as you can. Please do not post details publicly until we have had a chance to fix it.

Complaints

If you are unhappy with how a request or incident was handled, email hello@club-o.app. You can also complain to the UK Information Commissioner's Office at ico.org.uk. Clubo Software Ltd is registered with the ICO under reference ZC230387.

Related pages: privacy policy, data processing agreement, sub-processors.