Security & Privacy

Highest-standard security & data protection.

Trusted by the Cyprus Football Association with national-team data. Compliant with GDPR, Cyprus data protection law, and EU regulation. Built for minors' data with age-appropriate safeguards.

Compliance & standards

What we commit to — every client, every contract.

01

GDPR Compliant

Full compliance with EU General Data Protection Regulation (Regulation 2016/679). Data minimisation, purpose limitation, lawful basis for processing, right to access and erasure.

02

Cyprus Law 125(I)/2018

Compliant with Cyprus's Protection of Natural Persons with Regard to the Processing of Personal Data law. Governed by the laws of the Republic of Cyprus.

03

EU Data Residency

Match data, video and player records hosted on enterprise cloud infrastructure (AWS) in European Union regions. Your data stays in the EU.

Built for minors' data

Player privacy by design.

We work with U14–U19 players. Their data deserves more protection, not less. Our platform is designed around that reality.

Player Privacy by Design

Players see only their own data. No cross-player comparisons shown to the player themselves. No public profiles. Names and identifiers handled only as needed.

Role-Based Access Control

Every user accesses only what their role requires. Coaches see their team. Directors see their academy. Scouts see only clubs they're granted access to. Strict boundaries enforced at the platform level.

Confidentiality by Contract

Every client contract includes explicit confidentiality of match analysis, reports, video clips and player data. Used solely for the client's internal sporting purposes.

Data handling

How we treat your data.

What we collect

Match video, event-level data (220 labels per match), player performance metrics, derived metrics from SCIOS proprietary indices.

What we don't collect

Personal data beyond what's needed for sporting analysis. No financial data, no medical data (unless explicitly part of a fitness programme).

How long we keep it

Match data and clips kept for the contract duration plus an agreed retention period. Upon contract termination, data is returned or permanently deleted per the client's instructions, with written certification.

Who can access it

Only authorised users from the client organisation, plus the SCIOS analysts contracted to deliver the service. Multi-tenant isolation enforced at the platform level.

How we share it

Never. Client data is never shared with other clients, used for marketing, sold, or licensed to third parties — except with the client's explicit written consent.

If something goes wrong

Documented breach response process. Notification to affected clients within 72 hours per GDPR. Cooperation with the Cyprus Commissioner for Personal Data Protection.

Infrastructure

Modern cloud, highest-standard.

Cloud hostingAWS (EU regions)
DatabasePostgreSQL · Redis · DuckDB
ApplicationAngular 20 SPA · Go (Gin) API
AuthenticationEmail + password · SSO available for enterprise
EncryptionTLS 1.2+ in transit · Encrypted at rest
BackupsAutomated daily · Multi-region redundancy
Access logsAll user activity logged for audit
TerminationReturn or permanent deletion of all data per client request, certified in writing
Legal

Documents & references.

Detailed legal documents available below. For procurement teams, security questionnaires and DPAs (Data Processing Agreements) available on request.

Privacy questions: privacy@scienceofsports.net