Row HQ GDPR Compliance

Support Area

🚀

Support Area coming soon

UK GDPR Aligned

GDPR Compliance

Your data rights are protected. Learn how Row HQ complies with the UK GDPR and Data Protection Act 2018.

Last updated: May 2026

Back to Home

Aligned With UK GDPR From Day One

Row HQ has been designed with UK GDPR in mind, ensuring your data and your club members' data is protected to the high standards we describe below.

The UK General Data Protection Regulation (UK GDPR), alongside the Data Protection Act 2018, governs how organisations process personal data of individuals in the United Kingdom. Row HQ is designed to align with these requirements and has measures in place to protect your rights as a data subject.

Our Role Under UK GDPR

Data Processor

When rowing clubs use Row HQ to manage their members' data, we act as a Data Processor. This means:

  • We process personal data on behalf of rowing clubs
  • We follow the documented instructions provided by clubs (Data Controllers)
  • We implement appropriate technical and organisational security measures
  • We assist clubs in meeting their UK GDPR obligations

Data Controller

For account registration and billing information, we act as a Data Controller. This covers:

  • Club administrator contact information
  • Billing and payment details
  • Account settings and preferences
  • Support ticket communications

Lawful Basis for Processing

We process personal data based on the following lawful bases under Article 6 of the UK GDPR:

Contract Performance

Processing necessary to provide our services under the subscription agreement

Legitimate Interests

Processing for service improvement, security, and fraud prevention, balanced against your rights

Legal Obligations

Processing required to comply with UK laws and regulatory requirements

Consent

Processing based on your explicit, freely given consent for marketing communications

Your Rights Under UK GDPR

Under the UK GDPR, you have the following rights regarding your personal data:

Right of Access

Request a copy of the personal data we hold about you (subject access request)

Right to Rectification

Have inaccurate or incomplete personal data corrected without undue delay

Right to Erasure

Request deletion of your personal data, also known as the right to be forgotten

Right to Data Portability

Receive your data in a structured, commonly used, machine-readable format

Right to Object

Object to processing based on legitimate interests, including direct marketing

Right to Restrict Processing

Limit how we process your personal data in specific circumstances

How to Exercise Your Rights: Contact us at support@rowhq.app with your request. We will respond within one calendar month, as required by the UK GDPR.

Data Security Measures

We implement the following technical and organisational measures to protect personal data:

Technical Measures

  • Encryption in transit (TLS 1.3)
  • Encrypted data storage at rest (AES-256)
  • Dependency monitoring and timely security patches
  • Access logging and monitoring
  • Daily automated backups
  • DDoS protection at the network edge

Organisational Measures

  • Operational access to data on a strict need-to-know basis
  • Role-based access controls and authentication
  • Data Processing Agreements with our sub-processors
  • Privacy by design and default principles
  • Defined incident response and breach notification steps

Data Processing Agreement

As required by Article 28 of the UK GDPR, we provide a Data Processing Agreement (DPA) to all our customers. This agreement:

  • Defines our obligations as a data processor
  • Ensures compliance with UK GDPR requirements
  • Specifies security measures and breach notification procedures
  • Details sub-processor usage and data retention policies
  • Is automatically included in our Terms of Service

International Data Transfers

Row HQ servers are located in the United Kingdom. For any international transfers, we ensure:

  • Use of the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses
  • Adequate safeguards as required by UK GDPR Articles 44-49
  • Transparency about data location and onward transfers
  • Transfer Risk Assessments where required

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:

Active Accounts

Data retained for the duration of your service subscription

Cancelled Accounts

Data retained for 90 days after cancellation, then securely deleted

Legal Requirements

Financial records retained as required by HMRC and UK law (typically six years)

Personal Data Breach Procedures

In the unlikely event of a personal data breach, we will:

  1. Identify and contain the breach immediately
  2. Assess the risk to individuals' rights and freedoms
  3. Notify affected customers without undue delay
  4. Report qualifying breaches to the Information Commissioner's Office (ICO) within 72 hours, as required by UK GDPR Article 33
  5. Document all breach details and remediation steps
  6. Implement measures to prevent recurrence

Guidance for Rowing Clubs

As a rowing club using Row HQ, you remain the Data Controller for your members' data. We recommend:

Best Practices for Clubs

  • Obtain a clear lawful basis (consent or legitimate interests) for processing member data
  • Update your privacy notice to mention Row HQ as a processor
  • Apply data minimisation - only collect data necessary for club operations
  • Regularly review and update member permissions
  • Train committee members and coaches on data protection responsibilities
  • Respond to member subject access requests within one month
  • Keep a Record of Processing Activities (ROPA) under Article 30

Get in Touch About Data Protection

For any UK GDPR-related questions, data subject requests, or concerns:

Email: support@rowhq.app

Subject Line: "GDPR Request - [Your Request Type]"

Response Time: Within one calendar month, as required by UK GDPR

Supervisory Authority: You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you're unsatisfied with our response.

Start Free