Security & privacy
This page describes the security and privacy model SAITO is being built and validated against during piloting.

A sports club isn't just another CRM

Minors, medical data, families and payments live in the same platform. SAITO is built around that context: minimum data, role-based access and traceability where it matters.

Security principles

Controls ready from day one

Per-club data isolation

Each club operates in its own logical space. Queries are scoped per organisation so data never crosses entities.

Role-based permissions

Admin, manager, technical, medical and family. Each role only sees what they need to do their job.

Encryption in transit and at rest

TLS for all traffic and at-rest encryption for the database and file storage.

Sensitive-access logging

Actions on medical data, minors and payments are logged for the club's internal audit trail.

Specific controls for minors

Minor flagging, guardian management and age-based restrictions for communications and consents.

Sports-health module with restricted access

A restricted space for authorised roles to coordinate sensitive information, operational restrictions, incidents, appointments and sport follow-up, with access traceability. SAITO supports coordination and record keeping, not diagnosis or prescription.

Privacy as a design criterion

AI with permissions, limits and oversight

We do not train general models with your data

Club data is not used to train models shared with other customers or third parties.

AI only sees what you can see

Responses are generated only with context the user already has permission to access. No shortcuts past role permissions.

Human review for sensitive output

Output affecting health, minors or financial decisions is surfaced as a proposal for human review.

AI does not diagnose or replace professionals

SAITO does not use AI to diagnose, prescribe treatments or decide medical clearance. Sports-health features are oriented to coordination, restricted record keeping, communication and follow-up under professional supervision.

Configurable per module

AI can be limited, restricted to specific roles or disabled module by module from the club's settings.

Compliance & regulation

Designed to align with the EU and Spanish framework

GDPR and LOPDGDD

Designed to align with Regulation (EU) 2016/679 and Spanish data-protection law.

Health data as a special category

Medical data is treated as a special category under GDPR Art. 9, with restricted access and specific legal bases.

Minors and guardians

Minor identification, legal-guardian management and consent capture when required by the applicable legal basis.

Data Protection Impact Assessment (DPIA)

Templates and support for DPIAs on sensitive modules (health, minors, mass communication).

Data Processing Agreements

We sign a Data Processing Agreement with every customer for the data we process on their behalf.

Sub-processor management

Public list of sub-processors (hosting, email, AI) and a notification procedure when they change.

Breaches and GDPR rights

Documented breach-response procedure and handling of access, rectification, erasure, portability and objection rights.

ENS as an institutional target

Controls prepared to align with Spain's National Security Framework (ENS) as a target for public or institutional deployments.

We do not claim certifications we have not obtained. References to ISO 27001 or ENS refer to controls prepared to align with those frameworks and to a certification roadmap.

Trust roadmap

How our security posture grows

  1. 1

    GDPR baseline

    • Encryption, role-based access control and sensitive-access logging.
    • Data Processing Agreement and published sub-processors.
  2. 2

    Sensitive modules

    • DPIA templates for health, minors and communications.
    • Granular restriction of the medical module and enhanced traceability.
  3. 3

    Enterprise

    • SSO, per-club retention policy and auditable exports.
    • Certification roadmap aligned with ISO 27001.
  4. 4

    Advanced deployments

    • Controls prepared to align with ENS for institutional customers.
    • Data residency options and dedicated installations.

FAQ

Top security questions

Does SAITO use club data to train models?

No. Club data is not used to train general models and is not shared with other customers.

Can a coach see full medical records?

Not by default. The sports-health module is restricted to the healthcare role and to those the club explicitly authorises. Other roles only see availability or operational restrictions, never the sports-health record.

Does SAITO diagnose injuries?

No. SAITO does not diagnose, does not prescribe treatments and does not decide medical clearance. The platform supports coordination, restricted record keeping and follow-up under professional supervision; any clinical judgement belongs to healthcare staff.

What about minors?

Minors are explicitly flagged and linked to legal guardians. Communications and consents follow specific rules based on age and the applicable legal basis.

Early Adopters programme

SAITO free from 1 Oct to 31 Dec 2026 · apply before 30 Sep

We're opening spots for clubs, federations, universities and sport centres who want to use SAITO with no cost for 3 months. In exchange, we co-design the platform with you and prioritise your real use cases.

  • 3 months free, no card required

    From October 1 to December 31, 2026. No charges and no penalty if you decide not to continue.

  • Frictionless setup

    We set up the essentials so your team can start operating in days, not months.

  • Early Adopters launch terms

    If you continue in 2027, you keep preferred launch terms, confirmed with each Early Adopter.

  • Your data, always yours and exportable

    Leave any time with a full export. No retention clauses, no lock-in.

We're selecting 50 organisations for the pilot.

Commercial pricing will start from an indicative range per organisation and season, confirmed with Early Adopters.

Final programme terms are set out in the Early Adopter agreement. SAITO reserves the definition of the commercial plan.

Early Adopter application

Join our Early Adopters

Step 1 of 3
  1. 1
  2. 2
  3. 3

Let's start with the basics. Under 2 minutes.

We're selecting 50 organisations for the pilot