ClubOS legal
ClubOS Data Processing Agreement
This Data Processing Agreement (DPA) forms part of the ClubOS Club Subscription Terms between the Club as controller and BYTECODE CONSULTING LTD as processor.
It applies where Bytecode processes personal data on the Club's behalf to provide ClubOS. Defined terms have the meanings given in UK data-protection law and the Subscription Terms.
1. Scope and instructions
Bytecode will process Club personal data only on the Club's documented instructions, including the Subscription Terms, the Club's use and configuration of ClubOS, support requests and other written instructions consistent with the service.
Bytecode will tell the Club if, in its reasonable opinion, an instruction infringes applicable data-protection law. If UK law requires processing outside the Club's instructions, Bytecode will inform the Club before processing unless the law prohibits that notice.
2. Confidentiality and personnel
Bytecode will ensure that people authorised to process Club personal data are committed to confidentiality, receive appropriate guidance and have access only where needed for their duties.
3. Security
Taking account of the state of the art, implementation costs and the nature, scope, context and purposes of processing, Bytecode will maintain appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The current measures are summarised in Schedule 2. Bytecode may improve or replace individual measures provided the overall protection is not materially reduced.
4. Subprocessors
The Club gives general written authorisation for Bytecode to use the subprocessors listed in Schedule 3 and other subprocessors needed to provide ClubOS. Bytecode will impose materially equivalent data-protection obligations on each subprocessor and remains responsible for its subprocessors' compliance with those obligations.
Bytecode will give reasonable advance notice of a new or replacement material subprocessor. The Club may object on reasonable data-protection grounds. The parties will work in good faith on a practical resolution; if none is reasonably available, the Club may terminate the affected service.
5. International transfers
Bytecode will not transfer Club personal data outside the United Kingdom unless a lawful transfer mechanism and required safeguards are in place. This may include UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses.
6. Individual rights and compliance assistance
Taking account of the nature of the processing, Bytecode will provide reasonable assistance through appropriate technical and organisational measures so the Club can respond to requests to exercise data-protection rights.
Taking account of the processing and information available to it, Bytecode will reasonably assist the Club with security obligations, breach notifications, data-protection impact assessments and prior consultation with the ICO.
7. Personal-data breaches
Bytecode will notify the Club without undue delay after becoming aware of a personal-data breach affecting Club personal data. The notice will provide available information reasonably needed by the Club to meet its notification duties, and Bytecode will provide further relevant information as it becomes available.
8. Return and deletion
At the end of the service, Bytecode will, at the Club's choice, return or delete Club personal data and delete remaining copies unless UK law requires retention. Data in protected backups may remain until the normal deletion cycle, provided it is put beyond ordinary use and remains protected.
Bytecode may retain limited account, billing, security and agreement evidence where it acts as controller and retention is reasonably required by law or to establish, exercise or defend legal claims.
9. Information and audits
Bytecode will make available information reasonably necessary to demonstrate compliance with this DPA. Where that information is insufficient, the Club may request an audit by an independent auditor bound by confidentiality, on reasonable notice, during normal business hours and no more than once annually unless a breach or regulator requires otherwise.
The audit must avoid unnecessary disruption and access to another tenant's data. The Club bears its audit costs unless the audit identifies a material breach by Bytecode.
10. The Club's responsibilities
The Club is responsible for the lawfulness, fairness and transparency of its processing; its notices and lawful bases; the accuracy and minimisation of data; the instructions it gives Bytecode; and the administrator permissions it configures.
The Club must not instruct Bytecode to process personal data unlawfully and must take particular care with children's data, welfare information and any special-category data.
Schedule 1 — Processing details
- Subject matter: providing, securing, maintaining and supporting the ClubOS service configured by the Club.
- Duration: the subscription or authorised service period, plus the limited return, backup and deletion periods described above.
- Nature and purpose: collection, recording, organisation, storage, retrieval, consultation, transmission, restriction, backup and deletion as directed through ClubOS.
- Data subjects: Club administrators, officials, volunteers, members, prospective members, parents and guardians, children and young people, visitors, customers, event attendees and other people whose data the Club enters.
- Personal data: identity and contact details; membership and role information; family/guardian links; teams, fixtures, attendance and availability; communications; transaction and payment metadata; form responses; uploaded content; account, device, security and audit information; and other data the Club chooses to enter.
- Special-category or sensitive data: only where the Club deliberately uses an appropriate ClubOS feature and has a lawful basis, potentially including health, welfare, safeguarding, accessibility or equality information.
- Controller rights: the Club may configure the service, manage authorised users, access and correct records, request assistance, export available data and instruct return or deletion subject to the agreement and applicable law.
Schedule 2 — Security measures
- Tenant-scoped authorization and deny-by-default access controls.
- Authentication controls, role-based permissions and stronger controls for privileged platform access.
- Encryption in transit and encryption-capable managed storage services.
- Restricted production and infrastructure access based on operational need.
- Audit logging, monitoring, error handling and security-event investigation.
- Backups, service-resilience controls and tested recovery practices appropriate to the service.
- Secure software-development, dependency, change-management and vulnerability-remediation practices.
- Confidentiality obligations and security guidance for authorised personnel and contractors.
- Supplier assessment and contractual data-protection obligations for subprocessors.
Schedule 3 — Subprocessors
The providers used for a particular Club depend on its enabled features. The principal categories and providers are listed below. Bytecode will keep this schedule current when material subprocessors change.
- Amazon Web Services, including Cognito, AppSync, DynamoDB, Lambda, S3, CloudFront and related services — hosting, authentication, storage, delivery, monitoring and infrastructure operations.
- Stripe — ClubOS subscription billing and, where configured by the Club, payment-account and transaction processing services.
- Resend and/or configured email infrastructure — transactional email delivery.
- Google — sign-in or Club-enabled integrations where configured.
- Approved AI model and infrastructure providers, including AWS Bedrock, Anthropic or OpenAI — only for ClubOS AI features and subject to the feature's controls and instructions.
- Other providers expressly enabled by the Club through an optional integration.
11. Precedence and law
This DPA takes priority over the Subscription Terms to the extent of a conflict about personal-data processing. It is governed by the law and jurisdiction specified in the Subscription Terms.