ClubFlow only sets the cookies it needs: sign-in, language, this choice. With your OK we also count page visits, without cookies, to see which parts of the product get used. No advertising, ever.
The agreement that governs how ClubFlow processes personal data on the club’s behalf under Article 28 GDPR. English translation; the Swedish version prevails.
1.1The Club uses ClubFlow’s platform to manage squads, matches, player development, scouting and related activities under a separate agreement between the parties, for example a pilot agreement or a subscription agreement (the “Main Agreement”). When ClubFlow provides the platform, ClubFlow processes personal data on the Club’s behalf. This agreement (the “Agreement”) governs that processing in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
1.2The Agreement may be entered into on its own or attached to the Main Agreement. When the Agreement is an annex to the Main Agreement, it is deemed entered into when the parties have signed or otherwise approved the Main Agreement in writing, and it then does not need to be signed separately.
1.3The Agreement continues to apply if the Main Agreement is replaced by a new agreement for the same service, for example when a pilot becomes a paid subscription, unless the parties agree otherwise in writing.
1.4If the Agreement and the Main Agreement conflict, the Agreement prevails in matters concerning the processing of personal data.
1.5Terms used in the Agreement, such as personal data, processing, data subject, personal data breach and sub-processor, have the same meaning as in the GDPR.
2.1ClubFlow processes personal data solely to provide the platform to the Club under the Main Agreement. The nature and purpose of the processing, the categories of data subjects and personal data, and where the data is stored are set out in Annex A.
2.2ClubFlow may not process the Club’s personal data for its own purposes, for example marketing, sale to third parties or training AI models. ClubFlow may produce statistics on how the platform is used, provided the statistics contain no personal data from the Club’s data and cannot be linked to individual data subjects.
3.1ClubFlow processes personal data only on the Club’s documented instructions. The Main Agreement, the Agreement and the settings the Club makes in the platform (for example roles and permissions, enabled features and retention settings) constitute the Club’s instructions.
3.2If ClubFlow is required by Union or Swedish law to process the data in another way, ClubFlow shall inform the Club of that legal requirement before the processing begins, unless the law prohibits such information.
3.3ClubFlow shall immediately inform the Club if, in ClubFlow’s opinion, an instruction infringes the GDPR or other data protection law.
4.1The Club is the controller and is responsible for the processing having a legal basis, for data subjects receiving the information they are entitled to under Articles 13 and 14 GDPR, and for only entering personal data into the platform that is needed for the purpose.
4.2Many of the Club’s players are under 18. The Club is responsible for the processing of their data complying with the GDPR, and for guardians being informed or giving consent where required.
4.3If the Club enables wellness check-ins, data concerning health is processed, which is a special category of personal data under Article 9 GDPR. The Club is responsible for obtaining explicit consent from the player, and for players under 18 from the guardian where required, before the feature is used. ClubFlow stores the Club’s confirmation in the platform that such consent exists (version, time and who confirmed).
4.4The Club is responsible for which people in the Club are given accounts and which permissions they receive, and for removing access for people who should no longer have it.
5.1ClubFlow shall ensure that the people authorised to process the Club’s personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
5.2ClubFlow may not disclose the Club’s personal data to third parties beyond what follows from the Agreement or mandatory law. If an authority or anyone else requests access to the data, ClubFlow shall refer the request to the Club and inform the Club, unless the law prohibits it.
6.1ClubFlow implements technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures are described in Annex C.
6.2ClubFlow may change the security measures over time, provided the overall level of protection is not reduced.
7.1ClubFlow’s staff do not have access to the Club’s personal data in their day-to-day work. Access occurs only (a) when the Club has granted a named person at ClubFlow time-limited support access in the platform, for at most 30 days and revocable by the Club at any time, (b) when necessary to handle a personal data breach or a serious operational failure, or (c) when required by law.
7.2Support access is logged, and the Club can see who has had access and for what period.
8.1The Club gives ClubFlow a general prior authorisation to engage sub-processors. The sub-processors engaged when the Agreement is entered into are listed in Annex B and are approved through the Agreement.
8.2ClubFlow shall inform the Club in writing, for example by email to the Club’s contact person, at least 30 days before a new sub-processor is engaged or an existing one is replaced. The Club may object to the change on reasonable data protection grounds. If the parties cannot agree, the Club may terminate the Main Agreement and the Agreement with effect from the day the change takes effect.
8.3ClubFlow shall, by written agreement, impose on each sub-processor at least the same data protection obligations that apply to ClubFlow under the Agreement. ClubFlow remains fully liable to the Club for the performance of the sub-processor’s obligations.
9.1The Club’s personal data is stored within the EU/EEA. ClubFlow may transfer personal data to a country outside the EU/EEA only if the transfer meets the requirements of Chapter V GDPR, for example through an adequacy decision (including the EU-US Data Privacy Framework) or the European Commission’s standard contractual clauses. Any transfers and the safeguard used are set out in Annex B.
10.1ClubFlow shall assist the Club in fulfilling its obligation to respond to requests from data subjects under Chapter III GDPR. The platform contains tools that let the Club itself provide (a machine-readable copy of the data), rectify, anonymise and erase data about players and scouted players. If the Club cannot handle a request with these tools, the Club may contact privacy@theclubflow.com, and ClubFlow shall then respond within five working days.
10.2If a data subject contacts ClubFlow directly with a request concerning the Club’s data, ClubFlow shall without undue delay refer the data subject to the Club and inform the Club, and shall not respond to the request itself without the Club’s instruction.
10.3Taking into account the nature of the processing and the information available to ClubFlow, ClubFlow shall assist the Club in fulfilling its obligations under Articles 32–36 GDPR, for example with impact assessments and prior consultation with the Swedish Authority for Privacy Protection (IMY).
