GDPR baseline
- Encryption, role-based access control and sensitive-access logging.
- Data Processing Agreement and published sub-processors.
Minors, medical data, families and payments live in the same platform. SAITO is built around that context: minimum data, role-based access and traceability where it matters.
Security principles
Each club operates in its own logical space. Queries are scoped per organisation so data never crosses entities.
Admin, manager, technical, medical and family. Each role only sees what they need to do their job.
TLS for all traffic and at-rest encryption for the database and file storage.
Actions on medical data, minors and payments are logged for the club's internal audit trail.
Minor flagging, guardian management and consent with a proof record (version, date and time).
A restricted space for authorised roles to coordinate sensitive information, operational restrictions, incidents, appointments and sport follow-up, with access traceability. SAITO supports coordination and record keeping, not diagnosis or prescription.
Privacy as a design criterion
Club data is not used to train models shared with other customers or third parties.
Responses are generated only with context the user already has permission to access. No shortcuts past role permissions.
Output affecting health, minors or financial decisions is surfaced as a proposal for human review.
SAITO does not use AI to diagnose, prescribe treatments or decide medical clearance. Sports-health features are oriented to coordination, restricted record keeping, communication and follow-up under professional supervision.
AI can be limited, restricted to specific roles or disabled module by module from the club's settings.
Compliance & regulation
Designed to align with Regulation (EU) 2016/679 and Spanish data-protection law.
Medical data is treated as a special category under GDPR Art. 9, with restricted access and specific legal bases.
Minor identification, legal-guardian management and consent capture when required by the applicable legal basis.
Templates and support for DPIAs on sensitive modules (health, minors, mass communication).
We sign a Data Processing Agreement with every customer for the data we process on their behalf.
Public list of sub-processors (hosting, email, AI) and a notification procedure when they change.
Documented breach-response procedure and handling of access, rectification, erasure, portability and objection rights.
Controls prepared to align with Spain's National Security Framework (ENS) as a target for public or institutional deployments.
Trust roadmap
FAQ
No. Club data is not used to train general models and is not shared with other customers.
Not by default. The sports-health module is restricted to the healthcare role and to those the club explicitly authorises. Other roles only see availability or operational restrictions, never the sports-health record.
No. SAITO does not diagnose, does not prescribe treatments and does not decide medical clearance. The platform supports coordination, restricted record keeping and follow-up under professional supervision; any clinical judgement belongs to healthcare staff.
Minors are explicitly flagged and linked to legal guardians. Communications and consents follow specific rules based on age and the applicable legal basis.
1 month free from 1 October
Every organization can try SAITO for a full month, with no card and no commitment.
Preferential terms until 31 December
Sign up before that date to keep preferential terms and join the Early Adopter group.
You shape how the product evolves
As an Early Adopter you have a say in priorities: what you really need lands sooner in the platform.
Regular meetings and updates
We show you progress and listen to your needs continuously, not just on setup day.