Home
Clubium Logo
Home / Legal Center

Global Master Services Agreement

Comprehensive legal framework governing Clubium NexGen Hub's ecosystem of AI-driven platforms, including binding data stewardship, zero-retention privacy architecture, AML/KYC enforcement, and platform-specific operational protocols.

Legally Binding Master Framework

Governing Clubium NexGen Hub and all affiliated AI verticals.

Effective:
Last Review:

1. Absolute Privacy & Zero Data Exploitation Architecture

Governed by Article 5(1)(e) GDPR, CCPA §1798.100, and LGPD Art. 16

1.1 Stateless Processing & Immediate Data Expungement

The Clubium NexGen Hub ecosystem operates on a constitutionally protected "Privacy by Design" mandate. We strictly DO NOT archive, replicate, or warehouse any Personally Identifiable Information (PII) beyond the immediate transactional millisecond. All data processed through AI WhatsApp CRM, Medical Booking Platforms, Smart Menus, and Clubium Biz is transitory. Upon successful delivery to the merchant's encrypted local environment, all intermediary data packets are irreversibly purged within 100ms from all cloud caches, logs, and backups.

1.2 Strict Prohibition of Commercial Data Monetization

Clubium explicitly and contractually prohibits any commercialization, data-mining, algorithmic brokering, selling, licensing, or renting of merchant business intelligence or end-consumer data. We do not construct shadow profiles, engage in cross-device tracking, nor feed behavioral data into any third-party advertising network. Your proprietary data remains your exclusive intellectual property.

2. Granular Consent Management & Cookie Integrity

GDPR Art. 7 & ePrivacy Directive 2009/136/EC

Clubium enforces a stringent "Deny by Default" cookie and tracking policy across all domains. Absolutely no non-essential cookies, analytics pixels, device fingerprinting scripts, or tracking beacons are executed without explicit, proactive, and freely given consent.

Functional cookies strictly necessary for authenticated sessions within Clubium Biz Dashboards are heavily encrypted (AES-256), uniquely ephemeral, and programmatically configured to undergo automatic cryptographic self-destruction upon session termination or 60 minutes of inactivity.

⚖️ Legal Note: Consent logs are retained for 12 months as legally required by GDPR Art. 7(1) to demonstrate compliance, but these logs contain only hashed, non-identifiable references — never PII or browsing behavior.

3. Multi-Jurisdictional Compliance Matrix

GDPR | CCPA/CPRA | HIPAA | LGPD | PIPEDA | PDPA | APPI

Our enterprise-grade platforms are architected to satisfy the most rigorous data protection regimes globally:

US

Americas Compliance

  • CCPA & CPRA (California)
  • HIPAA (Health Insurance Portability)
  • PIPEDA (Canada)
EU

Europe & UK

  • GDPR (Regulation EU 2016/679)
  • Data Protection Act 2018 (UK)
  • Digital Markets Act (DMA)
AS

Asia-Pacific & MENA

  • PDPA (Singapore) & PDP Bill (India)
  • APPI (Japan) & PIPA (South Korea)
  • UAE Federal Decree-Law No. 45/2021

4. Financial Integrity: AML, CTF & Anti-Corruption

FATF Recommendations | Bank Secrecy Act | FCPA | UK Bribery Act 2010

4.1 Transaction Monitoring & KYC

All financial transactions processed via integrated payment gateways and Android POS Loyalty systems are subject to real-time AI-driven scrutiny. Suspected money laundering or terrorist financing activities are immediately reported to FinCEN or equivalent local financial intelligence authorities within 24 hours as mandated by law.

4.2 Zero-Tolerance Anti-Bribery (FCPA)

Clubium maintains a rigorously audited zero-tolerance policy toward corruption and bribery. We operate in full compliance with the US Foreign Corrupt Practices Act (FCPA) and the UK Bribery Act 2010. Merchants engaging in corrupt practices will face immediate termination of all software licenses and referral to prosecutorial authorities.

5. Ecosystem Integrity & Platform Mandates

Enforceable across Clubium Biz, Travel, POS, Smart Menu, Medical

To preserve a pristine, fraud-free digital environment matching the operational gold standards of industry giants (Yelp, Groupon, OpenTable), the following provisions apply:

AI WhatsApp CRM

Strict adherence to Meta's Business Messaging Policy. Spam or deceptive marketing triggers instant API key revocation.

Travel & Tourism

Algorithmic manipulation of ratings or offering financial incentives for positive reviews constitutes fraudulent business practice.

Android POS Loyalty

Merchants are legally obligated to honor all valid cashback points and digital rewards accrued by consumers.

Medical & Spa Booking

Clinics must uphold patient confidentiality. Unauthorized export of patient CRM records triggers immediate lockdown and forensic audit.

6. Limitation of Liability & Force Majeure

EXCLUSION OF CONSEQUENTIAL DAMAGES

LIMITATION OF LIABILITY: TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER CLUBIUM, ITS AFFILIATES, NOR LICENSORS SHALL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, ARISING FROM OR RELATING TO USE OF THE PLATFORMS.

While Clubium guarantees a 99.9% uptime SLA for Core Products, we shall not be liable for service interruptions caused by External API provider outages (Meta, Google Cloud, Stripe), Hardware failures on merchant endpoints, or Force majeure events.

This Master Services Agreement constitutes the entire and exclusive agreement between Merchant and Clubium NexGen Hub with respect to the Platforms and supersedes all prior agreements.

Legal & Compliance

Need clarification on compliance?

Our dedicated legal compliance team is available 24/7. Reach out to ensure your enterprise AI deployment meets all local and global operational standards securely.

Contact Legal
  • ISO 27001 Certified

  • Enterprise SLAs