Skip to main content
ClubBase

Security and data

How your studio data is protected

Protected sign-in, team permissions, change history and backups. Below we explain what works in ClubBase and how you can control access and data.

Connection and sign-in

Add protection on top of your password

The site and the CRM run over HTTPS: data travels between your browser and the service over a protected connection. Sign-up includes email confirmation, and frequent repeated sign-in attempts are limited.

The owner can turn on Two-factor protection («Двофакторний захист») in My ClubBase («Мій ClubBase»). After that, a new sign-in needs a code from an authenticator app after the password. Access to the separate ClubBase service control panel requires a second factor.

Team access

Everyone gets the part of the work they need

The owner invites the team and assigns roles. The server and the database check which studio a request belongs to. A link to another studio's profile does not open its data.

Owner
Runs the studio, its settings and team permissions.
Admin
Runs day-to-day work and studio settings, including data and the team.
Front desk
Handles day-to-day work without managing roles.
Specialist
Sees their own schedule, groups and attendance.
Finance
Works with payments and payroll without managing the schedule.

Activity log

You can see who made a change and when

For operations that go into the log, the person, the time and the details of the action are stored. That makes it easier to work out a change to a payment, attendance or settings.

Saved log entries cannot be rewritten after the fact. Access to the history depends on the person's permissions in the studio.

Backups

Data copies are stored separately

Backups are encrypted and sent to a separate server. Both creating a backup and restoring from it are tested.

Restore tested during the release on .

Personal data

Export, photos and data deletion

A user with the right permission can export a person's data from their profile. A photo is uploaded after consent is confirmed; images from Telegram are not copied automatically.

Anonymisation removes identifying data from the profile. Financial records, attendance and the change log are kept as a history of operations. A request to export or delete data can be sent to the team; the requester's identity is checked before it is carried out.

Materials for AI

Processing rules come before any file upload

Before AI features are switched on, we will state the provider, how data is transferred, how long materials are kept and how they are deleted.

Uploading a file does not by itself mean that everyone in it has consented to processing. Terms for client and children's data have to be set before the migration starts.

A question about data or a security issue

Write to the team: [email protected]. Include the page and what happened.

Email support