Skip to content
Security & privacy
This page describes the security and privacy model SAITO is being built and validated against during piloting.

A sports club isn't just another CRM

Minors, medical data, families and payments live in the same platform. SAITO is built around that context: minimum data, role-based access and traceability where it matters.

Security principles

Controls ready from day one

Per-club data isolation

Each club operates in its own logical space. Queries are scoped per organisation so data never crosses entities.

Role-based permissions

Admin, manager, technical, medical and family. Each role only sees what they need to do their job.

Encryption in transit and at rest

TLS for all traffic and at-rest encryption for the database and file storage.

Sensitive-access logging

Actions on medical data, minors and payments are logged for the club's internal audit trail.

Specific controls for minors

Minor flagging, guardian management and consent with a proof record (version, date and time).

Sports-health module with restricted access

A restricted space for authorised roles to coordinate sensitive information, operational restrictions, incidents, appointments and sport follow-up, with access traceability. SAITO supports coordination and record keeping, not diagnosis or prescription.

Privacy as a design criterion

AI with permissions, limits and oversight

We do not train general models with your data

Club data is not used to train models shared with other customers or third parties.

AI only sees what you can see

Responses are generated only with context the user already has permission to access. No shortcuts past role permissions.

Human review for sensitive output

Output affecting health, minors or financial decisions is surfaced as a proposal for human review.

AI does not diagnose or replace professionals

SAITO does not use AI to diagnose, prescribe treatments or decide medical clearance. Sports-health features are oriented to coordination, restricted record keeping, communication and follow-up under professional supervision.

Configurable per module

AI can be limited, restricted to specific roles or disabled module by module from the club's settings.

Compliance & regulation

Designed to align with the EU and Spanish framework

GDPR and LOPDGDD

Designed to align with Regulation (EU) 2016/679 and Spanish data-protection law.

Health data as a special category

Medical data is treated as a special category under GDPR Art. 9, with restricted access and specific legal bases.

Minors and guardians

Minor identification, legal-guardian management and consent capture when required by the applicable legal basis.

Data Protection Impact Assessment (DPIA)

Templates and support for DPIAs on sensitive modules (health, minors, mass communication).

Data Processing Agreements

We sign a Data Processing Agreement with every customer for the data we process on their behalf.

Sub-processor management

Public list of sub-processors (hosting, email, AI) and a notification procedure when they change.

Breaches and GDPR rights

Documented breach-response procedure and handling of access, rectification, erasure, portability and objection rights.

ENS as an institutional target

Controls prepared to align with Spain's National Security Framework (ENS) as a target for public or institutional deployments.

Trust roadmap

How our security posture grows

  1. 1

    GDPR baseline

    • Encryption, role-based access control and sensitive-access logging.
    • Data Processing Agreement and published sub-processors.
  2. 2

    Sensitive modules

    • DPIA templates for health, minors and communications.
    • Granular restriction of the medical module and enhanced traceability.
  3. 3

    Enterprise

    • SSO and per-club retention policy.
    • Certification roadmap aligned with ISO 27001.
  4. 4

    Advanced deployments

    • Controls prepared to align with ENS for institutional customers.
    • Designed for EU data residency and dedicated installations.
    • Reinforced isolation of financial and health data.

FAQ

Top security questions

Does SAITO use club data to train models?

No. Club data is not used to train general models and is not shared with other customers.

Can a coach see full medical records?

Not by default. The sports-health module is restricted to the healthcare role and to those the club explicitly authorises. Other roles only see availability or operational restrictions, never the sports-health record.

Does SAITO diagnose injuries?

No. SAITO does not diagnose, does not prescribe treatments and does not decide medical clearance. The platform supports coordination, restricted record keeping and follow-up under professional supervision; any clinical judgement belongs to healthcare staff.

What about minors?

Minors are explicitly flagged and linked to legal guardians. Communications and consents follow specific rules based on age and the applicable legal basis.

Early Adopters programme

Join the SAITO Early Adopters

  • 1 month free from 1 October

    Every organization can try SAITO for a full month, with no card and no commitment.

  • Preferential terms until 31 December

    Sign up before that date to keep preferential terms and join the Early Adopter group.

  • You shape how the product evolves

    As an Early Adopter you have a say in priorities: what you really need lands sooner in the platform.

  • Regular meetings and updates

    We show you progress and listen to your needs continuously, not just on setup day.

Early Adopter application

Join our Early Adopters

Step 1 of 3
  1. 1
  2. 2
  3. 3

Let's start with the basics. Under 2 minutes.

We're selecting 50 organisations for the pilot