Clayside
Clayside

Data processing terms

The data processing agreement between your club and us, written out. It forms part of our Terms, so it is already agreed. Print it for the folder.

Last updated 28 July 2026 · Version 1.0

The short version. Your club decides who goes in its league, so your club is the controller and we are the processor. We only ever act on your instructions, we hold your league in a database of its own, we use two suppliers and they are both named below, and when you leave you take everything and we delete the rest. Nothing here needs to be requested, signed or chased.

1. Who this is between

These terms are between your club (the controller) and Agentu Ltd, trading as Clayside, registered in England and Wales, company number 16191406, registered office 10 Campbell Crescent, East Grinstead, West Sussex, RH19 1JR (the processor).

They set out the terms required by Article 28(3) of the UK GDPR. They form part of our Terms of Service and take effect when your club starts a league, so there is nothing to sign and nothing to send back. If your club has its own template it would rather use, email hello@clayside.app and a person will read it.

Where these terms and the Terms of Service disagree about the processing of your league's personal data, these ones win.

One boundary worth stating plainly, because it decides who you write to. For the names and results inside your league, your club is the controller and we are the processor, and that is what this page covers. For your organisers' own accounts, and for the details given when somebody starts a league at /setup, we are the controller and our Privacy Policy is the document that speaks to it.

2. What we process, and for how long

The Article 28(3) description
Required detailWhat it is here
Subject matterRunning your club's box leagues and, if you use one, your club ladder.
DurationFor as long as your club has a league with us, and then for the deletion period in clause 10.
Nature and purposeStoring and displaying a roster, generating fixtures, recording and confirming scores, working out standings and ratings, keeping a season archive, and keeping an activity log of what your admins changed.
Type of personal dataPlayer names, the boxes and ladders they are in, and their results. For your organisers: a display name, an email address and hashed sign-in secrets. Free text an admin types when deleting a score or in the activity log. Nothing else, and there is no field for anything else.
Categories of data subjectYour club's players, including junior members if your club enters them, and the people your club gives admin access to.
Special category dataNone. Clayside is not built to hold health, safeguarding or any other special category data, and clause 8 of our Terms asks you not to put it in.

What your league holds about a player, in full, is listed on our safeguarding page. How long we keep what is in section 8 of the Privacy Policy, and that table is the one to read rather than a second copy of it here.

3. Your instructions

We process your league's personal data only on your club's documented instructions. Those instructions are: these terms, our Terms of Service, our Privacy Policy, and whatever your admins actually do in the app. Using a feature is an instruction to run it.

  • We will not use your league's data for anything of our own. Not to train a model, not to build a product, not to profile anybody, and not to sell or share with anyone at any price.
  • We never email your players. We hold no player email address, we do not ask your club for one, and there is no field to put one in. Our own occasional note about Clayside goes to club owners and admins only, with a one-click unsubscribe on it.
  • If UK or EU law ever required us to process your data beyond your instructions, we would tell you before doing it, unless that law forbids telling you.
  • If we think an instruction breaks data protection law, we will say so.

4. Confidentiality

Access to your club's data is limited to the people at Agentu who need it to run the service and fix it when it breaks. Everyone with access is under a duty of confidentiality that carries on after they stop working with us.

In practice that access is used for two things: investigating a fault you have reported, and keeping the platform running. We do not read club data out of curiosity, and there is no browsing tool that would make it convenient to.

5. Security

The measures we take, as required by Article 32. These are the real ones, not a list copied off another policy:

  • Your club's league is a separate database. Not a shared table with a club column in it. One club cannot query another's data because there is no query that reaches it, and there is no identifier to guess.
  • There are no passwords. Signing in is a link or a six-digit code sent by email, valid for 15 minutes. We cannot leak a password we never asked for.
  • Sign-in secrets are stored as one-way hashes, never in plain text, and a code guessed wrong five times invalidates itself.
  • Encrypted in transit and at rest. HTTPS everywhere, with encryption at rest by our hosting provider.
  • No third-party scripts or fonts on the pages your members use, so a visit to your league is not announced to anybody else.
  • Backups and restoration are handled by our hosting provider's point-in-time recovery for the database service, which is what would be used to restore a club after an incident.
  • Testing. Changes go through an automated test suite before they ship, and the security-relevant parts of the system are reviewed when they change.

