Data Processing Agreement
Last updated: September 30, 2026 · Version 2026-09-30
This Data Processing Agreement ("DPA") sets out how CLOUDSTACK SOLUTIONS S.R.L. processes personal data on behalf of the clubs that use ClubTide, as required by Article 28 of Regulation (EU) 2016/679 (GDPR). It forms part of the ClubTide Terms of Service (https://www.clubtide.app/terms).
1. Parties
This DPA is concluded between:
- the club, association or other organisation that holds a ClubTide account and accepts this DPA, acting as controller (the "Club"); and
- CLOUDSTACK SOLUTIONS S.R.L., with its registered office at Str. Albatrosului nr. 7, birou, sat Valea Lupului, com. Valea Lupului, jud. Iași, 707410, România, registration number J2021002547221, tax ID 44674705, email [email protected], acting as processor ("ClubTide", "we").
The Club accepts this DPA when it creates its ClubTide account or, for an existing account, when the club owner accepts it in the app. ClubTide records the version accepted, the date and the user who accepted it. The person accepting confirms that they are authorised to bind the Club.
2. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach", "special categories of personal data" and "supervisory authority" have the meaning given to them in the GDPR. In addition:
- "GDPR" means Regulation (EU) 2016/679 and the national laws that supplement it, including, in Romania, Law no. 190/2018.
- "Service" means the ClubTide platform (clubtide.app), including the staff application, the parent portal and the public registration forms.
- "Club Personal Data" means the personal data that ClubTide processes on behalf of the Club when providing the Service, as described in Annex 1.
- "Sub-processor" means a third party engaged by ClubTide that processes Club Personal Data.
- "Terms" means the ClubTide Terms of Service.
- "EEA" means the European Economic Area.
3. Scope and order of precedence
This DPA applies only to Club Personal Data. ClubTide acts as an independent controller for the data it processes for its own purposes, such as managing user accounts and their security, billing the Club's subscription and operating this website, as described in the Privacy Policy (https://www.clubtide.app/privacy).
If this DPA conflicts with the Terms in relation to the processing of Club Personal Data, this DPA prevails. Where Standard Contractual Clauses apply to a transfer, they prevail over this DPA.
4. Subject matter, duration, nature and purpose
The subject matter of the processing is the provision of the Service to the Club. ClubTide stores, organises, displays, transmits and deletes Club Personal Data as needed to run the Service: hosting the Club's records, sending emails and in-app notifications, generating documents such as invoices and signed consent forms, and exporting, anonymising or deleting data when the Club asks.
Processing lasts for as long as the Club uses the Service and, after that, until the Club Personal Data is deleted or anonymised as set out in the section on return and deletion. The categories of data subjects and personal data, the purposes and further details are set out in Annex 1.
5. The Club's responsibilities as controller
The Club decides why and how its members' data is processed and remains responsible for that processing. In particular, the Club is responsible for:
- having a lawful basis under Article 6 GDPR and, where special categories are involved, a condition under Article 9 GDPR, for all data it enters, imports or collects through the Service, including through its public registration forms;
- informing members, parents and guardians about the processing, in accordance with Articles 13 and 14 GDPR, through its own privacy notice;
- obtaining the consent of parents or guardians for children's data where the law requires it. The consent forms and registration consents in the Service help the Club collect and record consents, but the Club decides their wording and remains responsible for their validity and adequacy;
- keeping the data accurate and up to date, and entering only the data it actually needs, including in the custom member fields it defines;
- recording health, medical and emergency information only where this is lawful and necessary, and granting access to it only to staff who need it;
- managing its own users: assigning appropriate roles, removing access for people who leave the Club and, where appropriate, requiring two-factor sign-in for staff;
- responding to data subjects' requests and, where required, notifying personal data breaches to the supervisory authority and to the data subjects concerned;
- ensuring that its instructions to ClubTide comply with the GDPR.
6. Processing on documented instructions
ClubTide processes Club Personal Data only on the Club's documented instructions. The Terms, this DPA and the Club's use and configuration of the Service (including the settings chosen and the actions performed by its authorised users in the app) constitute the Club's complete instructions. Additional instructions outside the scope of the Service must be agreed in writing.
ClubTide does not process Club Personal Data for its own purposes, does not sell it and does not use it for advertising or profiling. If Union or Member State law requires ClubTide to process Club Personal Data in another way, ClubTide will inform the Club of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
ClubTide will immediately inform the Club if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions, and may suspend carrying out that instruction until the Club confirms or changes it.
7. Confidentiality
ClubTide ensures that the persons it authorises to process Club Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they access Club Personal Data only to the extent necessary to provide, support and secure the Service.
