Golfio F&B
PrivacyTermsDPASign in

Data Processing Agreement

Effective 14 July 2026 · Version 1.0

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the subscribing golf club (the Controller) and Conor Mac Aogain, sole trader trading as Golfio F&B, Ireland (the Processor). It applies automatically to every account — no signature is required — and satisfies Article 28(3) GDPR, the UK GDPR, and the Swiss FADP. A countersigned copy is available on request to conor@golfiofb.com.

1. Details of processing

Subject matterProvision of the Golfio F&B service: tee-sheet-driven staffing, rostering, reporting and compliance support.
DurationThe life of the club’s subscription, plus the deletion window below.
Nature & purposeStorage, structuring and analysis of the club’s operational data to generate demand forecasts, rosters, labour costs, reports and checklists.
Categories of data subjectsGolfers and society visitors named on tee sheets; the club’s staff; the club’s account holder.
Categories of personal dataNames, tee times and group membership from tee sheets; staff names, roles, availability, working preferences and optional hourly pay rates; rosters and logged cover counts. No special-category data is required by or should be uploaded to the service.

2. Processor obligations

Golfio shall:

  1. Follow instructions. Process the data only on the Controller’s documented instructions — in practice, the features the club uses — unless required otherwise by EU/member-state law, in which case Golfio informs the Controller first (unless the law prevents it). Golfio never sells the data, uses it for advertising, or trains machine-learning models on it.
  2. Confidentiality. Ensure any person authorised to process the data (currently only the operator) is bound by confidentiality.
  3. Security (Art. 32). Maintain the technical and organisational measures in the Annex below.
  4. Assist with data-subject rights. Refer any request received directly from a golfer or staff member to the Controller without undue delay, and provide reasonable assistance (search, export, correction, deletion tooling) so the Controller can respond within its deadlines.
  5. Breach notification. Notify the Controller without undue delay, and in any case within 48 hours of becoming aware of a personal-data breach affecting the club’s data, with enough detail to support the Controller’s own 72-hour obligation to its supervisory authority.
  6. Assist with compliance. Provide reasonable assistance with data-protection impact assessments and prior consultations, insofar as they concern the service.
  7. Deletion and return. On termination of the subscription, delete the club’s personal data, with residual encrypted-backup copies expiring on a rolling basis within 30 days — or first return an export if the Controller requests one before deletion.
  8. Audit. Make available the information reasonably necessary to demonstrate compliance with Article 28, including security documentation on request, and allow audits (at most once per year, on 30 days’ notice, at the Controller’s cost, without access to other clubs’ data).

3. Sub-processors

The Controller gives general authorisation for the sub-processors below. Golfio will give at least 14 days’ email notice before adding or replacing one; if the Controller reasonably objects on data-protection grounds and no resolution is found, it may terminate and receive a pro-rata refund of prepaid fees.

Sub-processorRoleLocation / transfer safeguard
SupabaseDatabase and authenticationData hosted in Zurich, Switzerland — an EU adequacy country; no further safeguard required
VercelApplication hosting and deliveryEU-US Data Privacy Framework / Standard Contractual Clauses
StripePayments (account-holder billing data only — no tee-sheet or staff data)EU-US Data Privacy Framework / Standard Contractual Clauses

4. International transfers

Club data at rest stays in Switzerland (adequacy decision). Where a sub-processor processes personal data outside the EEA, UK or Switzerland, the transfer is protected by the safeguards listed above. For UK clubs, references to the GDPR include the UK GDPR and transfers rely on the UK’s equivalent adequacy and addendum mechanisms; for Swiss clubs, the FADP applies correspondingly.

5. Liability and order of precedence

Liability under this DPA is subject to the cap and exclusions in the Terms of Service. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails.

Annex — Technical and organisational measures

  • Encryption in transit (TLS 1.2+) on every connection; encryption at rest on the database.
  • Per-tenant isolation enforced in the database itself: row-level security with write checks on every verb, so one club’s data is invisible to and unwritable by another’s session.
  • Identity verified server-side on every request from the signed session token; user identity is never taken from the request body.
  • Default-deny routing: every endpoint is authenticated unless explicitly public; state writes are validated against a strict field allowlist and size cap.
  • Database credentials with administrative scope are confined to a single server-side payment-webhook path and never reach the browser; passwords are stored only as salted hashes by the auth provider.
  • Origin/CSRF checks and rate-limiting on write endpoints.
  • Tee-sheet photo OCR runs client-side in the browser; photos are not uploaded to or retained on servers.
  • Encrypted backups with a bounded retention window (30 days) supporting point-in-time recovery.
  • Access to production data is restricted to the operator, for support and maintenance only.

Golfio F&B · operated by Conor Mac Aogain (sole trader), Ireland · conor@golfiofb.com

Privacy Policy · Terms of Service · Data Processing Agreement