Last updated: 31 August 2026
This Addendum forms part of the Terms & Conditions between Firebound Interactive, which operates the DutyGO service (“we”, the Processor) and the club or organisation that subscribes to the service (“you”, the Controller). It applies whenever we process personal data on your behalf, and it takes precedence over the Terms in the event of a conflict about data protection.
You do not need to sign anything separately: this Addendum is incorporated into the Terms and is accepted when you create an account. If your organisation requires a countersigned copy, contact us at dutygo@fireboundinteractive.uk.
For the member data you enter into DutyGO (names, contact details, qualifications, duty assignments, administrator notes, documents and check-in records), you are the Controller and we are the Processor. You decide what data is collected and why. We process it only to provide the service.
We are an independent Controller for your account and billing data, for enquiries you send us, and for technical data generated in securing the service. Our Privacy Policy governs that processing.
| Subject matter | Provision of the DutyGO duty roster and club management service. |
|---|---|
| Duration | For the term of your subscription, plus the retention periods set out in our Privacy Policy. |
| Nature and purpose | Storage, organisation, retrieval, transmission and erasure of member records for the purpose of operating duty rosters, swaps, check-ins, equipment requests, announcements and document sharing. |
| Types of personal data | Name, email address, phone number, vehicle registration, qualifications and expiry dates, duty and role assignments, equipment requests, administrator notes, check-in and check-out timestamps. |
| Categories of data subject | Your club’s administrators, members and volunteers. These may include members under 18 where your club chooses to add them; you remain responsible for the lawful basis and any parental consent. |
| Special category data | None. The service is not designed to hold special category or criminal offence data, and the Terms & Conditions prohibit entering it. |
In this clause, references to Articles within UK GDPR
We will:
You give us general written authorisation to engage the sub-processors listed in Section 6 of our Privacy Policy. That list is kept current and is the authoritative record.
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative; if we cannot, you may terminate your subscription without penalty.
We remain fully liable to you for the performance of any sub-processor’s obligations, and we impose data protection terms on each of them no less protective than those in this Addendum.
Personal data processed on your behalf is stored in Belgium, within the European Union, and that transfer is covered by the UK Government's adequacy regulations for the EEA.
Where a sub-processor processes personal data in a country without UK adequacy (Cloudflare's global edge network, and Stripe's US operations), the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. Details of the mechanism applied to a specific transfer are available on request.
We maintain, at a minimum:
We will notify you without undue delay of becoming aware of a personal data breach affecting personal data we process on your behalf. Our notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for more information, so far as that information is available to us, and supplemented in phases if it is not all available at once.
Reporting a breach to the ICO within 72 hours where required by law, and notifying affected individuals where required, remains your responsibility as Controller. We will provide reasonable assistance.
You can export your club’s staff data at any time using the CSV export in the website.
When your subscription ends, your club’s data is retained for 30 days so you can reactivate, and is then permanently deleted from our systems. Deletion covers member records, administrator notes, events, rosters, swaps, check-ins, equipment requests, documents and uploaded logos.
A sign-in account is shared across every club a person belongs to, so it is not deleted where they remain a member of another club on DutyGO. Where the deleted club was their last, the account is kept for 24 months so they can rejoin without losing it, and is then deleted automatically. An individual asking us to erase their account is actioned immediately and does not wait for that period.
You may request earlier deletion in writing, and we will comply within 30 days. Copies held in routine backups are deleted on the normal backup rotation, and remain subject to this Addendum until they are.
On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, we will make available the information reasonably necessary to demonstrate compliance with this Addendum. Where a physical or technical audit is genuinely required, we will cooperate in good faith, subject to reasonable confidentiality protections and to your bearing the reasonable costs.
You confirm that:
Nothing in this Addendum limits either party’s liability under the UK GDPR or the Data Protection Act 2018 to a data subject or a supervisory authority. In the event of a conflict between this Addendum and the Terms & Conditions, this Addendum prevails on matters of data protection.
This Addendum is governed by the laws of England and Wales, and is subject to the exclusive jurisdiction of the courts of England and Wales.
Data protection queries: dutygo@fireboundinteractive.uk. We are registered with the Information Commissioner’s Office under registration number ZC202413.