Document Information
- Document
- Data Processing Agreement (UK GDPR)
- Document ID
- CLB-DPA-001
- Category
- Governance
- Version
- 1.0
- Status
- Approved
- Effective Date
- 7 July 2026
- Last Reviewed
- 7 July 2026
- Next Review
- 7 July 2027
- Review Cycle
- Annual
- Owner
- Cluboom
- Contact
- support@cluboom.co.uk
This Data Processing Agreement (“DPA”) sets out the terms on which Cluboom processes personal data on behalf of a club, team or organisation that uses the Cluboom platform. It forms part of, and is governed by, the Cluboom Terms & Conditions. It is written for grassroots sports clubs and is intended to be read alongside the Privacy Policy and Security Policy. It is not legal advice.
1. Introduction
Clubs using Cluboom hold personal data about their players, parents, guardians, coaches and volunteers. Where Cluboom stores or handles that information on a club’s instructions, UK data protection law requires a written agreement between the club and Cluboom. This document is that agreement.
No signature is required. This DPA applies automatically from the date a club begins using Cluboom, for as long as Cluboom processes personal data on that club’s behalf. A club that requires a countersigned copy for its own records can request one from support@cluboom.co.uk.
2. Definitions
- UK GDPR — the UK General Data Protection Regulation, read with the Data Protection Act 2018.
- Club — the club, team, league or organisation that holds a Cluboom account and determines how member information is used.
- Cluboom — Cluboom, a trading name and product of D & D Home Maintenance Solutions Ltd (company number 14929079).
- Personal data — information relating to an identified or identifiable living person.
- Processing — any operation performed on personal data, including collection, storage, use, disclosure and deletion.
- Controller — the party that decides why and how personal data is processed.
- Processor — the party that processes personal data on the controller’s instructions.
- Subprocessor — a third party engaged by Cluboom to process personal data as part of delivering the platform.
- Data subject — the individual the personal data is about.
- Personal data breach — a security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
3. Roles of Controller and Processor
The club is the controller of the personal data it enters into, or generates through, Cluboom. The club decides which members are added, which teams exist, which staff have access and how the platform is used within the club.
Cluboom acts as processor for that data. Cluboom processes it only to provide and support the platform, and only in line with the club’s documented instructions — which include the club’s use of the platform’s features and settings, together with this DPA and the Terms & Conditions.
Cluboom is a separate controller for a limited set of its own data: account administrator contact details, billing records, support correspondence and technical logs used to keep the service secure and available. That processing is described in the Privacy Policy.
If Cluboom considers an instruction from a club to breach UK data protection law, Cluboom will inform the club and may decline to act on it.
4. Purpose of Processing
Cluboom processes club personal data solely to:
- create and manage member, team and club records;
- schedule training sessions, fixtures and other events;
- collect and display availability and attendance;
- record performance, development and fitness information entered by staff;
- record injuries and recovery updates shared between staff and parents;
- deliver notifications, reminders and announcements to the right people;
- authenticate users and enforce role-based access;
- provide technical support, backups, security monitoring and service maintenance.
Cluboom does not sell club personal data, does not use it for advertising, and does not use it to train third-party artificial-intelligence models.
5. Categories of Data Subjects
- Players, including children and young people;
- Parents, guardians and emergency contacts;
- Coaches, team admins and other club staff;
- Volunteers and committee members;
- Club administrators who manage the account.
6. Categories of Personal Data
- Identity and contact data — name, date of birth, email address, telephone number and, where a club chooses to record it, address.
- Membership data — team, squad, position, shirt number, role and membership status.
- Participation data — availability responses, attendance, selection and match involvement.
- Performance data — coach notes, ratings, development records and fitness measurements entered by club staff.
- Health-related data — injury records, recovery updates and any medical or allergy notes a club chooses to record. This is special category data under UK GDPR.
- Relationship data — links between players and their parents or guardians.
- Account and technical data — sign-in credentials, player PIN hashes, device and session information, notification preferences and activity logs.
- Images — profile photographs and club or team badges, where uploaded.
Clubs should only record health-related or other sensitive information where it is genuinely needed, and should not use free-text fields to store information the platform was not designed to hold.
7. Lawful Processing
The club is responsible for identifying and recording a lawful basis for each category of personal data it processes through Cluboom, and — where special category data such as injury or medical information is involved — an additional condition under Article 9 UK GDPR.
The club is also responsible for issuing its own privacy information to members and families, and for obtaining parental consent where that is the basis it relies on for children’s data.
Cluboom does not determine the lawful basis for club data and processes it only on the club’s instructions.
8. Cluboom Responsibilities
Cluboom will:
- process club personal data only on the club’s documented instructions;
- apply appropriate technical and organisational measures, as described in the Security Measures section below;
- ensure that everyone authorised to access club personal data is bound by confidentiality;
- assist the club, so far as reasonably practicable, with data subject requests, data protection impact assessments and consultations with the Information Commissioner’s Office;
- notify the club without undue delay after becoming aware of a personal data breach affecting its data;
- make available the information reasonably necessary to demonstrate compliance with this DPA;
- delete or return club personal data at the end of the relationship, as set out in the Termination section.
9. Club Responsibilities
The club will:
- ensure it has a lawful basis and, where required, valid parental consent for the information it records;
- provide its own privacy notice to members and families;
- keep information accurate and up to date, and remove members who are no longer involved with the club;
- grant access only to people who need it, and remove access promptly when a coach, volunteer or administrator leaves;
- keep account credentials and player PINs confidential, and encourage safe use of shared devices;
- avoid recording information that is excessive, irrelevant or better held elsewhere;
- handle safeguarding concerns through its own safeguarding procedures and the relevant statutory or governing bodies.
