Sub-processors
The third-party services ClubHelix relies on to deliver the platform, what each one does, and the personal data it handles on our behalf.
Last updated: 8 June 2026
This platform is operated by ClubHelix (“we”, “us”). To run a reliable, secure platform we use a small set of trusted third-party providers. Under data-protection law these are our sub-processors: services that process personal data on our instructions and on your behalf when you or your members use a ClubHelix site.
We choose providers that offer strong security and a data-processing agreement, share only the data each one needs to do its job, and keep the list below current. Every provider’s own privacy or data-processing terms — including their full legal entity name and data-residency commitments — are linked from their name.
Current sub-processors
- What it does
- Runs the ClubHelix application, serves every page over its global edge network, and provisions tenants’ custom domains.
- Personal data processed
- IP address, request metadata, and any content submitted through the site while it is being served.
- What it does
- Primary managed Postgres database, user authentication, and storage for uploaded files such as logos and gallery images.
- Personal data processed
- Account and member records, authentication credentials and sessions, and uploaded files.
- What it does
- Processes subscription billing for clubs and, where enabled, member registration and shop payments, including invoicing and tax handling.
- Personal data processed
- Name, email, billing address, payment-method/card details, and transaction history.
- What it does
- Sends transactional email (sign-in, receipts, notifications) and member broadcasts, with per-tenant DKIM signing.
- Personal data processed
- Recipient name and email address, and the content of the message sent.
- What it does
- Turnstile bot/abuse protection on public forms, and R2 object storage holding off-site backups of platform data.
- Personal data processed
- IP address and browser/device signals (Turnstile); backup copies of database content and files (R2).
- What it does
- Captures application errors and performance traces so we can diagnose and fix faults.
- Personal data processed
- IP address, account/user identifiers, and diagnostic metadata attached to errors.
- What it does
- Stores and indexes application logs for debugging, security and auditing.
- Personal data processed
- Request metadata and any account identifiers that appear in log lines.
- What it does
- Schedules and runs background workflows such as notifications, email fan-out and recurring maintenance tasks.
- Personal data processed
- Job payloads that may contain account and member identifiers.
- What it does
- Optional “Sign in with Google” authentication, and Google Search Console registration for paid tenants’ verified custom domains (search indexing).
- Personal data processed
- For sign-in: your Google email and basic profile. For Search Console: public site URLs and sitemaps only.
- What it does
- Powers the optional “Helix Assistant” editor, which generates site content and theme suggestions when an admin asks for them.
- Personal data processed
- The prompt and page/theme text an administrator chooses to submit to the assistant.
Web push notifications
If a member opts in to push notifications, their browser or device delivers those messages through the push service operated by their browser or operating-system vendor (for example Google, Apple or Mozilla). We sign and send messages to whichever endpoint the member’s own browser provides; we don’t choose that vendor and only send a message when there is something to notify.
Tenant-provided integrations
Some features only send data to a provider when a club’s administrators enable them — for example connecting their own payment payouts or embedding third-party content. Where a club configures such an integration, that provider acts as a sub-processor for that club’s data, in addition to the platform-wide list above.
Changes & how to object
This list may change as the platform evolves. When we add or replace a sub-processor we will update this page. If you have a data-processing agreement with us that entitles you to advance notice of changes, we will provide it as agreed. To ask a question, request details, or object to a particular sub-processor, contact us at security@clubhelix.au.