Data processing agreement

These terms apply between your club (the controller) and Clubo Software Ltd (company no. 17401263, ICO registration no. C2015283, the processor) whenever your club uses Clubo to hold member data. They form part of our terms of service.

Last updated 25 August 2026

1. Roles and subject matter

  • Your club is the controller of its members' personal data. It decides who to invite, what to record, what to charge and how long to keep records within the options the service offers.
  • We are the processor. We process member data only to provide the service, and only on your club's instructions.
  • Subject matter and duration: provision of the Clubo club management service for the length of your club's subscription, plus the wind-down period in section 8.

2. Nature and purpose of processing

Storing and displaying member profiles; sending fixture invitations, reminders and club announcements; recording availability and attendance; collecting membership fees, match fees, fines and shop or ticket orders; recording match statistics; and producing reports for club administrators.

3. Categories of data and data subjects

  • Data subjects: club members and players, club administrators, guests who buy tickets or submit enquiries.
  • Categories: name, email, phone, photo, date of birth where the club asks for it, playing position and kit sizes, availability and attendance, payment records and outstanding balances, match statistics, notification preferences and device registrations.
  • Card details: we never hold full card numbers. Card data is captured and stored by Stripe; we hold only a reference and the last four digits Stripe returns.
  • Clubs should not use free-text fields to record health information beyond what the physio module is designed for.

4. Our obligations

  • Process member data only on your documented instructions, including these terms.
  • Keep member data confidential and ensure anyone with access is bound by confidentiality obligations.
  • Not sell member data, use it for advertising, or use it to train models for our own purposes.
  • Assist your club in responding to data subject requests, using the export, correction and anonymisation tools in the admin area, and by helping directly where those tools are not enough.
  • Assist with your obligations around security, breach notification and impact assessments, taking into account the nature of the processing.

5. Security measures

  • Data in transit is encrypted with TLS; data at rest is encrypted by our hosting provider.
  • Row-level access rules isolate each club's data at the database level, so an administrator of one club cannot read, export or edit another club's data.
  • Administrative actions on member data — exports and anonymisations — are logged with the acting administrator and timestamp.
  • Sign-in supports password, passkey and an in-app PIN lock. Payments are handled by Stripe and never pass through our own card storage.
  • Access to production data by our staff is limited to what is needed to operate and support the service.

6. Sub-processors

Your club gives general authorisation for us to appoint sub-processors. The current list, with what each one does and where it is based, is published at our sub-processor list. We impose data protection obligations on each sub-processor no less protective than these terms, and we remain responsible for their performance. We will update that page before adding or replacing a sub-processor; if your club objects on reasonable data protection grounds, it may cancel the affected part of the service.

7. International transfers

Some sub-processors process data outside the UK. Where they do, transfers rely on the safeguards those providers offer, such as the UK International Data Transfer Addendum or standard contractual clauses.

8. Deletion and return of data

  • Club administrators can export a member's data or anonymise it at any time from the admin area.
  • On cancellation, we keep the club's data for 90 days so it can be restored or exported, then delete it.
  • Where we anonymise rather than delete, financial and match records are retained without the personal identifiers, so the club's accounts and reporting remain intact.
  • We may retain records for longer where law requires it, and only for as long as that requirement lasts.

9. Breach notification

If we become aware of a personal data breach affecting your club's data, we will notify the club's administrators without undue delay with the information we have, the likely consequences and the steps we are taking. We will keep the club updated as we learn more.

10. Audit and information rights

On reasonable written request, and no more than once a year unless required by a regulator or following a breach, we will provide the information your club needs to demonstrate compliance with these terms. Requests go to hello@club-o.app.

11. Precedence and changes

Where these terms conflict with our terms of service on the processing of member data, these terms take precedence. See also our privacy policy. We will update this page when our processing changes and change the date at the top.