Data processing agreement
Last updated 29 August 2026
This agreement forms part of our terms of service. It sets out how we handle personal data on your behalf, as UK GDPR requires. You do not need to sign anything — it applies automatically to every club.
1. Roles
You are the controller of the personal data you hold in ClubDock about your parents, children and staff. Pigeonhole Early Years Ltd is your processor. We process that data only on your documented instructions — using the service is your instruction — and for no purpose of our own.
If we are ever required by law to process it otherwise, we will tell you first unless the law prevents us.
2. What is processed
| Subject matter | Providing the ClubDock booking, attendance and payment-tracking service |
|---|---|
| Duration | For as long as your subscription continues, then twelve months after your account closes |
| Nature and purpose | Storing, organising, retrieving and displaying records so you can run your club; and sending emails you or your parents trigger |
| Types of data | Names, dates of birth, addresses, contact details, school, emergency contacts, people permitted to collect a child, allergies, dietary requirements and medical notes, bookings, attendance times, amounts owed and paid |
| Special category data | Health data — allergies, medical conditions and medication — where you record it, and any information about a child's needs that you choose to hold |
| Data subjects | Parents and carers, children, and your staff |
3. Our obligations
- Process personal data only on your instructions.
- Make sure everyone with access is under a duty of confidentiality, and give access only to those who need it.
- Apply the security measures in section 4.
- Use sub-processors only under section 5.
- Help you respond to requests from parents, children or staff exercising their rights, taking into account what the service can do.
- Help you with data protection impact assessments and with consulting the ICO, where the information is ours to give.
- Tell you without undue delay, and in any case within 24 hours, if we become aware of a personal data breach affecting your data, with what we know at the time.
- Delete or return the data at the end of the agreement, as section 7 describes.
- Make available the information you reasonably need to show we are meeting these obligations, and allow audits as section 8 describes.
4. Security
The measures we apply, taking account of the risk to the people concerned:
- Encryption in transit (TLS 1.2 or better) and at rest.
- No passwords: authentication is by single-use code to a verified email address, or by passkey. There is no password store to compromise.
- Strict separation between clubs. Every request is scoped to one club, and the separation is enforced in the data layer rather than by convention.
- Role-based access, so revenue and configuration are limited to managers.
- An audit trail of attendance actions, recording who did what and when.
- Access to production systems limited to those who need it, and logged.
- Automated monitoring and alerting for failures and unusual behaviour.
- Backups, held to the same standard as the live data.
5. Sub-processors
You consent to us using these sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft (Azure) | Hosting, storage and backups | United Kingdom |
| Resend | Email delivery | United States |
| Stripe | Subscription payments from clubs (no parent or child data) | Ireland and the United States |
| reCAPTCHA on public forms (no parent or child data) | United States |
We will give you at least 30 days' notice before adding or replacing a sub-processor. If you object on reasonable data protection grounds, you may cancel without penalty.
Each sub-processor is bound by terms no less protective than these. Where one is outside the UK, the transfer relies on the UK international data transfer addendum to the European Commission's standard contractual clauses, or on an adequacy decision.
6. Where data is held
Parent, child and staff records are stored in the United Kingdom. Email delivery and payment processing involve the transfers described above, under the safeguards named there.
7. Returning and deleting data
- You can export your reports as CSV at any time, including while your club is read-only.
- When your club closes its account, we keep the data for twelve months so you can return or retrieve it, and then permanently delete it. That deletion is automatic.
- If you want it deleted sooner, ask and we will do it — we will confirm when it is done.
- Backups are deleted on their own cycle, within 35 days, after which nothing remains.
8. Audits
We will answer reasonable questions about our security and data protection practices, and provide the documentation we hold. Where you need more than that, we will agree an appropriate audit with you, at reasonable notice, no more than once a year unless a breach or a regulator makes it necessary.
9. Liability and precedence
This agreement is subject to the limits of liability in our terms of service. Where this agreement and those terms conflict on data protection, this agreement prevails.
10. Contacting us about data protection
Email support@clubdock.co.uk, marking it for the attention of data protection, or write to 12 Cooper Road, Bristol, BS9 3RA, United Kingdom. We are registered with the Information Commissioner's Office under reference ZC136329.