ClubTitanProductFor clubsFor coachesFor parentsPricingSwitching?AboutSign inGet started
‹ Safeguarding & trust

Our compliance register

The official standard for each area of how we run the platform — and where we honestly stand. We link the real source every time, and we never mark something done before it is.

Corporate filingsplanned

Confirmation statement at least annually (14-day filing window); accounts to Companies House within 9 months of year end (first accounts 21 months from incorporation); CT600 within 12 months and corporation tax paid 9 months + 1 day. ECCTA: registered email, lawful-purpose statement, and director identity verification by the first confirmation statement after 18 November 2025.

gov.uk — life of a company: annual requirements
Tax & VATplanned

Monitor rolling 12-month taxable turnover against the £90,000 registration threshold (frozen through 2026/27) — the platform-fee revenue model makes this computable from our own billing ledger. Corporation tax dates are tracked under corporate filings.

gov.uk — register for VAT
ICO & data protectionplanned

Commercial controller — no exemption: tier 1 fee £52/yr (tiers £52/£78/£3,763 since 17 February 2025), renewal date tracked. DPIA genuinely complete before the first real child's data (launch-gating). ROPA and retention schedule maintained; 72-hour breach plan rehearsed; fractional DPO appointed around first real data; cookie banner and privacy notice aligned with the post-DUAA position.

ICO — data protection fee
Children's Codeplanned

Conformance checklist held as a CI/review gate: high-privacy defaults, no geolocation, no nudge techniques, guardian-owned child accounts. Reviewed quarterly and on any feature touching children's data.

ICO — Children's code guidance and resources
Online Safety Actplanned

Club messaging makes ClubTitan a regulated user-to-user service regardless of size. Pre-launch gate: illegal content risk assessment (a new service has three months from launch), children's access assessment and children's risk assessment, a content-reporting route, duties reflected in terms of service — then keep assessments current on change.

Ofcom — illegal content duties under the Online Safety Act
Safeguardingplanned

DSL named and trained (Paul initially) with training currency tracked; safeguarding policy review date; concern-report SLA metrics from the built machinery; the closed-loop comms invariants' pgTAP seals staying green in CI.

The FA — safeguarding
Payments & PCIplanned

Hosted checkout (web) + native PaymentSheet (mobile) keeps us at SAQ A — completed annually in the Stripe dashboard. The January 2025 SAQ A revision's script-attack eligibility criterion applies to embedded forms, not full redirects; moving web to inline Elements requires answering CSP/SRI first. Webhook signature verification and reconcile-to-payout checks stay green; funds are never pooled.

Stripe — security and PCI
App store programmesplanned

Apple: US$99/yr org membership (D-U-N-S verified), agreement re-acceptances gate releases, privacy nutrition labels truthful per submission, EU DSA trader status published. Google Play: US$25 one-time org account, Data safety form accurate, account deletion in-app plus a web deletion link, annual target-API-level updates.

Apple — EU DSA trader requirements
Processor DPAs & assuranceplanned

Per processor: signed DPA on file, region/transfer mechanism recorded, assurance report date tracked — Supabase (ISO 27001, SOC 2), Vercel (ISO 27001, SOC 2, PCI AoCs), Stripe (PCI DSS Level 1, SOC 2, ISO 27001), plus Railway, Resend, Meta/WhatsApp and Anthropic on the same pattern. Our own published sub-processor list stays current with a 30-day change-notice commitment to clubs.

Stripe — data processing agreement
Cyber security & certificationsplanned

The staged ladder: Cyber Essentials now (~£320–£600 +VAT, includes £25k cyber-liability cover) → CE Plus at the first school/council buyer → ISO 27001 only on written procurement demand → SOC 2 only for US. Annual independent pen test from launch; secrets rotation via the secwatch register; backup restore test date tracked.

NCSC — Cyber Essentials
Insuranceplanned

Employer's liability from the first employee (legal requirement); professional indemnity as the negligent-misstatement backstop for the club compliance screen; cyber cover (Cyber Essentials bundles a £25k starter layer).

gov.uk — employer's liability insurance
Comms & PECRplanned

Soft opt-in plus tokenised no-login unsubscribe in every marketing send — a domain invariant, CI-checked in the comms layer. The DUAA raised maximum PECR fines to UK GDPR levels (£17.5m or 4% of global turnover); cookie posture aligned with the DUAA low-risk analytics exemptions.

ICO — direct marketing and PECR