8. Security of processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks for data subjects, in particular children and people whose health data is recorded, ClubTide implements the technical and organisational measures described in Annex 2, in accordance with Article 32 GDPR.
ClubTide may update these measures as technology and the Service evolve, provided that the overall level of security is not reduced.
9. Assistance with data subject requests
Taking into account the nature of the processing, ClubTide assists the Club, through appropriate technical and organisational measures and insofar as possible, in responding to requests from data subjects exercising their rights under Chapter III of the GDPR. The Service provides the following tools for this purpose:
- member data export: all the data the Club stores about a member, in a structured, machine-readable format, available to authorised staff and to linked parents in the parent portal;
- rectification: authorised staff can correct member, family and guardian records at any time;
- anonymisation: a member's personal data can be anonymised while the invoices and payments needed for accounting are kept;
- retention settings: the Club sets a retention period after which archived members are anonymised automatically;
- consent records: consent signatures and withdrawals are recorded with the version of the text accepted;
- data requests log: the Club can record data subject requests and how they were resolved.
If ClubTide receives a request directly from a data subject concerning Club Personal Data, it will not respond on the merits, other than to refer the person to the Club, and will forward the request to the Club without undue delay where the Club can be identified.
10. Assistance with security, breaches and impact assessments
Taking into account the nature of the processing and the information available to it, ClubTide provides the Club with reasonable assistance in ensuring compliance with its obligations under Articles 32 to 36 GDPR: security of processing, notification of personal data breaches, communication of breaches to data subjects, data protection impact assessments and prior consultation of the supervisory authority.
This assistance includes making available this DPA, its annexes, the description of our security measures on the Security page (https://www.clubtide.app/security) and answers to reasonable questions. Where the Club requests assistance that goes beyond this and is not required because of a breach of this DPA by ClubTide, the parties will agree on it in advance, including any reasonable costs.
11. Personal data breaches
ClubTide will notify the Club without undue delay, and in any event within 48 hours after becoming aware of it, of any personal data breach affecting Club Personal Data. The notification is sent by email to the club owner's address and may also be shown in the app.
The notification will contain, to the extent available at that time, the information required by Article 33(3) GDPR:
- the nature of the breach, including, where possible, the categories and approximate number of data subjects and of personal data records concerned;
- the name and contact details of the ClubTide contact point from whom more information can be obtained;
- the likely consequences of the breach;
- the measures taken or proposed by ClubTide to address the breach, including measures to mitigate its possible adverse effects.
Where it is not possible to provide all the information at the same time, ClubTide will provide it in phases without undue further delay. ClubTide will take reasonable steps to contain and investigate the breach, will document it and will cooperate with the Club so that the Club can meet its own notification obligations. A notification is not an acknowledgement of fault or liability.
12. Sub-processors
The Club gives ClubTide a general written authorisation to engage sub-processors. The sub-processors currently engaged are listed in Annex 3.
ClubTide will inform the Club at least 30 days before a new or replacement sub-processor starts processing Club Personal Data, by email to the club owner and/or by a notice in the app, and will update Annex 3. Where a replacement is urgently needed for security or service continuity, ClubTide will give notice as soon as possible and the Club's right to object still applies.
The Club may object to a new sub-processor on reasonable data protection grounds by writing to [email protected] within the notice period. The parties will then discuss the objection in good faith, and ClubTide may propose a reasonable alternative. If no reasonable alternative is available within a reasonable time, the Club may terminate the affected Service by written notice before the new sub-processor is used for its data.
ClubTide imposes on each sub-processor, by written contract, data protection obligations that are equivalent in substance to those in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. ClubTide remains fully liable to the Club for the performance of its sub-processors' obligations.
13. International transfers
The Service is hosted primarily in the European Union, in Germany. ClubTide transfers Club Personal Data outside the EEA only where a sub-processor listed in Annex 3 processes it there, and only on the basis of a transfer mechanism under Chapter V GDPR: an adequacy decision of the European Commission (for example, the EU-U.S. Data Privacy Framework where the provider is certified under it) or the Standard Contractual Clauses adopted by the European Commission, together with supplementary measures where required.
Access to the Service by the Club's own users from outside the EEA is a decision of the Club.
14. Payments made through the Service
Online payments by members and parents to the Club run on the Club's own Stripe account, connected to ClubTide through Stripe Connect (Standard accounts), under the Club's own agreement with Stripe. For these payments, Stripe is not a sub-processor of ClubTide: the Club's relationship with Stripe is governed by the Club's agreement with Stripe.
Card details are entered only on pages hosted by Stripe and never pass through or get stored on ClubTide's servers. For payments made through the Service, ClubTide stores only Stripe identifiers and, for display, the card brand and the last four digits of the card.
