GDPR compliance
How SailHQ handles personal data, what your rights are, and how to exercise them.
GDPR aligned from day one
SailHQ has been built around UK GDPR requirements, so the tooling needed to meet your obligations is part of the platform - not an afterthought.
The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 set the rules for processing personal data. SailHQ provides the tools sailing clubs need to meet those rules and gives members clear rights over their own data.
Our role under GDPR
Data processor
When a sailing club uses SailHQ to manage its members' data, SailHQ acts as a data processor. That means:
- We process personal data on behalf of the sailing club
- We follow the instructions provided by the club (the data controller)
- We implement appropriate technical and organisational measures
- We help clubs meet their own GDPR obligations
Data controller
For account registration and billing, SailHQ acts as a data controller. That covers:
- Club admin contact information
- Billing and payment details
- Account settings and preferences
- Support requests and email correspondence
The controller is HQ Software Ltd, registered in England and Wales under company number 17341989, trading as SailHQ. Registered office: 128 City Road, London, EC1V 2NX, United Kingdom.
Lawful basis for processing
Personal data is processed on one of the following lawful bases:
Contract performance
Processing necessary to provide SailHQ under the subscription agreement.
Legitimate interests
Processing for service improvement, security, debugging, and fraud prevention.
Legal obligations
Processing required to meet legal or regulatory obligations.
Consent
For optional communications such as product newsletters, where you've explicitly opted in.
Data minimisation
SailHQ collects only what's needed to run a sailing club - typically name, email, contact details, membership category, and information related to duties and events. We don't track members across the web, don't run advertising profiling, and don't sell data to third parties.
Member rights
Under UK GDPR, members have the following rights over their personal data:
Right of access
Request a copy of the personal data held about you.
Right to rectification
Have inaccurate or incomplete data corrected.
Right to erasure
Request deletion of your personal data, subject to legal retention requirements.
Right to portability
Receive your data in a portable, machine-readable format.
Right to object
Object to certain types of processing.
Right to restrict
Restrict how we process your data while a query is being resolved.
How to exercise your rights: Email support@sailhq.app with the subject "GDPR Request" and the type of request. We will respond within 30 days.
Data retention
We retain data only for as long as necessary:
Active accounts
Member and club data is retained for the lifetime of your subscription.
Cancelled accounts
Data is retained for 90 days after cancellation, then securely deleted - giving you time to export or to change your mind.
Legal requirements
Some financial records are retained for the period required by UK law (typically 6 years).
Hosting and data residency
SailHQ servers are located in the United Kingdom. We do not transfer member data to non-UK jurisdictions for routine operation. Where any sub-processor is involved (for example, transactional email), we ensure appropriate safeguards are in place.
Contact our data protection team
For any GDPR-related question, data request, or concern:
Email: support@sailhq.app
Subject line: "GDPR Request - [Your Request Type]"
Response time: Within 30 days (as required by UK GDPR)
Supervisory authority: You can also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you're not satisfied with our response.