DutyGO DutyGO Back to site

Data Processing Addendum

Last updated: 31 August 2026

This Addendum forms part of the Terms & Conditions between Firebound Interactive, which operates the DutyGO service (“we”, the Processor) and the club or organisation that subscribes to the service (“you”, the Controller). It applies whenever we process personal data on your behalf, and it takes precedence over the Terms in the event of a conflict about data protection.

You do not need to sign anything separately: this Addendum is incorporated into the Terms and is accepted when you create an account. If your organisation requires a countersigned copy, contact us at dutygo@fireboundinteractive.uk.

Contents

  1. Roles
  2. Subject matter, duration, nature and purpose
  3. Our obligations as Processor
  4. Sub-processors
  5. International transfers
  6. Security measures
  7. Personal data breaches
  8. Deletion and return
  9. Audit
  10. Your obligations as Controller
  11. Liability and precedence
  12. Governing law
  13. Contact

1. Roles

For the member data you enter into DutyGO (names, contact details, qualifications, duty assignments, administrator notes, documents and check-in records), you are the Controller and we are the Processor. You decide what data is collected and why. We process it only to provide the service.

We are an independent Controller for your account and billing data, for enquiries you send us, and for technical data generated in securing the service. Our Privacy Policy governs that processing.

2. Subject matter, duration, nature and purpose

Subject matterProvision of the DutyGO duty roster and club management service.
DurationFor the term of your subscription, plus the retention periods set out in our Privacy Policy.
Nature and purposeStorage, organisation, retrieval, transmission and erasure of member records for the purpose of operating duty rosters, swaps, check-ins, equipment requests, announcements and document sharing.
Types of personal dataName, email address, phone number, vehicle registration, qualifications and expiry dates, duty and role assignments, equipment requests, administrator notes, check-in and check-out timestamps.
Categories of data subjectYour club’s administrators, members and volunteers. These may include members under 18 where your club chooses to add them; you remain responsible for the lawful basis and any parental consent.
Special category dataNone. The service is not designed to hold special category or criminal offence data, and the Terms & Conditions prohibit entering it.

3. Our obligations as Processor

In this clause, references to Articles within UK GDPR


We will:

  • Process personal data only on your documented instructions, which are these Terms, this Addendum, and your use of the service’s features, unless required to do otherwise by law, in which case we will tell you first unless the law forbids it;
  • Ensure that everyone authorised to process the data is bound by a duty of confidentiality;
  • Implement appropriate technical and organisational measures as required by Article 32, described in Section 6 below;
  • Respect the conditions in Sections 4 and 5 for engaging sub-processors;
  • Assist you, so far as reasonably possible, in responding to requests from data subjects exercising their rights;
  • Assist you with data protection impact assessments and with prior consultation of the ICO, where the processing requires it;
  • Delete or return the data at the end of the service, as set out in Section 8;
  • Make available the information you reasonably need to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in Section 9;
  • Tell you immediately if, in our opinion, an instruction from you infringes data protection law.

4. Sub-processors

You give us general written authorisation to engage the sub-processors listed in Section 6 of our Privacy Policy. That list is kept current and is the authoritative record.

We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate your subscription without penalty.

We remain fully liable to you for the performance of any sub-processor’s obligations, and we impose data protection terms on each of them no less protective than those in this Addendum.

5. International transfers

Personal data processed on your behalf is stored in Belgium, within the European Union, and that transfer is covered by the UK Government's adequacy regulations for the EEA.

Where a sub-processor processes personal data in a country without UK adequacy (Cloudflare's global edge network, and Stripe's US operations), the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. Details of the mechanism applied to a specific transfer are available on request.

6. Security measures

We maintain, at a minimum:

  • Encryption of personal data in transit over public networks;
  • Encryption at rest, as provided by our infrastructure providers;
  • Server-side authorisation, so that access controls are enforced by the database and the application rather than by the browser;
  • Tenant isolation, so that one customers data cannot be reached from another club’s account;
  • Role-based access within a customer, so that administrators, delegated role holders and ordinary members see only what their role permits;
  • Rate limiting on authentication, password reset, email sending and kiosk endpoints;
  • Passwords stored only as salted hashes by our authentication provider, never in plain text and never visible to us;
  • Automatic deletion of data at the end of the retention periods published in our Privacy Policy;
  • Periodic security review of the service, and remediation of findings on a risk-prioritised basis.

7. Personal data breaches

We will notify you without undue delay of becoming aware of a personal data breach affecting personal data we process on your behalf. Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for more information, so far as that information is available to us, and supplemented in phases if it is not all available at once.

Reporting a breach to the ICO within 72 hours where required by law, and notifying affected individuals where required, remains your responsibility as Controller. We will provide reasonable assistance.

8. Deletion and return

You can export your club’s staff data at any time using the CSV export in the website.

When your subscription ends, your club’s data is retained for 30 days so you can reactivate, and is then permanently deleted from our systems. Deletion covers member records, administrator notes, events, rosters, swaps, check-ins, equipment requests, documents and uploaded logos.

A sign-in account is shared across every club a person belongs to, so it is not deleted where they remain a member of another club on DutyGO. Where the deleted club was their last, the account is kept for 24 months so they can rejoin without losing it, and is then deleted automatically. An individual asking us to erase their account is actioned immediately and does not wait for that period.

You may request earlier deletion in writing, and we will comply within 30 days. Copies held in routine backups are deleted on the normal backup rotation, and remain subject to this Addendum until they are.

9. Audit

On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, we will make available the information reasonably necessary to demonstrate compliance with this Addendum. Where a physical or technical audit is genuinely required, we will cooperate in good faith, subject to reasonable confidentiality protections and to your bearing the reasonable costs.

10. Your obligations as Controller

You confirm that:

  • You have a lawful basis for the personal data you enter into DutyGO, and have provided the privacy information your members are entitled to;
  • You have obtained any consents your own processing requires;
  • You will keep member records accurate and remove members who should no longer have access;
  • You will not enter categories of data the service is not designed to hold, as described in Section 5 of the Privacy Policy;
  • Your instructions to us will comply with data protection law.

11. Liability and precedence

Nothing in this Addendum limits either party’s liability under the UK GDPR or the Data Protection Act 2018 to a data subject or a supervisory authority. In the event of a conflict between this Addendum and the Terms & Conditions, this Addendum prevails on matters of data protection.

12. Governing law

This Addendum is governed by the laws of England and Wales, and is subject to the exclusive jurisdiction of the courts of England and Wales.

13. Contact

Data protection queries: dutygo@fireboundinteractive.uk. We are registered with the Information Commissioner’s Office under registration number ZC202413.

Home · Privacy Policy · Terms & Conditions · Cookie Policy · Data Processing Addendum
© 2026 DutyGO. All rights reserved.