10. Security Measures
Cluboom applies technical and organisational measures appropriate to the risk, including:
- encryption of data in transit using TLS, and encryption of data at rest;
- row-level database security so that every read and write is checked against the requesting user’s club, team and role;
- role-based permissions that restrict staff, parent and player visibility;
- PIN-protected player profiles for shared and family devices;
- hashed credentials and PINs — never stored in readable form;
- rate limiting and monitoring on sign-in and access-code entry;
- audit logging of significant administrative actions;
- automated backups and tested restore procedures;
- a release process requiring automated type checks, unit tests and end-to-end tests before changes reach production.
Measures are reviewed as the platform develops and may be improved, provided the level of protection is not reduced.
11. Confidentiality
Access to club personal data is limited to the individuals who need it to operate or support the platform. Those individuals are subject to binding confidentiality obligations that continue after their engagement ends. Cluboom does not disclose club personal data to any third party except as set out in this DPA or where required by law, in which case Cluboom will inform the club unless legally prevented from doing so.
12. Subprocessors
The club gives general authorisation for Cluboom to engage subprocessors to deliver the platform. Cluboom uses subprocessors for cloud hosting and application delivery, managed database, authentication and file storage, transactional email delivery, and push-notification delivery.
Each subprocessor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA, and Cluboom remains fully liable to the club for their performance.
A current list of subprocessors is available on request from support@cluboom.co.uk and will be published as the Subprocessor Register (CLB-SUB-001). Cluboom will give clubs reasonable notice of any intended addition or replacement, and a club may object on reasonable data protection grounds; where an objection cannot be resolved, the club may terminate its use of the affected service.
13. International Transfers
Cluboom is built and supported in the United Kingdom and club data is hosted in the UK or European Economic Area wherever practicable. Where a subprocessor necessarily processes personal data outside the UK, Cluboom ensures an appropriate safeguard is in place — UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses — together with any additional measures required by a transfer risk assessment.
14. Data Subject Rights
Requests from players, parents, staff or volunteers to access, correct, delete, restrict, object to or port their information should be directed to the club as controller. Many can be resolved by the club directly within Cluboom, using the member, team and account management tools.
Where a club needs help, Cluboom will provide reasonable assistance — including export or deletion support — taking into account the nature of the processing. If a request reaches Cluboom directly, Cluboom will not respond to it substantively; it will refer the individual to their club and, where the club can be identified, notify the club without undue delay.
15. Personal Data Breaches
Cluboom will notify the club without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting that club’s personal data. The notification will describe, so far as known:
- the nature of the breach and the categories and approximate number of records affected;
- the likely consequences;
- the measures taken or proposed to address it and mitigate any adverse effects;
- a contact point for further information.
Where full details are not immediately available, information will be provided in phases as the investigation progresses. The club, as controller, is responsible for deciding whether to notify the Information Commissioner’s Office and affected individuals. Suspected security issues can be reported to support@cluboom.co.uk.
16. Data Retention
Club personal data is retained for as long as the club’s account remains active and the club chooses to keep it. Clubs control retention day to day by removing members, teams and records they no longer need.
Deleted records are removed from the live service and are cleared from routine backups within the ordinary backup cycle. Limited records may be retained for longer where required by law or to resolve a dispute, and are restricted to that purpose. Fuller detail will be published as the Data Retention Policy (CLB-DRET-001).
17. Termination
This DPA continues for as long as Cluboom processes personal data on the club’s behalf. When a club stops using Cluboom, it may request an export of its data within 30 days of the account closing. After that period, Cluboom will delete the club’s personal data from the live service and clear it from backups within the ordinary backup cycle, except where retention is required by law. Clubs should retain their own copies of any records they are obliged to keep.
18. Audit & Compliance
Cluboom will make available to the club the information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable written questionnaires about its security and data protection practices no more than once in any twelve-month period, unless a personal data breach or a regulator requires otherwise. Where a club is required by law or its governing body to carry out a further audit, the parties will agree its scope, timing and cost in advance so that it does not disrupt the service or compromise the confidentiality of other clubs.
19. Governing Law
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction over any dispute arising from it. Where this DPA conflicts with the Cluboom Terms & Conditions on a data protection matter, this DPA prevails.
20. Contact
Questions about this agreement, requests for a countersigned copy, or requests for the current subprocessor list can be sent to support@cluboom.co.uk.
Cluboom is a trading name and product of D & D Home Maintenance Solutions Ltd (company number 14929079), 24 Brynaeron, Dunvant, Swansea, United Kingdom, SA2 7UX.
Related Governance Documents
Cluboom maintains a single governance register. Every document in the register is published and publicly available. Browse the full library in the Governance Centre.
- Privacy PolicyCLB-PRIV-001
- Data Processing Agreement (UK GDPR)CLB-DPA-001This document
- Data Subject Rights PolicyCLB-DSR-001
- Data Retention PolicyCLB-DRET-001
- Children’s Data & Parental Consent PolicyCLB-CHILD-001
- Data Protection Impact Assessment (Public Summary)CLB-DPIA-001
- Security PolicyCLB-SECU-001
- Personal Data Breach Response ProcedureCLB-BREACH-001
- Subprocessor RegisterCLB-SUB-001
- Acceptable Use PolicyCLB-AUP-001
- Terms & ConditionsCLB-TERM-001
- Cookie PolicyCLB-COOK-001
- Refund & Cancellation PolicyCLB-REF-001
- Safeguarding & Child Protection PolicyCLB-SAFE-001
Questions about this document? Contact us at support@cluboom.co.uk.
Cluboom is a trading name and product of D & D Home Maintenance Solutions Ltd (company number 14929079), 24 Brynaeron, Dunvant, Swansea, United Kingdom, SA2 7UX.
