LEGAL

Privacy Policy

Who processes personal data on this platform, on what basis, and who is responsible for responding.

Last updated: 16 August 2026

1. Who we are and how to reach us

Cantera is operated by [POR PREENCHER — nome do titular], tax number [POR PREENCHER — NIF], with address at [POR PREENCHER — morada], and is available at canterasports.com and its subdomains. For any matter — including data protection and the exercise of data subject rights — the contact point is geral@canterasports.com. There is no obligation to appoint a Data Protection Officer under Article 37 of the UK/EU GDPR: our core activity consists neither of the large-scale processing of special categories of data nor of the regular and systematic monitoring of data subjects on a large scale.

2. Our two roles

This is the most important distinction in the document, and everything else depends on it — including who is responsible for answering a data subject's request. Cantera acts in two different roles, depending on the data concerned:

  • Data controller, for the data collected directly by us and whose purposes and means we determine: the account and authentication, subscription billing, customer support communications, and technical and security logs.
  • Data processor, under Article 28 GDPR, for all information that the club enters into the platform — athletes, guardians, members, staff, clinical data, school data, financial information, training sessions, matches and observations. In those cases the data controller is the club: it falls to the club to establish the lawful basis, obtain any necessary consents, inform the data subjects and respond to their requests. We process that data solely on the instructions of the club and to the extent necessary to provide the service to it.

In other words: Cantera builds and operates the tool; it is the club that decides what information is recorded in it and for how long. The terms of this processing form part of the contract entered into with the club.

3. What data is processed and on what basis

Each processing operation rests on a lawful basis under Article 6 GDPR. The two roles described in the previous section are kept apart:

As data controller

  • Account and profile: name, email, password (stored as a hash), language and appearance preferences and, where the «Continue with Google» option is used, the identifier of that account. Basis: performance of a contract (Article 6(1)(b)).
  • Subscription billing: details of the subscribing club and payment history. Basis: performance of the contract and compliance with a legal obligation (Article 6(1)(b) and (c)).
  • Customer support: the messages received and whatever is needed to answer them. Basis: performance of a contract and legitimate interests (Article 6(1)(b) and (f)).
  • Technical and security logs: IP address, user-agent and the time of the request, in order to detect abuse and diagnose faults. Basis: legitimate interests (Article 6(1)(f)).
  • Optional communications: only upon express request, and revocable at any time. Basis: consent (Article 6(1)(a)).

As data processor, on behalf of the club

  • Sporting data: teams, squads, training attendance, call-ups, matches, minutes played, events and statistics.
  • Personal records: athletes, guardians, staff and members — identification, contact details, photograph and documents.
  • Clinical data, where the club enables the corresponding module: injuries, treatments, medical examinations and sporting availability.
  • School data, where the club enables the corresponding module: educational establishment and school reports.
  • Financial information: monthly fees, payment notices, receipts and payments made by families to the club.
  • Member data: enrolment, category, membership fees and membership card.

For every processing operation in the second column, the lawful basis is determined by the club, not by us — typically the performance of the registration contract entered into with the athlete or with their legal representative.

4. Minors, health and school

Most of the data subjects whose data passes through this platform are children and young people, and part of the information is sensitive. It deserves to be said plainly:

  • Minors. The registration of a minor athlete is carried out by the club, with the involvement of the guardian, who is linked to the athlete's record. In Portugal, Portuguese Law 58/2019 sets 13 years as the minimum age at which a data subject may consent directly; below that age consent falls to the holders of parental responsibility. It falls to the club to ensure that this framework is respected.
  • Health. If the club enables the clinical module, injuries, treatments, medical examinations and the sporting availability of the athlete are recorded. These are special categories of data (Article 9 GDPR) and may be processed only under Article 9(2)(h) — sports medicine and health care by a professional bound by professional secrecy — or on explicit consent (Article 9(2)(a)). The applicable basis is determined by the club. Within the platform, access to this information is limited to those to whom the club has expressly granted the corresponding permission; that control applies to the record held in the platform and may not extend to the direct address of an uploaded file.
  • School. If the club enables the school module, the educational establishment and the school reports of the athlete may be recorded. The detailed information is locked behind a consent recorded on the athlete's file: while that consent does not exist, the platform does not even query it. The club may also permanently delete all detailed school data of an athlete, at any time.
  • Photographs. The file of an athlete, of a member or of a member of staff may include a photograph, uploaded by the club. It falls to the club to obtain the necessary authorisations, with the added care that the image of a minor demands.

A guardian wishing to know what information exists about their child, or to have it removed, should approach the club — the club is the data controller. See section 10.

