Kinetik Privacy Policy
Last updated: July 4, 2026 · v2.2
1. Data Controller
In compliance with Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 (LOPDGDD), and applicable data protection laws, we inform you that personal data collected through the Kinetik Platform will be processed by:
Data Controller:
- Name: Ignacio González Valero
- Tax ID: 47928301G
- Address: Avenida Madrid 39, 08227 Terrassa, Barcelona, Spain
- Contact Email: nachogova@hotmail.com
- Data Protection Officer (DPO): nachogova@hotmail.com
Any questions regarding privacy, data access, or exercise of rights should be directed to the above address.
2. Nature of Collected Data and Processing Purpose
2.1 User Identification Data
What data we collect:
- First and last name
- Email address
- Date of birth (for age verification)
- Profile photo (avatar)
- Authentication data (password hash managed by Amazon Cognito, session identifiers)
Processing purpose:
- Create and manage your user account.
- Verify identity and age.
- Enable access to Platform features.
- Service communications (account confirmation, password changes, security alerts).
- Sending commercial communications about Kinetik (new features, plan changes, relevant product notices) only if the user has given explicit consent, revocable at any time.
- Legal compliance.
Special protection for health data: Health and physical availability data (Section 2.3) receives enhanced treatment under Article 9 of the GDPR (special category). Kinetik applies additional access controls and auditing over this data.
No data selling: Kinetik does not sell, rent or transfer your personal data to third parties for commercial or advertising purposes under any circumstances. The only recipients are the providers strictly necessary to deliver the service (see Section 5).
Legal basis: Contract (service execution) and Consent (for commercial communications and health data).
2.2 Sports and Performance Data
What data we collect:
- Team Data: Name, sport, category, season, colors, technical notes.
- Player Data: Name, last name, jersey number, position, health data (availability, injuries).
- Event Data: Calendar (dates, times, opponents, free-text location), event types (match, training).
- Performance Statistics: Goals, minutes played, assists, cards, fouls committed.
- Participation Data: Call lists, attendance confirmations, availability status.
- Analysis Data: Tactical boards, coach notes, evaluations.
Processing purpose:
- Enable team management (roster, calendar, call lists).
- Statistics capture during sporting events.
- Individual and team performance analysis.
- Technical report generation.
- Communication with players (call lists, notifications).
Legal basis: Contract (sports management services) and Explicit Consent. By entering health data, you explicitly consent to its processing for sports management purposes. Important Note: The Platform does NOT provide medical diagnoses nor constitute professional advice.
2.3 Health and Physical Availability Data
What data we collect:
- Availability status (available, injured, doubtful).
- Injury descriptions (if applicable).
- Estimated return date.
- Perceived exertion (RPE) or fatigue (optional).
- Injury history (if recorded).
Processing purpose:
- Team workload management.
- Training and call list planning.
- Injury prevention.
- Communication with players about their status.
Legal basis: Explicit Consent (GDPR Article 9). By using health tracking features, you give your informed consent.
Important: This data serves as support tools for the coach. It does NOT replace medical consultations or professional diagnoses. You are responsible for consulting doctors, physiotherapists, or specialists before making health or injury decisions.
2.4 Payment and Subscription Data
What data we collect:
- Subscription type (TRIAL, PROMO, PREMIUM).
- License start and expiration dates.
- Transaction history (we do not store full credit card numbers).
- Billing information (if applicable).
Processing purpose:
- Subscription and license management.
- Premium feature access control.
- Billing and accounting records.
Legal basis: Contract (payment service execution).
Payment Processing: Payments are processed by specialized third parties:
- Mobile Platforms: Apple App Store (iOS) and Google Play Store (Android) — subject to their privacy policies.
- Payment Processor: RevenueCat (technical subscription management).
Kinetik Platform does not store or access credit card numbers. Please consult Apple’s, Google’s, and RevenueCat’s privacy policies for payment data processing details.
2.5 Device and Usage Data
What data we collect:
- Device type and model.
- Operating system and version.
- Kinetik application version.
- Crash/error data (when reported).
- Minimal connection data (IP, approximate country from IP).
Processing purpose:
- Compatibility and performance analysis.
- Platform improvement.
- Technical error debugging.
- Aggregated usage statistics (without personal identification).
Legal basis: Legitimate Interest (service improvement).
3. Device Permissions
The Platform requests limited device permissions. See also the Terms of Service, section 5.
3.1 Camera (active)
- Purpose: Scan QR codes to link players/staff to the team.
- Data generated: NONE stored. QR content is processed in memory and discarded.
- We do NOT record: Video, images, or camera frames.
