Privacy Policy
Last updated: September 4, 2026 • Version 1.3.0
1. Introduction
At Frostlete Inc. and our affiliated entities ("Frostlete", "we", "us", or "our"), we take your privacy seriously. This Privacy Notice (the "Privacy Notice") explains how we collect, use, and manage information related to you ("you", the "User") when you interact with our digital platforms, systems, or services.
This Privacy Notice applies to information we process when you engage with:
- Our website and other online tools (together, our "Digital Platforms"); and
- The broader Frostlete ecosystem, including our users, subscribers, visitors, and those accessing or using our technology or platforms (collectively, the "Frostlete Service" or the "Service").
We are committed to safeguarding your privacy and operating in line with applicable data protection standards. This Privacy Notice sets out our approach to handling "Personal Data", which includes any information that directly or indirectly identifies a living person, whether on its own or in combination with other data. We encourage you to review this Privacy Notice in full to understand how your Personal Data is processed. Please note that certain sections may apply only to individuals located in specific jurisdictions. For example, the legal bases for processing provided in the table below apply primarily to individuals subject to the General Data Protection Regulation (GDPR) and the UK Data Protection Act. Transparency is central to how we operate. We want you to feel confident in how we handle your data and are committed to treating your information with care and respect. If you have any questions or need more information, please do not hesitate to contact us.
2. Data Roles
Frostlete acts in different capacities depending on the specific context in which Personal Data is processed. In most cases, Frostlete acts as a data processor on behalf of its customers (e.g., sports teams, clubs, or organizations) that use the Frostlete Service to manage and analyze athlete data. In these circumstances, our role is limited to processing Personal Data under the instructions of our customers, who remain the data controllers.
However, there are limited situations where Frostlete independently determines the purposes and means of processing certain categories of Personal Data and therefore acts as a data controller. For example, we may process certain athlete data as a controller for the purposes of ensuring the security, integrity, and availability of our systems, platforms, and services. This includes processing data including IP addresses, log-in activity, and system access metadata to detect and respond to suspicious behavior, ensure system resilience, and comply with our legal obligations related to information security.
We are committed to providing transparency about our data processing practices and will continue to clearly distinguish between our role as a controller and as a processor in the contexts in which each applies.
3. Updates to This Privacy Notice
This Privacy Notice may be updated by us from time to time without notice to you. You should read this Privacy Notice before using the Service. If you cannot comply with all of the terms of this Privacy Notice, you may not access or use the Service.
We may update this Privacy Notice periodically to reflect changes in our practices or legal requirements. We encourage you to review it regularly to stay informed about how we handle your Personal Data. The latest version will always be indicated below.
If we make significant changes to how we use your Personal Data in ways that differ from what was stated at the time of collection, we will notify you. This notification may be provided through a notice on our Website, via email, or through other appropriate means.
4. Categories of Personal Data
In the course of providing the Frostlete Service, we may collect or receive the following categories of Personal Data, either directly from you, from our customers (e.g. teams, clubs, organizations), from third parties, or through automated means. These categories apply across jurisdictions and may be subject to local variations based on applicable laws:
a. Identification and Contact Data
Such as name, email address, mailing address, phone number, date of birth, identification numbers like user ID, athlete ID, device ID.
b. Account and Authentication Data
Such as login credentials, username, password, encrypted tokens, account status, user roles, and authentication history.
c. Device, Log and Technical Data
Including IP address, browser type, operating system, user agent string, access times, geolocation data where enabled, and device identifiers.
d. Usage and Activity Data
Interactions with the Frostlete Service, usage logs, activity submissions, performance data, and support history.
e. Medical, Physical and Health-Related Data
Sensitive Personal Data / Special Category Data under applicable laws
In jurisdictions that regulate the processing of sensitive or special category data (e.g., GDPR, UK GDPR, HIPAA, LGPD, PDPA), we may collect the following types of health-related data solely for purposes agreed upon with our customers and/or based on appropriate legal grounds:
- Medical history, injuries, diagnoses, treatment or rehabilitation data
- Physical characteristics, biometric measurements, and performance data
- Sleep patterns, fatigue levels, nutrition, hydration, and recovery metrics
- Psychological assessments, wellness check-ins, cognitive performance, or emotional wellbeing indicators
- Any data derived from sensors, wearables, or third-party integrations used to monitor or assess an athlete's health or performance
f. Professional and Team Context Data
Club or team affiliation, position, coaching staff inputs, attendance, training schedules, match participation, and internal assessments.