For the billing of the Club's own ClubTide subscription, Stripe processes the billing data of the club owner as ClubTide's provider. That processing is carried out by ClubTide as controller and is described in the Privacy Policy.
15. Information and audits
ClubTide makes available to the Club all information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, its annexes and answers to reasonable written questions.
ClubTide allows for and contributes to audits, including inspections, conducted by the Club or by an independent auditor mandated by the Club, under the following conditions:
- the Club gives written notice at least 30 days in advance, with the proposed scope and timing;
- audits take place at most once in any 12-month period, unless required by a supervisory authority or following a personal data breach affecting Club Personal Data;
- audits take place during normal business hours, without unreasonably disrupting ClubTide's operations and without access to the data of other clubs;
- the Club and its auditor are bound by confidentiality obligations; an auditor must not be a competitor of ClubTide;
- the Club bears the costs of the audit, including the costs of its auditor.
Audits of sub-processors are carried out, where possible, on the basis of the reports and certifications that they make available.
16. Return and deletion of data
While its subscription is active, the Club can export its data at any time with the export tools available in the Service. On request, ClubTide will provide reasonable assistance in exporting Club Personal Data in a commonly used, machine-readable format.
After the Service ends, ClubTide deletes or anonymises the Club Personal Data within 30 days, including any copies, as far as technically feasible, unless Union or Member State law requires the data to be stored (for example, invoice and payment records that must be kept for accounting or tax purposes). Data kept for that reason is processed only for that purpose and deleted when the retention period ends. The Club should export any data it needs before the Service ends. On request, ClubTide confirms the deletion in writing.
17. Children
Many members of sports clubs are children. ClubTide takes this into account in how the Service is designed:
- member profiles are never public: they are visible only to signed-in staff of the Club, according to their role, and to the parents and guardians linked to the child in the parent portal;
- children do not have their own accounts; parents and guardians access the parent portal on their behalf;
- access is restricted by role: coaches see only the members of the groups they teach, and health information is visible only to roles with that permission;
- children's data is never used for advertising or profiling and is never sold.
The Club remains responsible for obtaining the consent of parents or guardians where the law requires it.
18. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms, to the extent permitted by law. Nothing in this DPA limits the rights of data subjects under Article 82 GDPR or any liability that cannot be limited or excluded by law.
19. Term
This DPA takes effect when the Club accepts it and remains in force for as long as ClubTide processes Club Personal Data, including after the Terms end, until the data has been deleted or anonymised.
20. Changes to this DPA
ClubTide may update this DPA to reflect changes in the law, guidance from supervisory authorities, or changes to the Service or its sub-processors. Each version is identified by the version shown at the top of this page. ClubTide will notify material changes at least 30 days before they take effect, by email or in the app, and will ask the club owner to accept the new version in the app. Changes will not reduce the overall level of protection of Club Personal Data. Changes of sub-processors follow the procedure in the section on sub-processors.
21. Governing law and jurisdiction
This DPA is governed by the laws of Romania. Disputes arising out of or in connection with this DPA will be settled amicably or, failing that, by the competent courts at the registered office of CLOUDSTACK SOLUTIONS S.R.L., without prejudice to the rights of data subjects and the powers of supervisory authorities.
22. Contact
For any questions about this DPA or about the processing of Club Personal Data, write to us at [email protected].
Annex 1: Details of the processing
Categories of data subjects
- members and athletes of the Club, including children;
- parents, guardians and other family contacts of members;
- coaches and other staff of the Club who use the Service or are recorded in it;
- people who apply through the Club's public registration forms;
- other contacts of the Club whose details the Club enters in the Service.
Categories of personal data
- member identification and contact details: name, date of birth, gender, school, email, phone, address, joining date, status, notes, and the family, location, program and groups the member belongs to;
- family and guardian details: name, relationship to the member, email, phone, preferred language, billing and emergency contact flags, notification preferences and the link to a parent portal account;
- attendance: classes attended, attendance status, check-in time, source and notes;
- progression: ranks and promotion history, curriculum and skill evaluations, promotion recommendations, exam registrations and results;
- billing: memberships and plans, discounts, invoices and invoice items, payments, refunds, payment status, Stripe identifiers and the card brand and last four digits;
- consents: the text and version of the consent form accepted, the signer and their relationship to the member, the guardian, the date, the IP address and browser user agent at signing, and any withdrawal;
- custom member fields defined by the Club, with the values entered;
- registration applications: contact name, email and phone, the details of the children or members registered, custom field answers and the consent given;
- communications: announcements, emails and in-app notifications sent to families and staff;
- user accounts of staff and parents: name, email, role and permissions, language, password hash, last sign-in, two-factor sign-in settings (encrypted secret and hashed recovery codes) and, where used, the link to a Google account;
- audit and security records: audit log entries (who performed which action, when, from which IP address, with the values before and after), data requests and their resolution, session data (IP address and browser user agent).