11.1ClubFlow shall notify the Club without undue delay, and where possible within 24 hours, after becoming aware of a personal data breach affecting the Club’s data. The purpose is to enable the Club to notify IMY of the breach within 72 hours under Article 33 GDPR.
11.2The notification shall, to the extent the information is available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact person at ClubFlow. Information that is not immediately available may be provided in phases.
11.3ClubFlow shall take the measures reasonably required to limit the effects of the breach and assist the Club in its investigation and in any communication to the data subjects.
12.1ClubFlow shall give the Club access to the information needed to demonstrate that the obligations in the Agreement and Article 28 GDPR are met, including a current description of the security measures, the list of sub-processors and the Club’s own audit log in the platform.
12.2The Club is entitled once per calendar year to request a written answer to questions about ClubFlow’s processing. The Club is also entitled, with at least 30 days’ written notice, to have an independent auditor bound by confidentiality carry out an audit during normal office hours. The Club bears its own costs for the audit. The once-a-year limit does not apply where deficiencies have been identified or after a personal data breach.
12.3The Agreement does not limit the powers of IMY or any other supervisory authority.
13.1When the Main Agreement ends, the Club may export its data in a structured, machine-readable format for 30 days. ClubFlow assists with the export on request.
13.2After the export period, ClubFlow deletes the Club’s personal data unless the law requires continued storage. Data in backups is deleted when the backups are overwritten in the regular rotation, and no later than 90 days after the end of the export period. Until then, the data in backups may not be used for any other purpose.
13.3The Club may at any time during the term request earlier deletion. ClubFlow shall confirm in writing, on request, that the deletion has been carried out.
14.1The parties’ liability towards each other is governed by the Main Agreement. However, limitations of liability in the Main Agreement do not apply if ClubFlow processes personal data contrary to the Club’s instructions or breaches the Agreement intentionally or through gross negligence.
14.2The Agreement does not affect the parties’ liability towards data subjects under Article 82 GDPR.
15.1The Agreement applies from when it is entered into and for as long as ClubFlow processes personal data on the Club’s behalf, including during the period in section 13.
15.2Obligations that by their nature are intended to survive the end of the Agreement, for example confidentiality and deletion, continue to apply.
16.1Amendments and additions to the Agreement must be in writing and approved by both parties. ClubFlow may, however, update Annex A under section 16.2, Annex B under section 8 and Annex C under section 6.2.
16.2When ClubFlow adds new features, ClubFlow may update Annex A and shall inform the Club in writing at least 30 days in advance. A feature that involves new categories of data subjects or special categories of personal data (for example injury data or other health information) may be used only if the Club itself enables it in the platform.
16.3If changes to data protection law or guidance from IMY or the European Data Protection Board require it, the parties shall agree in good faith on the necessary amendments.
17.1The Agreement is governed by Swedish law. Disputes arising from the Agreement are settled by the general courts of Sweden.
The Agreement has been executed in two identical copies, or signed electronically, of which each party has taken one. If the Agreement is an annex to a signed Main Agreement, no separate signatures are needed, see section 1.2.
To provide ClubFlow’s platform to the Club under the Main Agreement, to the extent the Club uses it. The platform currently includes squad administration, matches and playing time, player development (individual development plans), assessments, scouting and transfers, application forms, wellness check-ins (if enabled), signals that point staff to what needs following up, and synchronisation of match and league table data from the Swedish Football Association (if enabled). New features the Club chooses to use fall under the same purpose, subject to the limits in section 16.2.
Collection through the Club’s users and forms, storage, structuring, compilation, rule-based profiling (signals, see below), display, export, anonymisation and erasure.
Data concerning health, only if the Club enables wellness check-ins: the player’s own rating of sleep, fatigue, muscle soreness, stress, mood and perceived exertion, body regions marked with how much they hurt, plus any free text. The data is deleted 12 months after the check-in date and when the player is anonymised. See section 4.3.
The platform computes signals about players: short messages to the Club’s staff about something that needs following up, for example that a player has had no playing time despite being available, that a development plan is due for follow-up, or that a contract is about to expire. A signal is an automated evaluation of personal aspects and therefore profiling under Article 4(4) GDPR.
Sweden (Stockholm). See Annex B for sub-processors and any transfers.
For as long as the Main Agreement applies, and thereafter under section 13.
| Sub-processor | Service and data | Place of processing | Safeguard |
|---|---|---|---|
| Supabase, Inc. (USA) | Database, authentication and file storage. All data in Annex A. | Sweden (AWS, Stockholm, eu-north-1) | Storage within the EU. Supabase’s DPA with standard contractual clauses for any access from the USA. |
| Vercel, Inc. (USA) | Hosting of the web application. Data passes through when displayed but is not stored. Request data (IP address, browser, URL) in operational logs. | Compute in Sweden (Stockholm, arn1). Operational logs in the USA. | EU-US Data Privacy Framework, with standard contractual clauses as a fallback. |
| Resend (USA) | Sending system emails: invitations, verification and password resets. Email address, name, club name. | EU (Ireland, eu-west-1) | Resend’s DPA with standard contractual clauses / DPF. |
| Lark Technologies Pte. Ltd. (Singapore) | Email for support. Only the personal data the Club itself sends to ClubFlow’s support addresses. | Japan | The Commission’s adequacy decision for Japan. Lark’s DPA with standard contractual clauses. |
The Swedish Football Association is not a sub-processor. When the Club enables synchronisation, ClubFlow fetches match, result and league table data from the association’s API using the Club’s own API key. No personal data is sent from ClubFlow to the association.
ClubFlow’s own measurement of how the Club’s staff use the platform (cookieless, consent-based and never on pages players use) contains no data from the Club’s data. ClubFlow is the controller for that measurement, and it is not covered by the Agreement.