SailHQ Security

Security for UK clubs

SailHQ Security

SailHQ uses UK hosting, encrypted traffic, hashed passwords, access controls and automatic backups to protect club data.

Last updated 20 August 2026

HTTPS

Encrypted in transit

UK hosted

Primary app and database

Local privacy

UK GDPR and Data Protection Act 2018

Backups

Regular and automatic

See how the platform protects data

Security starts with a small set of controls. Each one is easy to explain and check.

UK hosting

The SailHQ app and database run in the UK. This location is the same for every region. The host is SiteGround.

A UK host does not prove legal compliance. Each club must check the privacy rules for its members and data.

Encrypted traffic and hashed passwords

Production traffic uses HTTPS. Passwords are hashed. We do not store them as plain text. Secure sessions protect signed-in users.

Access based on club roles

Each club sets roles for admins, committees, race teams and members. Each role only sees the areas it needs.

Automatic backups

The host takes regular automatic backups. They can help recovery after faults, mistakes or data loss.

UK GDPR and Data Protection Act 2018

Use SailHQ within your UK privacy process

Your club decides why member data is used. SailHQ provides the controls and records that support your club, but the software does not replace its UK data protection duties.

Meet UK data protection duties

UK clubs must handle personal data under the UK GDPR and Data Protection Act 2018. The ICO has guidance for small clubs and membership organisations.

Read official privacy guidance

What the club still controls

  • Which member details it collects and why.
  • Who can view, change, export or delete records.
  • How long it keeps data after membership ends.
  • How it handles requests, complaints and breach notices.

Member privacy

Limit who sees each detail

Club roles control member records. Profile settings add another layer for contact details.

Phone visible to committee
Email visible to other members
Address visible to admins
Date of birth visible to members

Example settings. Club permissions still set the final access level.

Respond to incidents in a fixed order

Clear facts help the club make the right local report.
  1. 1 Identify the issue and stop further loss.
  2. 2 Check which systems, clubs and records are affected.
  3. 3 Tell affected clubs without undue delay.
  4. 4 Give each club the facts needed for its local reporting decision.
  5. 5 Fix the cause and record the work completed.

Local notification rule

If a breach is likely to risk people's rights and freedoms, the club must notify the ICO without undue delay and, where feasible, within 72 hours.

Read Information Commissioner's Office guidance
Checked country guidance

Keep RYA and club records connected.

The RYA sets national sailing guidance. Each committee still owns its local rules, people and evidence.

Keep RYA affiliation details current.

The RYA is the UK national governing body for sailing and boating. Affiliated clubs can use its club support, training and technical guidance.

What the club record should hold.

Record the affiliation owner, renewal date and the RYA contact used for each club decision.

Open the official source

Meet UK data protection duties.

UK clubs must handle personal data under the UK GDPR and Data Protection Act 2018. The ICO has guidance for small clubs and membership organisations.

What the club record should hold.

Record the lawful purpose, access owner, retention decision and member request history for each data set.

Open the official source

Set a clear safeguarding policy.

The RYA recommends an appropriate safeguarding policy for affiliated organisations with children, young people or adults at risk.

What the club record should hold.

Keep the policy owner, review date, welfare contact and training evidence beside the relevant club roles.

Open the official source

Ask a direct security question

Tell us which control, data flow or club process you need to check.