EvolixSport EvolixSport
БГ EN DE NL
Back to home
Terms of Service Privacy Policy Data Protection (GDPR)

Privacy Policy

Version 2.0 · Last updated: 5 September 2026

In brief. EvolixSport is a platform for managing sports clubs and federations. When a club or federation enters data about its athletes, coaches, parents and officials, the organization is the controller of that data and we process it on its behalf (as a processor under Art. 28 GDPR). For our own activities (website, customer accounts, invoicing, security and support) we are the controller. We do not sell personal data, we do not display advertising and we do not use children's data for profiling or advertising. Data is stored in the European Union. The only provider outside the EU is the language model that powers the DimAI assistant, and only text queries are sent to it.

1. Subject matter and scope

This policy explains how personal data is processed when visiting and using the website evolixsport.com, the Evolix Club platform (https://club.evolixsport.com), Evolix Federation (https://fed.evolixsport.com), the parent portal, the mobile and related interfaces, the application programming interfaces (APIs), the support, payment and communication systems, as well as the artificial intelligence features designated as DimAI.

The policy applies to athletes, including minors, parents and legal representatives, coaches, employees and representatives of clubs and federations, referees and officials, medical and other professionals, website visitors, prospective customers, partners in the partner program and all other users.

Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR), the Bulgarian Personal Data Protection Act and the applicable provisions of the AI Act (Regulation (EU) 2024/1689, the Artificial Intelligence Act).

2. Who processes the personal data

2.1. Controller for EvolixSport's own activities

The controller of personal data for the operation of the website, the registration and management of customer accounts, contracts and subscriptions, payments, security, support, the partner program, marketing and the development of the service is:

Legal nameEvolixSport – to be provided in the next update of this document
Company registration numberto be provided in the next update of this document
Registered addressto be provided in the next update of this document
Represented byto be provided in the next update of this document
Privacy e-mailoffice@evolixsport.com
Support e-mailsupport@evolixsport.com
Data Protection Officernot appointed (not mandatory for the operator); requests are handled via the e-mail above

2.2. Processing on behalf of clubs and federations

Where a club, academy or federation ("Customer") determines which individuals are registered, which sports, registration, medical, financial or other data is entered and for what purposes it is used, the Customer is the controller and EvolixSport processes the data on its behalf under a contract pursuant to Art. 28 GDPR. The terms of that agreement are published in the Data Protection (GDPR) section.

The Customer is obliged to provide its own information to the data subjects and to ensure an appropriate legal basis, including parental consent where necessary. EvolixSport does not substitute for these obligations. Where EvolixSport determines its own purposes, for example security, invoicing, prevention of abuse or product development, its role is determined separately for the respective activity.

If EvolixSport and a sports organization jointly determine the purposes and essential means of a given processing operation, an arrangement under Art. 26 GDPR is concluded and its essence is made available to the data subjects.

3. Core principles

Data is processed lawfully, fairly and transparently; for specific, explicitly stated purposes; to the minimum extent necessary; accurately and kept up to date; for a limited period; with appropriate security; and with documented accountability. The use of data for incompatible purposes, or the entry of sensitive information into an artificial intelligence module without a predetermined legal basis, necessity and safeguards, is not permitted.

4. Categories of personal data

Depending on the modules used and on what the Customer has decided to enter, the following categories may be processed:

  • Identification and registration data: names, date of birth, gender, nationality (federation module only), profile photo, internal identifier, license number or registration number. EvolixSport does not collect the Bulgarian personal identification number (EGN) or copies of identity documents; athletes are identified by an internal code.
  • Contact data: email, telephone, address, emergency contact (for athletes), preferred language.
  • Data of a parent or legal representative: names, email, telephone, relationship to the child, a record that parental consent has been given and its date.
  • Club and federation affiliation: club, team, age group, position, jersey number, licenses and registration, transfers, participations, referee appointments and assessments, disciplinary proceedings and decisions (federation module only).
  • Sports data: training sessions, attendance, match and tournament results, statistics, results of physical and cognitive tests, skill assessments, goals, achievements and activity points.
  • Physical measurements: height, weight, VO₂max, heart rate, time, speed and other measurements from tests (Beep, Yo-Yo, Cooper, sprint, strength, flexibility, etc.).
  • Wellness self-assessments: responses in wellness questionnaires and the training diary (sleep, fatigue, training load, muscle soreness, energy, mood). Because they may reveal information about health, we treat them as data under Art. 9 GDPR.
  • Health data: only where a specific module collects it: in the federation module, medical fitness certificates (number, date of examination, validity period, physician and medical institution, fitness conclusion, restrictions and, if recorded, diagnosis) and insurance policies; in the club module, "injured" status and the coach's notes on restrictions. They are entered only by authorized persons of the Customer; in the federation module they are encrypted at rest.
  • Photos, videos and extracted features: profile photos; media files of the federation; video recordings uploaded by a coach or athlete for movement analysis, and the body key points (pose) extracted from them. No facial, voice or emotion recognition is performed. Audio recordings are not currently processed.
  • Financial and contractual data: plan and access status; membership fees and charges that the club records for its own purposes. EvolixSport does not currently offer paid plans and does not collect payment data. When paid plans are introduced, full payment card data will be processed only by a licensed payment provider and will never reach our servers; this policy will be updated in advance.
  • Communications: support requests, in-system messages, notifications and feedback.
  • Technical data: IP address, browser and device type, login time, session identifier, security logs (failed login attempts, lockouts) and logs of actions in the system.
  • Data related to DimAI: questions to the assistant, the sports context used, the generated responses, analyses and recommendations, as well as request metadata (type, duration, token count, the first 200 characters of the message) for security and accounting purposes.
  • Partner data: when participating in the partner program: names, email, telephone, referral code, completed referrals and commissions.
  • Electronic signature and authentication data: in the federation module: names, role, time and technical data when match protocols are signed electronically; temporary PIN codes for officials. To prove the integrity of a protocol, only a cryptographic hash that contains no personal data may be published in a distributed ledger.
  • Cookies: only strictly necessary cookies in accordance with Section 15.

5. Sources of the data

Data may be provided by the data subject themselves, by a parent or legal representative, by the club, academy or federation (coach, administrator, authorized professional), generated through the use of the platform (results, statistics, logs), received from a connected club or federation system as part of a requested integration, or derived through the analysis of authorized video recordings and statistical data.

Data is not imported from public or third-party sources merely because it is technically accessible. For each source, the lawfulness, quality and right of use are documented.

6. Purposes and legal bases

PurposeLegal basis
Registration, access and management of a profile and customer accountArt. 6(1)(b) GDPR: contract or steps prior to entering into a contract; for profiles entered by the Customer, the legal basis is determined by the Customer
Training sessions, attendance, tournaments, licensing, registration and sports statisticscontract, legal obligation or legitimate interest depending on the specific role; for children, a separate assessment of the best interests of the child is made
Physical tests, self-assessments and sports recommendationscontract or legitimate interest; where the information reveals a health condition, explicit consent under Art. 9(2)(a) GDPR, obtained by the Customer
Health and medical data (medical certificates, insurance, restrictions)explicit consent under Art. 9(2)(a) GDPR or another applicable basis under Art. 9(2), determined and documented by the Customer as controller (e.g. compliance with regulatory requirements for admission to competitions)
Photos and videos for sports analysiscontract, legitimate interest or consent depending on the context, expectations and risk; for publication for promotional purposes, separate consent
DimAI analyses and general recommendationsthe legal basis follows the purpose and the input data; artificial intelligence does not constitute an independent legal basis
Invoicing and accounting (once paid plans are introduced)Art. 6(1)(c) GDPR: legal obligation; Art. 6(1)(b): contract
Security, prevention of fraud and abuse, protection of rightsArt. 6(1)(f) GDPR: legitimate interest following a balancing test
Support and communicationcontract, legitimate interest or consent depending on the request
Partner programArt. 6(1)(b) GDPR: contract with the partner
Electronic marketingconsent where required by law; existing customers are informed only within the limits permitted by law and with an easy opt-out