g. Marketing and Communication Preferences
Preferences for receiving communications, marketing opt-ins, and correspondence logs.
h. Sensitive Personal Information under Local Laws
Where applicable (e.g., under the CCPA/CPRA in California), we may collect "sensitive personal information" as defined by law, including:
- Government identifiers
- Precise geolocation
- Racial or ethnic origin (where relevant and permitted)
- Health information (as described above)
- Contents of messages (where not directed to us)
We will only collect and process these categories of data as permitted by applicable data protection laws, with appropriate safeguards and, where required, valid legal bases or consents.
6. Log Files and Technical Data
Like many digital platforms, Frostlete automatically collects certain technical information when you access or use our Service. This data is generated by your browser or device and is recorded in our server log files.
Log file data may include:
- Your IP address
- Browser type and version
- Operating system
- Referring and exit pages
- Date and time stamps of access
- Pages viewed and features used
- Device identifiers
This information is used to administer the Service, analyze trends, track user navigation, gather demographic information, and ensure the security and integrity of our systems. Log data is not linked to personally identifiable information except where necessary for security or fraud prevention purposes.
7. Data Security
At Frostlete, safeguarding your personal information is a core priority. We employ a range of technical, organizational, and procedural measures designed to protect your data against unauthorized access, loss, misuse, disclosure, alteration, or destruction. These safeguards are proportionate to the sensitivity of the data and the risks associated with its processing, and are implemented in accordance with applicable data protection laws and standards.
Despite our efforts, it is important to understand that no security system is infallible. While we are committed to maintaining robust protections, we cannot guarantee the absolute security of our systems or those of third parties with whom data may be shared, as outlined in this Privacy Notice. Additionally, data transmitted over the internet may be subject to interception or unauthorized access while in transit. We have put in place appropriate safeguards to minimize such risks, but your own actions are equally important in maintaining data security.
To help protect your information, we encourage you to:
- Use strong and unique passwords for your accounts
- Keep your login credentials confidential
- Ensure your devices and internet connections are secure when accessing our Service
Please also be cautious when communicating with us via email. Email is not always a secure transmission method, and we advise against sending sensitive or confidential information through unsecured channels wherever possible.
8. Data Retention and Deletion
At Frostlete, we retain Personal Data only for as long as it is necessary for the purposes for which it was collected, or as required under applicable legal, regulatory, or contractual obligations. The duration of storage depends on the category of data and the context of its use. For example:
| Data Type | Retention Period | Lifecycle treatment |
|---|---|---|
| Child accounts awaiting guardian consent | 30 days after the first actual guardian request dispatch; failed or uncertain delivery suspends expiry | Account deactivation and referral to the account-erasure worker unless consent is resolved, delivery needs review, or a legal hold applies. Existing accounts without dispatch evidence are held for reconciliation. |
| Club notice and guardian relationship evidence that is not consent evidence | 3 years after its purpose ends | Deletion after its purpose ends and the retention period expires, unless a legal hold applies. Actual consent evidence follows its separate consent retention period. |
| Guardian account request dispatch evidence | 3 years after the request cycle ends | Deletion unless a legal hold or unfinished account erasure requires continued retention. Account deletion removes the remaining request evidence. |
| Portable data-export files | 7 days after generation | Storage object deletion, followed by metadata soft-deletion |
| IP addresses and user-agent metadata in consent and security records | 90 days before anonymization | Anonymization |
| Deleted message records | 30 days after deletion | Hard deletion unless a legal hold applies |
| Independent personal invitation and rights-request evidence | 365 days after an independent safety case or contact invitation closes | Hard deletion of closed invitation, delivery and terminal privacy-request evidence unless an exact invitation or related-subject legal hold applies |
| Security event records | 1 year | Hard deletion unless a legal hold applies |
| Consent evidence | 7 years | Hard deletion unless a legal hold applies |
| Wellness check-ins | 2 years | Hard deletion unless a legal hold applies |
