Security & Data Protection

Club data belongs to the club — not to us

KAIZEA processes your club's player and training data — including your youth players' — exclusively in EU-certified data centers in Germany and the Netherlands: with a GDPR Art. 28 Data Processing Agreement, parental consent under GDPR Art. 8 for minors, special protection for health data under GDPR Art. 9, and export at any time. That keeps even your club's most sensitive data protected throughout, and in your own hands.

The situation today

Why is youth data in football especially sensitive?

Because KAIZEA processes health and wellness data from mostly minor players — a data category GDPR protects more strictly than ordinary contact data.

Health data gets special protection

Wellness and load data counts as a special category of personal data under GDPR Art. 9 — subject to a general processing ban that only explicit consent lifts.

Minors need parental consent

For children under 16, GDPR Art. 8 requires documented parental consent in Germany — a verbal nod at the season kickoff doesn't hold up legally.

The club carries the liability

Minors' health data sitting in WhatsApp groups and private spreadsheets is a GDPR risk — and the board carries that risk, not the individual coach.

Server location matters

Data protection officers ask this first: where does the data live? Tools hosted outside the EU are an extra risk for clubs running youth programs.

Legally, this isn't fine print: under GDPR Art. 9, health data counts as a special category of personal data subject to a general processing ban that only explicit consent lifts. For children under 16, GDPR Art. 8 adds another layer: without documented parental consent, no digital service like KAIZEA may process their data — Germany does not lower this age threshold through the opening clause. How KAIZEA implements both technically and organizationally is shown in the register below.

This page explains how KAIZEA meets legal requirements and does not replace individual legal advice.

How KAIZEA implements it

How does KAIZEA protect this data technically and legally?

Eight building blocks, from the legal basis to encryption — each one concrete, none of them optional.

GDPR Art. 8 — consent for minors

Children under 16 can only take part with documented parental consent — Germany doesn't lower this age threshold through the opening clause.

GDPR Art. 9 — health data as a special category

Wellness and load data falls under a general processing ban that only explicit consent lifts.

GDPR Art. 28 — Data Processing Agreement

Every club gets a Data Processing Agreement during onboarding, plus a guide for the club's data protection officer.

EU hosting in Germany and the Netherlands

All data lives in EU-certified data centers — no transfer to third countries outside the EU.

Encryption in transit and at rest

Connections are fully TLS-encrypted; stored data is encrypted on the servers.

Anonymized AI prompts, no PII in logs

Before training data reaches the language model, names are anonymized; personal data never ends up in log files.

Export & deletion at any time

Clubs, parents and players can fully export their data as JSON or have it deleted at any time — not just deactivated.

Separate AI opt-in

AI usage is its own, always-revocable consent step; opting out leaves the rest of the account fully intact.

At a glance

Where does your club's data actually end up?

In short: EU data centers, a GDPR Art. 28 Data Processing Agreement, role-based access, and export at any time — here are the details per area.

As of July 2026. All information compiled to the best of our knowledge.

Area KAIZEA's approach
Server location EU-certified data centers in Germany and the Netherlands
Third-country transfer None — processing stays exclusively within the EU
Encryption TLS in transit, encryption at rest
Data processing GDPR Art. 28 Data Processing Agreement, standard part of onboarding
Minor consent Parent role with a four-step, revocable consent flow under GDPR Art. 8
Health data Special category under GDPR Art. 9, requires its own consent
AI usage Separate opt-in; anonymized prompts, no PII in logs
Data export JSON, at any time — no lock-in through the data format
Deletion Fully on request, not just deactivation
Access rights Role-based: head coach, assistant coach, club admin, parents, players
Website analytics Cookie-free, self-hosted (Umami), no advertising tracking

Data ownership stays fully with the club: whatever you log in KAIZEA, you can take fully with you — during the pilot period, in ongoing operation, and on exit. Access is granular: head coaches, assistant coaches, club admins, parents and players each see only the data that belongs to their role — a player's wellness entries aren't a club-wide noticeboard.

More on the legal basis for youth data: KAIZEA for Parents · For Club Management · Privacy Policy.

Frequently asked questions

Is KAIZEA GDPR-compliant?

Yes. KAIZEA processes club data exclusively in EU-certified data centers (Germany and the Netherlands), provides clubs with a GDPR Art. 28 Data Processing Agreement, and enforces role-based access so data is only visible to the people who need it for their role.

Where is the data hosted?

In EU-certified data centers located in Germany and the Netherlands. There is no transfer to third countries outside the EU.

Who owns the data?

The club. Data ownership stays fully with the club — all data can be exported as JSON at any time, during or after a pilot period.

Is there a Data Processing Agreement?

Yes. KAIZEA provides a GDPR Art. 28 Data Processing Agreement along with a guide for the club's data protection officer — it's part of standard onboarding.

How does KAIZEA protect minor players?

Through two relevant GDPR articles: Art. 8 requires documented parental consent for children under 16, Art. 9 protects their health and wellness data as a special category. Parents are their own role in the system, give consent, and see their child's Load and wellness data.

Is personal data used in AI analysis?

Not in plain text. Before training data reaches the language model, names are anonymized, and personal data never ends up in log files. AI usage is also a separate, always-revocable opt-in — opting out leaves the rest of the account fully usable.

What data does the marketing website collect?

kaizea.com uses cookie-free, self-hosted analytics (Umami) with no personal tracking. There is no advertising tracking.

More: Privacy Policy · Pilot Program · Pricing & Pilot Phase · Questions to info@kaizea.com

Last updated: July 2026

The next step

Next season, your club runs on one platform.

We'll show you KAIZEA in 20 minutes: honest, no obligation, in plain English. Then you decide.

KAIZEA · kaizea.com