Sport99/Data Processing Agreement

Data Processing Agreement

Version 1.0Effective September 5, 2026

When a club, federation or other organisation uses Sport99 to manage its athletes, that organisation decides why and how the data is processed — it is the controller. Inovitus 9 d.o.o. processes the data on its behalf, as processor. Article 28 of the GDPR requires that relationship to be governed by a written contract. This is that contract. It is accepted at club registration, forms part of the Terms of Service, and applies for as long as the organisation uses Sport99.

1. Parties and roles

The controller is the club, federation or organisation that holds the Sport99 subscription and whose administrator accepted these terms. The processor is Inovitus 9 d.o.o., Slovenia, operating the Sport99 platform. Where an individual athlete holds their own Sport99 account outside any club, Inovitus 9 is the controller for that account and this agreement does not apply to it — the Privacy Policy governs instead.

2. Subject matter and duration

The subject matter is the processing of personal data necessary to provide the Sport99 platform to the controller: athlete and staff administration, training planning, attendance, performance and workload records, communications, wearable data ingestion, AI-assisted analysis, and billing. Processing lasts for the term of the subscription, plus the retention windows set out in section 11.

3. Processing only on instructions

We process personal data only on the controller's documented instructions, including for transfers to a third country, unless EU or Slovenian law requires otherwise — in which case we will tell the controller before processing, unless that law prohibits the notification.

The controller's configuration of the platform, its use of the features, and this agreement together constitute the documented instructions. If we consider an instruction to infringe the GDPR or other EU or Member State data protection law, we will tell the controller without delay and may suspend that instruction until it is resolved.

4. Confidentiality

Everyone we authorise to process personal data under this agreement is bound by a written confidentiality obligation or an appropriate statutory duty of confidence, which survives the end of their engagement. Access is granted on a need-to-know basis, reviewed periodically, and revoked when a role changes. Access to health records and medical notes requires elevated authorisation and is logged for audit.

5. Security of processing

We implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the cost of implementation, and the risk to data subjects — which is elevated here because the platform processes health data about children. The measures in force are listed in Annex II. We may update them, but not in a way that materially lowers the level of protection.

6. Sub-processors

The controller gives general written authorisation for the sub-processors listed in Annex III. We remain fully liable to the controller for their performance, and impose on each of them data protection obligations no less protective than those in this agreement. We will give the controller at least 30 days' notice before adding or replacing a sub-processor. The controller may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the controller may terminate the affected part of the subscription without penalty and receive a pro-rata refund.

7. International transfers

All personal data processed through Sport99 is stored in the European Union. We do not transfer personal data outside the European Economic Area except where a sub-processor listed in Annex III does so under an approved transfer mechanism — Standard Contractual Clauses, an adequacy decision, or the EU-US Data Privacy Framework — together with any supplementary measures the transfer assessment identifies. We will inform the controller before any new category of transfer begins.

8. Assisting with data subject rights

The platform gives the controller self-service tools for access, export, rectification, restriction and erasure, and these are the primary route for handling a request. Where a data subject contacts us directly, we will not respond on the controller's behalf; we will forward the request to the controller without undue delay and tell the data subject we have done so. Where a request cannot be satisfied through the self-service tools, we will assist by appropriate technical and organisational measures, taking into account the nature of the processing.

9. Personal data breaches

We will notify the controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the controller's data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — supplemented in phases where the full picture is not yet available. We will not notify the supervisory authority or data subjects on the controller's behalf unless the controller instructs us to.

10. Impact assessments and prior consultation

Because the platform processes special-category health data about minors on a significant scale, a data protection impact assessment is likely to be required of the controller under Article 35. We will provide the information reasonably needed to complete one — including the descriptions in Annexes I and II, our security posture, and our sub-processor arrangements — and will assist with any prior consultation with a supervisory authority that follows.

11. Return and deletion

On termination, the controller may export its data through the platform's export tools for 30 days. After that window, we delete the controller's personal data from active systems and, within a further 90 days, from backups, except where EU or Slovenian law requires continued storage — in particular billing records, which accounting law requires us to keep for 7 years, and consent records, which we retain as proof of compliance. We will confirm deletion in writing on request.

12. Audits and demonstrating compliance

We will make available to the controller the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the controller or an auditor it mandates. Audits are limited to once in any 12-month period unless a breach or a supervisory authority requires otherwise, must be requested with 30 days' notice, must not unreasonably disrupt the service or compromise the confidentiality of other controllers' data, and are at the controller's cost. We may satisfy an audit request by providing a current third-party assessment or security documentation where that reasonably answers the questions asked.

