This Privacy Policy describes how CoachMap collects, uses and shares information about you when you access or use our Platform and services.
1. Who We Are
CoachMap is a software-as-a-service sports planning platform for sports clubs. We are the Data Controller in respect of personal data collected directly through our Platform and website.
CoachMap is registered under Brazilian CNPJ No. [XX.XXX.XXX/XXXX-XX], with registered address at [Full address].
For data protection enquiries, contact us at: privacy@coachmap.io
2. Data We Collect
2.1 Account and User Data
- Full name, job title and organisation name.
- Professional email address.
- Login credentials (passwords are stored using irreversible cryptographic hashing; we never store plaintext passwords).
- Access logs: date, time and IP address of each session.
- Profile information optionally provided: date of birth, location and profile photo.
- Platform language preference.
2.2 Organisation Data
- Organisation legal name, address and contact details.
- Billing information (payment card processing is handled by our payment provider; we do not store card data).
- Team and organisational structure as configured by the Client.
2.3 Operational Data
- Training plans, sessions and events created within the Platform.
- Athlete profile data: name, date of birth, position and profile photo.
- Physical data optionally recorded: height, weight and season participation minutes.
- Individual Development Plan (IDP): structured assessments across four domains — psychosocial, technical, tactical and physical — including strengths, areas for development, skill scores (rated 1–5), observations, and short, medium and long-term goals.
- Training plans (macro, meso and micro cycles), sessions, activities and events, including tactical notes, equipment requirements and session conditions.
- Files and attachments uploaded to the Platform.
2.4 Sensitive Data — Athlete Development Records
The CoachMap Platform enables Clients to build structured Individual Development Plans (IDPs) for athletes. Some data categories within the IDP may constitute sensitive personal data under applicable law (including GDPR Article 9 and LGPD Article 5, II). These categories include:
- Biometric and physical data: height, weight, body composition metrics, physical test results (such as speed, strength, endurance and agility assessments), and season participation minutes.
- Psychosocial assessments: structured evaluations of an athlete's psychological wellbeing, behavioural patterns, motivational profile, interpersonal dynamics, areas of emotional or social development, and support requirements identified by the coaching staff.
- Technical and tactical development assessments: skill-level evaluations, performance scores, coaching observations and short, medium and long-term development goals recorded by the Client's technical staff.
CoachMap processes this data exclusively as a Data Processor acting on documented instructions from the Client (Data Controller). The Client is solely responsible for: (i) ensuring a valid and adequate legal basis exists for processing each category of sensitive data — which will typically require explicit consent from the athlete or, where the athlete is a minor, from their parent or legal guardian; (ii) providing appropriate information notices to athletes and their guardians; and (iii) complying with all obligations under applicable data protection law, including LGPD Article 11 (for sensitive data) and GDPR Article 9.
CoachMap does not collect sensitive athlete data independently. All such data is entered directly by the Client's authorised coaching staff through the Platform interface. CoachMap applies the same technical and organisational security measures described in Section 8 to all data — all data is encrypted in transit and at rest.
2.5 Usage and Technical Data
- Browser type, device type and operating system.
- Pages visited and features used within the Platform.
- Performance and error logs used to maintain and improve the Platform.
3. How We Use Your Data
We process personal data only for the following purposes:
- To provide, operate and maintain the Platform and related services.
- To authenticate users and manage access to the Platform.
- To process payments and manage billing and contract records.
- To provide technical support and respond to enquiries.
- To improve and develop the Platform, using aggregated and anonymised usage data.
- To send service-related communications, such as invoices, maintenance notices and security alerts.
- To comply with legal and regulatory obligations.
We do not use Client Data for marketing purposes. We do not sell personal data to third parties.
4. Legal Basis for Processing
We process personal data on the following legal bases:
- Performance of a contract: processing necessary to deliver the Platform to the Client.
- Legitimate interests: improving the Platform through anonymised analytics and maintaining security, where these interests are not overridden by individual rights.
- Legal obligation: retaining records as required by applicable law.
- Consent: where we rely on consent for a specific processing activity, we will obtain it separately and you may withdraw it at any time without affecting the lawfulness of prior processing.
5. Data Sharing
We share personal data only as follows:
- Sub-processors: third-party service providers who help us operate the Platform, including cloud hosting, payment processing and email delivery. All sub-processors are contractually bound by data protection obligations no less protective than those in this Policy. A current list of sub-processors is available at coachmap.io/subprocessors.
