Privacy Policy
Last updated: 20 July 2026This policy describes how Paak collects, uses and protects the personal data processed on paak.club and within the Paak application. It is written in compliance with the Swiss Federal Act on Data Protection (FADP, revised version in force since 1 September 2023) and, where applicable, the European General Data Protection Regulation (GDPR — EU Regulation 2016/679).
1. Controller
Emmara by Cyrille Barraud, Swiss sole proprietorship (UID CHE-309.503.616), St. Alban-Anlage 25, 4052 Basel, Switzerland.
For any question related to personal data: contact@paak.club.
2. Who this applies to: visitor, app user, or club member
Three distinct situations must be distinguished:
- Visitors of paak.club (marketing site) — you browse our public pages or fill in a contact form. Your data is processed by Paak.
- Paak app users (club directors, coaches, staff) — you have created an account and manage a club. Your account data is processed by Paak.
- Members of clubs managed in Paak (members, parents, minors) — your data has been entered by the club that registered you. In this case the club is the controller and Paak acts only as a processor (art. 9 FADP / art. 28 GDPR). For any question about your rights, contact your club first.
3. Data we collect
3.1 Visitors of paak.club
- Contact form / waitlist — first name, last name, email, declared role, club. Legal basis: consent (art. 6 FADP; art. 6(1)(a) GDPR).
- "Le Vestiaire" newsletter — email address, language, request and confirmation dates. Subscription is double opt-in: a confirmation email is sent and your address only joins the mailing list after you click the confirmation link (valid 48 hours); the timestamp of that confirmation is kept as proof of consent. Legal basis: consent (art. 6 FADP; art. 6(1)(a) GDPR), withdrawable at any time via the unsubscribe link present in every email. Sending goes through our processor Brevo (France, EU); your address is used for nothing else.
- Technical data — truncated IP address, browser type, pages viewed, via our self-hosted Matomo instance. Only collected if you accept analytics cookies.
3.2 App users (admin / staff accounts)
- Authentication credentials (email, Hanko session), first and last name, role in the club.
- Billing data if you upgrade to a paid plan (billing email and name).
- Minimal technical logs required for operation and security (access logs, connection history, failed attempts).
3.3 Data entered by clubs in the app
Clubs enter in Paak the data they need to manage their activity: member details, licences, fees, coaching, attendance, equipment. Paak hosts and secures this data on behalf of the club, without exploiting its content.
Two categories deserve a specific mention. Liability waiver: if the club has enabled a waiver at registration, the member's (or their legal guardian's) electronic signature is recorded together with the typed name, timestamp, IP address, browser identifier and a cryptographic fingerprint of the signed text — these elements constitute the proof of signature and are retained as such (see section 7). Gender: an optional field entered by the club or the member; it serves federation requirements (competition categories, licences) and aggregated, anonymised statistics — never individual profiling.
3.4 Member portal (account-less)
Every member can access a member portal without creating an account: the club emails them a secure personal link, and sensitive areas (profile, documents) additionally require a one-time code sent by email. The club remains the controller; Paak acts as processor (see section 2). In this context Paak processes:
- Portal session data — cryptographic hash (SHA-256) of the link and one-time code (never stored in clear text), creation / last-activity / expiry / revocation timestamps, IP address and browser. Purpose: portal operation and security (rate limiting, abuse detection). Justification: performance of the contract with the club and legitimate security interest.
- Documents voluntarily submitted by the member — medical certificate or licence, uploaded via the portal with explicit, versioned consent collected at the moment of upload (health data: art. 5 lit. c FADP; art. 9 §2 a GDPR). Files are encrypted at rest in dedicated storage and accessible only to the member's club, which reviews and validates them. Online upload is optional: the document can always be handed to the club directly, with no consequence for the member. The consent covers the digital upload channel — producing the document itself is governed by the applicable sports regulations (in France, the code du sport and federation rules). For members under 15 in France, consent is given jointly by the minor and the holder(s) of parental authority (art. 45, loi Informatique et Libertés).
