Privacy Notice
This notice explains how ClubiMotion handles personal data. It is written for two audiences: the coaches and club administrators who use the service, and the families whose children's records a club keeps in it. It is deliberately specific — where the service does something, it says so, and where it does not, it says that too.
Last updated — 28 August 2026
Two different roles, and which one applies to you
Most privacy notices assume a single relationship. This one cannot, because the service sits in two different positions depending on whose data is involved. Getting this wrong is the difference between sending a request to someone who can answer it and someone who cannot, so it comes first.
- Your own account. When you register a club, sign in, or manage your user profile, we decide how that data is handled. For that data we are the data controller.
- Athlete records. When your club adds athletes, records attendance or builds training sessions, your club decides what is recorded and why. Your club is the data controller. We act only as a processor under Article 28 GDPR, handling those records on the club's documented instructions.
- Technical records. Server logs and security records generated by running the service are ours, and we are the controller for them.
What this means in practice for a parent or guardian: if you want to know what a club holds about your child, or want it corrected or deleted, address the club. The club is the controller and is the party that answers those requests. We support the club in answering them, but we are not the party your family has a relationship with.
Who we are and how to reach us
ClubiMotion is operated by Andrei Covaliov, a sole trader (autónomo) established in Spain.
For any question about data protection, including a request to exercise your rights, write to [email protected]. We answer at that address; there is no separate form to fill in.
No Data Protection Officer has been designated. The service does not carry out large-scale monitoring of individuals, and it deliberately holds no special-category data, so the conditions in Article 37 GDPR that would make a designation mandatory are not met. If that changes, this notice will name the officer before the change takes effect.
What data is involved
Three groups, matching the three roles above.
- Your account: the club name and, if you provide it, its federation code; your first and last name; your email address; the password you set; and the data-protection contact name and address your club supplies at registration.
- Athlete records: first and last name; date of birth, together with the age and competition category derived from it; gender; and, where the club chooses to record them, an email address and a phone number. Alongside these, squad and group membership, and attendance marked per training session.
- Technical records: server logs that record event codes and internal identifiers — for example an athlete's internal id, or the name of a form field that failed validation. They record the names of fields and not their values, and a sign-in event is recorded without the email address used.
Some categories are deliberately absent, and their absence is a design constraint rather than an oversight. The service holds no national identity number (DNI, NIE or passport), no health or medical information of any kind, no bank or payment details, and no free-text notes about an athlete. There is no field for any of them. A free-text box on a child's record is precisely how special-category data ends up in a column nobody classified, so the service does not offer one.
Why the data is processed, and on what legal basis
Each purpose below is tied to the legal basis it rests on, as Article 13 requires.
- To provide the service to you and your club — creating and running your account, and making the training-management features work. Legal basis: performance of a contract, Article 6(1)(b).
- To keep accounts and data secure — authenticating you, managing sessions, limiting repeated sign-in attempts, and recording who performed sensitive actions. Legal basis: our legitimate interests, Article 6(1)(f). The interest is a concrete one: keeping records about children out of the hands of people who should not reach them.
- To meet our legal obligations, including keeping the accountability and audit records that data protection law requires. Legal basis: Article 6(1)(c).
- For athlete records, the legal basis is your club's to determine and to document, not ours. Depending on how a club is organised it will usually rely on its contract with the family, on its legitimate interest in running training safely, or on consent.
Who else sees the data
The data is not sold, is not used for advertising, and is not used to train machine-learning models. Two categories of recipient exist, both acting on our instructions under contract and neither permitted to use the data for its own purposes.
- Our hosting provider, which runs the application and the database on our behalf inside the European Union.
- An email delivery provider, used to send account messages such as address verification and coach invitations.
There is no analytics provider, no advertising network, no error-tracking service, and no third-party script, font or image loaded from anywhere else. This is a deliberate engineering decision and it is recorded as one: adding any of them would introduce a new recipient of your data, so it is a decision we would have to take openly and disclose here before it took effect.
