Privacy Policy
Last updated: 2026-09-11 · v3.0
1. Data we collect
What we hold depends on what you do with Goaliano. In full:
Account and profile: email address, password (stored as a hash only), name, date of birth or age band, country, position, the profile you fill in, your language, and — for a professional account — your role and the organisation you belong to. If you sign in through Google or our staff sign-in, we receive the identity that provider confirms; we do not receive your password there.
Guardian and consent records: for players under 18, the guardian's name, relationship to the child, email address, the guardian's verified identity status, and every consent given or withdrawn, with the date and the version of the notice consented to.
Identity verification: for adults who choose to verify, the state and outcome of the check (passed, failed, needs review), a provider reference and the reason code the provider returns. The document and selfie you present go to the verification provider (section 10) and are not stored by us. A child is never asked for a document or a biometric.
Video and evaluation data: the clips you upload, the scores, grades, reports and certificates produced from them, reviewer notes, and any appeal you file. Match clips usually show other people too; see section 3.
Membership and payments: the plan you hold, its dates and renewals, invoices, orders and refunds, and the reference our payment provider gives us. We never hold your full card number.
Activity: training plans and streaks, badges and challenges, GOOL points and how you earned or spent them, ambassador referrals, cart contents, messages you exchange through Goaliano, the questions you ask the help assistant, support tickets and notifications.
Technical data: IP address, device and browser type, the pages you use and when, and the security events around your account (sign-ins, failed sign-ins, changes to settings). Error reports from the software may contain the page you were on and the action that failed; they are scrubbed of personal fields before they are stored.
Biometric data: none today. Section 8 explains the face-comparison feature that exists in the software, why it is switched off, and what would change if it were ever switched on.
2. Lawful basis
Under UK GDPR (and, for our South African users, POPIA) we rely on: performance of the contract with you for everything needed to run your account, produce your evaluations, show you to the professionals you opt in to, and take payment; your consent for the optional things — visibility to scouts, the newsletter, a guardian's consent for a child's participation, and, if it ever exists, face comparison, for which we would ask separately and which you could refuse at no cost; our legal obligations for keeping financial records, answering lawful requests and, where it applies, sanctions and child-safety law; and our legitimate interests in keeping the service secure, preventing fraud and abuse, defending legal claims, and improving the service from aggregated, non-identifying usage. Where we rely on legitimate interests we have weighed them against your rights and you may object (section 4).
A child under 13 does not hold an account; a guardian we have verified administers a profile for them. For players aged 13–17 we rely on the guardian's verified identity and signed consent as the reasonable efforts UK GDPR Article 8 requires.
3. Video retention & anonymisation
The clips you upload are used to produce your evaluation and are shown to the reviewer panel and to any scout, coach or club you have chosen to be visible to. We keep your uploaded footage for 12 months after the evaluation is completed, after which it is deleted automatically. Your scores, your certificate and your report are kept — they do not contain the footage. You can delete any clip yourself at any time before then.
On account deletion, personal data is erased within 30 days of the end of the grace period and your original footage is deleted. We may instead keep an anonymised copy (face blur + metadata strip) for improving our models, because anonymised data is not personal data (GDPR Recital 26) — but only where that anonymisation has been enabled and each file is confirmed anonymised; anything we cannot prove was anonymised is deleted. This is currently NOT enabled, so today every original is deleted and no anonymised copy is kept.
Other people usually appear in a match clip. We process their images only as part of your footage, for the purposes above, on the basis of our legitimate interest in providing the service you asked for; we do not identify them, build profiles of them or show their faces anywhere other than inside your clips to the people who may see your clips. Anyone who appears in a clip and does not want to may write to privacy@goaliano.com and we will remove or blur it.
4. Your rights
You may access, export, rectify, or erase your personal data, object to processing based on our legitimate interests, restrict processing while a dispute is settled, and withdraw consent at any time without affecting what was done before. Export and deletion are self-service: from your settings you can download a complete copy of your data in a machine-readable file, and you can close your account, which starts a 30-day grace period during which you can cancel the request. A guardian has the same controls for a child's profile. For anything else, or if you cannot sign in, contact privacy@goaliano.com; we answer within one month.