- Legal requirements: where disclosure is required by applicable law, court order or regulatory authority.
- Business transfers: in connection with a merger, acquisition or sale of assets, personal data may be transferred to a successor entity subject to equivalent data protection commitments.
We do not sell, rent or share personal data with third parties for advertising or marketing purposes.
6. International Data Transfers
CoachMap is based in Brazil. When we process personal data from individuals in other countries, that data is transferred to and stored in Brazil. We ensure all such transfers are carried out under appropriate safeguards.
For transfers from the European Economic Area (EEA) and the United Kingdom, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision 2021/914). For UK transfers, we apply the UK Addendum to those SCCs where required. These clauses are incorporated into our Data Processing Agreement.
For transfers from other jurisdictions, equivalent contractual protections are applied in accordance with local law. A copy of the applicable transfer mechanism is available upon request at privacy@coachmap.io.
7. Data Retention
We apply different retention periods depending on the category of data:
Registration, billing and contractual records are retained for up to 5 years after the end of the Subscription, to comply with applicable fiscal and legal obligations (including Brazilian tax law and equivalent requirements in other jurisdictions).
Operational data entered by the Client, including athlete profiles, training plans and Individual Development Plan records, will be deleted within 30 days of account closure, unless the Client requests an export before that deadline. Upon termination, the Client may request a full data export within 30 days. After that period, we will securely delete all such data and a deletion certificate is available upon request.
Longer retention periods apply only where specifically required by applicable law.
8. Security
We maintain appropriate technical and organisational measures to protect personal data, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Multi-factor authentication (MFA) for administrator accounts.
- Role-based access controls applying the principle of least privilege.
- Automated encrypted backups with 30-day retention and periodic recovery testing.
- Continuous monitoring and audit logging with a minimum 12-month retention period.
In the event of a personal data breach likely to affect your rights, we will notify affected Clients and, where required, the relevant supervisory authority, in accordance with applicable law.
9. Your Rights
Subject to applicable law, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your data in certain circumstances.
- Restrict or object to certain processing activities.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, contact us at privacy@coachmap.io. We will respond within 15 days for requests under the LGPD, or within the timeframe required by the applicable law of your jurisdiction. You also have the right to lodge a complaint with the supervisory authority in your jurisdiction (including the ANPD — Autoridade Nacional de Proteção de Dados — in Brazil, available at gov.br/anpd).
10. Cookies
We use cookies and similar technologies as follows:
- Essential cookies: required for Platform functionality, including session management and authentication. These cannot be disabled.
- Analytics cookies: used to understand how the Platform is used in order to improve it. These can be disabled in your account settings.
We do not use advertising cookies or share cookie data with third-party advertisers. We do not currently respond to browser Do Not Track (DNT) signals, as there is no consistent industry standard for doing so.
11. Third-Party Services
The Platform uses third-party services for cloud infrastructure, transactional email and payment processing. These providers act as sub-processors and are listed at coachmap.io/subprocessors. We do not use third-party advertising networks, session recording tools or social media tracking pixels within the Platform.
12. Children
The Platform is intended for use by organisations and adult professionals. We do not knowingly collect personal data directly from individuals under 18. Where a Client uses the Platform in connection with youth athletes, the Client is the Data Controller for that data and is solely responsible for ensuring appropriate consents and lawful bases are in place.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify Clients of material changes by email at least 15 days before they take effect. The current version is always available at coachmap.io/privacy.
Data Processing Agreement
Incorporated into and forming part of the CoachMap Terms of Service · Last updated: May 2026
This Data Processing Agreement ("DPA") governs the processing of personal data by CoachMap on behalf of the Client in connection with the Platform. By subscribing to CoachMap, the Client enters into this DPA with CoachMap.
DPA 1. Definitions
Terms used but not defined in this DPA have the meanings given in the Terms of Service or in the GDPR (or applicable equivalent legislation). In this DPA:
- "Controller" means the Client, who determines the purposes and means of processing personal data.
- "Processor" means CoachMap, who processes personal data on behalf of the Controller.
- "Data Subject" means an identified or identifiable natural person whose personal data is processed.
- "Personal Data" has the meaning given in the GDPR or applicable equivalent law.
- "Processing" has the meaning given in the GDPR.
- "Sub-processor" means any third party engaged by CoachMap to carry out processing on behalf of the Controller.
- "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
DPA 2. Scope of Processing
- Subject matter: Processing of personal data of coaches, technical staff and athletes within the CoachMap sports planning platform.
