Datenschutzerklärung

Evolve Sports · Version 17.08.2026

1. Verantwortlicher

[VOLLSTÄNDIGER NAME/FIRMA], [ANSCHRIFT], [STEUER-/MWST.-NUMMER], E-Mail: [DATENSCHUTZ-E-MAIL].

Für die interne Verwaltung von Spielern, Mitgliedern, Teams, Anwesenheiten, Beiträgen und Vereinsdokumenten ist grundsätzlich der jeweilige Verein verantwortlich. Evolve verarbeitet diese Daten technisch im Auftrag des Vereins. Für Registrierung, Kontosicherheit, Abrechnung, Plattformbetrieb und eigenen Support ist Evolve selbst verantwortlich.

2. Welche Daten verarbeitet werden

3. Zwecke und Rechtsgrundlagen

Gesundheitsdaten, insbesondere sportmedizinische Bescheinigungen, werden nur verarbeitet, wenn der verantwortliche Verein hierfür eine zusätzliche Rechtsgrundlage nach Art. 9 DSGVO besitzt.

4. Minderjährige

Unter 14-Jährige dürfen einen einwilligungsbasierten eigenen Onlinezugang nur mit Zustimmung einer sorgeberechtigten Person nutzen. Vereinsseitig angelegte Spielerdatensätze sind nicht automatisch eigene Nutzerkonten. Eltern- und Spielerverknüpfungen werden zur Bereitstellung des vereinbarten Zugriffs verarbeitet.

5. Empfänger und Dienstleister

Dienstleister erhalten nur die Daten, die für ihre jeweilige Aufgabe erforderlich sind.

6. Übermittlungen außerhalb des EWR

Einzelne Anbieter können Daten auch in den USA oder anderen Ländern verarbeiten. Übermittlungen erfolgen auf Grundlage eines Angemessenheitsbeschlusses, des EU-US Data Privacy Framework oder geeigneter Garantien wie EU-Standardvertragsklauseln. Firebase Authentication wird nach Angaben von Google in den USA betrieben; regional wählbare Datenbankdienste werden in der konfigurierten Region genutzt.

7. Speicherdauer

Kontodaten werden grundsätzlich bis zur Löschung des Kontos gespeichert. Vereinsdaten werden nach Weisung des Vereins bzw. nach Vertragsende gelöscht oder zurückgegeben. Dokumente und Inhalte bleiben gespeichert, bis sie gelöscht werden oder ihr Zweck entfällt. Sicherheitsprotokolle werden nur so lange aufbewahrt, wie dies für Sicherheit und Fehleranalyse erforderlich ist. Abrechnungsunterlagen bleiben entsprechend gesetzlicher Aufbewahrungspflichten erhalten.

8. Push-Benachrichtigungen

Push-Nachrichten werden nur nach der Betriebssystemfreigabe zugestellt. Einstellungen können in der App oder im Betriebssystem geändert werden. Dabei werden eine Push-Kennung, Nutzerzuordnung und die für die Nachricht erforderlichen Inhalte verarbeitet.

9. Website

Beim Aufruf der Website verarbeitet der Hostinganbieter technisch notwendige Serverdaten, insbesondere IP-Adresse, Zeitpunkt, aufgerufene Seite und Browserinformationen. Optionale Analyse-, Marketing- oder Einbettungsdienste dürfen erst nach entsprechender Information und – soweit erforderlich – Zustimmung aktiviert werden.

10. Rechte

Betroffene Personen haben insbesondere Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch. Eine Einwilligung kann jederzeit für die Zukunft widerrufen werden. Anfragen können an [DATENSCHUTZ-E-MAIL] oder bei vereinsbezogenen Daten direkt an den jeweiligen Verein gerichtet werden. Außerdem besteht ein Beschwerderecht beim italienischen Datenschutzbeauftragten: Garante per la protezione dei dati personali.

11. Sicherheit und Änderungen

Evolve verwendet verschlüsselte Übertragung, Zugriffsbeschränkungen und weitere technische und organisatorische Schutzmaßnahmen. Diese Erklärung wird angepasst, wenn sich Dienste oder Verarbeitungen wesentlich ändern.

Informativa sulla privacy

Evolve Sports · Versione 17.08.2026

1. Titolare del trattamento

[NOME COMPLETO/AZIENDA], [INDIRIZZO], [CODICE FISCALE/PARTITA IVA], e-mail: [E-MAIL PRIVACY].

La rispettiva società sportiva è di norma titolare del trattamento per la gestione interna di giocatori, soci, squadre, presenze, quote associative e documenti societari. Evolve tratta tecnicamente tali dati per conto della società. Evolve è invece titolare autonomo per la registrazione, la sicurezza degli account, la fatturazione, la gestione della piattaforma e il proprio supporto.

2. Dati trattati

3. Finalità e basi giuridiche

I dati relativi alla salute, in particolare i certificati medico-sportivi, vengono trattati solo se la società responsabile dispone anche di una base giuridica ai sensi dell’art. 9 GDPR.

