Club Planner holds the details of hundreds of thousands of members across seven countries. We treat that data the way you would: hosted in the EU, protected under the GDPR, and only ever visible to the people who need it.
The essentials clubs and their members are entitled to expect — and what you can ask us about in detail.
Your data runs on Microsoft Azure in the West Europe region, so it stays on European infrastructure — never moved out of the EU without a reason and a legal basis.
Club Planner is built to the GDPR, and every club can sign a data-processing agreement (DPA) that sets out exactly how personal data is handled on their behalf.
Databases keep a point-in-time restore with up to 30 days of retention, so your data can be recovered to an earlier moment if something ever goes wrong.

Every connection to Club Planner — the desktop app, the member app and the website — runs over an encrypted HTTPS/TLS connection, so data in transit cannot be read along the way.
Members can prove who they are with itsme, and every staff member signs in under their own account, so actions are tied to a real person instead of a shared login.

Card payments run through Mollie, a licensed payment provider. Card details are handled by the provider — Club Planner never stores your members' card numbers.
Access is gated per employee: your reception sees check-ins while only management opens the financials, so each role reaches exactly what it needs and nothing more.
We work only with vetted sub-processors — such as our hosting, payment and messaging partners — each bound by a contract that holds them to the same data-protection standards. In the event of a data incident, we act in line with our GDPR notification obligations.
Members keep their rights over their own data — access, correction and deletion — and the privacy policy sets out how to exercise them. For the full legal detail, see the documents below.