Data Processing Agreement
Version 2026-09-23 · Applies to agencies that manage athletes on AthlyAI
Please have this reviewed. This agreement describes accurately how the platform actually works, and every security measure and retention period below comes from the setting the code enforces. It is not legal advice. Before you rely on it, have your own counsel review it — and if a clause does not match how your agency operates, write to us and we will amend it rather than leave you with a document that does not fit.
1.The parties, and who decides what
This agreement is between Lorenzo Peluso, trading as athlyai.com (Sole Trader (ditta individuale, Italy), VAT IT01888280888, Via Resistenza Partigiana 27/O, 97015 Modica (RG), Italia) — the Processor — and the agency that holds an AthlyAI agency account — the Controller.
The split is not a formality, and it is worth being blunt about it. For the athletes your agency adds to its roster, you decide: what you collect, on what legal basis, what you tell those athletes, and for how long you keep working with them. We hold and process that data on your instructions, and we do not use it for our own purposes.
There is one exception, stated here so it is not a surprise later. The coach directory is ours: we compile it from publicly published university athletics staff directories and we are the controller of it. When you email a coach through the platform, you are the controller of that email — its content, its timing, and the decision to send it.
2.What we process, and why
Subject matter and duration. Providing the AthlyAI agency platform, for as long as your account is open, plus the wind-down period in §11.
Nature and purpose. Storing athlete records and media; composing and sending outreach email on your behalf; recording delivery, opens, clicks and replies; giving your staff an inbox and an assistant over that material.
Categories of data subject:
- athletes on your roster, including minors (see §12);
- parents or guardians, where you record their details;
- college coaches you contact, and anyone who replies from their mailbox;
- your own staff, as users of the platform.
Categories of personal data:
- identity and contact details, date of birth, nationality, and the school and academic details you enter;
- sporting data: position, measurements, results, and video and photographs you upload;
- email content you send and replies you receive, plus delivery and engagement events (delivered, opened, clicked, bounced);
- account and log data for your staff: email address, role, sign-in records, and technical logs.
We do not ask for special category data under Article 9 and the product has no field for it. If you put it into a free-text field anyway — an injury history, a medical note — it is processed as ordinary text, with no additional safeguard, and that choice is yours.
3.Instructions
We process personal data only on your documented instructions. In practice your instructions are the actions your staff take in the product and the settings you choose, plus anything you send us in writing. If we believe an instruction breaches the GDPR or other EU or Member State law, we will tell you and may pause that processing until it is resolved.
If law requires us to process data beyond your instructions, we will inform you before doing so unless that law forbids the notice on important grounds of public interest.
4.Confidentiality
Everyone we authorise to process your data is bound by confidentiality. Today that is a small, named group; access to production data is limited to what is needed to run and support the service.
Two commitments that matter more than the sentence above, because they are the ones that get quietly broken: we do not read your athletes’ or coaches’ messages except when you ask us for support on a specific thread or where it is strictly necessary to fix a failure, and we do not use your data to train AI models.
5.Security measures (Article 32)
These are the measures in force, not a wish list. Each one is enforced by the system rather than by a habit:
- Encryption. In transit (TLS) everywhere, and at rest on the database and file storage.
- Tenant isolation. Every read and write is scoped to your agency, and every agency table has row-level security on with no public policy: nothing reaches the data except through server code that has already resolved who is asking. An advisor sees only the athletes assigned to them — including in the inbox, so a reply about an athlete they do not follow does not appear.
- Private media. Photographs and video are in private buckets and are served through short-lived signed URLs, never from a public link.
- Sending controls. Email goes out from your own connected mailbox or your own verified domain. Provider send limits are enforced before each send, duplicate outreach to the same coach is blocked, and every message carries a working one-click unsubscribe.
- Consent. The platform does not hold a send on consent, for adults or for minors. You record the consent you have collected, and collecting and recording it is your obligation as controller. We cannot verify the consent behind a record, so we do not claim to enforce one we cannot check.
- Resilience. Managed, backed-up database with point-in-time recovery.
- Masked telemetry. Session replay masks form inputs, so what your staff type is not captured.
6.Sub-processors
You give general authorisation for us to use the sub-processors below. We will tell you at least 30 days before a new one starts, so you can object; if you object on reasonable data-protection grounds and we cannot offer an alternative, you may terminate the affected service without penalty.
