Live · Season 2026/27
MK

Legal

Privacy Notice

v1.0 · Last updated August 2026

This notice explains how [Your Company Ltd] ("we") handles personal data in Apex PMS. It applies to club administrators, coaches, medical staff, athletes and guardians.

Who is responsible for your data

Where a club, school or academy uses Apex PMS to manage its athletes, that organization is the data controller and decides what data is recorded. [Your Company Ltd] acts as a data processor on their instructions. For account holders and billing, [Your Company Ltd] is the controller.

Contact: [privacy@yourdomain.com] · Data protection contact: [dpo@yourdomain.com] · [Registered address, Ireland]

What we collect

  • Account data: name, email address, organization, role and authentication records.
  • Athlete profile data: name, date of birth, team, playing position and availability status.
  • Wellness data: daily sleep, fatigue, soreness, stress and mood scores, and the readiness score derived from them.
  • Training, attendance and testing data: session participation, loads and physical test results.
  • Health data: injury records, body area, severity and return-to-play stage. This is special category data under Article 9 GDPR.
  • Consent records: who consented, when, the policy version, and guardian details for under-16 athletes.
  • Access logs: which staff member viewed an athlete's medical file and when.
  • Billing data: subscription plan and payment status. Card details are handled by Stripe and never stored by us.

Why we use it and our lawful basis

  • To provide the platform to the organization — performance of a contract (Article 6(1)(b)).
  • To monitor athlete wellbeing and manage injury risk — legitimate interests of the organization, balanced against athlete rights (Article 6(1)(f)).
  • To process health and injury data — explicit consent from the athlete, or from a parent/guardian for athletes under 16 (Article 9(2)(a)).
  • To take payment and meet accounting obligations — contract and legal obligation.
  • To keep the service secure and prevent misuse — legitimate interests.

Children and guardian consent

In Ireland a child under 16 cannot give valid consent to the processing of their data in an online service. Where an athlete is under 16, Apex PMS requires a recorded parental or guardian consent — capturing the guardian's name, relationship, email address and the date consent was given — before health data is processed. Consent can be withdrawn at any time by contacting the club or [privacy@yourdomain.com], and withdrawal is recorded against the athlete's file.

Who can see what

  • Coaches see wellness, attendance, training and testing data for their organization.
  • Injury and medical records are restricted to users with the medical or admin role. Coaches see only availability status, not clinical detail.
  • Every access to a medical record is written to an audit log visible to admin and medical staff.
  • Athletes can see their own records. Data is never shared between organizations.

How long we keep it

Each organization sets a retention period (three years by default) after which athlete records are deleted or anonymised. Billing records are kept for six years to meet tax law. Accounts closed by a customer are deleted within 30 days of the end of the subscription, subject to any legal hold.

Your rights

  • Access — get a copy of the data held about you.
  • Rectification — correct data that is wrong or incomplete.
  • Erasure — have your data deleted where there is no overriding reason to keep it.
  • Restriction and objection — limit or object to certain processing.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting processing already carried out.

Requests go to your club in the first instance, or to [privacy@yourdomain.com]. We respond within one month. You can also complain to the Data Protection Commission (Ireland).

Security

  • Data is encrypted in transit and at rest by our hosting provider.
  • Row-level access rules mean an organization's data can only be read by its own members.
  • Medical records are gated behind a dedicated role and access is logged.
  • Passwords are hashed; we never see or store them.

Sub-processors and transfers

We use a small number of vetted providers listed on our subprocessors page. Where data is transferred outside the EEA, it is covered by the European Commission's Standard Contractual Clauses.

Not medical advice

Apex PMS is a record-keeping and monitoring tool. Readiness scores, load metrics and return-to-play stages are informational only and are not a medical diagnosis, treatment plan or clinical decision-making system.

This document is a starting template provided with Apex PMS. Replace the bracketed placeholders with your own company details and have it reviewed by a qualified solicitor before you sign customer contracts.