padelistoES

Privacy Policy

Version 2026-07-22 · Effective 22 July 2026

This policy explains how The Applications Cloud, Sociedad Limitada (S.L.U.), Placa La Pau 1, piso 3, puerta 1, 08960 Sant Just Desvern (Barcelona), Spain, NIF/CIF B44614964 (“padelisto”) processes personal data. Full registration details appear in our Legal Notice. Contact: legal@theapps.cloud.

1. Our roles

We are a controller for business-account registration, contract acceptance, support, security, service administration and our marketing website. A club or coach is normally the controller for player, parent and guardian data entered into its workspace; for that data we act as its processor under our DPA. Players should normally direct requests to their club, and we will assist the club.

2. Data we process

  • Business account data: name, organisation, email, language, timezone, credentials and legal acceptance records.
  • Player and guardian data: names, WhatsApp or Telegram identifiers, phone numbers, language, adult/child indicator and parent-child relationship.
  • Service records: bookings, attendance, cancellations, balances, manual payment records, subscriptions, levels and notes.
  • Messaging data: message content, voice notes and transcripts, delivery/routing metadata, contact and group metadata, owner-handoff records and AI input/output.
  • Integration data: Google Calendar identifiers and encrypted OAuth tokens, locations and map queries, webhook metadata and connected-channel settings.
  • Technical data: IP address, browser/device data, timestamps, security events, diagnostic logs and aggregate website analytics.
  • Support data: correspondence, request details and evidence used to verify an export or deletion request.

3. Why and on what basis

As controller, we process data to enter into and perform the business contract, provide and secure the Service, prevent misuse, respond to requests and meet legal obligations. Our bases are contract, legal obligation and legitimate interests in operating a secure business service. Optional padelisto marketing requires consent where applicable and can be withdrawn at any time. The club determines the lawful basis for player processing and messaging.

4. Children

The Service is contracted only by adults acting professionally. It can store a minimal child profile under a parent or guardian account. Clubs must provide age-appropriate information and obtain parental or guardian authority where local law requires it. In Spain, processing based on a child’s consent requires parental or guardian consent when the child is under 14. Clubs should route child service messages through the responsible adult and avoid collecting a full date of birth unless independently necessary.

5. AI processing

Message or audio content needed to answer a request may be sent through OpenRouter to an approved Google or OpenAI inference endpoint. We require zero-data-retention routing and do not permit model training on this content. If a compatible zero-retention endpoint is unavailable, the AI function is disabled. The Service does not make solely automated decisions producing legal or similarly significant effects.

6. Recipients and providers

Our processors include Railway (hosting and storage), Resend (transactional email), OpenRouter and approved model endpoints (AI inference), Google services used as infrastructure/API processors, and Plausible (aggregate website analytics). Current details, locations and safeguards are in the Vendor Register.

Meta/WhatsApp, Telegram and Google Calendar are independently operated services that a club chooses to connect. They may process data for their own purposes under their own terms and are not automatically our subprocessors.

7. International transfers

Where data leaves the EEA, we rely on an adequacy decision or an applicable Data Privacy Framework certification where available, or the European Commission Standard Contractual Clauses with a transfer assessment and supplementary technical and organisational safeguards. Copies or further information are available on request.

8. Retention

  • Active workspace data: for the service relationship or until the club instructs deletion.
  • Unactivated workspaces: 14 days after registration.
  • Owner-handoff message content: 90 days after resolution; routing metadata: 30 days after inactivity.
  • Transactional email content and metadata at Resend: up to 30 days.
  • Pseudonymised production technical logs: up to 30 days.
  • Privacy-request records: 3 years after completion.
  • Blocked contract and DPA evidence: 5 years after the relationship ends.
  • Plausible aggregate analytics: 24 months.

Following a verified tenant deletion, active application data is removed when the operation completes. Railway volumes and their backups are queued for permanent deletion within 48 hours. Data legally required for claims or compliance is isolated, access-restricted and not used for ordinary business purposes.

9. Export and deletion requests

A workspace owner may contact support, including through WhatsApp. WhatsApp starts the request but does not authorise it. We send a single-use verification link to the owner email on file. An administrator can then prepare a portable export or delete the tenant. Export archives exclude passwords, API secrets, OAuth refresh tokens, private calendar/webhook tokens and WhatsApp authentication keys.

10. Security

Measures include tenant isolation, access control, encrypted transport, encryption of selected credentials at rest, secret separation, audit logging, backups, incident response, data minimisation and restricted administrator access. No system is completely secure; we review measures according to risk.

11. Your rights

Subject to the GDPR, you may request access, correction, erasure, restriction, portability or object to processing, and withdraw consent without affecting earlier processing. We may need to verify identity. If we process player data only for a club, we will refer the request to that club and assist it.

You may complain to the Spanish Data Protection Agency (AEPD) or another competent EEA supervisory authority.

12. Website analytics and cookies

We use Plausible in its cookie-free configuration for aggregate traffic statistics. We do not send account IDs, message content, email addresses or URL query strings to Plausible. Essential session and security cookies may be used in authenticated applications. We do not use advertising cookies.

13. Changes and contact

We will post updated versions and provide additional notice for material changes. Questions and rights requests: legal@theapps.cloud.