| Sub-processor | What it does | Location |
|---|---|---|
| Supabase | Database, authentication and file storage. Every record and file: athlete profiles, media, coach contacts, email bodies and delivery events. | EU (eu-central-1) |
| Vercel | Application hosting and serverless compute. Runs the application. Data passes through in memory during each request. | EU / US |
| Resend | Email delivery. Sends email from an agency’s own verified domain, and receives coach replies. Carries recipient address, subject and body. | US |
| Google (Gmail API) | Email delivery, only when an agency connects a Google mailbox. Sends from the agency’s own mailbox, on the agency’s own Google account, under a send-only scope. | US / global |
| Microsoft (Outlook / Graph API) | Email delivery, only when an agency connects a Microsoft mailbox. Same as above, on the agency’s own Microsoft account. | US / global |
| Groq | AI inference. Drafting and assistant answers. Receives the athlete and coach details needed for the text on screen. | US |
| Moonshot AI (Kimi) | AI inference. Same as Groq: drafting and assistant answers. | Non-EU |
| Google (Gemini API) | AI inference. Same as Groq: drafting and assistant answers. | US / global |
| Stripe | Payments. Subscription billing. Receives the agency’s own billing details — NOT athlete or coach data. | US / EU |
| Sentry | Error monitoring. Stack traces and request context when something fails. Not a data store: it receives whatever is in scope at the moment of an error. | EU |
| PostHog | Product analytics and session replay. Usage events and replays of agency staff sessions. Form inputs are masked (see the privacy policy). | EU |
Each of them is bound by terms no less protective than these. We remain responsible to you for what they do.
7.International transfers
Some sub-processors above are outside the EEA. Those transfers rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision where one covers the provider. If a mechanism we rely on is invalidated, we will move to a valid one or stop the transfer.
One point specific to this product: when your agency connects its own Google or Microsoft mailbox, the email is sent through your provider under your account. That relationship is between you and them, and it sits outside this agreement.
8.Retention and deletion
Records you create stay for as long as you keep them, because that is your decision to make. On top of that, the platform enforces its own maximum periods automatically:
- 365 days — the body text of outreach emails and of coach replies is redacted after this. The fact of the exchange (who, when, delivered, opened, replied) is kept, because it is what stops a coach being contacted twice and what proves a reply arrived; the words are not.
- 90 days — IP addresses and user agents attached to opens and profile views are anonymised.
A coach can ask to be removed from the directory at any time, and that removal also stops any further contact from any agency on the platform.
9.Helping you answer data subjects
If an athlete, a parent or a coach exercises a right — access, rectification, erasure, portability, objection — the request goes to you as controller, and we help you answer it.
Mostly you will not need us: from the athlete’s page you can export a complete machine-readable copy of everything held about them, and deleting the athlete removes the record and the associated files. Where a request needs something the product does not cover, write to privacy@athlyai.com and we will respond within 30 days. If a request reaches us directly, we will not answer it on your behalf: we will pass it to you and tell the person we have done so.
10.Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any case within 48 hours. The notice will describe what happened, which categories and roughly how many records are affected, the likely consequences, and what we are doing about it. Where we do not yet know something, we will say so and follow up rather than delay the first notice until the picture is complete.
Notifying your supervisory authority and the people affected is your call as controller. We will give you what you need to make it.
11.What happens when you leave
While your account is open you can export everything from the product at any time, athlete by athlete, in a machine-readable form. Do that before you leave: it is the fastest route and it needs nothing from us.
On termination, tell us whether you want your data returned or deleted, and we will do it within 30 days of the request. We are describing a process that runs on a request, not an automatic wipe on a timer — saying otherwise would be promising you something no part of this system performs today. Until you ask, the data stays as it is, still covered by this agreement, and still subject to the maximum retention periods in §8, which run regardless.
Anything we are required to keep by law stays subject to this agreement for as long as we hold it.
12.Minors
Many athletes on a recruiting roster are under 18, and the platform is built on that assumption rather than treating it as an edge case. The minimum age for an account is 16.
Guardian consent is yours to obtain and hold. Where an athlete is a minor, you must have the consent of a parent or guardian before their data is shared with coaches, whether by email or through an athlete page or showcase link you send. The platform does not stop a send or hide a page when that consent is not recorded: you represent that you hold it whenever you contact a coach on a minor’s behalf. We cannot verify the consent behind a record, and we do not claim to.
What the platform does do for minors: an athlete page is never offered to search engines unless the athlete’s recorded date of birth makes them an adult, and the consent fields remain available on every athlete so you can record who gave consent and when.
13.Audits
We will make available the information needed to show we comply with Article 28, and allow and contribute to audits. In practice, ask us: for a small provider, an honest written answer and the evidence behind it is worth more than a certificate nobody reads, and we would rather give you that than a slide. Where an on-site audit is genuinely necessary, we will agree reasonable notice and scope.
14.Order of precedence, language, changes
This agreement forms part of the Terms of Service. Where it conflicts with them on the processing of personal data, this agreement wins.
Language. The English text is the one that governs. Other pages of this site are machine-translated; this one is not, deliberately — an automatically translated contract clause is a risk, not a service.
Changes. If we change this agreement in a way that reduces your protection, we will tell you at least 30 days beforehand and you may terminate if you do not accept it. The version is at the top of this page.
Governing law. Italian law, courts of Ragusa, Italy — the same as the Terms of Service.
15.Contact
Data protection questions: privacy@athlyai.com. Registered address: Via Resistenza Partigiana 27/O, 97015 Modica (RG), Italia. Certified email (PEC): lorenzo.peluso@pec.fiscozen.it.
We have not appointed a Data Protection Officer: we are below the Article 37 thresholds. Write to the address above and it reaches a person, not a queue.