One exception, stated plainly because it is permanent. Parental or guardian consent records — the guardian's name, their relationship to the child, their email address, and the date consent was given or withdrawn — are RETAINED IN FULL and are NOT erased, anonymised or redacted when an account is deleted, including the child's account and the guardian's own. They are kept for as long as Goaliano operates. We rely on Article 17(3)(e) UK GDPR: the record is the evidence that a child's participation was authorised, and a dispute about that authorisation can be raised years after an account is closed. A record showing only that consent existed, without who gave it, would not answer the question it exists to answer. Every other right applies to these records as normal — you may ask for a copy, and you may ask us to correct anything inaccurate in them. This exception covers parental consent records and nothing else: your profile, your videos and every other category are erased or anonymised as described above. To object, contact privacy@goaliano.com; you may also complain to the UK Information Commissioner's Office (ico.org.uk).
A second exception, narrower and different in kind. If your account is BANNED for a breach of the terms, the self-service export and deletion controls are switched off while the matter is open, because those records are the evidence of what happened. Your rights themselves are unchanged: write to privacy@goaliano.com and we answer within one month. We may refuse an ERASURE where it would destroy evidence we need to establish, exercise or defend a legal claim (Article 17(3)(e)), and we will say so and say for how long — but a request for a COPY of your data is not refused on that basis. A SUSPENSION is not a ban and works the other way: it locks the product, not the exit, and you keep the self-service controls throughout.
If you are unhappy with how we handle a request you may complain to the UK Information Commissioner's Office (ico.org.uk), to the South African Information Regulator, or to the data protection authority of the EU country you live in.
5. Sharing
We share personal data with three kinds of recipient, and with nobody else.
The professionals you choose. A player's profile and evaluations are visible to scouts, coaches and clubs only where the player — or, for a minor, the guardian — has opted in. What a scout sees depends on the tier the scout holds: a score only; then attributes; then identity; then full contact details. A club or coach sees the players who have joined their squad. Reviewers see the clips they are asked to assess and not the player's identity.
Our service providers, who process data on our instructions and may not use it for anything else; they are listed in section 10, with where they are.
Authorities, where the law requires it or where it is necessary to protect a child or to establish, exercise or defend a legal claim. We tell you when we can lawfully do so.
We do not sell personal data, we do not share it with advertisers, and we do not use it to build profiles for anyone else's purposes.
6. Children
Goaliano Safe governs all under-18 accounts: consent-first, guardian-monitored, revocable at any time. Contact safe@goaliano.com. Where a check involves biometric data (section 8), we ask the parent or guardian, and the child's own agreement does not replace that consent. The consent record itself is kept permanently and is not erased with the account — see section 4, which explains why and what it contains.
7. Security
Data is encrypted in transit everywhere. Passwords are stored as salted hashes. Session cookies are set with the strictest browser protections. Video and documents are stored in access-controlled object storage and served only through short-lived signed links. Payments are handled by our payment provider under PCI DSS; we never see your full card number. Any biometric template that could ever exist (section 8) would be encrypted with a key that is held outside the database. Access to production systems is limited to named people with individual keys, and every administrative action on your account is logged. Error reports are scrubbed of personal fields before storage.
No system is perfectly secure. If a breach affects your personal data we tell the Information Commissioner's Office within 72 hours where the law requires it, and we tell you without undue delay where the breach is likely to put your rights at risk. Report a security concern to security@goaliano.com.
8. Face comparison — built, and switched off
Goaliano contains a face-comparison feature that would check whether the clips on an account are of the account holder. It is switched off, and you cannot turn it on. We are telling you it exists because we would rather you learn it from us than find it in the code.
It is off for a specific reason. We measured the first version before deciding, and at the threshold we tested it produced false matches many times more often for Black players than for White players. In this product a false match means telling a player the videos on their own account are not theirs. We were not willing to ship a known error that would fall hardest on our core market, so we did not. That version has since been replaced by a different recogniser that runs on our own servers; the new one has not yet been measured across groups, and it stays off until it has been and the results are published.
While it is off: no face template is created, stored or compared, and no biometric data of any kind is processed by us. The database table that would hold templates exists and is empty, and any template ever written to it would be encrypted with a key held outside the database. If we ever turn the feature on, we will ask for your consent separately from everything else, refusing will cost you nothing, we will ask your parent or guardian if you are under 18, and we will publish the fairness measurements that justified the change before it takes effect — not afterwards.