| Coach notes, workout logs, and recovery logs | 3 years after the last update | Hard deletion unless a legal hold applies |
| Personal media and free-text fields on medical events | 90 days after the event ends | Minimization unless specific retention consent or a legal hold applies |
| Player names and photos on a club’s archived team sheets | 1 year after the last edit to any sheet in the archive | Hard deletion of the whole archive, unless a legal hold applies. A club’s live team sheet is kept until the club replaces or deletes it, and is deleted with the club |
| Named personal and club Rugby XV projects and saved designs | 1 year after first archive; restoring or copying does not extend expiry | Expired work is hidden and deleted unless a legal hold applies. Unarchived work remains until archived or its owner is deleted. Personal work is deleted with the account; club work is deleted with the club |
| Accounts accepted for deletion | 30-day grace period, then erasure | Erasure after the grace period unless a legal hold applies |
Once the applicable retention period expires, or upon a valid request for deletion (where legally permissible), we follow a structured process to either:
- Securely delete the data from our live and archived systems, using methods consistent with ISO 27001 and NIST 800-88 standards; or
- Anonymize the data, where ongoing use is required for analytics, benchmarking, or research. Anonymization is performed in a manner that ensures the data can no longer be linked to any individual, consistent with GDPR Recital 26 and ISO/IEC 20889.
Where users request early deletion of their data, we may satisfy the request by anonymizing the data instead of deleting it — provided that the anonymization is irreversible and meets applicable legal standards. In such cases, the resulting data is no longer considered Personal Data and falls outside the scope of data protection laws.
Please note that we may retain certain data for longer periods if necessary to:
- Comply with legal, tax, regulatory, or accounting obligations
- Maintain accurate records in the event of complaints, disputes, or investigations
- Preserve information where we reasonably anticipate litigation or other legal claims
If you have questions about our data retention or deletion practices, or would like to request the removal of your Personal Data, please contact us at dpo@frostlete.com.
9. API and Data Processing
In those instances when Frostlete provides access to its services through an application programming interface ("API"), any Personal Data processed via the API is subject to this Privacy Notice and governed by the terms of the applicable agreement with the customer.
Customers are solely responsible for verifying and validating the manner in which they use the API, including the nature of any data submitted to or retrieved from it. It is the customer's responsibility to ensure that their API usage aligns with their internal policies, intended purpose, and applicable legal and regulatory obligations.
Frostlete does not assume responsibility for the privacy, security, or accuracy of data processed by external systems or third-party platforms that integrate with the Frostlete platform via the API. This includes any third-party tools or environments connected to our API by or on behalf of the customer.
To maintain the integrity and performance of our services, we monitor for abnormal or excessive use of the API. This may include high-frequency, automated, or otherwise intensive access patterns. In such cases, Frostlete may take steps to restrict or suspend API access — either temporarily or permanently — following reasonable attempts to notify the affected customer.
Frostlete also reserves the right to modify, restrict, or discontinue API access at any time, with or without prior notice, where necessary to protect the security, stability, or reliability of our systems.
Customers are expected to ensure that their use of the API complies with all relevant data protection requirements, including obtaining valid consent or establishing another lawful basis for any Personal Data processed through the API.
10. How We Share Personal Data
We may share your Personal Data in the following circumstances, always in accordance with applicable data protection laws and with appropriate safeguards in place:
10.1 Legal and Regulatory Compliance
We may disclose your information to law enforcement authorities, regulatory bodies, courts, or other governmental agencies if we are legally required to do so. This may include compliance with subpoenas, court orders, legal proceedings, or lawful requests from public authorities.
10.2 Business Transitions
If Frostlete is involved in a merger, acquisition, asset sale, reorganization, or similar business transaction, your Personal Data may be disclosed to relevant third parties as part of the due diligence process or transferred as part of the transaction itself. In such cases, we will take reasonable steps to ensure that your Personal Data continues to be protected in line with this Privacy Notice.
