1. Introduction
At AthletIQ, we understand that player biometric data is exceptionally sensitive. Your trust is paramount, and we treat data security and privacy as foundational principles of our platform. This Privacy Policy explains how we collect, use, store, and protect your data.
2. Data We Collect
AthletIQ collects the following categories of data:
- Biometric Data: Heart rate, HRV, sleep scores, recovery metrics, workload indices from wearables and wellness systems.
- Performance Data: GPS tracking, speed, distance, acceleration, positioning from suppliers like Catapult and STATSports.
- Player Information: Name, position, squad number, injury history, and performance notes.
- Account Data: Club name, administrator contact information, subscription details.
3. How We Use Your Data
We use collected data solely for:
- AI-driven injury risk prediction and real-time alerting
- Player form and performance trend tracking
- Squad availability and fitness dashboards
- Advanced analytics and customizable reporting
- System optimization and service improvement
We do not: sell data to third parties, use player data for marketing, share individual player metrics without explicit club consent, or process data outside the scope of performance and injury prevention.
4. Data Security & Protection
Data security is at the core of everything we build. We employ industry-standard safeguards:
- End-to-end encryption for data in transit and at rest
- Role-based access controls with multi-factor authentication
- Regular security audits and penetration testing
- Compliance with GDPR, CCPA, and relevant data protection regulations
- Secure API endpoints with rate-limiting and token-based authentication
5. Data Storage & Deployment Flexibility
We recognize that every club has unique infrastructure needs. AthletIQ is built on container-based architecture, giving you complete control over data residency:
Option 1: On-Premises Deployment
Deploy AthletIQ within your club's own data center or local servers. Your player biometric and performance data never leaves your facilities. You maintain full physical and administrative control.
Option 2: Cloud Deployment
Deploy on a private cloud or third-party cloud infrastructure of your choice (AWS, Azure, Google Cloud, or private cloud providers). You choose the region and maintain configuration control.
Option 3: Hybrid Deployment
Combine on-premises and cloud infrastructure. Real-time wearable data may be processed locally, while historical analytics run in the cloud—all under your governance.
Complete Club Autonomy: You are never locked into a storage solution. We work with your IT team to ensure AthletIQ integrates seamlessly with your infrastructure, data governance policies, and security requirements.
6. Data Retention & Deletion
Clubs retain ownership of all player data. You may:
- Request data export at any time in standard formats (CSV, JSON, XML)
- Delete specific player records or entire datasets upon request
- Set automatic retention policies (e.g., archive after 24 months, purge after 36 months)
- Retrieve historical data even after player departure
We comply with all deletion requests within 30 days. Backups are retained per your backup policy; once purged, data is removed from all systems.
7. Third-Party Integrations
When you connect wearable or GPS providers (Whoop, Catapult, STATSports, etc.), their data sharing agreements apply:
- We only access data you explicitly authorize through their APIs
- We do not sell or share third-party data
- Each provider's privacy policy remains in effect for their platform
- You can revoke access at any time without affecting other data in AthletIQ
8. Your Rights & Club Control
As a club using AthletIQ, you have the right to:
- Access all data collected on your players
- Correct inaccurate information
- Export your data in machine-readable format
- Request deletion of any records
- Audit our security practices and certifications
- Receive notice of any data breach or incident
9. Data Breach Notification
In the unlikely event of a confirmed data breach, we will notify affected clubs within 72 hours with details of the incident, scope, and remediation steps taken. We maintain comprehensive incident response procedures and cyber liability insurance.
10. Children's Data
If your club tracks player data for youth academies or players under 18, we apply enhanced protections and comply with child data protection regulations (COPPA in the US, GDPR Article 8 in the EU). Parental/guardian consent may be required per local law.
11. Changes to This Policy
We may update this Privacy Policy as our services evolve. Any material changes will be communicated to your club via email. Your continued use of AthletIQ implies acceptance of changes. You may always request a version of this policy effective at any prior date.
12. Contact & Support
For questions, requests, or concerns regarding your data and privacy:
- Email: privacy@athletiq.ai
- General Support: hello@athletiq.ai
- Data Subject Requests: Submit via your admin dashboard or email privacy@athletiq.ai
We aim to respond to all privacy inquiries within 5 business days.