Für die interne Verwaltung von Spielern, Mitgliedern, Teams, Anwesenheiten, Beiträgen und Vereinsdokumenten ist grundsätzlich der jeweilige Verein verantwortlich. Evolve verarbeitet diese Daten technisch im Auftrag des Vereins. Für Registrierung, Kontosicherheit, Abrechnung, Plattformbetrieb und eigenen Support ist Evolve selbst verantwortlich.
2. Welche Daten verarbeitet werden
Kontodaten: Name, E-Mail-Adresse, verschlüsselte Zugangsdaten, Sprache und Nutzer-ID.
Vereins- und Spielerdaten: Kontaktdaten, Geburtsdatum, Team, Sektion, Rollen und Verknüpfungen.
Organisationsdaten: Termine, Zu-/Absagen, Anwesenheiten, Statistiken, Fahrten und Reservierungen.
Dokumente: Mitgliedschafts- und Zahlungsnachweise, Identitätsdokumente sowie sportmedizinische Bescheinigungen, sofern vom Verein oder Nutzer hochgeladen.
Inhalte: Profilbilder, Beiträge, Bilder, Videos, Kommentare oder eigene Übungen, soweit genutzt.
Technische Daten: IP-Adresse, Geräte-/App-Informationen, Push-Kennung, Zeitpunkte sowie Fehler- und Sicherheitsprotokolle.
Abrechnungsdaten: Tarif, Zahlungsstatus, Transaktions- und Rechnungsdaten. Vollständige Kartendaten werden nicht von Evolve gespeichert.
3. Zwecke und Rechtsgrundlagen
Bereitstellung von Konto und Plattform: Vertragserfüllung bzw. vorvertragliche Maßnahmen.
Vereinsverwaltung: Verarbeitung im Auftrag und nach Weisung des jeweiligen Vereins.
Abrechnung und gesetzliche Nachweise: Vertragserfüllung und rechtliche Verpflichtungen.
Sicherheit, Fehlerbehebung und Missbrauchsschutz: berechtigtes Interesse an einem sicheren und stabilen Betrieb.
Optionale Veröffentlichungen oder Marketing: Einwilligung, sofern eine solche Funktion eingesetzt wird.
Gesundheitsdaten, insbesondere sportmedizinische Bescheinigungen, werden nur verarbeitet, wenn der verantwortliche Verein hierfür eine zusätzliche Rechtsgrundlage nach Art. 9 DSGVO besitzt.
4. Minderjährige
Unter 14-Jährige dürfen einen einwilligungsbasierten eigenen Onlinezugang nur mit Zustimmung einer sorgeberechtigten Person nutzen. Vereinsseitig angelegte Spielerdatensätze sind nicht automatisch eigene Nutzerkonten. Eltern- und Spielerverknüpfungen werden zur Bereitstellung des vereinbarten Zugriffs verarbeitet.
5. Empfänger und Dienstleister
Google/Firebase und Google Cloud: Authentifizierung, Datenbank, Dateispeicher und Backend-Funktionen.
OneSignal: Push-Benachrichtigungen und Geräte-/Push-Kennungen.
Amazon Web Services (AWS SES): Versand von E-Mails.
Stripe: Abonnement-, Zahlungs- und Rechnungsabwicklung.
Apple und Google: App-Verteilung und systemseitige Push-Zustellung.
Hostinger bzw. der tatsächlich eingesetzte Hostinganbieter: Bereitstellung der Website und des Webbereichs.
Dienstleister erhalten nur die Daten, die für ihre jeweilige Aufgabe erforderlich sind.
6. Übermittlungen außerhalb des EWR
Einzelne Anbieter können Daten auch in den USA oder anderen Ländern verarbeiten. Übermittlungen erfolgen auf Grundlage eines Angemessenheitsbeschlusses, des EU-US Data Privacy Framework oder geeigneter Garantien wie EU-Standardvertragsklauseln. Firebase Authentication wird nach Angaben von Google in den USA betrieben; regional wählbare Datenbankdienste werden in der konfigurierten Region genutzt.
7. Speicherdauer
Kontodaten werden grundsätzlich bis zur Löschung des Kontos gespeichert. Vereinsdaten werden nach Weisung des Vereins bzw. nach Vertragsende gelöscht oder zurückgegeben. Dokumente und Inhalte bleiben gespeichert, bis sie gelöscht werden oder ihr Zweck entfällt. Sicherheitsprotokolle werden nur so lange aufbewahrt, wie dies für Sicherheit und Fehleranalyse erforderlich ist. Abrechnungsunterlagen bleiben entsprechend gesetzlicher Aufbewahrungspflichten erhalten.
8. Push-Benachrichtigungen
Push-Nachrichten werden nur nach der Betriebssystemfreigabe zugestellt. Einstellungen können in der App oder im Betriebssystem geändert werden. Dabei werden eine Push-Kennung, Nutzerzuordnung und die für die Nachricht erforderlichen Inhalte verarbeitet.
