Privacy Policy
General Data Protection Regulation (GDPR)
We attach great importance to the protection of your data. This page details how Doinsport collects, uses, stores, and secures personal data in accordance with the GDPR.
Last updated: April 12, 2026
Table of Contents
1 – Commitments
DOINSPORT SAS is committed to processing all transmitted or collected data in compliance with applicable legislation, in particular the amended French Data Protection Act (Loi n°78-17 du 6 janvier 1978), the General Data Protection Regulation (EU) 2016/679 (GDPR), the ePrivacy directive, and associated national laws.
This policy applies to: professionals/partners, employees, job applicants, clients and prospects, users browsing www.doinsport.com, as well as users of the v3.doinsport.club platforms and branded mobile apps custom-built by Doinsport.
2 – GDPR Glossary
Personal Data: Any information identifying an individual directly or indirectly.
Processing: Any operation performed on data (collection, storage, modification, sharing, deletion, etc.).
Data Subject: An individual who can be directly or indirectly identified by the processed data.
Data Controller: The entity that determines the purposes and means of the data processing.
Data Processor: An entity processing data on behalf of the Data Controller.
Recipient: Any individual or organization to whom the data is disclosed.
Cookie: A small file stored on a device to facilitate navigation and/or measure user traffic.
Biometric Data: Data relating to physical, physiological, or behavioral characteristics that allow unique identification.
Pseudonymization: Separating identifying information from the main dataset to minimize security risks.
3 – Types of Data Collected
In accordance with the principle of data minimization, only strictly necessary data is collected:
Identity: Last name, first name, profile picture/logo.
Contact Details: Mailing address, phone number(s), email(s).
Professional Information: Role, status, compensation, benefits.
Technical Data: IP address, device type, browser, cookies.
Service Usage: Booking history, payment methods, sports and scheduling preferences.
Operational/Specific Data: Access controls, automated court lighting, and data integrated from third-party APIs.
4 – Purpose of Data Processing
Fulfilling legal and regulatory obligations.
Managing human resources and recruitment processes.
Managing client, supplier, and partner relations.
Providing, enhancing, and customizing online and on-site player services.
Securing, maintaining, and optimizing systems.
Billing, payment processing, and accounting.
Statistical analyses and improving the overall user experience.
Preventing fraud and securing financial transactions.
Executing marketing and communications (subject to prior consent where required).
5 – Data Access
Access to data is strictly restricted to authorized staff and service providers who are bound by confidentiality agreements. Our chosen data processors offer sufficient guarantees regarding safety, security, and GDPR compliance.
No data is sold, rented, or shared with third parties outside of legal/contractual requirements. In the event of a data transfer outside the European Union, appropriate safeguards are implemented (such as standard contractual clauses or equivalents).
6 – Data Retention Periods
Data is retained only as long as strictly necessary for the intended purposes:
Data Processing | Maximum Retention Period |
|---|---|
Recruitment | 2 years if the applicant is not selected |
HR Management | 5 years after the employee's departure |
Payroll | 5 years after payment |
Sales Leads | 3 years after the last contact |
IT & Access Logs | 2 years after user departure |
Biometric Data | Period limited to the purpose; immediate deletion in the event of consent withdrawal |
7 – User Rights
You have the following rights: access, rectification, erasure (the right to be forgotten), restriction of processing, objection, data portability, withdrawal of consent at any time, freedom from automated decision-making with legal effects, and notification in the event of a data breach affecting you.
To exercise your rights, please see DPO Contact Information.
8 – Security
Data encryption in transit and at rest.
Multi-factor authentication (MFA) and strict access controls.
Regular backups and system restoration tests.
Continuous security monitoring and incident response.
Employee training and data security awareness.
Established breach notification procedures to the CNIL and affected individuals in the event of high-risk security incidents.
9 – DPO Contact Information
DOINSPORT SAS – Data Protection Officer
7, rue François Moisson - 13002 Marseille - France: support@doinsport.com
Please specify the right you wish to exercise, your full name, contact information, and attach a valid proof of identity.
© 2026 DOINSPORT SAS - All rights reserved.





