ClubManager — Sub-processors and Third Party Services
1. What this page is
To deliver ClubManager we use a small number of suppliers who process personal data on our behalf. These are our sub-processors. We publish them here so that our customers can meet their own transparency obligations as data controllers.
This page forms part of the Data Processing Agreement at Schedule 3 of our Terms of Service.
2. What this page is not
It does not cover services you choose to connect to your account — see section 5. Nor does it cover any third party to whom you grant access through the ClubManager API; that access is controlled by you.
3. Our sub-processors
| Supplier | What they do | Data involved | Location | Transfer mechanism | Certifications |
|---|---|---|---|---|---|
| Hetzner Online GmbH | Hosting and infrastructure for all territories other than India | All data held in the Services | Germany and Finland | UK adequacy — both are EEA member states | ISO/IEC 27001:2022 covering its hosting services and data centres; BSI C5 Type 2; classified under the German KRITIS regulation |
| OVHcloud | Hosting and infrastructure for India | All data held in the Services for Indian customers | India | Storage does not leave India. See section 3.1 | ISO/IEC 27001, 27017, 27018 and 27701; PCI DSS; SOC 1 and SOC 2 Type 2 |
| Twilio Inc. (including SendGrid) | Email delivery; SMS delivery in some territories; WhatsApp delivery | Names, email addresses, mobile numbers, message content, engagement data | United States | EU-US Data Privacy Framework, UK Extension and Swiss-US DPF. Binding Corporate Rules and EU/UK Standard Contractual Clauses are also in place | ISO/IEC 27001, 27017 and 27018; SOC 2 Type II for SendGrid |
| Bird (formerly MessageBird) | SMS delivery in some territories | Names, mobile numbers, message content | Netherlands | UK adequacy — EEA | ISO/IEC 27001:2022; SOC 2 Type I and Type II, and SOC 3; registered with the Dutch Authority for Consumers and Markets |
| Meta Platforms Ireland Limited | WhatsApp message delivery | Mobile numbers, message content | Ireland | UK adequacy — EEA. Meta applies its own UK GDPR-compliant mechanisms for onward transfers to its affiliates | ISO/IEC 27001 and SOC 2 Type II for the WhatsApp Cloud API |
| Zendesk, Inc. | Customer support ticketing and support email | Email addresses and correspondence with our support team. Content is limited to what you choose to include in a ticket | United States | Binding Corporate Rules approved by the Irish Data Protection Commission; EU Standard Contractual Clauses; and the UK International Data Transfer Addendum. Also certified under the EU-US DPF, UK Extension and Swiss-US DPF | ISO/IEC 27001, 27018, 27701 and 42001; SOC 2 Type II |
| Cloudflare, Inc. | Content delivery and protection against denial-of-service attacks for our website; the security challenge applied at login | Visitor IP addresses and request metadata for our website; challenge data at login | United States, operating a global edge network | EU-US Data Privacy Framework, UK Extension and Swiss-US DPF. EU Standard Contractual Clauses and the UK Addendum are also incorporated in its data processing addendum | ISO/IEC 27001, 27018 and 27701; PCI DSS; SOC 2 Type II; BSI C5 |
We do not use analytics or advertising providers.
Availability monitoring. We use an independent third-party service to monitor whether our servers are reachable. It checks unauthenticated status endpoints that return only whether the service is up. It processes no personal data and holds no access to our systems, so it is not a sub-processor.
A note on messaging. Delivering SMS and WhatsApp messages necessarily involves mobile network operators in the recipient's country. Those carriers are not our sub-processors and are not within our control; our providers' own agreements govern that part of the chain.
3.1 India
For customers in India, all data is hosted on infrastructure located within India. Payments are processed on pages hosted by the payment provider, so card information is not handled by us.
Some processing takes place outside India, and we state this plainly rather than describing the arrangement as entirely in-country:
- our support team in the United Kingdom accesses the Indian infrastructure to provide support and onboarding;
- messages are delivered through Twilio, Bird and Meta;
- support correspondence is held in Zendesk.
Our position under India's Digital Personal Data Protection Act 2023. We apply the same standards to Indian customers as we do under UK GDPR. The club is the Data Fiduciary and we are the Data Processor, acting on its instructions. Section 16 of the Act permits transfer to any country other than those restricted by the Central Government, so the processing described above is permitted. We do not track members and we do not advertise to members, including children.
4. Changes to this list
We give at least 30 days' notice before adding or replacing a sub-processor. An Account Holder may object within that period on reasonable data protection grounds — see paragraph 4.4 of our Data Processing Agreement.
This page carries a "last verified" date at the top. We review it at least annually, and whenever a supplier changes.
5. Payment providers, and how card data is handled
We do not store card details.
Payment providers are chosen by you and connected to your account. They process payment data under their own terms and their own privacy policies.
| Provider | Territory | Type |
|---|---|---|
| Worldpay (formerly Payrix) | Multiple | Card and Direct Debit |
| Stripe | Multiple | Card |
| GoCardless | Multiple | Direct Debit and bank-to-bank |
| PayChoice | Australia and New Zealand | Direct Debit and card |
| Razorpay | India | Card and other Indian payment methods |
For most providers, the payment page is hosted by the provider. Card details are entered directly with the provider, which is certified to PCI DSS Level 1, and we never hold them.
Where card information is submitted through a server operated by us, it is passed directly to the payment provider and discarded immediately. It is not retained and is not written to logs.
GoCardless states that it acts as a data controller in its own right for payer and merchant personal data, rather than as a processor. Its own privacy policy applies to that processing.
6. Contact
Questions about this list: [email protected]
Club Manager Limited · Registered in England and Wales, company number 06734233.