Who else processes your data
Imperial Resources Limited runs your club's website, and uses a small number of other companies to do it. Article 28(2) of the GDPR entitles you, as the controller, to know who they are — so this is a public page rather than a schedule you have to ask for.
Adding to or replacing anything on this list means thirty days' notice by email before it takes effect, and a right to object. See clause 4 of the data processing agreement.
The list is short on purpose. Every company here is one more place your members' details exist, and one more thing that can go wrong.
Stripe Payments Europe, Ltd.
What they do. Takes card payments for bookings, the shop, donations and the club lottery.
What they hold. The payer's name, email address and card details. Card numbers never reach The Crest.
Where. Ireland, with processing in the United States.
Leaving the EEA. EU Standard Contractual Clauses, and Stripe's certification under the EU–US Data Privacy Framework.
Brevo (Sendinblue SAS)
What they do. Sends the emails the site generates: booking confirmations, receipts, enquiries forwarded to the club.
What they hold. The recipient's email address and the contents of the message.
Where. France.
Leaving the EEA. None. The data stays in the EEA.
Hetzner Online GmbH
What they do. Hosts the servers and the database the website runs on.
What they hold. Everything the site stores, at rest.
Where. Germany.
Leaving the EEA. None. The data stays in the EEA.
Cloudflare, Inc.
What they do. Serves the site's certificates, stores the club's photographs and files, and filters abusive traffic. Where spam protection is enabled, also checks that a contact form was filled in by a person rather than a script.
What they hold. The club's uploaded photographs and documents, and the visitor's IP address in transit. No cookie is set on the club's site.
Where. United States.
Leaving the EEA. EU Standard Contractual Clauses, and Cloudflare's certification under the EU–US Data Privacy Framework.
Apple, Google and Mozilla push services
What they do. Wake a phone or browser that asked for the club's alerts. The alert itself is fetched from the club's site, so these services never see what it says.
What they hold. The address the visitor's own browser gave for its alerts, and when each wake-up was sent. No name, email or content.
Where. United States.
Leaving the EEA. EU Standard Contractual Clauses, and each company's certification under the EU–US Data Privacy Framework.
Nobody else
In particular, and deliberately:
- No analytics provider. No club site sends anything to Google Analytics or any equivalent. Nobody is measuring your visitors.
- No advertising or marketing network.
- No font or script content delivery network. Everything a club's page loads comes from the club's own site.
- No mapping provider. A club's "find us" block is an address and a link, not an embedded map.
- No customer-support widget on club sites.
Where a club puts a video on a page, the player is loaded from YouTube or Vimeo only when a visitor presses play. Until then those companies receive nothing. They are not sub-processors: the visitor chooses to go to them.
Version v1. Questions go to privacy@thecrest.ie.