Working document — August 2026Internal

Legal architecture & data protection

Swiss-hosted model (Infomaniak), built for international use. This is Pivot's own planning reference — not the public Privacy & Terms of Service players and coaches see (that's here).

Goal: clearly define who's responsible for what data, what role Pivot plays, what role Infomaniak plays, and what documents and mechanisms need to exist to operate in Switzerland and open the service to clubs in other countries.
On this page:

1.Executive summary

The most coherent structure for Pivot separates data that belongs to a club's sporting context from data Pivot needs to run its own platform.

For player data entered by a club, the club is normally the controller. Pivot normally acts as processor: it processes that data on the club's behalf and instructions. Infomaniak acts as infrastructure provider and, for that same data, as Pivot's sub-processor.

For certain platform-specific data — user accounts, security, administration, billing, or necessary technical logs — Pivot can itself act as controller.

The .ch domain reinforces the project's Swiss identity, but doesn't by itself determine which data protection law applies. If Pivot serves people or organizations in the EU under circumstances covered by GDPR, GDPR applies alongside the Swiss FADP.

Guiding principle: Pivot shouldn't promise it "only stores" data. It's more accurate to state that it processes data exclusively to provide the requested service and per the client's instructions, without selling it or using it for advertising or other incompatible purposes of its own.

2.The three legal tiers

TierActorMain functionLegal relationship
1Club / organizationDecides why its players' sporting data is collected and used.Controller
2PivotProvides the app and processes the club's data to deliver the contracted features.Processor (for club data)
3InfomaniakHosting, infrastructure, and technical services contracted by Pivot.Sub-processor

Player / family  →  Club  →  Pivot  →  Infomaniak

3.Tier 1 — the club as controller

The controller is whoever determines the purposes and essential means of processing. In this model, the club decides which players it registers, what sporting information it needs, what it's used for, who can see it, and how long it should be kept.

Example

A coach registers in Pivot: a player's name, U10 category, attendance, an assessment of dribbling/shooting/passing, and follow-up notes. The reason that information exists comes from the club's own activity — Pivot doesn't decide which child gets assessed or for what sporting purpose.

Responsibilities that stay with the club

4.Tier 2 — Pivot as processor

Swiss authority guidance establishes that a processor must process data following the controller's instructions and, in principle, must not use it for its own purposes. The relationship should be organized contractually, covering security, confidentiality, sub-processing, and cooperation.

What Pivot can do within this model

What Pivot should commit to never doing with a club's data

5.Where Pivot is also a controller

The classification doesn't apply uniformly across the whole company. Pivot can be a processor for a club's sporting data and, at the same time, a controller for processing it carries out for its own needs.

Data / processingPivot's likely roleWhy
Player assessments entered by the clubProcessorThe club determines the purpose.
Attendance and team compositionProcessorManaged on the club's behalf.
A coach's Pivot accountControllerPivot needs to manage access, identity, and account security.
Billing / subscriptionControllerPivot determines the processing needed to administer the service.
Security logsController (or own necessary processing)Pivot must protect its infrastructure and prevent abuse.

6.Tier 3 — Infomaniak as infrastructure provider

Pivot plans to use Infomaniak as its server/infrastructure provider. Infomaniak's public documentation states its data and infrastructure are located in Switzerland and that its data centers are operated in Switzerland. From Pivot's side, this relationship needs to be covered by the terms and processing agreement applicable to the specific contracted service.

Contract chain: Club ↔ Pivot (DPA) and Pivot ↔ Infomaniak (DPA / processing terms).

Pivot should also maintain an up-to-date list of sub-processors who can actually access or process data. Infomaniak shouldn't be assumed to be the only one: transactional email, analytics, support, AI, external backups, or monitoring services could also become sub-processors if they receive personal data.

7.Swiss hosting and international context

Hosting data in Switzerland simplifies the starting point and reduces certain international transfers, but doesn't automatically make the service exclusively Swiss. Each provider and each data flow needs its own analysis.

The .ch domain is an identity and digital-presence decision; it doesn't replace analysis of establishment, users, processing activities, and where data actually resides.

8.Special attention to minors

Pivot is designed for sporting contexts where data about children and teenagers can exist. That calls for a deliberately conservative approach: data minimization, limited access, no profile-based advertising, and clear rules for photos, comments, and assessments.

