Purpose and legal status
Phoenix Utd CIC is an active Community Interest Company, company number 11027177. Its registered office is Office 1 Izabella House, 24–26 Regent Place, Birmingham, B1 3NJ. References to “PUCIC”, “we”, “us” and “our” in these documents mean Phoenix Utd CIC.
This public Data Processing Agreement policy sets the minimum operational terms PUCIC expects when it acts as a processor for another organisation or appoints a processor to handle personal data. It is not a substitute for a signed, transaction-specific data processing agreement.
Processing instructions and confidentiality
Personal data must be processed only on documented instructions, unless law requires otherwise. People authorised to process data must be subject to confidentiality duties and receive appropriate training. Processing purposes, categories, duration, data subjects and instructions must be specified in the relevant signed schedule.
Security and sub-processors
| Provider | Role in the PUCIC service | Current or planned use |
|---|---|---|
| Manus | Website hosting, application infrastructure and analytics | Website operation and aggregated site measurement |
| Microsoft 365 | Organisational email | Microsoft 365 is not used for the initial attachment-free referral workflow. |
| Mailchimp | Newsletter processor | Email-only double-opt-in newsletter when activated |
| Google Maps | Visitor-requested map service | Map panel is loaded only after a visitor requests it |
| Cloudflare | Web-security and delivery services | Where enabled for PUCIC web delivery |
Processors must use appropriate technical and organisational measures, restrict access, assist with security assessment and obtain written authorisation before appointing a new sub-processor where required. PUCIC must be told of material sub-processor changes in sufficient time to assess them.
Rights requests, incidents and assistance
Processors must promptly support PUCIC with data-subject rights requests, impact assessments, audits and relevant regulatory enquiries. A personal-data incident must be reported to PUCIC without undue delay, with enough information for PUCIC to assess the incident and meet its own obligations.
Return, deletion and audit
At the end of a service, personal data must be returned or deleted as agreed, unless retention is required by law. For PUCIC secure referrals, the approved period is 24 months before deletion. The initial workflow is attachment-free: it removes the encrypted referral record and its audit trail after the retention period. Any unexpected historic attachment record blocks automated deletion for documented manual physical-deletion review. Relevant compliance records must be available for reasonable audit.