3.2 Gallery / Photos (active, optional)
- Purpose: Upload user or player profile photo.
- Storage: Image is uploaded resized to our S3 bucket (
kinetik-prod-assets), encrypted at rest.
3.3 Push Notifications (NOT active)
We currently do not send push notifications nor request this permission. When implemented, explicit consent will be requested and this Policy will be updated with: which events trigger notifications, push provider used, device token retention, and opt-out option.
3.4 Location / GPS (NOT active)
We currently do not access device location. Event locations are entered as free text by the Coach. If geolocation is implemented in the future, this Policy will be updated and consent will be requested.
3.5 Cross-App Tracking (iOS ATT)
On iOS 14.5+ devices, the Platform does NOT request the “App Tracking Transparency” permission because we do not track your activity across other applications or websites. There is no cross-app tracking.
4. Minors
The safety and protection of minors is our highest priority.
4.1 Minimum Age
- Independent Registration: Permitted for those 14 and older. If you are under 14, you cannot register without parental authorization.
- As a Team Player: A minor under 14 can be invited if their Coach (team owner) has explicit parental/guardian authorization.
4.2 Coach Responsibilities
The Coach (team owner) is responsible for:
- Verifying that all minors under 14 invited to their team have prior written parental authorization.
- Complying with minor protection laws in your jurisdiction.
- Informing parents about what data is collected and how it is used.
- Specifically, having parental consent to upload photographs of minors to the roster.
4.3 Rights of Parents or Guardians
Parents or legal guardians may at any time:
- Request access to all personal data of their child processed on the Platform.
- Request the immediate deletion of the data (including photograph) by writing to
nachogova@hotmail.com. - Request the rectification of inaccurate data.
- Request information about with whom the data has been shared.
Requests will be handled within a maximum period of 30 days.
4.4 Protective Action
If we detect an account belonging to a minor under 14 without proper authorization, we will:
- Immediately block the account.
- Delete personal data.
- Notify the account holder (if applicable).
- Revoke the licence of the team whose responsible person (Coach owner) has added the minor without the corresponding parental authorization. Licence revocation is carried out without refund, as it is considered a serious breach of these Terms and of applicable minor-protection regulations.
5. Data Recipients and International Transfers
5.1 Sharing Within the Platform
Your data is visible to:
- Other team members based on their role and permissions (Coach, Delegate, Player).
- Owner’s Personnel only if necessary to resolve technical issues or support requests.
5.2 Processors and Data Processing Partners
To provide the service, we use the following trusted processors (Data Processing Partners under GDPR):
| Provider | Location | Purpose | Data |
|---|---|---|---|
| Amazon Web Services (AWS) | EU (eu-west-1, Ireland) | Storage (DynamoDB), files (S3), authentication (Cognito), serverless logic (Lambda) | All Platform data |
| RevenueCat | USA | Technical management of mobile subscriptions | Subscription and license data |
| Expo (EAS) | USA | App distribution, OTA updates | App configuration and version data |
| Apple / Google | USA | Distribution on App Store / Play Store and payment processing | Billing data (processed by them) |
Kinetik currently does not use third-party analytics, advertising, crash reporting, or cross-app tracking providers.
5.3 International Transfers
Data is primarily stored in the European Union (AWS eu-west-1, Ireland). However, some providers operate from the United States (RevenueCat, Expo, Apple, Google).
These transfers are safeguarded by:
- Adequacy Decision: Where applicable.
- EU-US Data Privacy Framework: For transfers to the US (when the provider is certified).
- Standard Contractual Clauses (SCCs): Included in processor contracts.
- Explicit Consent: Your acceptance of this Policy.
Right to Know: You may request specific details about transfers and safeguards by writing to nachogova@hotmail.com.
5.4 We Do Not Sell Data
Important Guarantee: Kinetik NEVER sells, shares, or trades your personal data. We do not share information with third parties for advertising, marketing, or profit purposes, except as legally required.
6. Data Storage and Security
6.1 Storage Infrastructure
Your data is stored in:
- Database: Amazon DynamoDB (tables encrypted at rest with AWS-managed keys).
- File Storage: Amazon S3, bucket
kinetik-prod-assets(profile photos, avatars). - Authentication: Amazon Cognito (User Pool + Identity Pool, secure credential management).
- Backups: Automatically performed by AWS (Point-in-Time Recovery on DynamoDB, versioning on S3 where applicable).
6.2 Local Device Storage
The Platform stores information on your device:
- JWT session tokens: In secure operating system storage (Keychain on iOS, EncryptedSharedPreferences on Android). On web, in
localStorageunder strict CSP. - Local preferences: Language, theme (light/dark), in
AsyncStorage(mobile) orlocalStorage(web). - Data cache: Information downloaded from the Platform for smooth navigation (managed by TanStack Query).