9. Website
Beim Aufruf der Website verarbeitet der Hostinganbieter technisch notwendige Serverdaten, insbesondere IP-Adresse, Zeitpunkt, aufgerufene Seite und Browserinformationen. Optionale Analyse-, Marketing- oder Einbettungsdienste dürfen erst nach entsprechender Information und – soweit erforderlich – Zustimmung aktiviert werden.
10. Rechte
Betroffene Personen haben insbesondere Rechte auf Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch. Eine Einwilligung kann jederzeit für die Zukunft widerrufen werden. Anfragen können an [DATENSCHUTZ-E-MAIL] oder bei vereinsbezogenen Daten direkt an den jeweiligen Verein gerichtet werden. Außerdem besteht ein Beschwerderecht beim italienischen Datenschutzbeauftragten: Garante per la protezione dei dati personali.
11. Sicherheit und Änderungen
Evolve verwendet verschlüsselte Übertragung, Zugriffsbeschränkungen und weitere technische und organisatorische Schutzmaßnahmen. Diese Erklärung wird angepasst, wenn sich Dienste oder Verarbeitungen wesentlich ändern.
La rispettiva società sportiva è di norma titolare del trattamento per la gestione interna di giocatori, soci, squadre, presenze, quote associative e documenti societari. Evolve tratta tecnicamente tali dati per conto della società. Evolve è invece titolare autonomo per la registrazione, la sicurezza degli account, la fatturazione, la gestione della piattaforma e il proprio supporto.
2. Dati trattati
Dati dell’account: nome, indirizzo e-mail, credenziali protette, lingua e ID utente.
Dati societari e dei giocatori: recapiti, data di nascita, squadra, sezione, ruoli e collegamenti.
Dati organizzativi: appuntamenti, conferme o disdette, presenze, statistiche, viaggi e prenotazioni.
Documenti: attestazioni di iscrizione e pagamento, documenti di identità e certificati medico-sportivi, se caricati dalla società o dall’utente.
Contenuti: immagini profilo, post, immagini, video, commenti o esercizi personali, se utilizzati.
Dati tecnici: indirizzo IP, informazioni su dispositivo e app, identificativo push, orari e registri di errore e sicurezza.
Dati di fatturazione: piano, stato del pagamento, dati di transazione e fatturazione. Evolve non memorizza i dati completi delle carte.
3. Finalità e basi giuridiche
Fornitura dell’account e della piattaforma: esecuzione del contratto o misure precontrattuali.
Gestione della società sportiva: trattamento per conto e secondo le istruzioni della società.
Fatturazione e adempimenti di legge: esecuzione del contratto e obblighi legali.
Sicurezza, risoluzione degli errori e prevenzione degli abusi: legittimo interesse a un funzionamento sicuro e stabile.
Pubblicazioni opzionali o marketing: consenso, se viene utilizzata tale funzione.
I dati relativi alla salute, in particolare i certificati medico-sportivi, vengono trattati solo se la società responsabile dispone anche di una base giuridica ai sensi dell’art. 9 GDPR.
4. Minori
I minori di 14 anni possono utilizzare un proprio accesso online basato sul consenso solo con l’autorizzazione di chi esercita la responsabilità genitoriale. I profili giocatore creati dalla società non costituiscono automaticamente account utente. I collegamenti tra genitori e giocatori vengono trattati per fornire l’accesso concordato.
5. Destinatari e fornitori
Google/Firebase e Google Cloud: autenticazione, database, archiviazione file e funzioni backend.
OneSignal: notifiche push e identificativi di dispositivo/push.
Amazon Web Services (AWS SES): invio di e-mail.
Stripe: gestione di abbonamenti, pagamenti e fatture.
Apple e Google: distribuzione dell’app e consegna delle notifiche push tramite il sistema operativo.
Hostinger o il fornitore di hosting effettivamente utilizzato: sito web e area web.
I fornitori ricevono esclusivamente i dati necessari per svolgere il rispettivo servizio.
6. Trasferimenti fuori dallo SEE
Alcuni fornitori possono trattare dati anche negli Stati Uniti o in altri Paesi. I trasferimenti si basano su una decisione di adeguatezza, sull’EU-US Data Privacy Framework o su garanzie adeguate, come le clausole contrattuali standard dell’UE. Secondo Google, Firebase Authentication è gestito negli Stati Uniti; i servizi di database con regione selezionabile vengono utilizzati nella regione configurata.
7. Periodo di conservazione
I dati dell’account vengono normalmente conservati fino alla cancellazione dell’account. I dati societari vengono cancellati o restituiti secondo le istruzioni della società o al termine del contratto. Documenti e contenuti restano memorizzati finché non vengono cancellati o viene meno la relativa finalità. I registri di sicurezza vengono conservati solo per il tempo necessario alla sicurezza e all’analisi degli errori. I documenti contabili restano conservati secondo gli obblighi di legge.
