Data processing terms
These terms are the data processing agreement required by Article 28 of the General Data Protection Regulation. They apply whenever Clubify processes personal data on behalf of a club, and they complete the [Terms of sale](sales) and the [Privacy policy](privacy).
1. Purpose
A club that uses Clubify to manage its members, teams, documents and communications decides alone what it collects and why. It is the controller. Clubify provides the tool that hosts and runs that data, and acts as the processor.
These terms set out what Clubify undertakes to do, and not to do, with that data. The club accepts them together with the Terms of sale, and the two form a single agreement.
Clubify acts as a controller for its own processing, namely customer account management, billing, platform security and its commercial relationship. That processing is governed by the Privacy policy, not by these terms.
2. Definitions
- Customer: the club, association, company or entity that subscribes to the Service and determines the purposes of the processing.
- Service: the Clubify platform and its web, mobile and desktop applications.
- Customer Data: the personal data that the Customer, its members or its users place in the Service, or that their use of it generates.
- Data subjects: the individuals to whom that data relates, in particular club members, their legal representatives, coaching staff and invited users.
- Sub-processor: a provider to which Clubify entrusts part of the processing in order to deliver the Service.
3. Description of the processing
Subject matter and nature. Hosting, storage, organisation, consultation, provision, backup and deletion of Customer Data, for the sole purpose of delivering the subscribed Service.
Purpose. To let the Customer run its activity: members and squads, teams and seasons, calendars and attendance, documents and contracts, internal communications, membership fees and finances, and the modules it has enabled.
Duration. The processing lasts for as long as the contract, extended by the retention and archiving periods described in section 11.
Categories of data. Depending on the modules the Customer enables:
- identification data: first name, last name, date of birth, email address, phone number, photograph;
- club life data: roles, teams, licences, attendance, call-ups, sporting results;
- documents and files placed by the Customer in the Drive, including contracts and administrative records;
- communication data: messages, notifications and their metadata;
- club financial data: membership fees, transactions, payment schedules;
- strictly necessary technical data: connection logs, IP address, device identifiers.
Categories of data subjects. Club members, coaching staff and volunteers, officers, legal representatives of underage members, and people invited by the Customer.
The Customer alone judges whether the data it places in the Service is relevant. It must refrain from recording data that is not necessary to its management, in particular health data outside the areas expressly provided for that purpose.
4. Customer instructions
Clubify processes Customer Data only on the Customer's documented instructions. Use of the Service, the configuration chosen by the Customer and these terms constitute those instructions.
The following are documented instructions from the Customer, without any further request being needed:
- running the features of the Service as the Customer configures and uses them;
- hosting, backup, restoration and technical monitoring operations;
- read-only access to Customer Data by authorised Clubify personnel, for support, corrective maintenance, security and improvement of the Service;
- measures required to respond to a security incident or to preserve the integrity of the platform.
Traceability of support access. Every access to Customer Data by Clubify personnel is recorded: who accessed it, the date and time, the club concerned and the reason for the access. That access is read-only and allows no modification of Customer Data. These logs are kept for twelve months. The Customer may obtain the extract concerning it on request.
If Clubify considers that an instruction from the Customer breaches applicable law, it informs the Customer without delay and may suspend that instruction.
5. Confidentiality
Clubify ensures that persons authorised to process Customer Data are bound by a duty of confidentiality, whether contractual or statutory, and that they receive the training needed to protect that data.
Access to Customer Data is limited to those who need it to perform their role, on a least-privilege basis. That authorisation is reviewed whenever a role changes and withdrawn when the person leaves.
6. Security
Clubify implements appropriate technical and organisational measures within the meaning of Article 32 of the Regulation, taking into account the state of the art, the cost of implementation and the nature of the processing.
Those measures include:
- encryption of communications in transit and encryption of backups;
- access control by role and by scope, keeping each club's data separate;
- user authentication and session management;
- logging of access and of sensitive operations;
- regular backups and restoration testing;
- antivirus scanning of files placed in the Service;
- monitoring of vulnerabilities affecting the components in use.
These measures evolve with the Service. Clubify may change them provided the level of protection of Customer Data is not reduced.
7. Sub-processors
The Customer authorises Clubify to use the sub-processors listed on the Sub-processors page, which forms an integral part of these terms. Each is bound by a contract imposing protection obligations equivalent to those in these terms.
Clubify informs the Customer of any addition or replacement of a sub-processor at least thirty days before it takes effect. The Customer may object on legitimate data protection grounds; failing agreement, it may terminate the affected part of the Service without penalty.
8. Data subject rights
Data subjects exercise their rights with the Customer, which is their natural point of contact since it is the controller.
Clubify assists the Customer through built-in features that allow data to be viewed, corrected, exported and deleted from the Service. Where those features are not enough, Clubify provides reasonable assistance within a timeframe compatible with the deadline imposed on the Customer.
If a data subject contacts Clubify directly, Clubify refers them to the Customer and informs the Customer without undue delay, without acting on the request itself.
9. Data breaches and impact assessments
In the event of a personal data breach affecting Customer Data, Clubify informs the Customer without undue delay after becoming aware of it, and at the latest within forty-eight hours.
That information covers, so far as it is available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. It is completed as the analysis progresses.
Notification to the supervisory authority and, where applicable, to the data subjects is for the Customer to make. Clubify provides it with the technical elements it needs.
Clubify also assists the Customer, within the limits of the information available to it, with data protection impact assessments and prior consultation of the supervisory authority where these are required.
10. Transfers outside the European Union
Customer Data is hosted within the European Union.
Some sub-processors listed in section 7 belong to companies established outside the European Union. Where a transfer may result, it is governed by the standard contractual clauses adopted by the European Commission or by any other mechanism recognised as providing appropriate safeguards.
Clubify provides the Customer, on request, with the safeguards in place for a given transfer.
11. Data at the end of the contract
At the end of the contract, the Customer has thirty days to export its data from the Service.
After that period, Clubify deletes or anonymises Customer Data, except for data it is legally required to keep, in particular accounting records relating to billing, and data present in backups.
Backups follow their own cycle and are overwritten within ninety days. No targeted restoration is performed on them to extract data after the end of the contract, unless legally required.
The retention periods that apply during the life of the contract are set out in the Privacy policy.
12. Demonstrating compliance and audits
Clubify makes available to the Customer the information needed to demonstrate compliance with the obligations laid down in Article 28 of the Regulation, in particular a description of the security measures, an up-to-date list of sub-processors and the extract of the access logs concerning it.
The Customer may request an audit once in any twelve-month period, save in the event of a proven security incident. The audit is carried out on documents, at the Customer's expense, on reasonable notice, during business hours, and without compromising the security or confidentiality of other customers' data. The parties agree the arrangements before it takes place.
13. Respective responsibilities
The Customer warrants that it has a legal basis for the processing it carries out, that it has informed the data subjects and, where required, obtained their consent or that of their legal representatives.
The Customer is responsible for the access it grants within its club, and for the relevance and accuracy of the data it records.
Clubify answers for its own breaches of these terms and for those of its sub-processors, within the limits set out in the Terms of sale.
14. Duration, changes and contact
These terms take effect for as long as Clubify processes Customer Data and end once the obligations in section 11 have been performed.
Clubify may amend them to reflect a regulatory change, a change to the Service or a change of sub-processor. Any substantial change is brought to the Customer's attention at least thirty days before it takes effect.
Where these terms and the Terms of sale conflict on the processing of personal data, these terms prevail.
The French version is the authoritative one. Other language versions are provided for information.
Any question about these terms may be sent through the Contact page.