Version 2026-09-10
This guide accompanies the privacy notice; it is not an agreement to waive rights or a separate blanket GDPR consent.
- Use the public privacy contact to describe the information or action requested. Never send passwords, private keys or verification codes.
- ClubAffili records the request, checks identity proportionately, identifies the responsible controller and routes any tenant-specific part appropriately.
- Access and export requests must avoid disclosing another person's or another tenant's information.
- Correction, erasure, restriction and objection requests are assessed against the relevant processing and legal obligations. Any refusal or extension needs a reason and complaint route.
- Marketing withdrawals must reach the actual sending systems and queued campaigns. A policy update must preserve the withdrawal.
- Account closure and retention are separate: explain any records kept, why, and for how long.
- An incident involving personal information is escalated immediately to the privacy/security owner. The operator assesses notification duties, including GDPR's 72-hour supervisory-authority deadline where applicable and notification to affected people where required.
The operator must maintain a processing register, retention schedule, processor agreements, transfer assessment where required, rights-request log and incident process. A DPIA or legitimate-interest assessment is completed where appropriate. Documents alone do not establish compliance.