Data Processing Agreement

Last updated: June 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Clubroom (“Processor”) and the club or organisation using Clubroom (“Controller”) under Article 28 of the EU General Data Protection Regulation (GDPR).

By using Clubroom as a club admin, your organisation accepts this DPA.

1. Parties

Processor: Clubroom, operated by ClubRoom, registered in Denmark (see Imprint).
Controller: The football club or organisation whose admin has created a club on Clubroom.

2. Scope of Processing

Clubroom processes the following personal data on behalf of the Controller, solely to provide the Clubroom service:

  • Player namesentered by club admins or coaches into team rosters
  • Team assignmentswhich players belong to which teams
  • Usage datafeature usage and session data tied to club member accounts

Clubroom will not process this data for any purpose other than providing the service.

3. Sub-processors

Clubroom uses the following sub-processors. By accepting this DPA you authorise their use.

Sub-processorPurposeLocationTransfer mechanism
SupabaseDatabase and authenticationEUNo transfer outside EU
StripePayment processingUSStandard Contractual Clauses
PostHogProduct analyticsEUNo transfer outside EU
SentryError monitoringUSStandard Contractual Clauses
ResendTransactional emailUSStandard Contractual Clauses

4. Data Subject Rights

Clubroom will assist the Controller in fulfilling requests from data subjects (e.g. players) to access, correct, delete, or export their personal data. Requests must be submitted to mail@clubroom.io and will be fulfilled within 30 days.

5. Security Measures

Clubroom implements the following technical and organisational measures:

  • Data encrypted at rest (AES-256) and in transit (TLS 1.2+)
  • Row Level Security enforced at the database layer — users can only access their own data
  • CSRF protection on all state-changing requests
  • Input validation on all API endpoints
  • Rate limiting to prevent abuse
  • Real-time error and anomaly monitoring via Sentry

6. Data Retention

Player data is retained for as long as the club account is active. Upon account closure or deletion, all associated personal data is deleted within 30 days.

7. Breach Notification

In the event of a personal data breach, Clubroom will notify the Controller within 72 hours of becoming aware of it, providing sufficient information to allow the Controller to fulfil their own notification obligations under GDPR Article 33.

8. Acceptance

By creating or administering a club on Clubroom, the Controller accepts this DPA. No wet signature is required.

Contact

Data protection questions: mail@clubroom.io