Privacy Policy
How Membrio handles personal data for clubs and their members, under the GDPR/AVG.
Membrio is a platform that clubs and associations use to communicate with their members and manage their membership administration. This policy explains what personal data we process, why, on what legal basis, and the rights you have.
Who is responsible for your data
Membrio is used by clubs to manage their own members.
- Your club is the data controller. It decides which member data it collects and why. Questions about your own membership record should go to your club.
- Membrio operates the platform as a data processor on behalf of each club, and only processes member data on the club’s documented instructions. A data-processing agreement governs this processing.
- For account data of the people who administer a club (name, email used to sign in), and for this website, Membrio acts as controller.
What data we process
What a club records about its members is chosen by the club. Membrio stores the following:
| Category | What it can include | Purpose |
|---|---|---|
| Account & sign-in | Email address, a hashed password, sign-in counts, sign-in timestamps and IP addresses, session data, and notification preferences | Sign-in and security |
| Two-factor authentication | Your 2FA secret and recovery codes, once you turn 2FA on | Protecting accounts |
| Member records | Per member a club records: first and last name, initials, gender, date of birth, email, phone number, postal address (street, postcode, town), a member number, and membership dates and history | Club administration |
| Groups & labels | The groups a member belongs to and any custom labels the club defines and applies | Club administration |
| Guests | Name and email of non-member contacts a club adds (for example a parent or guardian) | Club communication |
| Communication content | Messages, events (title, description, location, time), polls, and members’ poll responses | Club communication |
| Member imports | An uploaded membership list (its file name and rows) while the club imports it | Onboarding a club |
| Push tokens | Firebase Cloud Messaging (FCM) device token and platform (iOS/Android) | Push notifications |
| Calendar feed | A private token in your personal calendar (iCal) subscription link | Calendar subscriptions |
| Technical data | Minimal server logs (IP address, timestamp, error traces) and in-app notification records | Security and reliability |
The app does not store payment card or bank account details. We do not use advertising trackers, we do not sell personal data, and we do not use member data for advertising or profiling.
Children and young members
Clubs often have junior members, so a club may store personal data about people under 16 in Membrio, including a date of birth. Your club is the controller for that data: it decides whether to record it and is responsible for the legal basis, including obtaining consent from a parent or guardian where the law requires it. Membrio processes this data on the club’s instructions.
Additional information your club may store
A club decides what it records about its members within the fields Membrio offers. If your club records additional or sensitive information (for example an emergency contact, or health details relevant to an activity), your club is the controller for that information and decides whether recording it is necessary and lawful and who may see it. Membrio processes it on the club’s behalf.
Cookies
Membrio uses a session cookie that is strictly necessary to keep you signed in. This website additionally stores your language and theme preference in your browser. No analytics or advertising cookies are set.
Why we process it and the legal basis
- Performing the service (Art. 6(1)(b) GDPR): running the club platform, delivering messages, polls and events, and maintaining member records on the club’s behalf.
- Legitimate interests (Art. 6(1)(f) GDPR): keeping the platform secure and reliable (e.g. 2FA, minimal logging).
- Legal obligation (Art. 6(1)(c) GDPR): where we must retain limited data to comply with the law.
Push notifications
To deliver push notifications to the mobile apps, we register a device token with Firebase Cloud Messaging (Google) and send the notification content through that service. You can turn push notifications off in your device settings, which removes the token.
Sub-processors
We use a small number of carefully selected providers to run the service. Each is bound by a data-processing agreement.
| Sub-processor | Purpose | Region |
|---|---|---|
| Scalingo | Application hosting and database | EU |
| Lettermint | Transactional email (e.g. sign-in and notifications) | EU |
| Firebase Cloud Messaging (Google) | Push notification delivery | Global (Google); EU Standard Contractual Clauses |
Who at Membrio can access your data
Authorised Membrio staff can access club data only when it is necessary, for example for technical support, troubleshooting, maintenance or security. Access is limited to authorised people and is subject to confidentiality. Where reasonably possible, development and analysis use anonymised or pseudonymised data rather than live member data.
Security
We apply appropriate technical and organisational measures to protect personal data, including:
- encrypted connections (TLS/HTTPS) for data in transit;
- passwords stored only as salted hashes, and optional two-factor authentication;
- role-based access controls, so administrators only reach the members they manage;
- hosting within the EU with access controls and monitoring;
- regular security updates, and backups for recovery.
For security reasons we do not publish detailed information about our security infrastructure.
Data breaches
You can report a suspected security incident to security@membrio.eu. When an incident concerns personal data we process on a club’s behalf, we inform the club without undue delay after becoming aware of it. As the controller, the club assesses whether it must notify its supervisory authority and the people affected.
How long we keep data
- Member records are kept for as long as the club uses Membrio, and are deleted or returned on the club’s instruction or when the club stops using the service.
- Account data is kept while the account is active.
- Push tokens are removed when a device unregisters or is inactive.
- Member imports are kept only as long as needed to complete the import.
- Technical logs are kept only briefly for security and troubleshooting.
- Backups: after data is deleted from the active service it may remain in routine backups for a limited period before those backups are overwritten.
Exact retention periods are set by your club and can be confirmed with us: member records are deleted within 30 days after a club stops using Membrio.
Where your data is stored
Your Membrio data is stored and processed on services hosted in the European Union. The application and its database run on Scalingo in the EU, and transactional email is handled by Lettermint, whose infrastructure is entirely within the EU.
The one exception is push notifications. To deliver them we use Google Firebase Cloud Messaging (FCM), which does not offer an EU-only region, so a device token and the notification content pass through Google’s global infrastructure. This transfer relies on Google’s data-processing terms and the EU Standard Contractual Clauses. You can avoid it entirely by turning push notifications off on your device.
Anonymised and aggregate data
We may anonymise data so that individual people and clubs can no longer be identified from it, and use that anonymised data to improve the product, for statistics, capacity planning and technical quality. Anonymised data is not used to build commercial profiles of members.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. Because your club is the controller of your member record, please direct these requests to your club; we will support the club in fulfilling them. For account or website data, contact us directly.
You also have the right to lodge a complaint with your supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens.
Contact
For privacy questions or to exercise your rights, contact us at info@membrio.eu, or by post at Nieuwendijk 41, 8131 CD Wijhe, Netherlands.
Changes to this policy
We may update this policy as the service, the providers we use, or the applicable rules change. Material changes will be announced in the app or by email where appropriate. The date above shows when this policy was last updated.