8. Notifiche push
Le notifiche push vengono inviate solo dopo l’autorizzazione del sistema operativo. Le impostazioni possono essere modificate nell’app o nel sistema operativo. Vengono trattati un identificativo push, l’associazione all’utente e i contenuti necessari alla notifica.
9. Sito web
Quando viene visitato il sito, il fornitore di hosting tratta dati tecnici necessari, in particolare indirizzo IP, orario, pagina visitata e informazioni sul browser. Servizi opzionali di analisi, marketing o incorporamento possono essere attivati solo previa informazione e, ove necessario, consenso.
10. Diritti
Gli interessati hanno in particolare diritto di accesso, rettifica, cancellazione, limitazione, portabilità e opposizione. Il consenso può essere revocato in qualsiasi momento per il futuro. Le richieste possono essere inviate a [E-MAIL PRIVACY] o, per i dati della società sportiva, direttamente alla rispettiva società. È inoltre possibile presentare reclamo al Garante per la protezione dei dati personali.
11. Sicurezza e modifiche
Evolve utilizza trasmissione cifrata, limitazioni degli accessi e ulteriori misure tecniche e organizzative di protezione. La presente informativa viene aggiornata quando cambiano in modo sostanziale i servizi o i trattamenti.
The respective sports club is generally the controller for its internal management of players, members, teams, attendance, fees, and club documents. Evolve technically processes this data on behalf of the club. Evolve acts as controller for registration, account security, billing, platform operation, and its own support.
2. Data processed
Account data: name, email address, protected login credentials, language, and user ID.
Club and player data: contact details, date of birth, team, section, roles, and account links.
Organizational data: appointments, acceptances or declines, attendance, statistics, travel, and reservations.
Documents: membership and payment records, identity documents, and sports medical certificates if uploaded by the club or user.
Content: profile pictures, posts, images, videos, comments, or personal exercises where used.
Technical data: IP address, device/app information, push identifier, timestamps, and error and security logs.
Billing data: plan, payment status, transaction and invoice data. Evolve does not store complete card details.
3. Purposes and legal bases
Providing the account and platform: performance of a contract or pre-contractual measures.
Club administration: processing on behalf of and according to the instructions of the relevant club.
Billing and statutory records: performance of a contract and legal obligations.
Security, troubleshooting, and abuse prevention: legitimate interest in secure and stable operation.
Optional publications or marketing: consent, where such a function is used.
Health data, particularly sports medical certificates, is processed only where the responsible club also has a legal basis under Article 9 GDPR.
4. Minors
Children under 14 may use their own consent-based online access only with the approval of a parent or legal guardian. Player records created by a club are not automatically user accounts. Parent-player links are processed to provide the agreed access.
5. Recipients and service providers
Google/Firebase and Google Cloud: authentication, database, file storage, and backend functions.
OneSignal: push notifications and device/push identifiers.
Amazon Web Services (AWS SES): sending email.
Stripe: subscription, payment, and invoice processing.
Apple and Google: app distribution and system-level push delivery.
Hostinger or the hosting provider actually used: website and web area.
Service providers receive only the data needed for their respective tasks.
6. Transfers outside the EEA
Some providers may also process data in the United States or other countries. Transfers rely on an adequacy decision, the EU-US Data Privacy Framework, or appropriate safeguards such as the EU Standard Contractual Clauses. According to Google, Firebase Authentication is operated in the United States; database services with selectable locations are used in the configured region.
7. Retention
Account data is generally stored until the account is deleted. Club data is deleted or returned on the club’s instructions or at the end of the contract. Documents and content remain stored until deleted or until their purpose no longer applies. Security logs are retained only as long as necessary for security and troubleshooting. Billing records are retained in accordance with statutory requirements.
8. Push notifications
Push notifications are delivered only after operating-system permission has been granted. Settings can be changed in the app or operating system. A push identifier, user association, and the content needed for the notification are processed.
9. Website
When the website is accessed, the hosting provider processes technically necessary server data, particularly the IP address, time, page accessed, and browser information. Optional analytics, marketing, or embedded services may be activated only after appropriate information and, where required, consent.
10. Rights
Individuals have rights including access, rectification, erasure, restriction, data portability, and objection. Consent can be withdrawn at any time for the future. Requests may be sent to [PRIVACY EMAIL] or, for club-related data, directly to the relevant club. A complaint may also be submitted to the Italian data protection authority, the Garante per la protezione dei dati personali.
11. Security and changes
Evolve uses encrypted transmission, access restrictions, and further technical and organizational safeguards. This Policy will be updated if services or processing activities change materially.