Skip to content
ClubPress
For committees

Data processing agreement

The contract between your club and ClubPress that data protection law requires. A club admin accepts it the first time they sign in.

Data Processing Agreement

Between the football club named on the ClubPress account (the Club, the controller) and Rendella Media Ltd, trading as ClubPress (ClubPress, the processor).

This agreement forms part of the Club's ClubPress subscription. It exists because the UK GDPR and EU GDPR (Article 28) require a written contract whenever one organisation processes personal data on another's behalf. It is written in plain English on purpose; where it and the law differ, the law wins.

1. What this covers

ClubPress provides the Club with a website and admin system. In doing so, ClubPress stores and processes personal data that the Club collects from its members, players, parents and guardians, volunteers, sponsors and website visitors. The Club decides why and how that data is used; ClubPress acts only on the Club's instructions.

Subject matter: hosting and operating the Club's site and admin. Duration: for as long as the Club has a ClubPress subscription, plus the deletion period in section 8. Nature and purpose: storing, displaying, emailing and reporting on the data below so the Club can run its membership, fixtures, news, shop and communications.

Types of personal data:

  • Parents/guardians: name, email, phone, postal address, second-contact name and phone, payment method reference (card brand and last four digits — never the full card number, which Stripe holds).
  • Players, including children: name, date of birth, gender, medical notes the parent chooses to give, emergency contact, photo consent, team.
  • Registrations and payments: plan, amount, payment status, instalment schedule, consents given and when.
  • Club users: name, email, role, sign-in activity.
  • Website visitors: enquiry form contents; newsletter email address and confirmation; analytics as described in section 6.
  • Photos: images the Club uploads to its gallery or news, which may include identifiable people.

Data subjects: the Club's members and players (many of them children), their parents and guardians, the Club's volunteers and committee, sponsors' contacts, and visitors to the Club's site.

2. The Club's responsibilities

The Club, as controller:

  • decides what data to collect and is responsible for having a lawful basis for it;
  • is responsible for the accuracy of the data and for keeping its own privacy notice up to date (ClubPress provides a template);
  • obtains any consent that is needed, including consent from a person with parental responsibility where a child's data is involved, and consent for photographs;
  • responds to requests from individuals (access, correction, deletion, objection) using the tools ClubPress provides;
  • keeps its admin sign-ins secure and removes users who leave the Club.

3. ClubPress's responsibilities

ClubPress, as processor, will:

  • process the data only to provide the service and only on the Club's documented instructions (using the admin is an instruction). If ClubPress believes an instruction breaks the law, it will say so;
  • make sure everyone at ClubPress who can access club data is bound by confidentiality;
  • keep the security measures in section 5 in place;
  • only use the sub-processors in section 4, and tell the Club before adding or replacing one, giving the Club a reasonable chance to object;
  • help the Club respond to individuals' requests, and to meet its own obligations on security, breach notification and impact assessments, given the nature of the processing;
  • delete or return the data at the end of the service (section 8);
  • make available the information needed to show these obligations are met, and allow audits on reasonable notice;
  • not transfer data outside the UK and EEA except through the sub-processors listed, each of which is covered by an adequacy decision or standard contractual clauses.

4. Sub-processors

ClubPress uses these organisations to deliver the service. The current list is also shown in the platform admin.

Sub-processor What for Where
DigitalOcean Hosting, database, file storage and backups London, United Kingdom
Stripe Card payments for registrations and the shop. Payments are made into the Club's own Stripe account; ClubPress never holds card numbers. Ireland / United States, under Stripe's DPA and standard contractual clauses
Resend Sending registration, payment, sign-in and reminder emails from mail.clubpress.app United States, under Resend's DPA and standard contractual clauses
AI text provider (when the Club enables generated match reports) Turning a score and a coach's note into a draft report. ClubPress sends the minimum needed: team names, score, the coach's note and any scorer names the coach types. To be confirmed before the feature is switched on for the Club

ClubPress will give the Club at least 30 days' notice of a new sub-processor by email to the Club's admin users.

5. Security

ClubPress keeps, and will keep:

  • all traffic encrypted in transit (HTTPS everywhere, HSTS);
  • passwords stored only as salted hashes; sign-in links that expire; role-based access so an editor cannot see registrations;
  • every club's data separated by tenant scoping at the application level — a club can never query another club's rows;
  • an audit log of changes to club data, who made them and when, kept for the period in the retention schedule;
  • encrypted daily backups held for 30 days;
  • access to production limited to named ClubPress staff with two-factor authentication;
  • dependencies and the operating system patched on a regular cycle.

6. Analytics and cookies

Club sites and the ClubPress marketing site may use a web analytics service to count visits. Where the service is cookieless and collects no personal data, no consent banner is shown. Where the service sets tracking cookies, the site asks visitors for consent before it loads and honours their choice. The provider in use is listed in section 4 when analytics are enabled.

7. Personal data breaches

If ClubPress becomes aware of a breach affecting the Club's data, it will notify the Club's admin users by email without undue delay and within 72 hours of becoming aware, with what is known at the time: what happened, what data and roughly how many people are affected, what ClubPress has done, and what the Club should consider doing. ClubPress will keep the Club updated as more is learned. Whether to notify the ICO or Data Protection Commission, and the individuals, is the Club's decision as controller; ClubPress will help.

8. Ending the service

When the Club's subscription ends, ClubPress will:

  • give the Club 30 days to export its data (registrations and households export to CSV/JSON from the admin; pages, posts and documents can be downloaded);
  • then delete the Club's data from production, and let it age out of backups within a further 30 days;
  • keep only what the law requires ClubPress itself to keep (for example, invoices to the Club).

9. Data retention during the service

ClubPress applies the retention schedule published alongside this agreement (docs/legal/retention-schedule.md) automatically. The Club can delete or anonymise a household at any time from the registrar's screen; payment records are kept, without personal details, because the Club must retain financial records.

10. Liability and governing law

Each party is liable for its own breaches of data protection law. Liability under this agreement is subject to the limits in the main ClubPress terms. This agreement is governed by the law of Ireland (or, for a Club based in the United Kingdom, the law of England and Wales).


Version 1.0 — September 2026. The Club accepts this agreement when its first club administrator signs in to the ClubPress admin; the date and the person accepting are recorded on the Club's account.