GDPR Compliance
Your data rights are protected. Learn how Row HQ complies with the UK GDPR and Data Protection Act 2018.
Last updated: May 2026
Aligned With UK GDPR From Day One
Row HQ has been designed with UK GDPR in mind, ensuring your data and your club members' data is protected to the high standards we describe below.
The UK General Data Protection Regulation (UK GDPR), alongside the Data Protection Act 2018, governs how organisations process personal data of individuals in the United Kingdom. Row HQ is designed to align with these requirements and has measures in place to protect your rights as a data subject.
Our Role Under UK GDPR
Data Processor
When rowing clubs use Row HQ to manage their members' data, we act as a Data Processor. This means:
- We process personal data on behalf of rowing clubs
- We follow the documented instructions provided by clubs (Data Controllers)
- We implement appropriate technical and organisational security measures
- We assist clubs in meeting their UK GDPR obligations
Data Controller
For account registration and billing information, we act as a Data Controller. This covers:
- Club administrator contact information
- Billing and payment details
- Account settings and preferences
- Support ticket communications
Lawful Basis for Processing
We process personal data based on the following lawful bases under Article 6 of the UK GDPR:
Contract Performance
Processing necessary to provide our services under the subscription agreement
Legitimate Interests
Processing for service improvement, security, and fraud prevention, balanced against your rights
Legal Obligations
Processing required to comply with UK laws and regulatory requirements
Consent
Processing based on your explicit, freely given consent for marketing communications
Your Rights Under UK GDPR
Under the UK GDPR, you have the following rights regarding your personal data:
Right of Access
Request a copy of the personal data we hold about you (subject access request)
Right to Rectification
Have inaccurate or incomplete personal data corrected without undue delay
Right to Erasure
Request deletion of your personal data, also known as the right to be forgotten
Right to Data Portability
Receive your data in a structured, commonly used, machine-readable format
Right to Object
Object to processing based on legitimate interests, including direct marketing
Right to Restrict Processing
Limit how we process your personal data in specific circumstances
How to Exercise Your Rights: Contact us at support@rowhq.app with your request. We will respond within one calendar month, as required by the UK GDPR.
Data Security Measures
We implement the following technical and organisational measures to protect personal data:
Technical Measures
- Encryption in transit (TLS 1.3)
- Encrypted data storage at rest (AES-256)
- Dependency monitoring and timely security patches
- Access logging and monitoring
- Daily automated backups
- DDoS protection at the network edge
Organisational Measures
- Operational access to data on a strict need-to-know basis
- Role-based access controls and authentication
- Data Processing Agreements with our sub-processors
- Privacy by design and default principles
- Defined incident response and breach notification steps
Data Processing Agreement
As required by Article 28 of the UK GDPR, we provide a Data Processing Agreement (DPA) to all our customers. This agreement:
- Defines our obligations as a data processor
- Ensures compliance with UK GDPR requirements
- Specifies security measures and breach notification procedures
- Details sub-processor usage and data retention policies
- Is automatically included in our Terms of Service
International Data Transfers
Row HQ servers are located in the United Kingdom. For any international transfers, we ensure:
- Use of the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses
- Adequate safeguards as required by UK GDPR Articles 44-49
- Transparency about data location and onward transfers
- Transfer Risk Assessments where required
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
Active Accounts
Data retained for the duration of your service subscription
Cancelled Accounts
Data retained for 90 days after cancellation, then securely deleted
Legal Requirements
Financial records retained as required by HMRC and UK law (typically six years)
Personal Data Breach Procedures
In the unlikely event of a personal data breach, we will:
- Identify and contain the breach immediately
- Assess the risk to individuals' rights and freedoms
- Notify affected customers without undue delay
- Report qualifying breaches to the Information Commissioner's Office (ICO) within 72 hours, as required by UK GDPR Article 33
- Document all breach details and remediation steps
- Implement measures to prevent recurrence
Guidance for Rowing Clubs
As a rowing club using Row HQ, you remain the Data Controller for your members' data. We recommend:
Best Practices for Clubs
- Obtain a clear lawful basis (consent or legitimate interests) for processing member data
- Update your privacy notice to mention Row HQ as a processor
- Apply data minimisation - only collect data necessary for club operations
- Regularly review and update member permissions
- Train committee members and coaches on data protection responsibilities
- Respond to member subject access requests within one month
- Keep a Record of Processing Activities (ROPA) under Article 30
Get in Touch About Data Protection
For any UK GDPR-related questions, data subject requests, or concerns:
Email: support@rowhq.app
Subject Line: "GDPR Request - [Your Request Type]"
Response Time: Within one calendar month, as required by UK GDPR
Supervisory Authority: You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you're unsatisfied with our response.