Privacy Policy
In plain English: what supodo does with your data
1. Which services does this cover?
supodo is a platform for sport for people with disabilities, for inclusive sport, and for senior sport. supodo has several services. One person runs all of them. This document covers all supodo services. The services have no legal pages of their own. They point to these pages instead.
For example, these services:
- supodo landing page — the website
- supodo manager — the management tool for clubs and events
- supodo app — finding and following activities
- supodo link — the short links
- supodo auth — signing in, and user accounts
- supodo mail — newsletter sign-up and sending emails
supodo may have more services. You reach them at supodo.com or at supodo.link. This document covers those too.
We also have internal test systems. This document does not cover them. Those systems have their own details.
Sections 6 to 11 are sorted by service. Section 6 applies to all of them. Each section after that applies only to the service in its heading. This page does not cover our internal test systems.
2. Who is responsible?
This person is responsible for your data. That is true for every service in section 1.
supodo
Marib Aldoais
Leimbergerstraße 43a
91052 Erlangen
Germany
Email: kontakt@supodo.com
Phone: +49 170 9000109
Is there a data protection officer?
No. We do not need one. Here is why. A German law says when a company needs one. You need one if at least 20 people work with data on computers all the time. Only one person works here. The law is the German Federal Data Protection Act, section 38(1). If you have a question about your data, just write to us. Our address is above.
3. Why are we allowed to use your data?
We may only use your data if we have a reason for it. The law calls that reason a legal basis. The law is called the GDPR. That stands for General Data Protection Regulation. It is a European law. In this text we name our reason at every point. There are four reasons:
We need the data for our service
You want to use something. We need certain data to give it to you. Your user account, for example. Or your sign-in. Without that data it does not work. The rule is Article 6(1)(b) GDPR.
We have a good reason of our own
Sometimes we have a good reason of our own. The law calls this a legitimate interest. An example: our pages have to run safely. Then we have to check something. Is our reason more important than your interest in your data? Only if the answer is yes may we use it. In this text we always say what our reason is. So you can judge it yourself. You can also say no. Section 15 explains how. The rule is Article 6(1)(f) GDPR.
You said yes
Sometimes we ask you first. You then say yes. The law calls that consent. The newsletter is an example. You can take your yes back at any time. What happened before that stays lawful. The rule is Article 6(1)(a) GDPR.
A law tells us to
Sometimes we have to keep data. A law says so. Letters and emails are an example. The rule is Article 6(1)(c) GDPR.
Where we rely on a good reason of our own, we weighed things up first. So we compared our reason against your rights. You can ask us what the result was. We will tell you.
4. Data about health and disability
This is the most important section on this page. Please read it. Even if you skip the rest.
Why this matters here
We never ask about your health. We never ask about a diagnosis. We never ask about a disability. We do not store anything like that. Even so, someone could guess something about your health from your data. Here is an example. You are a member of a club for sport for people with disabilities. Or you take part in an event that this club runs. Someone could then work out: this person may have a disability. The law calls that an inference. And for the law, that is already enough. A senior European court has decided this twice. The court is the Court of Justice of the European Union. The judgments are from 1 August 2022 and 4 October 2024. With single activities it is even clearer. An activity can have a target group. For example: sport for blind people. Or wheelchair sport. Or sport for people of short stature. Then the guess is even clearer.
When this guess is not possible
Not every membership allows such a guess. We do not want to claim more here than is true. In senior sport, you only learn something about a person's age. Age says nothing about health. In mixed groups you learn nothing at all. Everyone does sport together there. That is the whole point of inclusion. For single activities our software can tell. That is because a target group can be recorded there. For whole clubs our software cannot tell. When we are not sure, we protect the data especially well.
How we handle this data
So we are extra careful with all data about roles, membership and taking part:
- We do not pass it on. Only the organisation or event you joined yourself gets it. And organisations running an event together, where that is needed.
- We do not publish it. What is public is the activities themselves. So the clubs and the events. The people behind them are never public.
