Draft — not ready to publish

Every item marked “To confirm” below is a factual or legal claim that has to be verified by your counsel, your DPO and your hosting setup before this page goes public. Nothing on this page should be published as-is. Items marked “In the platform” were verified against the Sophi codebase.

Security & data protection

How Sophi handles athlete health data.

Sophi processes special-category health data about professional athletes. This page sets out who is responsible for what, who can see what, and what happens to the data — so your DPO and legal team can assess us properly rather than take our word for it.

In the platform To confirm

01Roles and responsibilities

Controller and processor
The club or federation is the data controller. Sophi acts as processor and only processes athlete data on your documented instructions.
Data Processing Agreement
A GDPR Article 28 DPA is signed before any athlete data is loaded. A copy is available for your legal team to review in advance.
Lawful basis for health data
State which GDPR Article 9(2) condition the processing relies on, and how it is documented with each club. This is a legal position that must be settled with counsel before publication.
Sophi legal entity and DPO contact
Registered company name, address, registration number and the contact point for data-protection enquiries.

02Where the data lives

Platform
Athlete records are stored in a managed PostgreSQL database on Supabase, which also provides authentication.
Hosting region and residency
Name the region athlete data is stored and processed in, and whether any processing happens outside the EEA.
Sub-processors
Publish the list of sub-processors, what each one processes, and where. Include a notification process for changes.
Encryption
Confirm encryption in transit and at rest as configured on your plan, and state it explicitly.

03Who can see what

Role-based access
Every account has a role — doctor, physiotherapist, masseur, fitness coach, coach or administrator — and the interface a person sees follows that role.
Coaching staff do not see clinical detail
Clinical records such as occurrences and diagnoses are restricted at the database level by row-level security, so coaching roles cannot read them even through the API.
Squad and organisation scoping
Records are scoped to an organisation and a squad, so staff only see the athletes they are responsible for.

04Audit trail

Medical record access is logged
Defined actions on athlete and medical records — reading an athlete, reading a consultation or document, creating a consultation, updating a rehabilitation assessment, advancing or overriding a rehab phase, and issuing an API token — are written to an audit log with the acting user, their organisation and a timestamp.
Log retention and access
State how long audit logs are kept, who at the club can review them, and how you provide them if the club is asked to account for a decision.

05Accounts and API access

Authentication
Staff sign in with email and password through Supabase Auth; sessions are carried in cookies and refreshed server-side.
API tokens are short-lived
REST API tokens expire 30 minutes after they are issued and never expose the underlying Supabase refresh token.
Password policy, MFA and session limits
State the password policy, whether multi-factor authentication is available, and how staff access is revoked when someone leaves the club.

06Athletes and their rights

Consent register
Sophi keeps a per-athlete consent record with the date consent was given, shows which athletes are missing it, and exports the register as a CSV for your files.
Access, correction and erasure requests
Describe how the club services an athlete's Article 15 access request or an erasure request through Sophi, and the turnaround you commit to.
What happens when a player leaves
State what happens to a player's record on transfer or contract end, and the retention period applied.

07Ownership, export and exit

The club's data stays the club's
State plainly that the club owns its data, that a full export in open formats is available on request at any time including at contract end, and what happens to the data after termination.
Backups and recovery
State backup frequency, retention and your recovery objectives.
Breach notification
State the process and the timeframe within which you notify the club of a personal data breach, so it can meet its own 72-hour obligation.

08Clinical position

Sophi supports decisions, it does not make them
Sophi surfaces a daily risk score and names the variable driving it. What to do about it is a clinical decision that stays with the club's medical staff.
Regulatory classification
Sophi's position on EU MDR classification needs to be settled with regulatory counsel and stated here in plain terms. Do not publish a classification claim before that advice is in writing.

09Questions from your DPO or legal team

Send them to us directly and we will answer in writing.

Email us