La confianza empieza por la transparencia.
TeamFeePay está hecho para las personas que gestionan clubes de fútbol de base — y para la confianza que depositan en nosotros con los datos de sus socios. Explora nuestras certificaciones, prácticas de seguridad y los controles que protegen tus datos.
Explora nuestra postura de confianza
Cada control que operamos, mapeado a los estándares que importan a tu equipo.
Security practices
How we protect the platform, our people, and the data clubs entrust to us.
Data protection
Encryption, key management, retention, and how we handle data subject rights.
Identity & access
Authentication, MFA, RBAC, and how we manage access to systems and customer data.
Infrastructure
Where the service runs, how it is hardened, and how we maintain availability.
Privacy
GDPR, ISO 27018 cloud privacy controls, and how we minimise personal data.
Incident response
How we detect, contain, and communicate security incidents — and the SLAs we hold.
Actualizaciones recientes
Lo último de nuestros equipos de seguridad y cumplimiento.
Incident response programme
Severity tiers, SLAs, and how we communicate incidents to customers.
International data transfers
How we manage cross-border transfers under UK and EU rules.
Our role under UK GDPR
Where we act as a processor, where we act as a controller, and what that means.
Data retention and deletion
Defaults, customer overrides, and how we honour deletion requests.
Preguntas frecuentes
Respuestas rápidas a las preguntas más comunes de seguridad y compras.
How do I request your SOC-style report or pen-test summary?
Visit the Compliance page and click the document you need. You'll be asked to provide your business email and accept a short NDA — after that the download is immediate and stored against your visitor record for re-download.
Where is customer data stored?
All production data is stored in UK and EU regions on tier-1 cloud providers. We do not store production data outside of the UK/EEA.
Are you GDPR compliant?
Yes. We process personal data in line with UK GDPR and the Data Protection Act 2018. ISO/IEC 27018 governs our handling of personal data in cloud environments.
How do you handle cardholder data?
We are a PCI DSS Level 2 service provider and minimise the cardholder data we ever see by routing card capture directly to our PSP. The platform itself stores only token references.