Security and data
How your studio data is protected
Protected sign-in, team permissions, change history and backups. Below we explain what works in ClubBase and how you can control access and data.
Connection and sign-in
Add protection on top of your password
The site and the CRM run over HTTPS: data travels between your browser and the service over a protected connection. Sign-up includes email confirmation, and frequent repeated sign-in attempts are limited.
The owner can turn on Two-factor protection («Двофакторний захист») in My ClubBase («Мій ClubBase»). After that, a new sign-in needs a code from an authenticator app after the password. Access to the separate ClubBase service control panel requires a second factor.
Team access
Everyone gets the part of the work they need
The owner invites the team and assigns roles. The server and the database check which studio a request belongs to. A link to another studio's profile does not open its data.
- Owner
- Runs the studio, its settings and team permissions.
- Admin
- Runs day-to-day work and studio settings, including data and the team.
- Front desk
- Handles day-to-day work without managing roles.
- Specialist
- Sees their own schedule, groups and attendance.
- Finance
- Works with payments and payroll without managing the schedule.
Activity log
You can see who made a change and when
For operations that go into the log, the person, the time and the details of the action are stored. That makes it easier to work out a change to a payment, attendance or settings.
Saved log entries cannot be rewritten after the fact. Access to the history depends on the person's permissions in the studio.
Backups
Data copies are stored separately
Backups are encrypted and sent to a separate server. Both creating a backup and restoring from it are tested.
Restore tested during the release on .
Personal data
Export, photos and data deletion
A user with the right permission can export a person's data from their profile. A photo is uploaded after consent is confirmed; images from Telegram are not copied automatically.
Anonymisation removes identifying data from the profile. Financial records, attendance and the change log are kept as a history of operations. A request to export or delete data can be sent to the team; the requester's identity is checked before it is carried out.
Materials for AI
Processing rules come before any file upload
Before AI features are switched on, we will state the provider, how data is transferred, how long materials are kept and how they are deleted.
Uploading a file does not by itself mean that everyone in it has consented to processing. Terms for client and children's data have to be set before the migration starts.
A question about data or a security issue
Write to the team: [email protected]. Include the page and what happened.