7. Children's data

EvolixSport is also designed for sports clubs and academies, which is why the processing of children's data is a foreseeable core activity. Enhanced transparency, data minimization, restricted access and privacy-by-default settings apply.

  • Where the provision of a service directly to a child is based on consent, for a child under 14 years of age the consent is given or authorized by a parent or guardian in accordance with Bulgarian law. Identity and representative authority are verified in a proportionate manner.
  • A child's profile is created by the Customer (a coach or club administrator) or by a parent/legal representative. The parent obtains access to the child's data through the parent portal only after an invitation with a code issued by the club, and sees only the data of the respective child.
  • Where the legal basis is a contract, a legal obligation or the legitimate interest of the organization, formal consent is not collected merely as a token safeguard.
  • Children's data is not used for behavioral advertising, commercial profiling or model training. The publication of photos and videos of children for promotional purposes or on social media is regulated separately from participation in sports activities and requires a separate legal basis.
  • Upon reaching the age of majority, the athlete may take control of their profile, and the parent's access is terminated at the athlete's request or at the request of the Customer.

8. Photos, video and video analysis

Photos and video recordings may be processed for sports analysis, tactical preparation, statistics, match reporting, security or communication only if the purpose has been determined in advance and the individuals have been informed. For each feature, the type of recording, the scope, access, retention period, download options and the consequences of refusal are defined.

The video analysis module extracts body key points (pose and movement) from the recording in order to assess technique and load. The automatic extraction of body and movement features is not biometric identification: the system does not aim to uniquely recognize a face and does not compare faces or voices between recordings. If a biometric identification feature is planned in the future, it will not be activated without a separate legal analysis, an impact assessment and an applicable legal basis under Art. 9 GDPR.

Video analysis is performed on our infrastructure in the EU. Video files are not currently sent to external providers. If we activate an external provider for video analysis, it will be added to the list of sub-processors before activation.

9. Use of artificial intelligence: DimAI

9.1. Transparency

Before any direct interaction, the user is clearly informed that they are communicating with an artificial intelligence system and not with a human. DimAI provides general sports, tactical, conditioning and informational recommendations. They do not replace a physician, psychologist, physiotherapist, coach, referee or other qualified person. Content generated by artificial intelligence (for example automatic match reports or articles) is labeled as such where required by the AI Act.

9.2. Input data and provider

DimAI uses an external language model provided by Groq, Inc. (United States). Only the text data necessary for the specific request is transmitted to the provider: the user's question and sports context, for example the name or initials of an athlete, age group, position, test results, attendance, self-assessments and statistics. In the federation module, names are pseudonymized before transmission. Contact data, payment data, medical documents, photos and videos are not transmitted. Under the provider's applicable terms, requests are not used to train or improve its models and are not retained by it after the request has been processed, except for a short period for security purposes. The current list of providers and transfer mechanisms is set out in Sections 11 and 12.

Before activating a new AI module, we document the exact input and output data, the purpose, the logic of the analysis, the known limitations, the human oversight and the categories of data subjects affected.

9.3. Limitations and human oversight

Users must not enter medical diagnoses, psychological assessments, identity documents or other sensitive data into DimAI, unless the specific module has been expressly approved for their processing and the interface provides the corresponding information.

DimAI output is treated as supporting information. Decisions concerning health, training load, selection, licensing, disciplinary measures, contracts, participation or exclusion are made by a competent person who can verify the sources and reject the recommendation.

