ClubKeeper
SecurityPrivacyTermsDPAAccessibilityLog in

Legal

Data Processing Agreement

Last updated 9 September 2026

This agreement applies whenever a club uses ClubKeeper to hold personal data about its members, players, guardians or staff. Under UK GDPR the club is the controller and ClubKeeper is the processor: the club decides what data it holds and why, and we process it only to provide the service.

It takes effect automatically when a club starts using ClubKeeper and forms part of our Terms of Service. A club that needs it signed as a separate document can ask, and we will sign this text.

1. Who the parties are

The processor is ClubKeeper, operated by Jason Cheeseman as a sole trader while a limited company is being incorporated. When that company exists this agreement will be updated to name it, and clubs will be told directly.

Postal address:
34 Delorean Way
Brackley
Northamptonshire
NN13 6BF

The controller is the club. Where a club is itself acting for a league or county association, that relationship is between the club and them; it does not change ours.

2. Subject matter, duration, nature and purpose

We process personal data solely to run the club administration features a club has chosen to use: membership and player records, subscriptions and invoicing, fixtures and availability, club communications, safeguarding records, and financial bookkeeping. Processing lasts for as long as the club has an active account, and then for the period in section 9.

3. Types of personal data

  • Children’s data — name, date of birth, gender, shirt number, photograph, FA registration status, medical and dietary notes, and emergency contact details.
  • Special category data — safeguarding concerns and case notes, welfare records, criminal-record-check (DBS) status, and any health information a club records.
  • Adults’ data — names, email addresses, phone numbers, roles, qualifications, and where a club runs payroll, pay records and the tax figures its accountant supplies.
  • Financial data — invoices, payments and reconciliation records. Card details are never held by ClubKeeper; payments go directly to the club’s own Stripe account.

Categories of data subject: players (mostly children), their parents and guardians, club officials and volunteers, coaches, and paid staff.

4. Processing only on the club’s instructions

We process personal data only on the club’s documented instructions, which for most purposes means the actions the club takes in the product. We will not use a club’s data for our own purposes, will not sell it, and will not use it to train anyone’s AI models.

If we are ever required by law to process data beyond those instructions, we will tell the club before doing so unless the law forbids telling them.

When we look inside a club. To answer a support question or investigate a fault we may need to see a club’s records. Ordinary support access expires by itself after 10 minutes from the moment we enter, and every visit is written to the club’s own activity log where the committee can see it. Safeguarding concern records are excluded from that access entirely — reaching one requires a separate, deliberate grant with a written reason, which lasts 60 minutes, notifies the club’s Welfare Officer as it happens, and is kept permanently.

5. Confidentiality

Everyone with access to club data is bound to confidentiality. Today that is one person — Jason Cheeseman. When ClubKeeper has staff or contractors, they will be under written confidentiality obligations before being given any access, and this section will be updated to say so rather than left to be assumed.

6. Security measures

The measures below are the ones actually in place. Where something is planned rather than done, it is marked as such — a club deciding whether to trust us with children’s records is entitled to the real position.

  • All traffic encrypted in transit (HTTPS); data encrypted at rest by our hosting providers.
  • Passwords stored only as hashes, never in readable form.
  • Two-factor authentication is required for every role that can reach children’s records, safeguarding files or club finances, and is enforced on every session — pages and data exports alike.
  • Every query is scoped to the club the user is signed in to, enforced in the application and covered by automated tests that specifically attempt to read another club’s data and check the attempt fails. A second, database-level enforcement layer is in progress and is not yet in force.
  • Access to safeguarding records is restricted by role and separately logged.
  • Nightly encrypted backups, held outside our database provider, encrypted so that neither the backup host nor the database host can read them.
  • Error diagnostics go to Sentry in the EU (Frankfurt) with identifiers for children, guardian invite links and access tokens stripped before sending.

7. Sub-processors

The club gives general authorisation for the sub-processors below. We will give clubs at least 30 days’ notice before adding or replacing one, and a club that objects on reasonable data-protection grounds may terminate without penalty and take its data with it.

  • Supabase — database hosting, United Kingdom (London).
  • Vercel — application hosting and public-page visit counts.
  • Resend — transactional email.
  • Stripe — card payments, made directly to the club’s own account.
  • Sentry — error diagnostics, European Union (Frankfurt).
  • Anthropic — the in-app help assistant. It receives a question, the asker’s role, the club name and the page; it has no access to club records and cannot look anything up.
  • Google (Firebase Cloud Messaging) — push notifications, only for clubs using the mobile app.
  • Giphy — optional GIF search in club chat.

Each is engaged under terms no less protective than this agreement, and we remain responsible to the club for what they do.

8. Helping the club meet its own obligations

  • Data subject requests. Members can export their own data and delete their own account from within ClubKeeper. Where a club needs to answer a request itself, we will help, at no charge, within the time the club needs to meet its statutory deadline.
  • Personal data breaches. We will notify the club without undue delay and in any event within 72 hours of becoming aware of a breach affecting its data, with what we know, what we are doing, and what the club may need to report. The club, as controller, decides whether to report to the ICO.
  • Impact assessments. We will provide the information a club reasonably needs for a DPIA or prior consultation.

9. Deletion and return

On termination, a club may export its data in a portable format. We then delete it within 90 days, except where a law requires longer retention — financial records being the usual case — in which case what is kept, and for how long, is stated to the club.

Backups age out on their own schedule, currently 90 days. Data deleted from the live system may persist in an encrypted backup until then; it is not restored to the live system except as part of recovering from an incident.

10. Audits and information

We will make available the information a club needs to demonstrate compliance with Article 28, and will answer a club’s security questionnaire. For a platform of this size a written response is what we can offer rather than an on-site audit; a club needing more should say so before signing up so we can agree it rather than disappoint later.

11. International transfers

Club data is stored in the United Kingdom. Sentry processes error diagnostics in the EU, which is covered by UK adequacy. Where any other sub-processor transfers data outside the UK or EU as part of its own infrastructure, that transfer relies on the standard contractual safeguards in that provider’s terms.

12. What this agreement does not yet cover

Stated plainly, because a club is entitled to know what is still being built:

  • Database-level tenant isolation is in progress and not yet in force. Separation between clubs today is enforced in the application and by tests, not by the database itself.
  • Backup restores are not yet exercised on a schedule. Backups run nightly and are encrypted; a documented, timed restore rehearsal is the next step and will be recorded here.
  • ClubKeeper is not yet ICO-registered. Registration will be complete before any club’s real records enter the platform.

13. Governing law

This agreement is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it. Where anything here conflicts with our Terms of Service, this agreement takes precedence on matters of data protection and the Terms take precedence on everything else.

14. Contact

Data protection questions, breach notifications and requests under this agreement: jason@clubkeeperapp.com. A named person replies within one working day.

If a club believes we have mishandled its data it can complain to the Information Commissioner’s Office.

ClubKeeper — the committee’s back office for grassroots clubs. Back to home