Security and data protection

Protecting your club’s data is at the heart of everything we build. Discover the measures and protocols we implement to ensure the confidentiality, integrity, and availability of your information.

Security approach

An ISMS structured around international information security standards

Hosting sicuro

EU data centers operated by IONOS SARL

GDPR compliant

Full compliance with European data protection regulations

Secure payments

Powered by Stripe, PCI-DSS Level 1 certified

Hosting sicuro nell'UE

All your data is hosted by IONOS SARL, located in Sarreguemines, France, within European Union data centers. This guarantees that your information never leaves European jurisdiction.

Encryption in transit

All communications between your browser and our servers are protected by TLS (HTTPS) encryption, ensuring that no third party can intercept your data in transit.

Encryption at rest

Sensitive data stored in our databases benefits from encryption at rest, adding an additional layer of protection against unauthorized physical or logical access.

Automated backups

Automated daily backups with a rolling 90-day retention period ensure your data can be recovered in any situation. Backup integrity is regularly tested.

Data separation

Each club’s data is logically isolated within our infrastructure, preventing any cross-access between organizations and ensuring strict confidentiality.

Cancellazione controllata

Alla chiusura del suo account, i suoi dati personali vengono cancellati o anonimizzati in modo irreversibile, nei tempi e secondo le eccezioni legali dettagliate nella nostra informativa sulla privacy.

Role-Based Access Control (RBAC)

We implement a granular permission system that ensures each user only accesses the data and features corresponding to their role within the club. Permissions are configurable by administrators.

Principle of least privilege

By default, users receive only the minimum permissions strictly necessary for their function. This approach minimizes the attack surface and limits the impact of any potential compromise.

Secure authentication

Passwords are hashed using modern algorithms. Two-factor authentication (2FA) is available to add an extra layer of protection. Sessions are managed securely with automatic expiration mechanisms.

Administrative audit trail

All sensitive actions such as role changes, data deletions, access modifications, and configuration changes are logged with full traceability, enabling thorough security reviews when needed.

Session management

User sessions are protected against hijacking and fixation attacks. Automatic timeouts ensure that inactive sessions are terminated, reducing exposure to unauthorized access.

Invitation-based access

Access to club spaces is controlled through a secure invitation system. No one can join a club environment without explicit authorization from an administrator.

OWASP Top 10 protection

Our development practices systematically integrate protection against the main application vulnerabilities identified by OWASP: XSS, CSRF, SQL injection, IDOR, and more.

Penetration testing

We conduct regular security testing to proactively identify and fix vulnerabilities before they can be exploited, ensuring our platform stays ahead of emerging threats.

Dependency management

All third-party dependencies are regularly audited through automated tools to detect and patch known vulnerabilities, keeping our software supply chain secure.

Code review

Every code change undergoes systematic peer review before being deployed to production, ensuring quality, consistency, and the absence of security regressions.

Secure development lifecycle

Security is integrated at every stage of our development process, from design and architecture decisions to testing and deployment, following industry best practices.

Monitoring and alerting

Our systems are continuously monitored for unusual activity, performance anomalies, and potential security threats, with automated alerting to enable rapid response.

Centralized account management

We use a centralized account management system that streamlines control and monitoring of user access to enhance security across all our internal systems.

Password management

We maintain the integrity and security of login credentials through a robust password management system. Two-factor authentication (2FA) is mandatory for all accounts, adding an essential layer of protection against unauthorized access.

Principle of least privilege

Access privileges are carefully managed according to the principle of least privilege. Users only receive the minimum level of access required to perform their tasks, minimizing potential security risks.

Security watch

We maintain a continuous watch on vulnerabilities, emerging threats and security best practices to proactively adapt our defenses and keep the platform up to date.

Awareness and training

Security awareness is an ongoing commitment. Regular training, participation in professional security communities, and continuous self-education ensure that security decisions are always informed by the latest standards and threats.

Incident management

A documented procedure enables us to detect, respond to, and communicate about security incidents swiftly and transparently, ensuring continuous improvement of our defenses.

Our approach

Information Security Management System (ISMS)

Clubify has implemented an Information Security Management System (ISMS) structured around internationally recognized information security standards. This methodical framework shapes our entire approach to protecting your data.

Our ISMS is built on formal risk assessment, proportionate safeguards, and continuous improvement, providing a structured and rigorous approach to information security.

  • Formal identification and assessment of risks to user data
  • Proportionate technical and organizational measures
  • Continuous monitoring, auditing and improvement of our security practices
  • Documented policies, procedures and controls

Management statement

Clubify’s management is committed to an information security approach aimed at ensuring the confidentiality, integrity, and availability of information entrusted by its users.

This commitment is reflected in the implementation of an ISMS structured around internationally recognized information security standards, together with a process of continuous improvement of our security posture.

Adequate resources are allocated to maintain and improve our security level, and all team members are made aware of their responsibility in protecting information.

Evan Petit, founder & president of Clubify

Questions about our security?

Our team is available to answer any questions about how we protect your data.