Security & privacy

Security and personal data protection

Kluboš processes your club's data under GDPR, on servers in the EU, with a data processing agreement and an audit trail that cannot be edited after the fact.

How we protect your club's data

Data in the EUThe app and the database run in Hetzner data centers in Falkenstein and Nuremberg, Germany. Backups are encrypted, kept for 30 days, and stored separately from live data.
Data Processing Agreement (DPA)Every organization gets a Data Processing Agreement with Standard Contractual Clauses, including a list of sub-processors.
Technical and organizational measuresEncrypted transport (TLS) on every public interface, encrypted communication between cluster nodes, and sign-in through the central identity system Keycloak with server-side authorization.
Immutable audit trailEvery change — who did what, and when — is written to an audit trail that cannot be edited or deleted after the fact.
Self-service export and erasureYou can export a member's data in a machine-readable format or erase it at any time, respecting the legal retention periods for accounting records. Free in every tier, no exceptions.
Consent by purposeMarketing and other consents are managed separately by purpose, and a member can withdraw any of them at any time.
Legal guardiansA guardian role acts on behalf of their wards — for example a member who hasn't created their own account yet.
Sign-in and accessSign-in runs through the central identity system, and access to every action is checked server-side by role and by organization/club scope.
WCAG AA accessibilityThe interface meets WCAG AA and is available in Slovak, Czech and English.

Legal documents

The full text of every document is on its own page, including a history of earlier versions.

Question about security or GDPR?

Write to us — we're happy to explain anything in more detail.