EvolixSport EvolixSport
БГ EN DE NL
Back to home
Terms of Service Privacy Policy Data Protection (GDPR)

Data Protection (GDPR)

Version 2.0 · Last updated: 5 September 2026

In brief. This document is intended for the clubs and federations that use EvolixSport and for all individuals whose data is processed in the platform. It defines the roles under the GDPR, contains the data processing agreement under Art. 28 GDPR, the current list of sub-processors, the technical and organizational measures, the breach procedure and the way in which every data subject can exercise their rights. How we process data as a controller for our own activities is described in the Privacy Policy.

1. Roles under the GDPR

ActivityRole of EvolixSportRole of the club / federation
Website, registration and management of customer accounts, contracts and subscriptions, invoicing, security, support, partner program, marketingcontroller-
Data of athletes, parents, coaches, referees and officials entered in Evolix Club or Evolix Federation; training sessions, tests, registration, licenses, medical certificates, disciplinary proceedings, club financesprocessor under Art. 28 GDPRcontroller
DimAI: analyses and recommendations based on the data of the club or federationprocessor; the language model provider is a sub-processorcontroller: decides whether and for what purposes DimAI is used
Aggregated, anonymized statistics about the platformcontroller-

2. Data processing agreement (Art. 28 GDPR)

This section constitutes a personal data processing agreement between the Customer (controller) and EvolixSport (processor) and forms an integral part of the Terms of Service. Customers who wish to receive a signed copy or have specific requirements may write to us at office@evolixsport.com.

2.1. Subject matter, duration, nature and purpose

The subject matter of the processing is the provision of the EvolixSport platform as a service. The processing continues for the term of the contract and for the period under clause 2.6 after its termination. The nature of the processing includes collection, storage, structuring, retrieval, consultation, analysis, transmission within the platform, restriction and erasure. The purpose is the management of the Customer's sports activities: administration of athletes and staff, training sessions, tests, competitions, licensing, financial and document management, and support through DimAI.

2.2. Types of data and categories of data subjects

The categories of data and data subjects are described in Section 4 of the Privacy Policy. Special categories of data (health data, wellness self-assessments) are processed only to the extent that the Customer decides to enter them and ensures a legal basis under Art. 9(2) GDPR. Children's data is processed in accordance with Section 7 of the Privacy Policy.

2.3. Obligations of the processor

EvolixSport:

  • processes the data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required to do so by law, in which case it informs the Customer in advance to the extent permitted by law; instructions are given through the settings and features of the platform and in writing;
  • informs the Customer immediately if, in its opinion, an instruction infringes the GDPR or other applicable law;
  • ensures that persons with access to the data have committed themselves to confidentiality and have been trained;
  • implements the security measures under Section 5 and updates them in accordance with the risk;
  • engages sub-processors only under the conditions of Section 3;
  • assists the Customer with appropriate technical and organizational measures in fulfilling data subject requests under Chapter III of the GDPR, including through the export, rectification and erasure features in the platform, and forwards requests received within 5 business days;
  • assists the Customer with regard to the security of processing, breach notification, data protection impact assessments and prior consultation with the supervisory authority;
  • makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR and allows for audits, including on-site inspections, conducted by the Customer or an auditor mandated by the Customer, on reasonable notice (at least 30 days, except in the event of an incident), no more than once a year and subject to the confidentiality of other customers;
  • maintains a record of the categories of processing activities carried out on behalf of the Customer.

2.4. Obligations of the Customer

The Customer is responsible for the lawfulness of the data and instructions, for informing the data subjects, for the existence of a legal basis, including parental consent and a basis under Art. 9 GDPR, for the accuracy of the data, for managing user roles and access within its organization, and for deciding whether and how it uses DimAI.

2.5. Security breaches

EvolixSport notifies the Customer without undue delay, and as a rule within 48 hours, after becoming aware of a security breach affecting the Customer's data, providing the available information on the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences and the measures taken. Notification of the supervisory authority and of the affected data subjects is the obligation of the Customer as controller; EvolixSport provides assistance.

