← Home

Privacy

1. Who is responsible for the data

Your Academy is the controller of the data it enters about you and your children, and of what is created inside its academy. Elite Academy processes it as a processor, under a data processing agreement with the club.

Elite Academy is the controller of: login credentials and login history, billing, security logs and support correspondence.

Data protection contact: privacy@joineliteacademy.com.

2. What data we hold

We do not ask for special-category data (such as health). A reflection may contain anything the child says — we treat it as the most sensitive thing we hold (section 5). Reasons for absence come from a fixed list with no health category.

3. Purposes and legal bases

4. Children

5. Reflections, recordings and assessments

Written to be read by a fourteen-year-old.

Reflections and coach assessments are not sold, not used for advertising, not used to train any AI model and not shared with any other Academy.

6. Who sees your data

Inside the service — as set out in section 7.5 of the Terms. Outside it — nobody, except the processors in section 7 and authorities where the law requires. We do not sell data and have no advertisers. There are no ads in Elite Academy.

7. Processors and where data lives

Rules: hosting in the European Economic Area; AI processing in the EU; a contractual ban on training models on our data; recordings are not kept by the provider. Clubs are told [30] days before the list changes.

8. How long we keep data

The rule: the shortest period the law requires.

9. Your rights

You have the right to access, correct and erase your data, to restrict processing, to data portability and to object, as well as to withdraw consent and to complain to the Polish supervisory authority (Prezes UODO). Send requests to the Academy or to us — we pass them on within [3 business days] and help answer within a month. A Parent exercises the rights of a child under 16; a Player aged 16 or over may do so themselves. In the app you can remove a child, withdraw photo consent and close your account. A request to erase a child's reflections is honoured without argument.

10. Security

Database-level access control enforcing the rules in the Terms; encrypted connections; encryption at rest; hashed passwords; single-use, time-limited activation codes; logged staff access. We tell the Academy about a breach within [24] hours, and the authority within 72 hours where required.

11. Analytics and phone permissions

We use no third-party advertising or analytics tools and no crash reporting.