Privacy Policy

Version 1.0 · Last updated [DATE]
Not yet legal advice. A working draft for review. Complete every highlighted field and have a qualified data protection lawyer review it before publishing. This is more important here than on most sites: the system holds children's names, dates of birth and parents' contact details, and it operates in countries covered by the GDPR, the UK GDPR, POPIA (South Africa), the NDPR (Nigeria), Egypt's PDPL, Kenya's Data Protection Act and others. Rules on children's data differ between them.

1. Two different roles we play

This matters, because your rights depend on which applies.

SituationWho decides how data is usedOur role
You contact us, or you are a customer of ours We do Controller
You are a player, parent or student whose details sit in an academy's system The academy does Processor, acting on the academy's instructions

If you are a player or a parent and you want your records changed or deleted, contact your academy, not us. They control that data. We will help them act on your request, but we cannot act on it without them.

2. Data we hold as controller

About our own customers and enquirers:

We do not sell this data, and we do not share it for advertising.

3. Data we process for academies

Each academy gets its own separate database. We process what they put into it, which typically includes:

We process this only on the academy's instructions. We do not use it for our own purposes, do not sell it, do not use it for advertising, and do not use it to train machine learning models.

4. Children's data

Coaching academies teach children, so most records in the system relate to a child. We treat this as the most sensitive thing we handle.

[If you will have customers in the United States, take advice on COPPA. If in the EU or UK, confirm your position on the age of digital consent, which varies between 13 and 16 by member state.]

5. Sub-processors and hosting

We use a small number of providers. We do not add one without updating this list.

ProviderWhat it doesWhere
Supabase Database and authentication for each academy's instance Region chosen per customer
Netlify Hosting and delivery of the panel and booking page Global edge network
Resend Sending transactional email, such as booking notifications [confirm region]

Each is bound by its own data processing terms. We will give customers at least [30] days' notice before adding or replacing a sub-processor, so they can object.

6. Where data is stored

We create each academy's database in the region closest to them, so a South African academy's records need not sit in the United States. Tell us your preferred region at setup and we will use it where the provider offers one.

Where personal data is transferred out of the UK, the EEA or another region with transfer restrictions, we rely on [Standard Contractual Clauses / UK IDTA / adequacy — confirm which applies to you].

7. How we protect it

8. How long we keep it

DataKept for
Academy records, while a subscription is activeAs long as the academy keeps them
Academy records, after terminationAvailable for export for [30] days, deleted from live systems then, and from backups within [90] days
Our billing and tax records[6-7] years, as tax law requires
Enquiries that do not become customers[24] months
Marketing site server logs[90] days

9. Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent.

You can complain to your data protection regulator — for example the ICO in the UK, your national authority in the EEA, the Information Regulator in South Africa, or NDPC in Nigeria.

10. Cookies and tracking

Our marketing site sets no cookies and runs no analytics, advertising or third-party tracking scripts. That is why you were not shown a cookie banner. The demos store their sample data in your browser's local storage so your changes survive a refresh; it never leaves your device and the Reset button clears it.

An academy's panel uses local storage to keep you signed in and to queue writes made while offline. That is necessary for the service to work.

[If you later add analytics, this section must change and you will probably need a consent banner in the EU and UK.]

11. Breach notification

If we become aware of a personal data breach affecting an academy's instance we will notify that academy without undue delay and in any event within [72] hours, with what we know, what we are doing, and what they may need to tell their regulator or their families. As controller, the academy is responsible for notifying its regulator and the people affected.

12. Changes

We will update this policy when what we do changes. Material changes are notified to customers by email at least [30] days before they take effect. The version and date at the top always reflect the current text.

13. Contact

[REGISTERED COMPANY NAME]
[REGISTERED ADDRESS]
Privacy enquiries: sleektechsport@gmail.com
+1 346 5100 7207
[Data Protection Officer and EU/UK representative, if you are required to appoint one]