13. Liability and precedence

Each party is liable for its own compliance with the GDPR in its own role. The liability provisions of the Terms of Service apply to this agreement, except that nothing limits either party's liability to a data subject under Article 82. Where this agreement conflicts with the Terms of Service or the Privacy Policy on a matter of data protection, this agreement prevails. Where it conflicts with mandatory law, the law prevails and the rest of this agreement stands.

Annex I — Description of the processing

Categories of data subjects: athletes (including minors), parents and guardians, coaches and technical staff, club administrators, medical and physiotherapy staff where the club grants them access, and visitors or prospective members using front-desk features.

  • Identity and contact data: name, email address, phone number, date of birth, profile photograph, club and squad affiliation, role.
  • Training and performance data: attendance, sessions, workloads, benchmarks, test results, coach notes, competition results, GPS and movement tracks.
  • Special category data under Article 9: injury records, medical and physiotherapy notes, mental wellbeing check-ins, nutrition entries, and biometric measurements imported from wearable devices — heart rate and variability, sleep, recovery and readiness scores.
  • Guardian and safeguarding data: guardian identity and contact details, consent records, and the age-related access restrictions derived from them.
  • Financial data: membership fees, invoices, payment status and VAT identifiers. Card details are handled by Stripe and never stored by us.
  • Technical data: authentication events, IP address, device and browser information, audit logs.
  • Nature and purpose: collection, recording, organisation, structuring, storage, retrieval, consultation, analysis (including AI-assisted analysis), disclosure to authorised club users, restriction, erasure and destruction — for the purpose of operating a sports club's athlete management, training planning and administration.
  • Duration: for the term of the subscription plus the retention periods in section 11.

Annex II — Technical and organisational measures

  • Data residency: all personal data stored and processed within the European Union (Microsoft Azure, Sweden Central).
  • Tenant isolation: multi-tenant row-level security, with every query scoped to the requesting tenant and enforced below the application layer.
  • Encryption: TLS for data in transit; encryption at rest for databases, backups and file storage.
  • Access control: role-based access, least privilege, mandatory multi-factor authentication for all accounts, and elevated authorisation with audit logging for health and medical records.
  • Special category safeguards: health data processed only against a recorded explicit consent, with automatic redaction of health content before AI processing where consent is absent.
  • AI scope limitation: AI features operate only on the requesting athlete's data and the requesting club's tenant; wearable and health data is never used for advertising, profiling, or for training models across other clubs or customers.
  • Logging and monitoring: authentication and administrative action audit logs, anomaly and rate-limit monitoring, and alerting on privileged access.
  • Resilience: automated backups with tested restoration, and infrastructure redundancy within the EU region.
  • Personnel: confidentiality undertakings, access review on role change, and prompt revocation on departure.
  • Secure development: code review, dependency scanning, and separation of production from development environments.

Annex III — Approved sub-processors

The controller authorises the following sub-processors. The current list is maintained here and in the Privacy Policy; changes follow the notice procedure in section 6.

  • Microsoft Ireland Operations Ltd (Microsoft Azure) — cloud infrastructure, database hosting and AI inference. European Union.
  • Stripe Payments Europe Ltd — payment processing and invoicing. EU servers with data residency enabled; Standard Contractual Clauses and/or the EU-US Data Privacy Framework for any non-EU transfer.
  • Microsoft Ireland Operations Ltd (Azure Communication Services) — transactional and multi-factor authentication email delivery. European Union.
  • Wearable and fitness providers connected by an athlete's own choice — Garmin, Apple Health, Fitbit and Google Fit, Whoop, Polar, Strava, Suunto — act as independent controllers for their own services; Sport99 receives data from them on the athlete's instruction and does not send personal data back to them.

Contact

Questions about these terms, audit requests, or a signed counterpart on your own paper: legal@sport99.ai

Trust & Compliance

Built for athletes.
Engineered for governance.

🇪🇺

EU hosted

Sweden Central · GDPR by design

🛡

GDPR · Art. 9

Health-data consent, athlete-grade privacy

🏛

Slovenian SaaS

Inovitus 9 d.o.o. · EU-VAT compliant

🧠

Governed AI

Content safety, prompt-shielded, EU-processed

🔐

Multi-tenant RLS

Row-level isolation, MFA enforced

🌍

14 languages

EN · SL · SV · DE · ES · FR · IT · PL · NL · FI · JA · KO · ZH