Trust
Our privacy commitments
We are not certified by a third party, and we will not pretend otherwise. Instead we self-attest against UK GDPR, EU GDPR and India's DPDP Act 2023, publish the evidence behind each claim, and show live numbers on how we actually perform. Anything below that you cannot verify yourself is a bug — tell us.
How we're doing, right now
These figures are read from our live systems, not written by hand. They cover the last 12 months.
0
Data-rights requests received
0 completed, 0 in progress
—
Median time to fulfil
Statutory deadline is one month
0
Requests past deadline
We publish this even when it isn't zero
0
Notifiable breaches
Reported to a supervisory authority in the last 12 months
—
Last retention purge
Automated deletion job
18 Aug 2026
Policies last updated
Versioned below
What we commit to
- You can act without asking us. Export, correction, restriction, objection and deletion are self-serve in Settings → Privacy, and take effect immediately rather than entering a queue.
- Young athletes are locked by default. Under-16 profiles are invisible until a guardian verifies consent by one-time code, and re-lock the moment consent is withdrawn.
- No selling, no ad-tech. We do not sell personal data, we run no third-party advertising trackers, and we never run behavioural advertising to under-18s.
- Access is enforced in the database. Row-level security means an interface mistake cannot leak another member's data.
- Retention is executed, not promised. Scheduled jobs delete data past its stated period, and the last run date is published above.
- We publish our register. The full record of processing activities is below — purpose, lawful basis, recipients and retention for every activity.
Record of processing activities
Account and profile management
- Purpose
- Create and maintain member accounts and sport profiles
- Lawful basis
- Contract (Art. 6(1)(b))
- Data categories
- Identity, Contact, Date of birth, Sport profile data, Photographs
- Data subjects
- Athletes, Parents/guardians, Club and academy staff, Experts
- Recipients
- Hosting provider, Email provider
- Retention
- For the life of the account, then 30 days after deletion
- Transfers
- Hosting in EU/regional cloud regions
- Safeguards
- Row-level access control, encryption in transit and at rest
Discovery and scouting
- Purpose
- Allow verified clubs, academies and experts to find and contact athletes
- Lawful basis
- Consent (Art. 6(1)(a)) — controlled by the athlete's discoverability setting
- Data categories
- Sport profile data, Location (region level), Performance evidence
- Data subjects
- Athletes
- Recipients
- Verified clubs, academies and experts on the platform
- Retention
- While discoverability is enabled
- Transfers
- None beyond hosting
- Safeguards
- Discoverability can be switched off instantly; minors gated by guardian consent
Verification and KYC
- Purpose
- Confirm identity of members and legitimacy of organisations to keep the network safe
- Lawful basis
- Legitimate interests (Art. 6(1)(f)) — safeguarding and fraud prevention
- Data categories
- Identity documents, Organisation registration documents
- Data subjects
- Athletes, Organisations
- Recipients
- Platform review team
- Retention
- 24 months after decision, then deleted
- Transfers
- None beyond hosting
- Safeguards
- Restricted admin access, all access audit-logged
Messaging and notifications
- Purpose
- Enable safe communication and send service notifications
- Lawful basis
- Contract (Art. 6(1)(b))
- Data categories
- Message content, Contact details, Notification preferences
- Data subjects
- All members
- Recipients
- Email provider
- Retention
- 24 months from last message activity
- Transfers
- Email provider may process outside the UK/EU
- Safeguards
- Moderation, blocking and reporting tools; minors contactable only through the platform
AI-assisted assessment and recommendations
- Purpose
- Generate development summaries, triage signals and match recommendations
- Lawful basis
- Legitimate interests (Art. 6(1)(f)) — with an opt-out and human review of consequential decisions
- Data categories
- Sport profile data, Assessment answers, Stated needs
- Data subjects
- Athletes, Organisations, Experts
- Recipients
- AI gateway provider
- Retention
- Derived outputs retained for 12 months
- Transfers
- AI processing may occur outside the UK/EU
- Safeguards
- Opt-out available in settings; no fully automated decisions with legal effect
Billing and subscriptions
- Purpose
- Take payment for paid plans and expert services
- Lawful basis
- Contract (Art. 6(1)(b)) and legal obligation for records
- Data categories
- Billing contact, Plan and payment metadata
- Data subjects
- Paying members and organisations
- Recipients
- Payment provider
- Retention
- 7 years for financial records
- Transfers
- Payment provider processes in the US/EU
- Safeguards
- No card data is stored by us
Safeguarding of minors
- Purpose
- Verify guardian consent and restrict exposure of under-16 athletes
- Lawful basis
- Consent of the holder of parental responsibility (Art. 8) and legitimate interests in safeguarding
- Data categories
- Date of birth, Guardian name and email, Consent records
- Data subjects
- Athletes under 18, Parents/guardians
- Recipients
- Email provider
- Retention
- For the life of the account plus 12 months of consent records
- Transfers
- None beyond hosting
- Safeguards
- Accounts locked until guardian verification; guardian can withdraw at any time
Security, moderation and audit
- Purpose
- Detect abuse, investigate reports and keep an audit trail of administrative access
- Lawful basis
- Legitimate interests (Art. 6(1)(f)) — platform safety
- Data categories
- Reports, Access logs, IP and device metadata
- Data subjects
- All members
- Recipients
- Hosting provider
- Retention
- Audit logs 24 months; moderation records 24 months after closure
- Transfers
- None beyond hosting
- Safeguards
- Least-privilege admin roles, tamper-evident audit log
Policy versions
privacy · v1.0
Effective 18 Aug 2026
First published privacy notice covering UK GDPR, EU GDPR and India DPDP 2023, including self-serve data rights and guardian consent for under-16s.
cookies · v1.0
Effective 18 Aug 2026
First published cookie notice with granular consent categories and no non-essential storage before consent.
terms · v1.0
Effective 18 Aug 2026
First published terms of service for athletes, organisations and experts.
security · v1.0
Effective 18 Aug 2026
First published security practices statement, including encryption, access control, audit logging and vulnerability disclosure.
minors · v1.0
Effective 18 Aug 2026
First published safeguarding statement for athletes under 18.
Read the detail
- Privacy notice
- Protecting young athletes
- Security measures and responsible disclosure
- Subprocessors and international transfers
- Cookie notice
- Make a data request
Questions, or want our DPA or a completed security questionnaire? Email privacy@striide.app.