Data protection
Subprocessors
We use a small number of service providers to run this platform. Each one processes personal data only on our documented instructions, under a written data processing agreement. Where a provider operates outside the European Economic Area, the transfer relies on the European Commission's Standard Contractual Clauses together with supplementary technical measures.
Hosting, database and file storage provider
- Purpose
- Runs the application, the PostgreSQL database, and encrypted file storage.
- Location
- European Union
- Safeguard
- Processing within the EEA; data processing agreement in place.
Transactional email provider
- Purpose
- Delivers account, attendance, contribution and report emails.
- Location
- European Union, with support access possible from outside the EEA
- Safeguard
- Standard Contractual Clauses and supplementary technical measures.
Error and performance monitoring
- Purpose
- Captures application errors so faults can be diagnosed.
- Location
- European Union
- Safeguard
- Personal data minimised in captured payloads; DPA in place.
We update this page before any new subprocessor begins processing personal data. Members and staff may object to a new subprocessor by contacting the privacy contact given in our privacy notice.