- We check every access in the database itself. Not just in the app. Access is tied to your account.
- We do not use the data for advertising. We do not rate people with it. We do not run any analysis about individual people.
What is still open
We are still working out how to classify this guess in legal terms. We are telling you openly. We do not want to hide it. Until then, this is where we stand. If you create a role yourself, we need it for your service. If an organisation enters you, then the organisation has a good reason of its own: it wants to run its own sport. When we finish working this out, we will change this section. One more thing matters. You can end any role, any membership and any participation at any time. We then delete the record.
5. Children and young people
In youth sport, children and young people use our services too. Sometimes we ask permission first. That permission only counts from age 16. This is in Article 8(1) GDPR. Countries are allowed to set a lower age. Germany did not do that. So in Germany the age is 16. Anyone under 16 needs a parent's permission. One more thing is important. A sport activity can have a lowest age. And a highest age. Do you take part in an activity for children? Then someone can guess your rough age. Even if you never told us your date of birth. We never ask for an age.
This age limit only applies when we ask permission first. It does not apply when we need the data for our service. And it does not apply when we have a good reason of our own.
Our newsletter is for adults. We do not knowingly sign up children under 16. If we find out about one, we delete the sign-up.
Sometimes an organisation enters a child. As a member, for example, or as someone taking part. The organisation then asks the parents for permission. Not us. We do not know the parents. We cannot ask them. The organisation is responsible for this.
Are you a parent or guardian? Do you have a question about your child's data? Or should we delete it? Then write to us. Our address is in section 2. We deal with these requests first.
6. This applies to every service
This section always applies. It does not matter which of our services you use.
Where are our servers?
Our services run on servers in Germany. We rent these servers from a company. All the data from your use sits there.
This is the company:
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
We need the servers so our services can run. And we have a good reason of our own: our services should be safe and fast. For that we need a company that knows how to do this.
We have a contract with this company. The law calls it a data processing agreement. It is in Article 28 GDPR. The company may only use the data the way we tell it to. Both servers are in Nuremberg. The contract only allows processing inside the European Union. So the company does not take your data to other countries.
Log data
You use the management tool, the app or a short link. Your requests then go through our database and our sign-in service. These make a note of the requests that reach them. This is what is in it:
- when the request came
- which part was asked for
- what kind of request it was
- whether the request worked
- your IP address. That is your device's number on the internet.
- the identifier of your browser
We do not join this data up with other data. We do not build a profile about you from it.
We have a good reason of our own for this. Our services should run properly. We want to find faults. And we want to stop attacks. We also count for a short time: how often is a form sent from one internet address? If there are too many, we refuse the next ones. We do not store these counts. After a short time they are gone.
We have not yet decided how long we keep these logs. We keep them for as long as we need them. We need them to find faults. And to look into attacks and stop them. As soon as we have decided, we will write it here.
Cookies and storage on your device
Cookies are small files on your device. We only use cookies that are technically necessary. For signing in to the management tool and the app, for example. We do not have to ask permission for those cookies. A German law allows this: section 25(2) no. 2 of the TDDDG. We use no cookies for advertising. We use no cookies to count visitors. We do not embed fonts, maps or videos from other companies. That is why you see no cookie window on our pages.
We store three more things on your device. We do not have to ask permission for these either. First: a cookie remembers which language you chose. This happens on the website, in the management tool and in the app. Our pages stay in that language while your browser is open. When you close the browser, your browser deletes the cookie. Second: in the management tool, your browser remembers whether you closed the side bar. Third: in the management tool, a cookie remembers up to twelve organisations. These are the organisations you manage and opened most recently. Then the side bar can show you those first. We delete this cookie after 30 days. This display is part of the management tool. You opened the management tool yourself. So the cookie is necessary for the management tool. We do not evaluate these. We do not join them with anything. On the short links we store nothing at all on your device. Section 10 says more.