9. Automated decisions, and your right to contest them
Some checks are automated, including the face comparison in section 8. Under UK GDPR Article 22 and POPIA §71 you have the right to ask a person to look at any automated decision about you, to tell us why you think it is wrong, and to have it reconsidered. You can file that from your dashboard. We aim to answer within 72 hours; if we do not answer in that time, the decision is set aside in your favour automatically. If a reviewer cannot tell either way, that also counts in your favour — we do not leave an unproven accusation standing against you. The same right applies to identity-verification and credential decisions: where a check we or our verification provider run says no, you can ask a person to review it and we tell you the outcome.
10. Who processes data for us, and where
Most of Goaliano runs on servers we operate ourselves in the European Union (France), rented from a hosting company that has no access to the data on them: our application, database, email, sign-in for staff, e-signature for guardian consent, analytics, error reporting, newsletter and the face-comparison software described in section 8 all run there. The providers that see personal data are:
Cloudflare (US and worldwide) — network security, content delivery and the object storage that holds videos, documents and images, under its EU/UK data-transfer terms.
Stripe (US and Ireland) — card payments. Stripe receives your card details directly and gives us a reference; it is an independent controller for its own fraud prevention.
Veriff (Estonia, EU) — identity verification for adults who choose it. Veriff receives the document and selfie, returns the result to us, and keeps the documents under its own retention (a few months) as an independent controller; a child is never sent to Veriff.
DeepSeek (China) — the language model behind the help assistant. When you use the assistant, the text of your conversation and the help-centre passages we retrieve for it are sent to DeepSeek to generate the answer; your account identifiers are not. Do not put personal details into the assistant that you would not want sent there, and you can use Goaliano fully without it.
A print-on-demand partner — only when you order a printed certificate or merchandise, and only your name, shipping address and the order.
The merchandise store at shop.goaliano.com is a separate site with its own privacy policy.
We do not use any other third-party analytics, advertising or tracking service. We update this list before a new provider receives personal data, not after.
11. International transfers
Your data is held in the UK and the EU. Where a provider in section 10 is outside the UK and the EU we rely on the UK's adequacy regulations where they cover the destination, and otherwise on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, together with the provider's own safeguards. For the help assistant, the only data that leaves that protection is the text of the conversation you choose to have with it; the assistant is optional. You can ask privacy@goaliano.com for a copy of the safeguards that apply to a given provider.
12. How long we keep data
Account, profile, scores, reports and certificates: for as long as the account exists, then erased 30 days after you close it (the grace period in which you can change your mind).
Uploaded footage: 12 months after the evaluation is completed, then deleted automatically; you can delete a clip sooner.
Guardian consent records: permanently (section 4 explains why).
Payment, invoice and refund records: 7 years from the transaction, as UK company and tax law require, even after the account is closed; the record is reduced to what those laws need.
Records of automated decisions and of appeals: 7 years, so that a decision can be examined afterwards.
Security and activity logs: 2 years.
Help-assistant conversations: 12 months.
Shopping carts: 90 days of inactivity.
GOOL point ledgers: 2 years after the account closes, then deleted, unless points ever become redeemable, in which case the financial period applies.
Demo and test accounts: 30 days.
Error reports: 90 days.
Where a legal claim, an investigation or a child-safety matter is open, the records it concerns are kept until it closes, as section 4 describes. These periods are enforced by scheduled jobs in our software, not by hand.
13. Cookies and analytics
Goaliano sets only the cookies needed to sign you in and remember your settings; the Cookie Policy (/legal/cookies) names each one. Our analytics run on our own server, set no cookie and do not identify you; they count pages and countries so that we know what is used. We do not use advertising or cross-site tracking.
14. Marketing and the newsletter
We send you service messages about your account, your evaluations and your membership; you cannot opt out of those while you have an account, because they are how the service works. The newsletter is separate and optional: you join it by double opt-in, it is sent from its own address, and every issue carries an unsubscribe link that works immediately. We do not send marketing on behalf of anyone else and we do not give your address to anyone for theirs.
15. Changes and contact
This policy carries its version and effective date at the top. When we change it materially — a new purpose, a new provider that sees personal data, a change to a retention period or to the face-comparison position in section 8 — we tell you by email and by a notice in the service before the change takes effect, and we keep the previous versions on request.
The controller is K&K Innovation Solutions Ltd (UK company no. 17094329), London, United Kingdom. Questions and requests about your data: privacy@goaliano.com. Child safety: safe@goaliano.com. Security: security@goaliano.com. If you are not satisfied with our answer you may complain to the UK Information Commissioner's Office (ico.org.uk), to the South African Information Regulator, or to your national data protection authority in the EU.