Data processing
The summary a club, federation or insurer normally asks for. A signed agreement on your own paper is available — ask.
Roles
You are the controller. The athletes are your patients, the clinical record is yours, and you decide what is recorded and why. Priveo is the processor. We hold and compute on that data strictly to provide the service you asked for, and for nothing else.
What is processed
| Category | Examples |
|---|---|
| Health data (special category) | Daily wellness scores, pain reports and sites, injuries and diagnoses, strength tests, rehab stage and clearance decisions |
| Identity | Athlete name, date of birth, playing position, body mass |
| Practitioner account | Your email address, practice name, billing reference |
| Children | Youth athletes are in scope. Growth measurements are recorded for the growth-velocity advisory. Consent is yours to obtain; Priveo records the version and timestamp. |
Purpose and instruction
We process only to run the service: storing what you enter, computing the nightly clinical metrics, sending you one daily digest, and taking payment. We do not process it for our own purposes, we do not sell it, and there is no machine-learning model anywhere in the product to feed.
Security measures
- Row-level security in the database. Isolation between practices is enforced by Postgres on every query, not by application code that could be bypassed. A practice cannot read another practice’s athletes even if the application asked it to.
- Encrypted in transit and at rest.
- Least privilege. Anonymous visitors can execute exactly two functions — the public calculators — and can read no table at all.
- Audit trail. Clearance decisions, stage advances, overrides and consent are recorded with who did them and when.
- Scrubbed diagnostics. Error reports have names, emails, clinical fields and tokens removed before they leave the browser. Session replay is off.
Sub-processors
Listed in full, with location and role, on the sub-processors page. We update it before adding one, not after.
International transfers
Athlete data is held in the EU (Frankfurt). Billing and email involve providers that may process outside the EU under standard contractual clauses; no athlete data goes to either — Stripe receives your billing details only, and the digest email contains what you already see in the app.
Your rights as controller
- Export any athlete’s full record as JSON at any time, from the app.
- Request deletion from settings; it is recorded and actioned.
- Ask us anything about how a specific field is handled and get a real answer.
Breach
If athlete data is exposed, you are told without undue delay and told what was affected — not a generic notice weeks later.
At the end
When you leave, you export first and we delete after. Deletion cascades: removing a practice removes its athletes and their clinical records.
Written to be accurate and readable, not to be exhaustive. It is not legal advice. If your club, federation or insurer needs a signed agreement or a specific clause, email us and you will get a real answer from a person.