Security
All our pages are encrypted. You can tell by the https at the start of the address. So nobody can read along. We also protect your data with technical measures. For example, the database itself checks who is allowed to see what. This is in Article 32 GDPR.
Links to other websites
Our pages contain links to other websites. We are not responsible for those websites. We do not know what happens to your data there. Please read their own privacy page. Do that before you enter any data there.
Data only goes to the other website once you click the link. It has to work that way technically. The internet only works like this. This data goes with you: your IP address, the time, your operating system and your browser.
7. The website (supodo.com)
On this website you can write to us. And you can sign up for our newsletter. There is no user account here.
The contact form, email and phone
You write to us through the contact form. We then use your email address, the subject and your message. We need that to answer your question. And in case we have to ask something back. You get a confirmation by email. That email repeats your message. Do you write by email or ring us instead? The same applies to that data.
Is your question about a contract with us? Then we need the data for that. Is it about something else? Then we have a good reason of our own: we want to answer questions people ask us. Do you tell us more about yourself than we asked? That is your own choice.
We need your email address. Otherwise we cannot reply. The form does not ask for your name. But you do not have to give us your email address. No law and no contract requires it.
Once your question is answered, we delete it. Unless a law says we have to keep it.
The newsletter
For the newsletter we use your email address. And the language you chose. We do not ask for your name when you sign up. You can add it yourself later. Signing up takes two steps. First you sign up. Then you get an email. In that email you confirm the sign-up. We store when you signed up and when you confirmed. That way we can prove you said yes. We also store whether the email arrived. Then we stop sending to wrong addresses.
You said yes. That is our reason. You can take your yes back at any time. Every newsletter has a link for that. Or just write to us. We then stop sending.
We send the newsletter ourselves. We use a program for that. The program is called Listmonk. It runs on servers that we rent. Sections 6 and 11 say more. No other company sends the newsletter for us.
We store your data until you unsubscribe. After that we keep the proof for a while. That is: that you said yes, and that you took it back. We need that if anyone asks about it later.
Protection for our forms
Sometimes computer programs send thousands of messages to forms automatically. That is called spam. We use a protection against it. There is a box to tick below every form. You tick the box. Only then does your browser get a sum from us to work out. It works the sum out in the background. Nothing happens for this before that. You do not have to solve a picture puzzle. One thing matters here. This protection runs on our own servers. No outside company is involved.
You tick the box. Your browser then fetches the sum from our server. It works out the answer on your device. Then it sends the answer back to us. Nothing else is sent. We see your IP address while it does. That happens on every visit to our servers. We use it to count requests. Section 6 says more. We do not look at details about your browser or your device for this. And no data goes to other companies.
We have a good reason of our own for this. We do not want spam in our forms. And we want to stop people misusing our confirmation email. Otherwise someone could write to strangers using our name.
8. The management tool for clubs and events (manager.supodo.com)
The management tool is for people who work for a club. They look after its activities and events. You need a user account for it.
You sign in through our central sign-in. Section 11 says what data that involves. In the management tool we also store which role your account has, in which club and in which event. And who created a record. For clubs, contact details, images and short links we also store who changed the record last.
For each club and each event we store what the people in charge enter. For example: name, description, type of club, sports, target groups, times, places, addresses, costs, pictures and links to social networks. And contact details like email address, phone number and fax number. Watch out for one thing. Contact details often belong to a particular person. Even when they sit under a club.
About people we store roles. A club has these roles: admin, member and follower. An event has these roles: event manager, taking part, support and follower. Technically a role is only three things: a link to your account, a link to the club or event, and the kind of role. Section 4 says what someone could still guess from that.
Sometimes a club enters data about a person who has no account. We then do not get the data from that person. We get it from the club. We have to tell you this. It is in Article 14 GDPR. The club has to make sure the entry is allowed. And the club has to inform the person. Not us.
A club or an event becomes public when the club sets it that way. Before that, only accounts with a role can see it. Roles, memberships and taking part are never public.