Special categories of personal data
Health and emergency information (medical restrictions, allergies and emergency notes) is processed only if the Club chooses to record it. These fields are visible only to users whose role includes the permission to view sensitive member data. Custom member fields may also contain special categories if the Club defines them so; the Club is responsible for doing so only where lawful.
Nature of the processing
Collection through the Service (staff entry, CSV import, registration forms and the parent portal), storage, organisation, consultation, display, transmission by email and in-app notifications, generation of documents (invoices, signed consent forms), export, anonymisation and deletion.
Purposes
- administration of the Club's members, families, groups and staff;
- class scheduling and attendance;
- progression tracking, promotions and exams;
- membership billing, invoices and payments;
- communication with members, parents and guardians;
- records the Club keeps for compliance, such as consents, data requests and the audit log.
Frequency and duration
Processing is continuous for as long as the Club uses the Service. Within that period, the Club controls how long data is kept, including through its retention settings. After the Service ends, data is deleted or anonymised as set out in the section on return and deletion.
Annex 2: Technical and organisational measures
This annex describes the measures in place at the date of this version. The same measures are explained in plain language on the Security page (https://www.clubtide.app/security).
Hosting and network
- servers and the application database are hosted by Hetzner Online GmbH in Germany (European Union);
- traffic to clubtide.app passes through Cloudflare, which provides DNS, content delivery and protection against attacks and abusive traffic;
- all connections use HTTPS (TLS), including the app, the parent portal, the public forms and the website;
- session cookies are marked secure and HTTP-only, so browsers send them only over encrypted connections and page scripts cannot read them.
Authentication
- passwords are stored only as bcrypt hashes;
- two-factor sign-in with an authenticator app (TOTP); the two-factor secret is stored encrypted and recovery codes are stored only as hashes;
- the club owner can require two-factor sign-in for all staff;
- sign-in, two-factor codes and password reset requests are rate limited;
- Cloudflare Turnstile bot protection on sign-in, sign-up, password reset and public registration forms;
- email verification links are signed and expire; password reset links use single-use tokens that expire after one hour.
Authorisation and separation of data
- role-based access (owner, admin, coach, front desk, parent), each role with a defined set of permissions;
- coaches see only the members and classes of the groups they teach;
- health and emergency fields are visible only to roles with the sensitive data permission;
- parents see only the children linked to them, in a separate portal without access to staff screens;
- per-club tenant isolation: every record belongs to one club, every lookup is scoped to the signed-in user's club, and requests for another club's records are answered as not found; this isolation is covered by automated tests.
Logging and accountability
- an audit log of important actions (for example member changes and archiving, promotions, payments and refunds, data exports and anonymisation, consent signatures and withdrawals, settings and two-factor changes), with the user, the time and the IP address;
- consent forms are versioned and each signature keeps a snapshot of the text accepted.
Payments
- card details are entered only on Stripe-hosted pages, so ClubTide's part of card handling falls under the simplest PCI DSS scope (SAQ A);
- ClubTide stores only Stripe identifiers and the card brand and last four digits.
Data protection tools
- member data export in a structured, machine-readable format;
- member anonymisation that keeps accounting records;
- a configurable retention period with automatic anonymisation of archived members;
- a log of data subject requests.
Organisational measures
- confidentiality obligations for authorised personnel and access on a need-to-know basis, as set out in the section on confidentiality;
- personal data breach handling and notification as set out in the section on personal data breaches;
- sub-processors engaged only under written contracts with equivalent data protection obligations.
Annex 3: Sub-processors
ClubTide currently engages the following sub-processors for Club Personal Data:
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH (Germany) | Hosting, database and file storage | European Union (Germany) | Not applicable (processing in the EU) |
| Cloudflare, Inc. | DNS, content delivery, DDoS and web application firewall protection, Turnstile bot protection | Global network | EU-U.S. Data Privacy Framework / Standard Contractual Clauses |
| Stripe Payments Europe, Limited (Ireland) and its affiliates, including Stripe, Inc. | Billing of clubs' ClubTide subscriptions (see the section on payments) | Ireland (EU) and United States | EU-U.S. Data Privacy Framework / Standard Contractual Clauses |
| Email delivery provider | Sending the platform's emails (notifications, invoices, password resets) | To be confirmed | To be confirmed |
Members' and parents' payments to the Club run on the Club's own Stripe account under the Club's agreement with Stripe; for those payments Stripe is not a sub-processor of ClubTide.
Google is not a sub-processor for Club Personal Data. Signing in with Google is optional and concerns only the account of the user who chooses it.