- Privacy choices — the portal includes a consent center where the member can review and withdraw consent at any time (art. 7 §3 GDPR) — withdrawal applies to consent-based processing such as uploaded documents. For processing based on legitimate or public interest (for example aggregate statistics), the member can object (art. 21 GDPR). A restriction-of-processing request (art. 18 GDPR) switches the portal to read-only.
4. Purposes
- Provide the Paak service and associated support.
- Process payments and issue invoices.
- Send operational communications (registration confirmation, payment reminders, security alerts).
- Improve the product through aggregated statistics (only with analytics-cookie consent).
- Comply with our legal obligations (accounting, requests from competent authorities).
5. Legal bases (GDPR) / grounds of justification (FADP)
- Contract performance — user accounts, billing, service operation.
- Consent — analytics cookies, voluntary contact forms, marketing communications.
- Legitimate interest — service security, fraud prevention, functional improvement.
- Legal obligation — accounting retention, responses to authorities, FIJAISV compliance (art. L.212-9 French Sports Code) for concerned clubs.
6. Processors and recipients
We rely on European processors to deliver the service. No data is transferred outside the European Union or Switzerland (see section 11 for the one exception, which is under your control).
| Provider | Role | Country |
|---|---|---|
| OVHcloud | Application and database hosting | France (EU) |
| Hanko | Authentication (passkeys, sessions) | Germany (EU) |
| Mollie | Online payments (fees, equipment, subscriptions) | Netherlands (EU) |
| Brevo (ex-Sendinblue) | Transactional emails and newsletters | France (EU) |
| Matomo (self-hosted) | Website analytics — on our own OVH server | France (EU) |
Data-processing agreements (DPA, art. 28 GDPR / art. 9 FADP) are in place with each of these providers.
7. Retention
- User account — throughout the duration of use, then up to 90 days after termination before final deletion.
- Billing data — 10 years (Swiss accounting obligation, art. 958f CO).
- Waitlists and contact requests — up to 2 years after the last exchange, unless you unsubscribe.
- Member data managed by a club — for as long as the club retains it. Deletion requests go through the club.
- Member-portal sessions — purged 90 days after expiry or revocation; one-time codes purged 30 days after use or expiry.
- Documents submitted via the member portal — for as long as the club retains them; deleted immediately when the right to erasure is exercised.
- Technical security logs — 12 months maximum.
- Newsletter — until you unsubscribe; subscription requests never confirmed join no list and follow the "waitlists" duration above.
- Waiver signature evidence — retained beyond an erasure request only to the extent necessary for the establishment, exercise or defence of legal claims (art. 17(3)(e) GDPR), then deleted.
8. Your rights
Under the FADP and the GDPR, you have the following rights:
- Access — obtain a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data (subject to legal obligations).
- Restriction — temporarily suspend a contested processing activity.
- Objection — refuse processing based on legitimate interest or marketing.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, with no retroactive effect.
To exercise these rights on data managed by your club, address your club first (Paak acts as processor in that case). For data we process as controller (website, admin account, billing), write to contact@paak.club. We answer within 30 days.
9. Supervisory authority
You have the right to lodge a complaint:
- with the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern — edoeb.admin.ch (for Swiss residents);
- or with the data protection authority of your EU country of residence (e.g. the CNIL in France — cnil.fr).
10. Security
Data is encrypted in transit (TLS 1.2+), user passwords are replaced by passkeys (Hanko, passwordless authentication), database backups are encrypted. Administrator access is logged and protected by strong authentication.
11. International transfers
No data is transferred to a third country by the processing we operate. The entire infrastructure is hosted in the European Union, with exclusively European processors. Switzerland benefits from an adequacy decision from the European Commission, ensuring equivalent protection in both directions.
One exception is under your control: if you choose Sign in with Google on the login page, you authenticate directly with Google LLC (United States), which is certified under the EU-US and Swiss-US Data Privacy Frameworks. Our infrastructure and our processors remain European; optional third-party sign-in is the user's choice. Passkeys and email one-time codes, which are the default, involve no non-European provider.
12. Changes to this policy
We may update this policy to reflect legal or technical developments. The last update date appears at the top of this document. Material changes will be notified by email to active users.