We need the data for the account, the sign-in and the club's own content. And for the public activities we have a good reason of our own: people should be able to find sport for people with disabilities, inclusive sport and senior sport. That is exactly what our platform is for.
Content stays stored until the club deletes it. Roles stay stored until they end. Do you delete your account? Then we delete your roles with it.
9. The app (app.supodo.com)
In the app you search for activities and look at them. You do not need to sign in for that. You can also follow clubs and events.
You do not need to sign in to search and look around. Only the data in section 6 comes up. So mainly the log files.
At some point you do something we have to store. Following a club, for example. We then set up an account for your device automatically. That account is anonymous. That means: it holds no name. It holds no email address. It holds no password. It is only a number in your browser. We need the number so you can find your list again. We cannot see who you are. Even so, that number counts as personal data. This is in Article 4(1) GDPR.
You follow a club or an event. We then store a follower role for it. So: a link to your account, a link to the activity, and the time. Only you can see that list. Please also read section 4. It applies even if you only follow.
We need this anonymous account for your list. Without an account the list cannot work technically. And the list is exactly what you wanted.
Do you clear the data in your browser? Then you cannot reach your anonymous account any more. Some anonymous accounts never follow anything. We delete those automatically after 30 days. For anonymous accounts with a list we have not set a time limit yet. We will set one and write it here. But you can write to us at any time. We then delete your anonymous account straight away.
10. The short links (supodo.link)
Some internet addresses are very long. So we also have short ones. A short link forwards you to the right page. There is no sign-in here. We store no content from you.
You open a short link. We look up where it belongs. Then we forward you there. The target is a supodo page or somebody else's website.
This service sets no cookies. It stores nothing on your device. It uses no programs to count visitors. It builds no profile about you.
The log files in section 6 come up. We also limit how many times one IP address can call the service. That protects it against misuse. We have a good reason of our own: the service should keep running.
We forward you. From that moment data goes to the target. That is true even when the target is somebody else's website. It has to work that way technically. This data goes with you: your IP address, the time, your operating system and your browser. For somebody else's website, the company behind it is responsible. Not us.
11. Signing in, accounts and emails (auth.supodo.com, mail.supodo.com)
We use two programs for signing in and for emails. We run these programs ourselves. They run on servers that we rent. Section 6 says more.
For your user account we store: your username, your email address, your first name and your last name. We do not store your password as text. We only store a scrambled check value. Nobody can work your password back out from it. We also store passkeys, if you set any up. And: whether your email address is confirmed, linked accounts from other providers, when you signed in, your session keys, and how often a sign-in failed. We also record when you accepted our terms of use. We have to be able to prove that.
Our sign-in service also makes a note of what happens with your account. For example: when you sign in. When you sign out. When a sign-in does not work. When you set up an account. When you confirm your e-mail address. And when you change your password. It stores: the time, what happened, the number of your account, and your IP address. We do this for the security of the accounts. And to look into misuse. The legal basis is Article 6(1)(f) of the GDPR. After 90 days we delete these notes automatically.
You register for the first time. We then send an email to your address. You have to confirm that email. Without confirming, you cannot use the account. We send that email through a mailbox at our server company. No other company is involved.
You can also sign in with your Google account. Google then sends us three things: your email address, your name and a number. We make an account here from that. Google has already checked your email address. So we do not send a confirmation email. Google is responsible for your data at Google. You decide yourself whether to use this route. Do you not want it? Then register with an email address and a password.
For the newsletter we store this in our own program: your email address, your name, whether you are signed up, and whether our emails arrive. Section 7 says more about the newsletter.
We need the data for your account and for signing in. For confirming the email address we have a good reason of our own: accounts should be safe. The same goes for counting failed sign-ins. For the newsletter, you said yes.
We store your account data until you delete your account. Or until you ask us to delete it. We delete session data quickly. We delete the sign-in notes automatically after 90 days.