10.3 With Your Consent
We may share your Personal Data where you have given us explicit consent to do so. This may include, for example, opting in to receive marketing communications, participating in research, or enabling specific product features or third-party integrations.
10.4 Law Enforcement and Regulatory Requests
We assess and respond to information requests from law enforcement or regulatory authorities with care. Any disclosure is subject to verification that the request is lawful, necessary, and proportionate.
10.5 Internal Transfers Within Frostlete
Your Personal Data may be shared across entities within the Frostlete group to support operational efficiency, customer service, compliance, and security. We apply consistent and appropriate data protection standards across all internal transfers, regardless of location.
10.6 Transfers to External Third Parties
Where we share your Personal Data with external service providers, business partners, or other third parties, we do so in accordance with applicable data protection laws. We require these recipients to adhere to contractual obligations that ensure your data is protected and processed only for the purposes specified by Frostlete.
International Transfers
Where your Personal Data is transferred outside of your country or region (including transfers from the EU or UK to countries not deemed to provide an adequate level of protection), we implement appropriate safeguards including Standard Contractual Clauses or other lawful transfer mechanisms to ensure your rights are upheld.
11. Your Data Protection Rights
Depending on your jurisdiction, you may have the following rights in relation to your Personal Data. We are committed to facilitating the exercise of these rights in a timely and transparent manner:
11.1 Right of Access
You have the right to request a copy of the Personal Data we hold about you, along with information about how it is processed.
11.2 Right to Rectification
You may request the correction of inaccurate or incomplete Personal Data that we hold about you.
11.3 Right to Erasure ("Right to Be Forgotten")
You may request the deletion of your Personal Data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent and no other legal basis for processing applies.
11.4 Right to Restrict Processing
You may request that we limit the processing of your Personal Data in certain circumstances, for example while we verify its accuracy or assess a legitimate interest claim.
11.5 Right to Data Portability
Where processing is based on your consent or a contract, you may request to receive your Personal Data in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller where technically feasible.
11.6 Right to Object
You may object to the processing of your Personal Data where such processing is based on legitimate interests, including profiling. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
11.7 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
11.8 Right Not to Be Subject to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing, including profiling, where such decisions produce legal or similarly significant effects on you, unless the processing is necessary for a contract, authorized by law, or based on your explicit consent.
11.9 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or place of the alleged infringement, if you believe that the processing of your Personal Data infringes applicable data protection laws.
11.10 Right to Non-Discrimination
Where applicable (e.g., under the CCPA/CPRA), you have the right not to be discriminated against for exercising your data protection rights. We will not deny you goods or services, charge different prices, or provide a different quality of service because you exercised your rights.
To exercise any of these rights, please contact us at dpo@frostlete.com. We will respond to your request within the timeframe required by applicable law (typically within 30 days).
12. International Data Transfers
In the course of providing the Frostlete Service, your Personal Data may be transferred to, stored in, or processed in countries other than your country of residence. These countries may have data protection laws that are different from those of your jurisdiction.
When transferring Personal Data internationally, we take appropriate steps to ensure that your data is afforded an adequate level of protection, consistent with the requirements of applicable data protection laws. The safeguards we rely on include, but are not limited to:
- Adequacy decisions — Transfers to countries that have been formally recognized as providing adequate data protection (e.g., by the European Commission or the UK Secretary of State)
- Standard Contractual Clauses (SCCs) — Pre-approved contractual terms adopted by the European Commission or equivalent UK clauses, binding both the exporter and importer to uphold data protection standards
- Binding Corporate Rules (BCRs) — Internal policies adopted by multinational organizations and approved by supervisory authorities, governing intra-group transfers
- Supplementary measures — Additional technical, organizational, or contractual safeguards where necessary, as recommended by the European Data Protection Board (EDPB) or equivalent regulatory guidance
- Consent — In limited circumstances, your explicit consent may serve as the basis for an international transfer, where no other safeguard is available
We regularly assess the legal frameworks of the countries to which Personal Data is transferred to ensure ongoing compliance. Where we become aware of a risk that the legal framework of a recipient country may undermine the effectiveness of the safeguards applied, we will take additional protective measures or, if necessary, suspend the transfer.