- Duration: For the term of the Subscription plus any legally required retention period.
- Nature and purpose: Storing, displaying, backing up and making available personal data for the purpose of providing the Platform to the Controller.
- Types of personal data: Names, email addresses, professional roles, access logs, performance metrics and other operational data as described in Section 2 of the Privacy Policy.
- Categories of data subjects: Coaches, technical staff and other Users authorised by the Controller. Athlete data includes profile information (name, date of birth, position), physical measurements (height, weight, participation minutes) where entered by the Client, and structured development assessments across psychosocial, technical, tactical and physical domains. The Client, as Data Controller, is responsible for ensuring lawful basis for all athlete data entered into the Platform.
DPA 3. Processor Obligations
CoachMap shall:
- Process personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by applicable law.
- Ensure that personnel authorised to process personal data are subject to binding confidentiality obligations.
- Implement and maintain the technical and organisational security measures described in Section 8 of the Privacy Policy.
- Not engage any Sub-processor without prior authorisation from the Controller, as described in DPA 5.
- Assist the Controller in fulfilling its obligations to respond to Data Subject rights requests.
- Assist the Controller in ensuring compliance with security, breach notification, data protection impact assessment and prior consultation obligations.
- At the Controller's election, delete or return all personal data upon termination of the service, and delete existing copies unless retention is required by law.
- Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and allow for audits conducted by the Controller or a designated third-party auditor (no more than once per calendar year, with at least 30 days' prior written notice, at the Controller's cost), provided that such audits are conducted during normal business hours, do not unreasonably interfere with CoachMap's daily operations, do not access or expose the data of other CoachMap clients, and do not involve disclosure of CoachMap's proprietary source code, algorithms or technical infrastructure beyond what is strictly necessary to verify compliance with this DPA.
DPA 4. Controller Obligations
The Controller shall:
- Ensure it has a valid and lawful basis for processing each category of personal data submitted to the Platform.
- Provide appropriate privacy notices to Data Subjects as required by applicable law.
- Not instruct CoachMap to process personal data in a manner that would violate applicable law.
- Be solely responsible for obtaining any consents required for processing personal data relating to minors.
- Promptly notify CoachMap of any change in applicable data protection law that may affect CoachMap's processing obligations.
DPA 5. Sub-processors
The Controller grants CoachMap general written authorisation to engage the Sub-processors listed at coachmap.io/subprocessors. CoachMap will notify the Controller of any intended additions or replacements at least 15 days in advance. The Controller may object on reasonable grounds within that period by written notice to privacy@coachmap.io. If the parties cannot resolve the objection within 15 days, either party may terminate the affected service without penalty.
CoachMap imposes data protection obligations on all Sub-processors no less protective than those in this DPA and remains fully liable for their compliance.
DPA 6. International Data Transfers
Where personal data is transferred from the EEA or the UK to CoachMap in Brazil, such transfers are made under the Standard Contractual Clauses (SCCs) approved by the European Commission (Module 2 — Controller to Processor, Implementing Decision 2021/914). For UK transfers, the UK Addendum to those SCCs is applied where required.
The SCCs are incorporated into this DPA by reference. In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail. A copy is available at privacy@coachmap.io. For transfers from other jurisdictions, CoachMap applies equivalent contractual protections consistent with applicable local law.
DPA 7. Security Incidents
CoachMap will notify the Controller without undue delay following confirmation of a Security Incident that has demonstrably affected Controller personal data. The notification will include, to the extent then available: the nature of the incident; categories and approximate number of affected data subjects and records; likely consequences; and measures taken or proposed. CoachMap will not be required to notify the Controller of security events that are investigated and determined not to constitute a confirmed Security Incident affecting personal data.
The Controller is responsible for notifying the relevant supervisory authority and affected Data Subjects in accordance with applicable law.
DPA 8. Data Protection Impact Assessments
CoachMap will provide reasonable assistance to the Controller in carrying out data protection impact assessments (DPIAs) and, where required, prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to CoachMap.
DPA 9. Term and Termination
This DPA remains in effect for as long as CoachMap processes personal data on behalf of the Controller and terminates automatically upon expiry or termination of the Terms of Service. Obligations relating to data deletion, confidentiality and ongoing legal requirements survive termination.
DPA 10. Governing Law
This DPA is governed by the laws of Brazil. Where mandatory provisions of the Controller's applicable data protection law impose specific requirements on data processing agreements, those provisions shall form part of this DPA and prevail in the event of any conflict.