This data is deleted when uninstalling the app or logging out.
6.3 Security Measures
We implement:
- Encryption in Transit: HTTPS/TLS 1.2+ for all client-server communications.
- Encryption at Rest: Data in DynamoDB and S3 encrypted with AWS KMS.
- Authentication: Email/password (SRP protocol) and Google OAuth.
- Access Control: Roles and permissions applied on client and in Identity Pool IAM policies.
- Auditing: Access logs in AWS CloudTrail and Lambda logs.
Liability Limits: Although we implement high standards, no system is 100% secure. You are responsible for keeping your password confidential and notifying us of unauthorized access.
7. Data Retention Period
7.1 Active User Data
While you maintain an active account and use the Platform, we retain your data.
7.2 Account Deletion
When you request account deletion:
- Cognito (identity): Deleted immediately. You will no longer be able to log in.
- DynamoDB data: Cascading deletion — teams you own, players, events, statistics, attendances, tactical boards, licenses, memberships.
- S3 photos: Deleted immediately (best-effort).
Deletion is irreversible. Except for periodic backups (overwritten within 30-90 days), there is no way to recover the data.
7.3 Retention by Legal Obligation
Certain data is retained longer due to tax or legal obligations:
- Transaction records (billing): 6 years (Spanish tax obligation).
- CloudTrail access records: 90 days (standard AWS cycle).
- Security incident records: Until resolution + 1 year.
8. User Rights (GDPR)
Under GDPR, you have the right to:
8.1 Right of Access
Request a copy of all personal data we hold about you in readable format.
8.2 Right to Rectification
Correct inaccurate or incomplete data (e.g., change name, email, profile photo).
Player data managed by the team: A player’s sports and federative data (jersey number, position, technical notes, availability data) is entered and managed by the Coach who owns the team, as the responsible party for team data. If a player detects incorrect data, the usual and fastest route is to ask the Coach to modify it from their account. Notwithstanding, the player can always exercise their rectification right directly by writing to nachogova@hotmail.com.
8.3 Right to Erasure (Right to Be Forgotten)
Request deletion of your data, except where legal obligations require retention.
8.4 Right to Restrict Processing
Request that we limit use of your data (e.g., during a dispute).
8.5 Right to Data Portability
Receive your data in structured format (JSON) for transfer to another service.
8.6 Right to Object
Object to processing of your data for certain purposes.
8.7 Rights Related to Automated Decision-Making
Request human intervention in fully automated decisions affecting you (e.g., automatic account blocking).
8.8 How to Exercise Your Rights
To exercise any of these rights, write to:
- Email: nachogova@hotmail.com
- Address: Avenida Madrid 39, 08227 Terrassa, Barcelona, Spain
Include in your request:
- Full name.
- Email registered in Kinetik.
- Clear description of the right you wish to exercise.
- Copy of your ID or identity document.
- Signature (if by postal mail).
We will respond to your request within 30 days (extendable to 60 in complex cases) in accordance with GDPR.
9. Cookies and Tracking Technologies
9.1 On Mobile Platform
The mobile app (iOS/Android) does not use traditional cookies. Instead:
- JWT Session Tokens: Stored in Keychain / EncryptedSharedPreferences.
- Anonymous Identifiers: Only for internal aggregated analysis.
9.2 On Website (kinetik.ngv.digital)
If you access Kinetik from web, we use:
localStorage: Session tokens (equivalent to session cookie, strictly necessary technical use).localStorage: Local preferences (language, theme).
We currently do not use analytics, advertising, or tracking cookies. If added in the future, a consent banner will be implemented per the ePrivacy Directive.
10. Policy Modifications
The Owner reserves the right to modify this Policy at any time. Changes will be notified through:
- In-app notifications in Kinetik.
- Email to your registered address.
- Publication at
kinetik.ngv.digital/legal/.
Your Consent: Continued Platform use after modifications implies acceptance of the new Policy. If you disagree, you may request account deletion.
11. Contact and Complaints
11.1 Privacy Questions
For any privacy-related questions or requests, contact:
- Email: nachogova@hotmail.com
- Address: Avenida Madrid 39, 08227 Terrassa, Barcelona, Spain
11.2 Complaints to Data Protection Authority
If you believe your rights have been violated, you have the right to file a complaint with the competent Data Protection Authority. In Spain: Spanish Data Protection Agency (AEPD):
- Website: www.aepd.es
- Phone: +34 901 100 099