Back Kairon KAIRON SPORTS

Contents

1. Scope 2. Controller 3. Data and sources 4. Purposes and legal bases 5. Academy and minors 6. Recipients and transfers 7. Client mandates 8. Retention 9. Security 10. Rights 11. Automated decisions 12. Changes

Privacy Policy

Last reviewed: 14 September 2026

This notice explains how personal data is handled through the public KAIRON website, professional conversations, research based on public sources, KAIRON SPORTS project enquiries, qualification work and signed engagements, and enquiries about KAIRON ACADEMY.

This notice covers current enquiries, professional communication and public-source research. References to future client work or Academy participation explain what must be put in place before those activities start. An activity-specific notice supplements this policy; neither a notice nor a contract can remove statutory data protection rights.

1. Scope

This policy applies when you visit kaironsports.com, email KAIRON, request or book a meeting, participate in a professional discussion, appear in relevant institutional research based on public sources, engage KAIRON SPORTS or enquire about KAIRON ACADEMY.

It does not govern a third party merely because the website links to that service. Optional content from another provider is identified before it is loaded where appropriate.

If a separate Academy interest form is offered, its collection notice explains the specific fields, consent and storage arrangements. No interest form constitutes enrolment or payment.

2. Controller and contact

The controller for the public website and KAIRON's own professional activities is Dámaso Mengod Pérez, operating the KAIRON SPORTS and KAIRON ACADEMY project names. Those names do not, by themselves, identify separate incorporated entities.

Privacy requests may be sent to hello@kaironsports.com. Academy enquiries may also be sent to academy@kaironsports.com. Current operator and contracting information is set out in the Legal Notice and in any signed engagement.

Commercial and correspondence address
KAIRON Sports Dámaso Mengod Pérez
c/o ExpertFid & Audit SA
Avenue Viollier 13
1260 Nyon, Vaud, Switzerland

3. Data we handle and where it comes from

3.1 Website, enquiries and meetings

  • Identity and contact details, professional role, organisation and preferred language.
  • Correspondence, meeting details, relationship history and information you choose to provide.
  • Technical and security data such as IP address, request time, browser, device and delivery logs generated by hosting, email and security providers.

3.2 Institutional research and client work

  • Information from public sources about clubs, companies, officeholders, employees and institutional stakeholders where relevant to a legitimate football project research or qualification question.
  • Material supplied under authority by a client, including organisational documents, interview notes, workshop contributions, decision records and deliverables.
  • Professional observations and working evidence used to distinguish facts, hypotheses, contradictions and unknowns.

Sources may include the person concerned, their employer or club, an authorised client contact, official registers, governing bodies, club publications, reputable public sources and direct professional interaction.

3.3 Academy enquiries

  • Contact details supplied by a club, coach, parent, guardian or authorised adult.
  • Limited contextual information needed to assess a proposed collaboration or answer an enquiry.

The controlled Academy pre-launch register may collect a guardian's name and contact details, the player's age band, broad area, categorical football context, development objective, schedule, language, practical territory and a non-binding price-readiness signal. It deliberately does not request the player's name, health data, identity documents or detailed club information.

The register measures whether a credible first group exists. Submitting it does not reserve a place, create a contract, authorise participation or permit a payment. Do not send medical records, safeguarding material, identity documents, detailed information about a child or match footage through the register or a general enquiry.

Public availability does not remove data protection rights. When we collect personal data indirectly, the applicable information duties still apply. Where Article 14 GDPR applies, information is due within one month, or earlier at first contact or disclosure, unless a documented legal exception applies.

4. Purposes and legal bases

Where the GDPR applies, the legal basis depends on the purpose and the person involved:

  • Requested pre-contractual steps and contract performance (Article 6(1)(b)): information needed to respond to a person’s request for services or perform a contract with that person. Communication with someone acting for a club or company normally relies on legitimate interests instead.
  • Legitimate interests (Article 6(1)(f)): relevant professional enquiries, proportionate institutional research, service planning, security and the establishment or defence of legal claims. Necessity and the impact on the individual must be assessed.
  • Legal obligations (Article 6(1)(c)): records or disclosures required by the law applicable to the activity.
  • Consent (Article 6(1)(a)): optional uses that require a separate choice, such as promotional image use or communications for which consent is required. Optional trackers also follow the applicable cookie rules.

Providing enquiry information is voluntary, but without relevant contact details or project context we may be unable to reply or arrange a meeting. A general enquiry is not consent to unrelated marketing. Personal data is not sold.

KAIRON does not commission general-purpose model training using client or player information. This is distinct from a provider’s own handling of submitted content, which depends on the service, account settings and applicable terms. Identifiable client files, children’s information and sensitive data must not be submitted to an AI service without a specific lawful-purpose, provider and security review.

5. Academy, minors and sensitive information

KAIRON ACADEMY is currently being developed as an initiative for player development. A parent, guardian, club or authorised adult should initiate an enquiry involving a minor. A pre-launch interest signal or general enquiry does not amount to consent for participation, image use, health processing or unrelated marketing.

