Keep each organisation in its own lane.
We can walk your technical reviewer through the way organisation boundaries are designed, how access fails safely and how cross-organisation access is tested.
Clubs hold personal information and make decisions that affect real people. We explain how YourZown approaches access, consent and accountability. We are clear about what is live, what is improving and what evidence is available.
We keep the marketing language plain, then go deeper with your IT lead, DPO or safeguarding owner when the organisation needs technical detail and supporting evidence.
We can walk your technical reviewer through the way organisation boundaries are designed, how access fails safely and how cross-organisation access is tested.
Sign-in, account recovery, administrator access and volunteer handovers belong in the same conversation. We explain which methods are live and how access is removed when a role ends.
We distinguish protection in transit, at rest and at field level, then explain key management, backups and role-based access without using ‘encrypted’ as a catch-all answer.
We can show what happens when consent is missing, how its state is recorded, how withdrawal behaves and where the club’s own legal responsibility begins.
We can show what is recorded, who can see it, how records are protected from casual alteration and which sensitive values are deliberately kept out of the audit view.
We’ll make exports, deletion and retention responsibilities clear, including the exceptions that apply to financial or safeguarding records.
YourZown does not currently claim ISO 27001 or SOC 2 certification. We share the architecture, testing, incident-response and sub-processor information available for your review.
We provide the current hosting region, sub-processors and relevant transfer information during your security and data-protection review.
Organisation boundaries are a critical part of the platform. We can explain how access is separated and share the testing evidence available for your review.
We will walk your treasurer through the payment provider, settlement route, responsibilities and fees before payments are enabled.
We can show the available export and deletion workflows, including the cases where legal retention duties or a person’s relationship with another organisation affect what can be removed immediately.
Not currently. We would rather say that plainly and share the architecture, testing, incident-response and sub-processor information that is relevant to your review.
Book a walkthrough and bring the questions that matter to your organisation.