5. When information leaves the platform

Not everything happens within the screen of a signed-in user. These are the principal situations in which information leaves the platform, and they are worth knowing:

  • Links accessible without a password. So that a guardian may confirm a call-up, or a family pay a notice, without having to create an account, links are generated with a long, unpredictable code specific to that call-up, that document or that membership card. They give access to nothing else — but whoever holds the link can open it. Such a link should therefore be treated as an access code, and not forwarded to anyone who should not see that information.
  • Emails sent by the club. Call-ups, payment notices, payment reminders, thank-you messages and birthday greetings leave the platform on behalf of the club, to the contact details recorded by the club.
  • Device notifications. Where these are authorised in the browser, delivery passes through the notification service of the maker of that browser (for example Google, Mozilla or Apple). That service receives what is needed to deliver the notification; it is neither engaged nor controlled by us. The authorisation may be revoked at any time in the browser settings.
  • Federation documents. The platform generates official forms pre-filled with the data of the athlete — namely Modelo 1 and Modelo 2 of the federation and Modelo 9 of the IPDJ, the Portuguese institute for sport and youth — intended to be submitted to those bodies. Submission is carried out by the club and at its own decision.

In every case, the information of a club is not visible to another club: every query is filtered by the club of the user.

6. Subprocessors

In order to provide the service we rely on the suppliers below, all contractually bound by obligations of confidentiality and of compliance with the GDPR:

  • Supabase — database, file storage and real-time synchronisation. Infrastructure in the European Union (Frankfurt).
  • Vercel — application hosting and execution of the automated tasks. Infrastructure in the European Union (Frankfurt).
  • Stripe Payments Europe (Ireland) — club subscription and payments by families. We do not store card numbers.
  • EasyPay (Portugal) — payments by families through MB WAY and Multibanco.
  • Resend (United States) — delivery of transactional emails.
  • Google (United States) — solely the optional «Continue with Google» authentication. Where that option is not used, no data is communicated to it.

We never sell, transfer or share personal data for advertising or marketing, whether ours or that of third parties. Nor do we use third-party analytics: there is no Google Analytics or any other audience-measurement tool in this application. Data may be disclosed where the law or a competent authority so requires, and any material change to this list is communicated in advance.

7. Where the data is held

The data of the club and of its athletes is stored on servers in the European Union (Frankfurt). Some of the suppliers listed above have a parent entity outside the European Economic Area — that is the case, among others, of Supabase, Vercel, Stripe, Resend and Google. In those cases the safeguards of Chapter V GDPR apply: adherence to the EU-US Data Privacy Framework and/or Standard Contractual Clauses, accompanied by encryption in transit and at rest. Payment processing through EasyPay, a Portuguese company, remains within the European Union.

8. How long data is kept

Data processed by us as controller

  • Account: for as long as it remains active and, where deletion is requested, for up to 30 days after that deletion.
  • Billing: for the tax retention period legally required in the applicable jurisdiction.
  • Technical and security logs: 90 days.

Data processed on behalf of the club

  • During the contract: for as long as the club remains a customer, and in accordance with the retention decisions it takes.
  • After termination: the club has 30 days to export the information, after which the data is permanently deleted.

Mandatory statutory periods — in particular tax and accounting obligations — prevail over those indicated above.

9. Security and personal data breaches

Technical and organisational measures appropriate to the risk are applied:

  • Encryption in transit (TLS) and at rest.
  • Isolation between clubs: every database query is filtered by the club of the user making it, so that the information of one club cannot be reached from another.
  • Access control by group and permission: within the club, each user sees only the areas and the teams assigned to them by the club, with the sensitive areas — such as clinical and school information — requiring their own permission.
  • Logging of sensitive operations and continuous monitoring of the platform.

Personal data breach. Should a breach occur affecting data processed on behalf of a club, that club — as the data controller — is notified without undue delay and within 72 hours at the latest of us becoming aware of it, in accordance with Article 33(2) GDPR.

10. Data subject rights and how to exercise them

The data subject has the rights provided for in Articles 15 to 22 GDPR:

  • Access — to know what data exists and to obtain a copy.
  • Rectification — to correct inaccurate or outdated data.
  • Erasure — the «right to be forgotten», where applicable.
  • Restriction of processing.
  • Objection to processing.
  • Portability — to receive the data in a structured, machine-readable format.
  • Withdrawal of consent at any time, where consent is the basis of the processing, without affecting the lawfulness of what was processed beforehand.

The addressee of the request depends on the role involved (section 2). As regards account, billing and customer support data, the contact point is geral@canterasports.com. As regards data that a club has entered into the platform — concerning athletes, guardians, members or staff — the request should be addressed first to that club, which is the data controller and the only party able to decide upon it; any such request reaching us is forwarded to the club concerned, in accordance with Article 28(3)(e) GDPR. No automated individual decisions producing legal effects on data subjects are taken (Article 22). There is also the right to lodge a complaint with the supervisory authority: the CNPD in Portugal, the AEPD in Spain, or — under the UK GDPR — the ICO in the United Kingdom.

11. Cookies and local storage

Only what is necessary for the platform to work is used — keeping the session signed in, protecting against request forgery, and remembering language and appearance preferences. No advertising or audience-measurement cookies are used. The full list, with the name, purpose and duration of each one, is set out in our Cookie Policy.

12. Changes to this policy

This policy may be updated. Material changes are communicated at least 30 days in advance, by email to registered users and by notice on the platform. The version in force is the one published on this page, and the last-updated date at the top always reflects it. For any question, the contact point is geral@canterasports.com.