9.Legal documents Pivot should have

  1. Terms of Service — governs the commercial/usage relationship: accounts, access, obligations, availability, IP, liability, suspension, termination.
  2. Privacy Policy — explains processing where Pivot is controller: account data, contact, billing, security, cookies/analytics if any, retention, recipients, and rights.
  3. Data Processing Agreement (DPA), Pivot–Club — governs processing Pivot does on the club's behalf: object, duration, data categories, instructions, confidentiality, security, sub-processors, incidents, rights, deletion/return.
  4. Sub-processor list — identifies vendors that can process client data, starting with Infomaniak and adding any future service that actually touches data.
  5. Retention & deletion policy — defines what's kept, for how long, what happens when an account ends, and how backups work.
  6. Technical and organizational measures (TOMs) — internal/contractual document: access controls, encryption, backups, incident management, logging, patching, segregation, recovery.

Pivot's current public Privacy & Terms of Service page combines (1) and (2) into one accessible document, with elements of (3) referenced conceptually. Items 3–6 as standalone formal documents are not yet drafted — see section 15.

10.What the Pivot–Club DPA should contain

11.Digital acceptance model

For an online platform, acceptance can be organized traceably during club sign-up. The interface should distinguish between accepting the Terms of Service and acknowledging/entering into the DPA where applicable.

  1. The admin creates the organization account.
  2. The club or organization contracting Pivot is identified.
  3. Links to the Terms of Service, Privacy Policy, and DPA are shown.
  4. The admin confirms they're authorized to act on the club's behalf.
  5. The version of the documents accepted, date/time, and appropriate technical evidence are recorded.
  6. Material changes are notified and, where necessary, re-acceptance is requested.

Pivot's current implementation covers steps 1, 2, 3 (partially — Terms of Service and Privacy Policy are combined into one document; a standalone DPA link is not yet in place), 5 (a versioned, timestamped log — see terms_acceptances), and 6 (the version constant exists to support this, though the re-prompt flow itself isn't built yet). Step 4 — an explicit "I'm authorized to act for this club" confirmation, distinct from the general terms checkbox — is not yet implemented.

12.Recommended clause wording (draft concept)

"The Client determines the purposes of processing the personal data it enters into Pivot and warrants it has the legal bases necessary for that processing. Pivot processes that data on the Client's behalf and solely to provide the service's features, per the Client's documented instructions and the applicable data processing agreement."

This is a working concept, not a final contractual clause. The final version needs to be adapted to the legal entity operating Pivot, the business model, and the actual features offered.

13.Responsibility flow when something goes wrong

SituationMain actorPivot's role
A parent asks to correct a player's assessment.ClubProvide the technical means to correct it, where needed.
A club asks to export all its data.Club / PivotProvide export mechanisms per contract and features.
A breach is detected at Pivot.PivotAct immediately, contain, document, and notify the club per law and the DPA.
A security issue at a sub-processor.Pivot + providerManage the incident and pass on necessary information to the club.
A club ends its subscription.Club / PivotApply the return, export, deletion, and backup-cycle procedure.

14.Technical decisions with legal consequences

Current state, for reference: primary database and file storage run on Supabase infrastructure; no email-sending, analytics, or external AI vendor is integrated yet; no player photos are stored (removed by design — see Privacy & Terms section 4); authentication is email/password via Supabase Auth, no 2FA yet; row-level security (not just app-layer checks) enforces access by role.

15.Practical implementation plan

  1. Define the legal entity that will own and operate Pivot.
  2. Finalize the data map: exactly what information can be entered in each module.
  3. Confirm the specific Infomaniak service and keep its applicable terms/DPA.
  4. Create the sub-processor registry.
  5. Draft the Terms of Service, Privacy Policy, and Pivot–Club DPA.
  6. Create a retention and deletion policy.
  7. Design in-app roles and permissions.
  8. Implement traceability of document acceptance.
  9. Define an incident/breach procedure.
  10. Review any future integration before sending it personal data.
  11. Get a professional legal review before public launch — especially given minors' data and international expansion.

16.Sources consulted

This document is a legal and product architecture to prepare Pivot. It does not replace individualized legal advice and is not itself the final contracts.