2.6. Deletion and return

After termination of the contract, the Customer may export its data in a structured, machine-readable format within 90 days. After this period, EvolixSport deletes or anonymizes the data, including in backups at their next cycle, except to the extent that EU or member state law requires retention. Upon request, EvolixSport confirms the deletion in writing.

3. Sub-processors

The Customer gives general authorization for the use of the following sub-processors (processors under Art. 28(2) GDPR). A contract imposing the same data protection obligations is in place with each of them.

Sub-processorActivityCountryTransfer mechanism
Hetzner Online GmbHHosting of the applications and databases, file storage, backupsGermany (EU)within the EEA – not required
Groq, Inc.Language model for DimAI (chat assistant, analyses and recommendations). Receives text prompts only; data is not used for model trainingUnited StatesEU Standard Contractual Clauses (Art. 46 GDPR) and/or EU-US Data Privacy Framework

Planned sub-processor (not yet active): Stripe Payments Europe, Ltd. (Ireland (EU)) – Processing of online payments and subscriptions. Payment card data is processed by Stripe only. It will be added to the list at least 30 days before activation.

We notify Customers of any intended change, namely the addition or replacement of a sub-processor, at least 30 days in advance through the platform or by email. The Customer may object within this period on reasonable grounds relating to data protection; if no solution is found, the Customer may terminate the contract for the affected service without penalty. The current version of the list is always published on this page.

4. International transfers

Data is stored and processed in the European Union (data center in Germany). The only transfer outside the European Economic Area is the transmission of text queries to the provider of the language model for DimAI in the USA. It is based on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR and, where the provider is certified, on the EU-US Data Privacy Framework. Supplementary measures: only the necessary text data is transmitted, without contact, payment or medical data, photos or videos; names are pseudonymized in the federation module; the connection is encrypted; the provider is contractually restricted from using the data for training and from retaining it after processing. A Customer that does not wish any transfer to take place may choose not to activate DimAI for its organization. A copy of the applicable safeguards is provided upon request.

5. Technical and organizational measures

AreaMeasures
EncryptionHTTPS/TLS for all connections; encryption at rest of special categories of data, access codes and sessions in the federation module; passwords stored only as a hash (Argon2id); backups on secured infrastructure in the EU
Access controlrole-based model with least-privilege permissions (administrator, coach, athlete, parent, referee, official); logical separation of each customer's data; the parent portal grants access only to the data of the respective child; temporary, time-limited PIN codes for match officials
Authentication and sessionssessions with limited duration and secure cookies (HttpOnly, Secure, SameSite); rate limiting and temporary lockout after repeated failed login attempts; two-factor verification for the operator's administrative access; separate, hidden administration panel
Traceabilitysecurity logs (logins, lockouts, administrative actions) and logs of access to sensitive data in the federation module; retained for 12 months
Application securityprotection against CSRF, XSS and SQL injection; sanitization of input data and uploaded files; restrictions on file types and sizes; security HTTP headers; periodic security reviews and remediation of vulnerabilities
Availability and recoveryregular automatic backups; recovery procedure; separate production and development environments; no real personal data in test environments
Organizational measurescontractual confidentiality; need-to-know principle; incident procedure and breach register; register of data subject requests; access reviews; data protection and AI literacy training
DimAIminimization of transmitted data; pseudonymization; no training at the provider; request log (metadata); ability to deactivate the module for an individual customer; human oversight of the results

6. Security breaches: procedure

  1. Reports are received at support@evolixsport.com and registered immediately.
  2. The moment of awareness is determined and the 72-hour period under Art. 33 GDPR begins.
  3. Technical containment is carried out: blocking of affected accounts, suspension of the affected module or integration (each module, including DimAI, can be stopped independently), preservation of evidence and logs.
  4. The risk to the rights and freedoms of the affected data subjects is assessed.
  5. The affected Customers are notified (under clause 2.5) and, where EvolixSport is the controller, the Bulgarian Commission for Personal Data Protection (CPDP) within 72 hours and the affected data subjects without undue delay if a high risk is likely.
  6. A root cause analysis is carried out and corrective measures are tracked. All breaches, including those not subject to notification, are documented.