Where the data is kept
The application and its database run on infrastructure located in the European Union, and the data is not transferred outside the European Economic Area. If that ever changes, a lawful transfer mechanism will be in place and this notice updated before any data moves.
How long it is kept
Different records have different lifetimes, because they answer different obligations.
- Account data is kept while the account exists. When a club closes its account, its data is made available to the club and then deleted or irreversibly anonymised.
- Athlete records are kept while the athlete and the club are active. When an athlete is deleted, the records that belong to them — including their attendance history — are erased or anonymised with them.
- Audit records, which note who performed a sensitive action and when, are kept separately and for longer, because accountability obligations require it. They never contain the content of a personal record.
- Server logs are held by the hosting platform under its own retention window and are operational records rather than a store of personal data.
Your rights, and where to send a request
You have the right to ask for access to your data, to have it corrected, to have it deleted, to restrict how it is used, to object to its use, and to receive it in a portable form. Where processing rests on consent, you may withdraw that consent at any time, and doing so does not affect what was lawful before.
Which address to use depends on whose data the request is about, and this follows directly from the two roles described at the top.
- About your own account: write to [email protected].
- About an athlete's records: write to the club. The club is the controller, decides the outcome, and holds the context needed to answer.
One thing worth saying plainly: during this stage of the service these requests are handled through a documented manual procedure rather than a self-service control. There is no download-my-data button in the application yet. The right is honoured; only the automation is unbuilt, and a request will be answered within the time the law allows.
If you believe your data has been handled improperly you may complain to the Spanish Data Protection Agency, the Agencia Española de Protección de Datos, at www.aepd.es. We would rather you told us first, but the right does not depend on that.
Children's data
The service is not offered to children. Accounts belong to adults acting for a club — an administrator or a coach — and athlete records are entered by the club, never by the athlete.
Under Article 7 of the Spanish data protection act, a person aged 14 or over can consent to the processing of their own data; below that age it is for the holder of parental authority or guardianship to consent. Because your club is the controller for athlete records, obtaining and recording that permission is the club's responsibility, as are its safeguarding duties under Spanish child-protection law. Our agreement with the club requires it.
The design supports that responsibility rather than relying on it alone. The service collects no health information and offers no free-text field on an athlete's record, so a category of data that would demand special protection cannot quietly accumulate in it.
Cookies and information stored in your browser
The application sets only cookies that are strictly necessary for it to function: a session cookie that keeps you signed in, and security cookies that protect the sign-in and registration forms against cross-site request forgery. There are no analytics, advertising or profiling cookies, and no cookie is set by a third party.
Because these cookies are strictly necessary to deliver the service you asked for, Article 22.2 of the Spanish information society services act does not require consent for them. That is why you are not asked to accept cookies and see no cookie banner — not an omission, but the consequence of not setting any cookie that would need one.
The application also keeps a small amount of information in your browser's own storage: which training group you last selected on the calendar and attendance screens, so that choice survives a reload, and a signal that signs you out of other open tabs when you sign out of one. Neither holds personal data or any credential.
How the data is protected
Connections to the service are encrypted in transit. Reaching any club data requires an authenticated session, and every request is authorised on the server against the club and the squads the requester belongs to, so one club's data is never servable to another. Sensitive values are kept out of logs by design rather than by redaction after the fact.
If a personal data breach occurs we are required to notify the Spanish Data Protection Agency within 72 hours where the breach is likely to result in a risk to people's rights, and to inform the people affected where that risk is high. Where your club is the controller, we support the club in meeting that duty and notify the club without undue delay.
Changes to this notice
This notice will be updated when the service changes in a way that affects it. The date shown at the top is the date it last changed. Where a change materially affects how athlete records are handled, club administrators will be told before it takes effect rather than left to notice the new date.
Contact
Questions about this notice, or about anything described in it, go to [email protected].