4. Minori

I minori di 14 anni possono utilizzare un proprio accesso online basato sul consenso solo con l’autorizzazione di chi esercita la responsabilità genitoriale. I profili giocatore creati dalla società non costituiscono automaticamente account utente. I collegamenti tra genitori e giocatori vengono trattati per fornire l’accesso concordato.

5. Destinatari e fornitori

I fornitori ricevono esclusivamente i dati necessari per svolgere il rispettivo servizio.

6. Trasferimenti fuori dallo SEE

Alcuni fornitori possono trattare dati anche negli Stati Uniti o in altri Paesi. I trasferimenti si basano su una decisione di adeguatezza, sull’EU-US Data Privacy Framework o su garanzie adeguate, come le clausole contrattuali standard dell’UE. Secondo Google, Firebase Authentication è gestito negli Stati Uniti; i servizi di database con regione selezionabile vengono utilizzati nella regione configurata.

7. Periodo di conservazione

I dati dell’account vengono normalmente conservati fino alla cancellazione dell’account. I dati societari vengono cancellati o restituiti secondo le istruzioni della società o al termine del contratto. Documenti e contenuti restano memorizzati finché non vengono cancellati o viene meno la relativa finalità. I registri di sicurezza vengono conservati solo per il tempo necessario alla sicurezza e all’analisi degli errori. I documenti contabili restano conservati secondo gli obblighi di legge.

8. Notifiche push

Le notifiche push vengono inviate solo dopo l’autorizzazione del sistema operativo. Le impostazioni possono essere modificate nell’app o nel sistema operativo. Vengono trattati un identificativo push, l’associazione all’utente e i contenuti necessari alla notifica.

9. Sito web

Quando viene visitato il sito, il fornitore di hosting tratta dati tecnici necessari, in particolare indirizzo IP, orario, pagina visitata e informazioni sul browser. Servizi opzionali di analisi, marketing o incorporamento possono essere attivati solo previa informazione e, ove necessario, consenso.

10. Diritti

Gli interessati hanno in particolare diritto di accesso, rettifica, cancellazione, limitazione, portabilità e opposizione. Il consenso può essere revocato in qualsiasi momento per il futuro. Le richieste possono essere inviate a [E-MAIL PRIVACY] o, per i dati della società sportiva, direttamente alla rispettiva società. È inoltre possibile presentare reclamo al Garante per la protezione dei dati personali.

11. Sicurezza e modifiche

Evolve utilizza trasmissione cifrata, limitazioni degli accessi e ulteriori misure tecniche e organizzative di protezione. La presente informativa viene aggiornata quando cambiano in modo sostanziale i servizi o i trattamenti.

Privacy Policy

Evolve Sports · Version 17 August 2026

1. Controller

[FULL NAME/COMPANY], [ADDRESS], [TAX/VAT NUMBER], email: [PRIVACY EMAIL].

The respective sports club is generally the controller for its internal management of players, members, teams, attendance, fees, and club documents. Evolve technically processes this data on behalf of the club. Evolve acts as controller for registration, account security, billing, platform operation, and its own support.

2. Data processed

3. Purposes and legal bases

Health data, particularly sports medical certificates, is processed only where the responsible club also has a legal basis under Article 9 GDPR.

4. Minors

Children under 14 may use their own consent-based online access only with the approval of a parent or legal guardian. Player records created by a club are not automatically user accounts. Parent-player links are processed to provide the agreed access.

5. Recipients and service providers

Service providers receive only the data needed for their respective tasks.

6. Transfers outside the EEA

Some providers may also process data in the United States or other countries. Transfers rely on an adequacy decision, the EU-US Data Privacy Framework, or appropriate safeguards such as the EU Standard Contractual Clauses. According to Google, Firebase Authentication is operated in the United States; database services with selectable locations are used in the configured region.

7. Retention

Account data is generally stored until the account is deleted. Club data is deleted or returned on the club’s instructions or at the end of the contract. Documents and content remain stored until deleted or until their purpose no longer applies. Security logs are retained only as long as necessary for security and troubleshooting. Billing records are retained in accordance with statutory requirements.

8. Push notifications

Push notifications are delivered only after operating-system permission has been granted. Settings can be changed in the app or operating system. A push identifier, user association, and the content needed for the notification are processed.

9. Website

When the website is accessed, the hosting provider processes technically necessary server data, particularly the IP address, time, page accessed, and browser information. Optional analytics, marketing, or embedded services may be activated only after appropriate information and, where required, consent.

10. Rights

Individuals have rights including access, rectification, erasure, restriction, data portability, and objection. Consent can be withdrawn at any time for the future. Requests may be sent to [PRIVACY EMAIL] or, for club-related data, directly to the relevant club. A complaint may also be submitted to the Italian data protection authority, the Garante per la protezione dei dati personali.

11. Security and changes

Evolve uses encrypted transmission, access restrictions, and further technical and organizational safeguards. This Policy will be updated if services or processing activities change materially.