7. Rights of data subjects: how to exercise them

Every data subject has the rights under Art. 15-22 GDPR: access, rectification, erasure, restriction, portability, objection, withdrawal of consent and safeguards in relation to automated decision-making.

  • Self-service: registered users can download all of their data in a machine-readable format (JSON) and submit an erasure request from their profile. Parents can view and manage their child's data through the parent portal.
  • By email: office@evolixsport.com. State who you are, which club or federation the request relates to and what you are requesting. We may ask for proportionate verification of identity, for example confirmation from the registered email address, without collecting unnecessary data.
  • Timeframe: a response without undue delay and, as a rule, within one month; for complex or numerous requests, an extension of up to two months, of which you will be informed. Requests are free of charge, except for manifestly unfounded or excessive requests.
  • Where your club or federation is the controller: we forward the request to it within 5 business days and assist it; the final decision is its own. You may also contact the organization directly.
  • Erasure: erasure requests are fulfilled within 30 days after confirmation by the controller, unless the law requires retention; upon request, we confirm the deletion or anonymization carried out.
  • Objection to a DimAI result: you may request human review of any recommendation or assessment; the review is carried out by a competent person of the Customer with our assistance and is documented.
  • Complaint: to the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, cpdp.bg, or to the supervisory authority in your place of residence in the EU, without prejudice to the right to a judicial remedy.

We keep a register of the requests received and the decisions made on them.

8. Children and parents

A child's profile is created by the club or by a parent/legal representative. For a child under 14 years of age, where the legal basis is consent, it is given by a parent or guardian. The parent obtains access only through an invitation with a code issued by the club and sees only the data of their own child, including test results, attendance, self-assessments and, if the club has entered them, training restrictions. In the event of a dispute over parental rights, the club, as controller, decides who is granted access; we follow its instructions. Children's data is not used for advertising, commercial profiling or model training.

9. DimAI and the AI Act (Regulation (EU) 2024/1689)

  • Classification: DimAI is a general-purpose artificial intelligence system used for sports analyses and recommendations. It does not fall within the prohibited practices under Art. 5 of the AI Act and is not used for high-risk purposes under Annex III (e.g. decisions on access to education, employment or the evaluation of individuals with significant consequences). The assessment is reviewed for every new feature.
  • Role: EvolixSport is a deployer of a general-purpose language model from an external provider and the provider of the DimAI application that uses it.
  • Transparency (Art. 50 AI Act): users are informed that they are interacting with artificial intelligence; automatically generated content is labeled as such.
  • Human oversight: the results are supporting information; decisions are made by a competent person who can reject the recommendation.
  • Prohibited uses: no emotion recognition, social scoring, biometric identification or manipulative techniques are performed.
  • AI literacy (Art. 4 AI Act): our team and the Customers' administrators receive information and guidance on the capabilities, limitations and risks of DimAI.
  • Incidents: errors, complaints and incidents related to DimAI are registered and analyzed; any Customer may request deactivation of the module for its organization.

10. Impact assessment and accountability

We maintain a record of processing activities under Art. 30 GDPR. For the processing of children's data, health data and the use of DimAI, a data protection impact assessment under Art. 35 GDPR is carried out and periodically updated. New features affecting these categories are released after an assessment and, where necessary, after consultation with the supervisory authority.

11. Retention and deletion

The retention periods by category are set out in Section 13 of the Privacy Policy. Deletion covers the database and the file storage; backups are overwritten within their cycle. For data for which the Customer is the controller, the periods are determined by the Customer and applied through the deletion and anonymization features in the platform.

12. Contact

Legal nameEvolixSport – to be provided in the next update of this document
Company registration numberto be provided in the next update of this document
Registered addressto be provided in the next update of this document
Represented byto be provided in the next update of this document
Privacy e-mailoffice@evolixsport.com
Support e-mailsupport@evolixsport.com
Data Protection Officernot appointed (not mandatory for the operator); requests are handled via the e-mail above

This document is current as of the date indicated at the top and is reviewed upon every change of sub-processor, transfer, security measure or AI feature.

© 2026 EvolixSport · Terms of Service · Privacy Policy