If you would like more information about the specific transfer mechanisms we rely on, or to request a copy of the applicable safeguards, please contact us at dpo@frostlete.com.
13. Children's Privacy
Frostlete is committed to protecting the privacy of children and young people in compliance with GDPR Article 8, the UK Age Appropriate Design Code, and applicable local privacy laws.
13.1 Age Verification
Frostlete collects date of birth during registration to determine applicable consent requirements. We use this information solely to establish whether a user falls below the digital age of consent in their jurisdiction (16 in most EU member states, 13 in the United Kingdom and United States) and to apply appropriate safeguards.
13.2 Guardian Consent Flow
For users under the applicable digital consent age, we require verifiable parental or guardian consent before processing personal data beyond what is strictly necessary for account creation. Guardians are verified through email confirmation and must explicitly consent to each category of data processing, including:
- Communication and messaging features
- Health and physiotherapy data
- Photo and video processing
- Development tracking and analytics
- Data sharing with club staff
13.3 Limited Access Mode
While awaiting guardian consent, minors can view basic club information — schedules, events, and rosters — but cannot access messaging, health features, development tracking, or have photos processed. This ensures no personal data is collected or processed beyond the minimum necessary until valid consent is established.
13.4 Health Data for Minors
Processing of health-related data (injuries, physiotherapy, rehabilitation, strength and conditioning) for minors requires explicit guardian consent under both GDPR Article 8 (conditions applicable to child's consent) and Article 9 (processing of special categories of personal data). Health data processing will not commence until a verified guardian has granted specific consent for this category.
13.5 Data Retention
The account-consent period is 30 days from the first recorded guardian request dispatch, not from account creation. Resending does not restart that period. Failed or uncertain delivery, an unresolved request history, or a legal hold suspends automatic expiry for review. Existing pending accounts without dispatch evidence receive no invented deadline. When an eligible request expires without consent, the account is deactivated and queued for the account-erasure process without another waiting period. Queued erasure is not reported as completed deletion; failures remain available for retry, and legal holds continue to apply. Separately retained club facts follow their stated purpose and retention. Privacy requests can be made without signing up by contacting dpo@frostlete.com.
13.6 Right to Withdraw Consent
Guardians may withdraw consent at any time through their account settings or by contacting us at dpo@frostlete.com. Withdrawal of consent will immediately restrict the minor's access to consent-dependent features. Previously processed data will be handled in accordance with our data retention policies in Section 8.
13.7 Age Transitions
Account consent and guardian access are separate decisions. The current account flow requires guardian consent for users under 16. Turning 16 does not by itself transfer club records or grant access to another person. Guardian access for youth team records expires at the recorded age or season boundary and must not continue past adulthood. Age and authority that cannot be established safely require review; we do not promise an automatic account transition or advance notice that has not been delivered.
13.8 Team Records Without Player Accounts
When a club uses manager-led records, its authorized staff can maintain a player's name, team and season affiliation, shirt number and playing positions without creating an account for that player or a guardian. The club must record its processing basis and when and how it provided the relevant notice through its registration process. Notice delivery does not establish consent or parental responsibility. This operation excludes contact details, exact dates of birth, photographs, health and injury information, emergency contacts and unrestricted notes. Unknown age receives the protections applied to youth records.
Optional guardian access is separate from the player's account consent. The adult must verify their account, and the club must verify their authority for that child. Access is limited to the approved child and club; it does not disclose another child's records, another guardian's contact details, staff notes or private health and coaching records. For ages 16–17, optional guardian access and identification in outward graphics require the young person's assent. Guardian access expires at adulthood and no later than the earlier verified age transition or season end. If the club cannot establish that boundary, optional access and name sharing remain unavailable.
Youth names are hidden from outward graphics and shareable reports unless separately permitted for that purpose. Offline permission can be recorded without signup. Withdrawal stops future output, although an already downloaded image cannot be recalled. The approved operational retention limit is 3 years after the season ends; identity retained while season affiliation is reaffirmed, then 3 years after the final affiliation ends. Verified erasure may shorten this period; an active legal hold may defer deletion.