One limit we would rather write down than bury: the shareable link a club posts to its box's group chat is a key. Anyone holding it can enter scores as anyone in that box. It is built that way deliberately, because the alternative is forty accounts and forty forgotten passwords, but it is your club's to look after.

6. Sub-processors

Your club gives general authorisation for the sub-processors below. Each is under a written contract with terms no weaker than these, and we stay liable to you for what they do.

WhoWhat they processWhat for
Cloudflare, Inc.Everything in your league. Your connection passes through them.Hosting and database storage.
Resend (Plus Five Five, Inc.)The recipient's email address and the message.Delivering sign-in codes, invites and confirmations to your admins. Never to a player.

Two more suppliers are named in section 6 of our Privacy Policy and are deliberately not in this table, because neither touches your league's data: Cloudflare Turnstile sees a visitor's IP address on the signup page only, and GoCardless sees the name, email and bank details of a club owner who sets up a Direct Debit, which is our own controller data rather than yours.

Changing the list. If we add or replace a sub-processor we will email club owners at least 30 days beforehand. If your club objects on reasonable data protection grounds, tell us within those 30 days and we will either find another way or let you leave, with your export in hand and no charge for the unused part of anything you have paid.

7. Helping with a player's request

If a player asks us directly for their data, or to correct or delete it, we will not answer for your club. We will tell them to ask you, tell you it happened, and help you answer.

Most of the help is already built, which is faster than any process we could promise:

  • Access and portability: a club owner can download the entire league, every player, every result and every season, as one file, from inside the app. No request form, no waiting, no charge.
  • Correction: an admin can edit a player's name directly.
  • Erasure: an admin can remove a player from a roster. Removing somebody does not erase results already played, for the reason set out in section 9 of the Privacy Policy; if a name has to go entirely, ask us and we will work out with you how to do it properly.

Where you need more than the app gives you, we will provide it, and we will not charge for it.

8. Breaches, and helping you assess risk

If there is a personal data breach affecting your league, we will tell you without undue delay and in any case within 24 hours of becoming aware of it. Your club is the controller, so the 72-hour clock for telling the ICO is yours, and telling you inside 24 hours is what makes it possible to keep.

We will tell you what happened, which data and roughly how many people are affected, what we think the consequences are, and what we are doing about it. If we do not know all of that yet we will say what we know and follow up rather than wait.

We will also help you with a data protection impact assessment or a consultation with the ICO, if the scale of your processing ever means you need one. For a club box league it almost certainly does not, and we would say so rather than sell you a document.

9. International transfers

Your club's database is pinned to the EU when it is created. That is a constraint our hosting provider enforces rather than a preference we express, it binds the main copy and every replica, and it cannot be loosened afterwards, by us or by them.

One honest exception, the same one the Privacy Policy makes: email leaves. Sign-in codes and invites go through Resend, and mail in transit is not covered by the constraint above.

Cloudflare and Resend are both US-headquartered, so where data does travel it is covered by the safeguards UK law requires: the UK Addendum to the EU Standard Contractual Clauses, under each supplier's own data processing agreement, and both are certified under the UK–US Data Bridge.

10. Deletion and return

Return first. Your export works on your last day exactly as it does on your first: one file, one click, every player, every result and every season, from inside the app. Take it before you go, because the next part is final.

Then deletion. When your club closes its league, or asks us to delete it, we delete the whole database within 30 days, and no backup survives it. We keep nothing back except where UK law requires it, which in practice means accounting records for a club that has paid us, and those hold no player data.

A trial nobody ever confirmed is deleted on its own timetable, set out in section 8 of the Privacy Policy. That is the one case where the deletion happens without anybody asking for it, and we email you first.

11. Audit

We will give you the information you reasonably need to show that we are meeting these terms. In the first instance that is this page, our Privacy Policy, our safeguarding page and an honest answer to an email, which for a club box league is normally the whole of it.

If your club needs more than that, write to hello@clayside.app and we will agree something proportionate: a written answer to a questionnaire, or an audit at reasonable notice, in working hours, no more than once a year unless a breach or a regulator says otherwise, and on terms that keep other clubs' data out of it. We are a small company and we will not pretend to a certification we do not hold.