Privacy Policy
Club Technology Ltd respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store and protect personal data when you visit our website, contact us, enquire about our services, or engage with us as a client, supplier or business contact.
This policy applies to the Club Technology website at www.clubtechnology.co.uk and to general business enquiries and communications with Club Technology Ltd.
It is separate from The Clubhouse Privacy Policy, which explains how personal data is processed within The Clubhouse client portal at clubhouse.clubtechnology.co.uk/privacy.
1. Who we are
Club Technology Ltd is a private limited company incorporated in England and Wales.
Company name: Club Technology Ltd
Company number: 16998317
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Website: www.clubtechnology.co.uk
Email: privacy@clubtechnology.co.uk
For the purposes of UK data protection law, including the UK GDPR and the Data Protection Act 2018, Club Technology Ltd is the controller of personal data collected through this website and through general business communications.
Where we process personal data on behalf of a client in the course of delivering managed IT services, we usually act as a processor. That processing is governed by our Data Processing Agreement and the relevant client contract. The DPA confirms that Club Technology acts as processor for client employee, contractor and contact data processed in connection with managed services, while the client remains the controller.
2. Personal data we collect
We may collect and process the following types of personal data.
Information you provide to us
This may include:
- Your name
- Job title
- Company name
- Business email address
- Telephone number
- Any information you include in an enquiry form, email, meeting request or other communication
- Preferences or requirements you share with us in relation to our services
Website and technical information
When you visit our website, we may collect limited technical information, including:
- IP address
- Browser type and version
- Device type
- Operating system
- Pages visited
- Date and time of visit
- Referring website or source
- Cookie preferences
- Security and access logs
Some of this information may be collected through cookies or similar technologies. Please see our Cookie Policy for more information.
Client and service-related information
If your organisation becomes a client, we may process business contact information relating to authorised client contacts, decision-makers, finance contacts and service stakeholders.
Where we provide managed IT services, additional personal data may be processed under the relevant client agreement and Data Processing Agreement. This may include account and identity data, authentication data, device and endpoint data, IT support data, Microsoft 365 data, and activity logs, depending on the services provided.
3. How we use personal data
We use personal data for the following purposes:
- To respond to enquiries submitted through our website
- To communicate with prospective clients, clients, suppliers and business contacts
- To arrange meetings, demonstrations or consultations
- To provide information about our services
- To prepare proposals, statements of work and commercial documentation
- To deliver managed IT services to client organisations
- To manage client relationships and ongoing service communications
- To maintain the security, performance and reliability of our website
- To improve our website, content and user experience
- To comply with legal, regulatory, accounting and contractual obligations
- To establish, exercise or defend legal claims
4. Our lawful bases for processing
We only process personal data where we have a lawful basis to do so.
Depending on the context, we may rely on one or more of the following lawful bases:
Legitimate interests
We may process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include responding to business enquiries, managing client relationships, improving our website, maintaining security and developing our services.
Contract
We may process personal data where it is necessary to enter into or perform a contract with your organisation.
Legal obligation
We may process personal data where necessary to comply with legal, regulatory, tax or accounting obligations.
Consent
We may rely on consent for certain activities, such as non-essential cookies or electronic marketing where consent is required. Where we rely on consent, you can withdraw it at any time.
5. Marketing communications
We may use your business contact details to send relevant information about Club Technology services, events, insights or updates where we are legally permitted to do so.
You can opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us at privacy@clubtechnology.co.uk.
We will not sell your personal data to third parties.
6. Cookies and similar technologies
Our website uses cookies and similar technologies to make the website work, improve performance, understand how visitors use the site, and support security.
Cookies that are strictly necessary for the website to function may be used without consent. For non-essential cookies, such as analytics or marketing cookies, we will ask for consent where required.
The ICO states that website visitors need to be told that cookies are being used and what they do, and that non-strictly necessary cookies require the user’s agreement. PECR applies to cookies and similar technologies whether or not the information collected is personal data.
Please see our Cookie Policy for more information about the cookies we use and how you can manage your preferences.
7. Who we share personal data with
We may share personal data with trusted third parties where necessary for the purposes described in this policy.
These may include:
- Website hosting and infrastructure providers
- IT, security and support providers
- Email and business productivity providers
- CRM or sales management platforms
- Website analytics providers
- Professional advisers, such as accountants, lawyers or auditors
- Regulators, public authorities or law enforcement agencies where required by law
For managed IT services and The Clubhouse portal, the DPA identifies Microsoft Corporation, NinjaOne LLC, Freshworks Inc. and an EU-based hosting provider as sub-processors used in service delivery.
We require service providers to protect personal data appropriately and only process it for authorised purposes.
8. International transfers
We aim to keep personal data within the UK or European Economic Area where possible.
Where personal data is transferred outside the UK or EEA, we will ensure appropriate safeguards are in place. These may include adequacy regulations, standard contractual clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms.
Our DPA confirms that The Clubhouse application and its primary database are hosted within the European Union, and that personal data does not routinely leave the UK/EEA without adequate safeguards.
9. How long we keep personal data
We only keep personal data for as long as necessary for the purposes for which it was collected, including legal, accounting, contractual and reporting requirements.
As a guide, we expect to retain:
| Type of data | Typical retention period |
| Website enquiry data | Up to 2 years from last meaningful contact |
| Business contact data | For the duration of the business relationship, then reviewed periodically |
| Marketing contact data | Until you opt out or we determine the data is no longer relevant |
| Website security and access logs | Up to 12 months |
| Client service records | In accordance with the relevant client agreement, DPA or legal requirement |
| Support correspondence | Up to 7 years where required for legal, regulatory or business records |
The DPA includes specific retention periods for managed service and Clubhouse-related data, including 12 months for portal audit logs and security/access logs, and 7 years for support correspondence.
10. How we protect personal data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures may include:
- Access controls
- Role-based permissions
- Multi-factor authentication for administrative accounts
- Encryption in transit
- Secure password handling
- Audit logging
- Security monitoring
- Vulnerability management and patching
- Confidentiality obligations for personnel
The DPA sets out further security measures used in connection with managed services and The Clubhouse, including TLS 1.2 or higher, AES-256-GCM encryption for stored credentials and sensitive data, bcrypt password hashing, role-based access controls, MFA for administrative accounts and audit logging.
11. Your data protection rights
Depending on the circumstances, you may have the following rights under UK data protection law:
- The right to access your personal data
- The right to correct inaccurate or incomplete personal data
- The right to request deletion of your personal data
- The right to restrict processing
- The right to object to processing
- The right to data portability
- The right to withdraw consent where processing is based on consent
- The right to complain to the Information Commissioner’s Office
To exercise your rights, please contact us at privacy@clubtechnology.co.uk.
We may need to verify your identity before responding to a request. We will respond within the timescales required by data protection law.
12. Complaints
We would appreciate the opportunity to resolve any privacy concern directly. Please contact us first at:
privacy@clubtechnology.co.uk
You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection.
Information Commissioner’s Office
Website: www.ico.org.uk
Telephone: 0303 123 1113
13. Links to other websites
Our website may contain links to third-party websites, including partner platforms or external resources. We are not responsible for the privacy practices, content or security of those websites.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, website, legal obligations or data processing practices.
The latest version will always be published on this page.
15. Contact us
For questions about this Privacy Policy or how we handle personal data, please contact:
Club Technology Ltd – Data Protection
71-75 Shelton Street
Covent Garden
London
WC2H 9JQ
Email: privacy@clubtechnology.co.uk
Website: www.clubtechnology.co.uk