1. Two different roles we play
This matters, because your rights depend on which applies.
| Situation | Who decides how data is used | Our role |
|---|---|---|
| You contact us, or you are a customer of ours | We do | Controller |
| You are a player, parent or student whose details sit in an academy's system | The academy does | Processor, acting on the academy's instructions |
If you are a player or a parent and you want your records changed or deleted, contact your academy, not us. They control that data. We will help them act on your request, but we cannot act on it without them.
2. Data we hold as controller
About our own customers and enquirers:
- Contact details — name, business name, email, phone, country. Used to answer enquiries and provide the service. Lawful basis: contract, or legitimate interest in responding to you.
- Billing details — invoices, amounts, payment references. Lawful basis: contract and legal obligation (tax records).
- Support correspondence — emails you send us. Lawful basis: legitimate interest in running a support service.
- Server logs for our marketing site — IP address, page, timestamp, user agent. Lawful basis: legitimate interest in security and in knowing the site works.
We do not sell this data, and we do not share it for advertising.
3. Data we process for academies
Academy records are held in one database in which every row is tagged with the academy it belongs to, and the database refuses to return, change or delete a row belonging to anyone else — the check sits in the database, not in the application above it. We process what an academy puts in, which typically includes:
- Student name, date of birth, level, and notes the coach writes
- Parent or guardian email and phone number
- Attendance records, including whether a session was held, rained off or cancelled
- Prepaid lesson balances and expiry dates
- Invoices and payment status
- Booking requests submitted through the academy's public booking page — name, email, phone, chosen slot and any message
We process this only on the academy's instructions. We do not use it for our own purposes, do not sell it, do not use it for advertising, and do not use it to train machine learning models.
4. Children's data
Coaching academies teach children, so most records in the system relate to a child. We treat this as the most sensitive thing we handle.
- The academy is the controller and is responsible for obtaining consent from a parent or guardian where the law requires it.
- Our public booking page asks for a player's name and a contact email. It is designed to be completed by a parent or guardian, and says so.
- We do not knowingly collect data directly from children for our own purposes, and our marketing site is not directed at children.
- The system does not profile children, does not target advertising at them, and has no social features.
- Academies should not record health, medical or other special category data without taking their own advice.
- If a coach uses the optional drafting tool to help write a reply, a child’s first name and what they wrote in their own check-in are sent to Anthropic to produce that draft. No surname, contact details or records are sent, the draft is not stored, and a coach reads and sends every message themselves. A coach who never presses that button sends nothing there at all.
Because the academy is the controller, it is the academy — not us — that must meet the rules where it operates: COPPA in the United States for children under 13, and the age of digital consent in the EU and UK, which varies between 13 and 16 depending on the country. We build for parental consent by default, but we cannot give an academy legal advice about its own obligations.
5. Sub-processors and hosting
We use a small number of providers. We do not add one without updating this list.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database and authentication | Canada (AWS ca-central-1) |
| Vercel | Hosting and delivery of the panel, booking and check-in pages, and the functions that send email | Global edge network; company established in the United States |
| Resend | Sending transactional email, such as booking notifications | Company established in the United States |
| Anthropic | Writes message drafts when a coach presses “Draft”. It is sent a player’s first name only, what that person wrote in their own check-in, and what the coach says they want to get across — never a surname, an email address, a phone number, a date of birth, an attendance record or an invoice. Drafts are returned to the coach’s screen and are not stored by us. Nothing is sent to anyone until the coach reads it and presses send. No data is sent to Anthropic unless a coach presses that button. | Company established in the United States |
Each is bound by its own data processing terms. We will give customers at least 30 days' notice before adding or replacing a sub-processor, so they can object.
jsDelivr was removed from this list on 30 August 2026. It is a content delivery network, and until then it served the Supabase JavaScript library our pages load in your browser — which meant it received your IP address and browser version. It never received an academy record. That library is now served from this site, so the request never leaves us. Removing a sub-processor needs no notice; we are saying it here because a list of who sees your data is only worth anything if it is current in both directions.
6. Where data is stored
We create each academy's database in the region closest to them, so a South African academy's records need not sit in the United States. Tell us your preferred region at setup and we will use it where the provider offers one.
Where personal data is transferred out of the UK, the EEA or another region with transfer restrictions, we rely on the transfer terms in each provider's own data processing agreement, which we have accepted with each of them.
7. How we protect it
- Separation is enforced below the application. Academies share one database, and every row carries the academy it belongs to. Whether a row can be read, changed or deleted is decided by a Postgres row level security policy rather than by a filter in our own code, so a mistake in the application above cannot widen it.
- Row level security is enabled on every table. An unauthenticated visitor can read published booking slots and submit a booking request, and nothing else. They cannot read a single student record, invoice, or anyone else's booking.
- Privileged keys stay on the server. Service role keys live only in server-side environment variables and are never included in a page sent to a browser.
- Traffic is encrypted in transit with TLS. Data is encrypted at rest by our hosting providers.
- Text submitted by the public is escaped before display, so a booking cannot inject content into a coach's panel.
- Access to customer databases by our staff is limited to what is needed to set up or support an instance.
8. How long we keep it
| Data | Kept for |
|---|---|
| Academy records, while a subscription is active | As long as the academy keeps them |
| Academy records, after termination | Available for export for 30 days, deleted from live systems then, and from backups within 90 days |
| Our billing and tax records | 7 years, as tax law requires |
| Enquiries that do not become customers | 24 months |
| Marketing site server logs | 90 days |
9. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent.
- If you are a player or parent: contact your academy. They control your records. Every academy can export or delete a student's data themselves from within the panel.
- If you are our customer or enquirer: contact us at the address below. We will respond within one month.
You can complain to your data protection regulator — for example the ICO in the UK, your national authority in the EEA, the Information Regulator in South Africa, or NDPC in Nigeria.
10. Cookies and tracking
Our marketing site sets no cookies and runs no analytics, advertising or third-party tracking scripts. That is why you were not shown a cookie banner. Since 30 August 2026 there is no third party your browser contacts at all — the one library the pages need in order to run is served from this site, not from a content delivery network. We load no fonts, scripts or images from anyone else.
An academy's panel uses local storage to keep you signed in and to queue writes made while offline. That is necessary for the service to work.
If we ever add analytics we will say so here first, and ask for consent where the law requires it.
11. Breach notification
If we become aware of a personal data breach affecting academy records we will notify that academy without undue delay and in any event within 72 hours, with what we know, what we are doing, and what they may need to tell their regulator or their families. As controller, the academy is responsible for notifying its regulator and the people affected.
12. Changes
We will update this policy when what we do changes. Material changes are notified to customers by email at least 30 days before they take effect. The version and date at the top always reflect the current text.
13. Contact
Sleek&Tech System Ltd · RC 9771734 · Nigeria
Privacy enquiries: info@sleektechsport.com
We have a Data Protection Officer, registered with the Nigeria Data Protection Commission. Anything about how your data is handled — a request, a complaint, or a question you would rather put to them directly — reaches them at info@sleektechsport.com.