GolfBox ProPlanner

The processed data

  • The subject matter and duration of processing
    • Members can book individual- and group lessons with a teaching pro. Date and time is registered with the booking as well as payment information if applicable. Members can buy and use value cards for discounts on lessons. ProPlanner might be connected to external databases to be able to search and select members. Data is processed for the duration of 5 years until it is automatically deleted/anonymized. Data with no reference to the member can be processed without any expiry.
  • The nature and purpose of the processing
    • Records of booked lessons and utilization of value cards are processed to give the teaching pro the ability to create income and to offer members the service of improving their golf game, and to optimize future utilization based on statistical data. 
  • The types of personal data
    • GolfBox may process personal data such as member number, name, gender, telephone/mobile, e-mail address, postal address, transaction purchase and amount on behalf of the club / organization.
    • GolfBox does not process any special category or sensitive data such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health or sex life or sexual orientation, civil registration numbers, or data related to criminal records.
  • The category of the data subject
    • Member
  • The physical location (of servers) where personal data is processed
    • GolfBox hosting environment is located within EU/EEA

 

Payment Provider Integration

The processed data with sub-processor

  • The subject matter and duration of processing
    • Collecting payments through different payment providers such as Nets, Paytrail, PayPal, and Payex on behalf of clubs/organizations. GolfBox is transferring personal data to the provider including the amount to pay and receives acknowledgement of received payment back and registers this purchase, such as a tee time, a lesson, and a competition entry, has been payed within each designated module. Data is registered and processed in GolfBox for as long as the payment exists.
  • The nature and purpose of the processing
    • Clubs/organizations can receive payments online for their products offered.
  • The types of personal data
    • GolfBox may process personal data such as member number, name, telephone/mobile, e-mail address, postal addresses, transaction purchase and amount on behalf of the club / organization.
    • GolfBox does not process any special category or sensitive data such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health or sex life or sexual orientation, civil registration numbers, or data related to criminal records.
  • The category of the data subject
    • Member
  • The physical location (of servers) where personal data is processed
    • GolfBox hosting environment is located within EU/EEA

 

Players First integration

The processed data with sub-processor

  • The subject matter and duration of processing
    • Players First offers clubs/organizations a software product which enables the clubs/organizations to conduct surveys and follow up, based on members and activity data. GolfBox provide and transfer data to Players First. Nothing in this regard is registered with GolfBox.
  • The nature and purpose of the processing
    • Clubs/organizations using Players First will receive valuable information about members and guests to improve their product and increase their business.
  • The types of personal data
    • GolfBox may process personal data such as member number, name, gender, telephone/mobile, e-mail address, postal address on behalf of the club / organization.
    • GolfBox does not process any special category or sensitive data such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health or sex life or sexual orientation, civil registration numbers, or data related to criminal records.
  • The category of the data subject
    • Member
  • The physical location (of servers) where personal data is processed
    • GolfBox hosting environment is located within EU/EEA

 

Security measures

The processor is required to ensure a high level of security in its products and services, which is ensured by relevant organizational, technical, and physical security measures required by information on security measures as described in Article 32 of the GDPR.

The processor regularly evaluates the security measures in place for all products and services to ensure they meet industry standards.

Currently the security measures evaluate to these main elements:

  • Data is encrypted in transit via HTTPS and SSL certificates
  • The data importer will use up-to-date virus checking software to assist the prevention and detection of malware or similar damaging code within the data importer’s systems
  • The data importer implements firewalls in a manner that prevents them from being bypassed
  • All individuals hired by or otherwise working for the data importer are assigned unique accounts which must not be shared, and must be kept confidential
  • Individuals are forced to change passwords upon first logging into an account
  • Password configurations are enforced and ensure a minimum level of password integrity
  • Policies ensures leavers will have access permissions promptly revoked
  • Remote access is through secure VPN