12. Who gets your data?
We do not pass your data to anyone else. There are three exceptions: the cases on this page, cases where you said yes, and cases where a law makes us. Two companies are involved. One company works on our instructions. One company is responsible for itself. That company is only involved if you want it to be:
Hetzner Online GmbH in Nuremberg, Germany
This company provides the servers. All our services run on them. We have a contract with the company. The contract is dated 16 February 2026. We signed it on 7 August 2026. It only allows processing inside the European Union. One thing matters here. In that contract we wrote down clearly that someone could guess something about health or disability from our data. Section 4 explains why.
Google Ireland Limited in Dublin, Ireland
You can sign in to us with a Google account. Section 11 says more. Google does not work on our instructions here. Google is responsible for itself. You sign in with Google directly. Google then sends us your email address, your name and an identifier. For people in Europe, the company Google Ireland Limited is responsible. This company is based in Dublin in Ireland. Ireland is part of the European Union. Google can also pass your data to the USA. Google decides that itself. And Google has to answer for it itself. You do not have to use Google. You can also make an account with an email address and a password.
These companies get no data
Our sign-in, our database and our newsletter program are software. We run this software ourselves. It runs on the servers from section 6. We rent these servers. There is no other company behind it that gets your data. Our newsletter does not run at some other company either. Only the emails go through a mailbox at our server company.
There are two more cases. First: you join a club yourself. That club then sees your data. The club is responsible for it from then on. Second: sometimes we have to give data to authorities or courts. We only do that when a law makes us.
13. Does data go to other countries?
Your data stays in Germany. We do not send any data to a country outside Europe ourselves. If you sign in with a Google account, the company Google Ireland Limited in Ireland is our counterpart. Ireland is part of the European Union. Google can still pass your data to the USA. Google decides that itself. Sections 11 and 12 say more.
14. How long do we keep your data?
We keep your data only as long as we need it. Where we can give you an exact time, we do. Where we have not set a time yet, we say that too. We would rather tell you the truth than make something up.
- Log data from the database and the sign-in service: we have not set a period for these yet. We keep them for as long as we need them: to find faults and to stop attacks. Section 6 says more.
- Your question by form, email or phone: until the question is answered. Unless a law says otherwise.
- Newsletter: until you unsubscribe. We keep the proof a little longer.
- User account and sign-in data: until you delete the account. We delete session data quickly. We delete sign-in notes after 90 days.
- Roles, memberships and taking part: until they end. Or until the account is deleted.
- Content in the management tool, including uploaded pictures: until the organisation deletes it.
- Anonymous app accounts that follow nothing: 30 days. A program then deletes them automatically. It runs every day.
- Anonymous app accounts with a list: we have not set a time limit here yet. What matters is how long the list is still useful to you. We will set the limit and write it here. Do you write to us? Then we delete the account straight away.
Sometimes we are not allowed to delete data. For example because we still need it for another permitted purpose. We then lock the data. That means: we only use it for that one purpose. For nothing else.
15. Your rights
You have rights. You can use them at any time. It costs you nothing. And you do not have to give a reason. Only for an objection do we need a reason.
- See your data: you may ask which data we hold about you. We also tell you what we use it for, how long we keep it and who gets it. And we send you a copy. This is in Article 15 GDPR.
- Correct your data: is something wrong? Then we have to correct it. Is something missing? Then we have to add it. This is in Article 16 GDPR.
- Delete your data: you may ask us to delete your data. That applies when we do not need it any more. And when no law makes us keep it. This is in Article 17 GDPR.
- Lock your data: you may ask us to store your data only. We then may not use it any further. That is useful while we are checking a mistake, for example. This is in Article 18 GDPR.
- Take your data with you: you may get your data from us. In a file computers can read. We send it to you. Or we send it straight to another company. This covers the data you gave us yourself. This is in Article 20 GDPR.
- Take your yes back: did you say yes to something? You may take that back at any time. It has to be as easy as saying yes was. What happened before stays lawful. This is in Article 7(3) GDPR.