EvolixSport does not use artificial intelligence for emotion recognition, social scoring, manipulative techniques or other prohibited practices under Art. 5 of the AI Act. If a feature falling within the scope of high-risk systems is developed, it will not be released without a new legal and technical assessment.

9.4. Accuracy and objections

Artificial intelligence may generate incomplete, inaccurate or inappropriate information. Any user may request human review, contest a result and report a problem at office@evolixsport.com. Material errors and the corrective actions taken are documented.

10. Automated decision-making and profiling

EvolixSport does not make decisions based solely on automated processing which produce legal effects concerning the data subject or similarly significantly affect them. Sports assessments and DimAI recommendations are subject to meaningful human review by a coach or another competent person. If such decision-making is introduced, the policy will be updated before its activation with information about the logic involved, the significance and the envisaged consequences; the right to human intervention, to express one's point of view and to contest the decision will be guaranteed; and an impact assessment will be carried out.

11. Recipients and processors

Access to personal data may be granted to: authorized EvolixSport personnel, only to the extent necessary for maintenance and security; the respective Customer and its authorized users according to their roles; the providers listed below; accountants, lawyers and auditors where necessary; competent authorities where there is a legal basis. A contract under Art. 28 GDPR is in place with each processor, and the use of sub-processors is controlled.

Sub-processorActivityCountryTransfer mechanism
Hetzner Online GmbHHosting of the applications and databases, file storage, backupsGermany (EU)within the EEA – not required
Groq, Inc.Language model for DimAI (chat assistant, analyses and recommendations). Receives text prompts only; data is not used for model trainingUnited StatesEU Standard Contractual Clauses (Art. 46 GDPR) and/or EU-US Data Privacy Framework

Planned sub-processor (not yet active): Stripe Payments Europe, Ltd. (Ireland (EU)) – Processing of online payments and subscriptions. Payment card data is processed by Stripe only. It will be added to the list at least 30 days before activation.

The website loads fonts and libraries from content delivery networks (Google Fonts, jsDelivr, unpkg). When these are loaded, the browser transmits the visitor's IP address to the respective provider. These providers do not receive any other data from us.

12. International transfers

The applications, databases, files and backups are stored in a data center in Germany (EU). The only transfer outside the European Economic Area is to the provider of the language model for DimAI in the USA. It is carried out on the basis of the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where the provider is certified, the EU-US Data Privacy Framework, with supplementary measures: transmission of only the necessary text data, pseudonymization, encryption in transit and a contractual prohibition on use for training. Data subjects may request information about, or a copy of, the applicable safeguards at the personal data email address indicated.

13. Retention periods

Data is not retained for longer than necessary. The specific period depends on the purpose, the contract, legal obligations, limitation periods, anticipated disputes and the Customer's instructions.

CategoryPeriod / criterion
Customer account, profiles and sports data in the modulesfor the term of the contract or membership; after termination of the agreement, access is blocked and the data is retained for 90 days for export and restoration, after which it is deleted or anonymized, unless the law requires otherwise
Sports history, standings and resultsperiod and legal basis determined by the Customer; archived and public results may be retained in anonymized or aggregated form
Children's dataperiodic review; deletion or anonymization when the purpose ceases to apply (e.g. leaving the club), unless there is a legal basis for archiving
Health data and self-assessmentsuntil the expiry of the document (certificate, insurance policy) or until the purpose determined by the Customer ceases to apply; no longer than the lifetime of the profile
Photos and videos for analysisuntil deleted by the user or the Customer, but no longer than the lifetime of the profile; extracted features follow the retention period of the recording
DimAI conversations and resultsfor the lifetime of the account, unless deleted earlier by the user; request metadata: 12 months; at the provider: not retained after processing, except for a short period for security purposes in accordance with its terms
Financial and accounting recordsthe statutory accounting and tax retention periods (up to 10 years)
Security and access logs12 months, unless there is an incident or a legal requirement
Support requestsup to 24 months after the request is closed
Marketing consentuntil withdrawn and for a limited evidentiary period thereafter
Data subject requests and breach registerfor the period necessary to demonstrate compliance (as a rule, 5 years)