Before any live activity begins, the operating entity and venue will issue information specific to that activity covering the responsible adults, safeguarding route, emergency data, lawful bases, recipients, retention, permissions and applicable local rules. Health, injury, biometric, wearable or performance data will only be collected where genuinely necessary, with an identified legal basis and additional safeguards.

Photography and video permissions will be separate from participation wherever required. Refusing optional promotional image use will not, by itself, prevent participation.

6. Recipients, providers and international transfers

Access is limited to people and providers who need the information for an authorised purpose. Current provider categories include:

  • Cloudflare, for website delivery, resilience and security;
  • Google Workspace, for business email and related collaboration services;
  • Cal.com, if a visitor chooses to load or open the booking service;
  • professional advisers, contractors or authorities where necessary, authorised or legally required.
  • authorised research and writing tool providers, including supervised AI services, where the purpose and data justify their use;

Providers may process data from jurisdictions outside the European Economic Area or Switzerland. Where required, KAIRON will rely on an adequacy decision, approved contractual clauses or another lawful transfer mechanism and assess supplementary safeguards appropriate to the risk.

Links to clubs, Instagram and other external services open their own websites. Their processing is governed by their notices.

You may contact us to identify the recipients and countries relevant to your data and request information about, or a copy of, the applicable transfer safeguards, subject to lawful redactions.

For the Academy interest register, Cloudflare also provides database hosting and bot protection. Cal.com states that booking data is processed in the United States, with additional subprocessors where applicable. Its privacy notice describes those transfers and its retention rules. Booking details may also reach the calendar or video service connected to the appointment. Using email instead avoids the calendar service, but email has its own providers.

7. Controller and processor roles on signed project engagements

KAIRON is controller for its website, business administration, security and professional activities whose purposes and means it independently determines.

For client work, the role follows the real processing. KAIRON may act as processor where it handles personal data only on a client's documented instructions, and as an independent controller for limited professional, legal or administrative purposes it determines itself.

Where Article 28 GDPR or an equivalent processor rule applies, the parties will sign terms covering the parties, subject matter, duration, purpose, data, data subjects, instructions, confidentiality, security, subprocessors, rights support, incidents, audits and return or deletion. A public webpage is not a substitute for those terms.

8. Retention

Data is kept only for as long as reasonably needed for the stated purpose, then deleted, anonymised or restricted unless law or a legal claim requires longer retention.

  • General business enquiries that do not progress are normally reviewed within 24 months.
  • The Academy interest database assigns a deletion date 180 days after submission and has a daily cleanup schedule. Withdrawal can be requested earlier. A separate later relationship does not automatically extend this register’s retention. Service backups may retain deleted records until their documented rotation; any restoration must reapply deletions before operational reuse.
  • Contract, invoice, accounting and legal records follow applicable statutory periods.
  • Mandate material follows the written client schedule and any required legal hold.
  • Provider security and delivery logs are retained for limited periods set according to operational and security needs.

Public-source research is reviewed when a case changes, closes or is reused. Personal identifiers that are no longer necessary must be removed or anonymised; retaining a source for reference does not justify keeping all personal data indefinitely.

9. Security and incidents

KAIRON applies measures proportionate to the activity and risk, including data minimisation, limited access, encrypted transport where supported, controlled sharing, provider review and separation of public and private material. No internet service can be guaranteed completely secure.

If you believe personal or confidential information has been sent to the wrong address, exposed or misused, contact hello@kaironsports.com promptly. Legally required notifications will be made to the competent authority and affected people.

10. Your rights

Depending on the applicable law and conditions, you can request access, correction, deletion, restriction, portability and information about recipients, or withdraw consent for future processing. You may object to processing based on legitimate interests on grounds relating to your situation. You can object to direct marketing at any time.

Write to hello@kaironsports.com. Identity evidence is requested only where reasonably necessary, not automatically. Do not send an identity document with your initial request.

Where the GDPR applies, we respond without undue delay and within one month. A necessary extension of up to two further months will be explained within the initial month. Requests are normally free; any lawful exception or refusal must be explained.

You can complain to the competent supervisory authority, in particular in your place of habitual residence, work or the alleged infringement. Relevant authorities include the CNIL in France, the AEPD in Spain and the FDPIC in Switzerland.

A deletion request should identify the enquiry or booking and the email used, without attaching identity documents initially. We assess relevant mailbox, calendar, database and working copies, and explain any lawful retention exception. Deleting a message alone does not delete copies held in another service.

11. Automated decisions

The public website does not make decisions producing legal or similarly significant effects through automated processing. Any future use of analytics, profiling, wearable technology or automated assessment concerning players will require a separate documented review before deployment.

Research and drafting may be assisted by supervised AI providers. Relevant public professional information or authorised correspondence may be processed for that purpose; outputs require human review. These tools do not determine player admission or make legally significant decisions about individuals.

12. Changes and questions

This policy will be updated when the operating entity, services, Academy model, providers or processing materially changes. The review date identifies the current public version.

Questions may be sent to hello@kaironsports.com. Information about website storage technologies is available in the Cookie Notice.

© 2026 KAIRON SPORTS. All rights reserved.

Legal notice Privacy Cookies Website terms