Your right to object
Sometimes we use your data because we have a good reason of our own. You may object to that. You tell us: in my situation this does not fit. And you explain briefly why. We then stop. There is one exception. We can prove that our reason really does weigh more. This text names our reason at every point. So you can explain your objection. The right is in Article 21(1) GDPR.
How to use your rights
Just write to us. Our address is in section 2. A letter or an email is enough. There is no special form. We answer as fast as we can. At the latest within one month. Is your question very complicated? Then we may need longer. Two months longer at most. We will tell you if that happens. One more thing. We must not give your data to the wrong person. So sometimes we ask a question to check it is really you. We only ask what we have to.
Complaints
Are you unhappy with our answer? Then please write to us again. We look at every complaint ourselves. And we answer you. You can also complain to a government authority. You may always do that. You do not have to ask us first. This is in Article 77 GDPR. This is the authority responsible for us:
Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany
16. Does a computer make decisions about you?
No. No computer here decides about you on its own. We do not rate you. We do not sort you into groups. We show you no advertising. The protection program in section 7 only checks one single entry in a form. It does not judge you as a person. Did it not work? Then try again. Or send us an email. The rule is Article 22 GDPR.
17. Notes for people outside Europe
supodo is for sports communities in Germany and Europe. Anyone anywhere can open our pages. But we do not offer our services into other countries on purpose. One thing matters here. Privacy laws in other countries usually only apply once a company actually looks for customers there. Not just because you can open the page there. So the GDPR and German law are what govern us. Here are a few notes anyway.
Australia
We do no business in Australia. So Australian privacy law does not apply to us. But we still follow the idea behind the Australian rule APP 1: a privacy page should be clear and up to date. Australia asks for two extra pieces of information. Here they are:
Who abroad gets data, and in which country? Your data sits in Germany. Only one company outside Germany gets data: the company Google Ireland Limited in Ireland. And that only happens if you sign in with a Google account. Google can also pass your data to the USA. Sections 11, 12 and 13 say more.
How we deal with a complaint: write to us. Our address is in section 2. We confirm your complaint arrived. We look at it ourselves. We answer within one month. And we explain our decision. Do you disagree with it? Then contact the authority in section 15.
USA
California has a privacy law. It is called the CCPA. It only applies to large companies. We are far too small for it. We do no business there either. And we do not sell data. Not ever. The USA also has a law protecting children. It is called COPPA. It does not apply to us. Our services are not made for children in the USA.
Canada
We do no business in Canada. So the Canadian privacy law PIPEDA does not apply to us. Canada also has an anti-spam law. It is called CASL. Our newsletter meets those rules anyway: we only send it after you sign up and confirm. Every email says who it is from. And every email has a link to unsubscribe.
Other countries
We say nothing here about the United Kingdom, Switzerland, Brazil, China or the individual US states. Here is why: we are not looking for customers there. If that changes, we will add to this text. Beforehand, not afterwards.
18. Reports about content that breaks the law or our rules
Do you report content to us? Then we save: the kind of your report. The address of the page. And your description. Did you give your name and your email address? Then we save those too. The report also contains data about the other person. We only use this data for the report.
Is it about content that breaks the law? Then a law says that we must deal with the report. It is the Digital Services Act of the European Union. Is it only about our own rules? Then there is no law for that. We then deal with the report because we want to enforce our rules.
We need the address of the page. And we need your description. Without them we cannot do anything. We also need your name and your email address. Only reports about the sexual abuse of children are different. Then you may report without a name. But then we cannot write back to you.
The other person does not get your name. And not your email address either. We only tell the other person the reason for our decision.
We keep your report for 3 years. The 3 years start at our decision. The reason: in that time someone can go to court. Then we must show what we did.
19. Changes to this page
Sometimes we change this page. Because we add a new service, for example. Or because a law changes. The version on this page is always the one that counts. The date is at the bottom. Is a change important for you? Then we also tell you inside the service it affects. And if we need your yes for something, we ask you again first.
Last updated: 14 August 2026