You do not need a Frostlete account to request access, correction, restriction or erasure of a club record. Contact the club or dpo@frostlete.com. We verify the person or their representative against the club's records and protect other people's information when responding.
If you believe we may have inadvertently collected data from a child without valid consent, please contact us at dpo@frostlete.com.
14. Managing Your Account and Communication Preferences
You can manage your account settings and communication preferences directly through the Frostlete Service. This includes the ability to:
- Update your profile information and contact details
- Adjust your notification and communication preferences
- Review and manage your consent settings
- Request a copy of your Personal Data
- Request the deletion of your account and associated data
If you need assistance managing your account, please contact us at dpo@frostlete.com.
15. Opting Out of Marketing Communications
If you have opted in to receive marketing communications from Frostlete, you may opt out at any time by:
- Clicking the "unsubscribe" link in any marketing email
- Updating your communication preferences in your account settings
- Contacting us directly at dpo@frostlete.com
Please note that even if you opt out of marketing communications, we may still send you service-related messages that are necessary for the operation of your account or the Frostlete Service (e.g., security alerts, account updates, transactional notifications).
16. Global Scope and Applicability
Frostlete operates globally, and this Privacy Notice is designed to comply with data protection laws applicable in the jurisdictions in which we operate or provide services. Depending on your location, additional rights or obligations may apply to the processing of your Personal Data.
The following laws and regulations are among those we consider and, where applicable, comply with:
- European Union — General Data Protection Regulation (GDPR)
- United Kingdom — UK GDPR and Data Protection Act 2018
- United States — California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), Health Insurance Portability and Accountability Act (HIPAA) (where applicable), and other state-level privacy laws
- Australia — Privacy Act 1988 and Australian Privacy Principles (APPs)
- Singapore — Personal Data Protection Act (PDPA)
- Brazil — Lei Geral de Proteção de Dados (LGPD)
- Canada — Personal Information Protection and Electronic Documents Act (PIPEDA)
- New Zealand — Privacy Act 2020
- South Africa — Protection of Personal Information Act (POPIA)
Where local laws require additional disclosures, rights, or protections beyond those set out in this Privacy Notice, we will comply with those requirements. If you have questions about how your local laws apply to your use of the Frostlete Service, please contact us at dpo@frostlete.com.
17. Governing Law and Jurisdiction
The applicable governing law and jurisdiction depend on your location and the nature of your relationship with Frostlete:
United Kingdom, European Economic Area, and Switzerland
If you are located in the UK, EEA, or Switzerland, this Privacy Notice and any disputes arising from or in connection with it shall be governed by and construed in accordance with the laws of England and Wales, without regard to conflict of law principles. The courts of England and Wales shall have non-exclusive jurisdiction.
United States
If you are located in the United States, this Privacy Notice and any disputes arising from or in connection with it shall be governed by the laws of the State of Delaware, without regard to conflict of law principles. Any dispute shall be resolved in the state or federal courts located in Delaware.
Australia
If you are located in Australia, this Privacy Notice and any disputes arising from or in connection with it shall be governed by the laws of the Commonwealth of Australia and the State of New South Wales. The courts of New South Wales shall have non-exclusive jurisdiction.
Singapore
If you are located in Singapore, this Privacy Notice and any disputes arising from or in connection with it shall be governed by the laws of Singapore. The courts of Singapore shall have non-exclusive jurisdiction.
All Other Jurisdictions
For users located outside the jurisdictions listed above, this Privacy Notice shall be governed by the laws of England and Wales, unless local law requires otherwise. Nothing in this Privacy Notice limits your rights under the mandatory data protection laws of your country of residence.
18. Contact Information
If you have any questions, concerns, or requests relating to this Privacy Notice or our data processing practices, please contact our Data Protection Officer:
Data Protection OfficerFrostlete Inc.
Email: dpo@frostlete.com
We aim to respond to all data protection inquiries within 30 days of receipt. If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority in your jurisdiction.