14. Security

We implement technical and organizational measures appropriate to the risk, including:

  • encryption in transit (HTTPS/TLS) for all interfaces and security HTTP headers;
  • encryption at rest of special categories of data and of access codes in the federation module; passwords are stored only as a hash using a modern algorithm (Argon2id);
  • a role-based model with least-privilege permissions and logical separation of each Customer's data; parents, coaches, clubs and federations see only the data they need;
  • session protection (limited duration, secure cookies), rate limiting and temporary lockout after repeated failed login attempts, two-factor verification for the operator's administrative access;
  • logging of access to sensitive data and of administrative actions;
  • regular backups in the EU, vulnerability and update management, periodic security reviews and an incident procedure;
  • contractual confidentiality for all persons with access.

Users are obliged to safeguard their login credentials and to notify us immediately of any suspected abuse at support@evolixsport.com. No internet system can guarantee absolute security. In the event of a security breach, we document the case, assess the risk and, where necessary, notify the Commission for Personal Data Protection (CPDP) within 72 hours of becoming aware of it, the affected Customers without undue delay, and the affected data subjects where there is likely to be a high risk to their rights.

15. Cookies and external resources

We use only strictly necessary cookies, for which no consent is required. We do not use analytics, advertising or tracking cookies and we do not track users after they log in to the platform.

CookiePurposeDuration
Session cookie (session identifier)login, session maintenance, protection against cross-site request forgery (CSRF)up to 30 minutes of inactivity or until the browser is closed
langremembers the language selected by the user12 months

If we introduce optional cookies or analytics technologies in the future, they will be activated only after prior valid consent through a consent panel in which refusing is as easy as accepting, and without loading optional scripts before a choice has been made.

16. Rights of data subjects

Subject to the conditions of the GDPR, every data subject has the right to information about and access to their data; rectification; erasure; restriction of processing; data portability; objection to processing based on legitimate interest; withdrawal of consent given, without affecting the lawfulness of processing carried out before the withdrawal; safeguards in relation to automated decision-making; and to lodge a complaint with a supervisory authority.

Requests may be submitted to office@evolixsport.com. Registered users may download a copy of their data in a machine-readable format (JSON) and submit an erasure request from their profile in the platform. To protect the data, proportionate verification of identity may be requested. A response is provided without undue delay and, as a rule, within one month; for complex or numerous requests, the period may be extended by a further two months, of which the data subject is informed.

Where EvolixSport processes data solely on the instructions of a Customer, the request is forwarded to the respective controller (the club or federation) within 5 business days, and EvolixSport provides the agreed assistance. The Customer is responsible for the final decision on the request.

A complaint may be lodged with the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, cpdp.bg, without prejudice to the right to a judicial remedy. Data subjects in other EU member states may contact the supervisory authority in their place of residence.

17. Mandatory and voluntary provision of data

Fields required for registration, a contract, licensing, security or a legal obligation are marked as mandatory. Without them, the respective service may not be provided. Data for optional features, marketing or personalization is provided voluntarily, and refusal does not restrict the core service where the data is not necessary for it.

18. Changes to the policy

The policy is reviewed whenever there is a change in functionality, AI model, provider, data category, purpose, legal basis, transfer or regulatory requirement. The current version is published with a version number and date. For material changes, appropriate notice is given, in the platform or by email, and, where necessary, renewed consent is requested.

19. Contact

Questions and requests regarding personal data may be addressed to EvolixSport by email at office@evolixsport.com. Technical questions: support@evolixsport.com. Data Protection Officer: not appointed (not mandatory for the operator); requests are handled via the e-mail above.

© 2026 EvolixSport · Terms of Service · Data Protection (GDPR)