Draft — not ready to publish
Every item marked “To confirm” below is a factual or legal claim that has to be verified by your counsel, your DPO and your hosting setup before this page goes public. Nothing on this page should be published as-is. Items marked “In the platform” were verified against the Sophi codebase.
Security & data protection
How Sophi handles athlete health data.
Sophi processes special-category health data about professional athletes. This page sets out who is responsible for what, who can see what, and what happens to the data — so your DPO and legal team can assess us properly rather than take our word for it.
In the platform To confirm
01Roles and responsibilities
- Controller and processor
- The club or federation is the data controller. Sophi acts as processor and only processes athlete data on your documented instructions.
- Data Processing Agreement
- A GDPR Article 28 DPA is signed before any athlete data is loaded. A copy is available for your legal team to review in advance.
- Lawful basis for health data
- State which GDPR Article 9(2) condition the processing relies on, and how it is documented with each club. This is a legal position that must be settled with counsel before publication.
- Sophi legal entity and DPO contact
- Registered company name, address, registration number and the contact point for data-protection enquiries.
02Where the data lives
- Platform
- Athlete records are stored in a managed PostgreSQL database on Supabase, which also provides authentication.
- Hosting region and residency
- Name the region athlete data is stored and processed in, and whether any processing happens outside the EEA.
- Sub-processors
- Publish the list of sub-processors, what each one processes, and where. Include a notification process for changes.
- Encryption
- Confirm encryption in transit and at rest as configured on your plan, and state it explicitly.
03Who can see what
- Role-based access
- Every account has a role — doctor, physiotherapist, masseur, fitness coach, coach or administrator — and the interface a person sees follows that role.
- Coaching staff do not see clinical detail
- Clinical records such as occurrences and diagnoses are restricted at the database level by row-level security, so coaching roles cannot read them even through the API.
- Squad and organisation scoping
- Records are scoped to an organisation and a squad, so staff only see the athletes they are responsible for.
04Audit trail
- Medical record access is logged
- Defined actions on athlete and medical records — reading an athlete, reading a consultation or document, creating a consultation, updating a rehabilitation assessment, advancing or overriding a rehab phase, and issuing an API token — are written to an audit log with the acting user, their organisation and a timestamp.
- Log retention and access
- State how long audit logs are kept, who at the club can review them, and how you provide them if the club is asked to account for a decision.
05Accounts and API access
- Authentication
- Staff sign in with email and password through Supabase Auth; sessions are carried in cookies and refreshed server-side.
- API tokens are short-lived
- REST API tokens expire 30 minutes after they are issued and never expose the underlying Supabase refresh token.
- Password policy, MFA and session limits
- State the password policy, whether multi-factor authentication is available, and how staff access is revoked when someone leaves the club.
06Athletes and their rights
- Consent register
- Sophi keeps a per-athlete consent record with the date consent was given, shows which athletes are missing it, and exports the register as a CSV for your files.
- Access, correction and erasure requests
- Describe how the club services an athlete's Article 15 access request or an erasure request through Sophi, and the turnaround you commit to.
- What happens when a player leaves
- State what happens to a player's record on transfer or contract end, and the retention period applied.
07Ownership, export and exit
- The club's data stays the club's
- State plainly that the club owns its data, that a full export in open formats is available on request at any time including at contract end, and what happens to the data after termination.
- Backups and recovery
- State backup frequency, retention and your recovery objectives.
- Breach notification
- State the process and the timeframe within which you notify the club of a personal data breach, so it can meet its own 72-hour obligation.
08Clinical position
- Sophi supports decisions, it does not make them
- Sophi surfaces a daily risk score and names the variable driving it. What to do about it is a clinical decision that stays with the club's medical staff.
- Regulatory classification
- Sophi's position on EU MDR classification needs to be settled with regulatory counsel and stated here in plain terms. Do not publish a classification claim before that advice is in writing.
09Questions from your DPO or legal team
Send them to us directly and we will answer in writing.