FM Athletes takes the protection of your personal data seriously. This policy explains what data we collect, why, on what legal basis, how long we keep it and what your rights are, in accordance with Regulation (EU) 2016/679 (GDPR) and French Law No. 78-17 of 6 January 1978 as amended (the 'Informatique et Libertés' Act). This document is a translation of the French original. In case of any discrepancy, the French version prevails.
Data controller
The data controller is José Javier Figueredo, sole trader (entrepreneur individuel), trading under the name FM Athletes, 65 avenue de la Gare, 74100 Annemasse, France.
For any question about your data: fmathletes@gmail.com.
Data we collect
Through the evaluation form:
- first name and surname, email address, phone / WhatsApp number, country;
- age, sport, position, high-school graduation year, English level;
- a link to a video and a free-text message;
- if the athlete is a minor: name, email address and phone number of the parent or legal guardian.
When performing the service: sports and academic data (results, school reports, statistics, videos, English test scores), login details for the recruiting accounts created in the athlete's name (email, X, FieldLevel), correspondence with college coaches, billing and payment data.
Technical data: connection logs kept by our hosting provider for security purposes; aggregated, anonymous visitor statistics (Vercel Web Analytics, without cookies and without storing IP addresses).
We do not ask for special categories of data within the meaning of Article 9 GDPR. If you choose to share such data with us (for example medical information about an injury), it will only be used to the extent strictly necessary for the service requested.
Purposes and legal bases
- Responding to your evaluation request: pre-contractual steps taken at your request (Art. 6(1)(b) GDPR).
- Performing the contract (recruitment service, FM Apps Subscription), including managing the recruiting accounts and communicating with coaches: performance of a contract (Art. 6(1)(b) GDPR).
- Billing and accounting: compliance with our legal obligations (Art. 6(1)(c) GDPR).
- Website security and anonymised audience measurement: FM Athletes' legitimate interest in ensuring the proper functioning and improvement of the website (Art. 6(1)(f) GDPR).
- Using the athlete's name or image for marketing purposes (for example testimonials or success stories): only with your separate written consent (Art. 6(1)(a) GDPR), given by the parent or legal guardian in the case of a minor, which may be withdrawn at any time.
Sharing the athlete's sports profile with US college programmes is the core of the service: it is carried out in performance of the contract, with the client's agreement.
Retention periods
- Prospects (people who filled in the form without becoming clients): 3 years from the last contact, in line with CNIL recommendations.
- Clients: for the duration of the contract, then 5 years from its end (limitation period) for evidential purposes.
- Invoices and accounting records: 10 years (Article L123-22 of the French Commercial Code).
- Hosting provider's technical logs: a limited period set by the provider for security purposes.
At the end of these periods, the data is deleted or anonymised.
Recipients
Your data is processed by FM Athletes only. It may be disclosed to our processors, strictly for the purposes of the service:
- Vercel Inc. (United States): website hosting and anonymous audience measurement;
- Resend, Inc. (United States): delivery of emails sent through the website's forms;
- Google Ireland Ltd / Google LLC (Gmail): the fmathletes@gmail.com mailbox that receives those emails.
When performing the recruitment service, the athlete's sports and academic profile is shared with US college coaches and programmes, and on the FieldLevel and X platforms (the athlete's profile).
If you contact us via WhatsApp, you are choosing to use a Meta service, to which Meta's own privacy policy applies.
We never sell or rent your data.
Transfers outside the European Union
Some recipients are located in the United States. These transfers are safeguarded:
- for our processors, by certification under the EU-US Data Privacy Framework and/or by Standard Contractual Clauses adopted by the European Commission;
- for US college coaches and programmes, the transfer is necessary for the performance of the contract entered into at your request (Art. 49(1)(b) GDPR).
Minors
In France, a minor may consent alone to the processing of their data in connection with information society services from the age of 15 (Article 45 of the 'Informatique et Libertés' Act); below 15, the consent of the holder of parental responsibility is required.
For our contractual service, where the athlete is under 18, the contract is always signed by the parent or legal guardian, and the evaluation form requires the parent's or guardian's contact details.
Parents or legal guardians may exercise the minor athlete's rights on their behalf. We only share the information strictly necessary for recruitment.
Your rights
You have the following rights over your data:
- right of access, rectification and erasure;
- right to restriction of processing and right to object;
- right to data portability;
- right to withdraw your consent at any time, where processing is based on consent;
- right to give instructions on what happens to your data after your death (Article 85 of the 'Informatique et Libertés' Act).
To exercise your rights, write to fmathletes@gmail.com. If we have reasonable doubts, we may ask you to prove your identity. We reply within one month, which may be extended by two months for complex requests.
You have the right to lodge a complaint with the CNIL (3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr) or with the supervisory authority of your country of residence. Residents of Switzerland may also contact the Federal Data Protection and Information Commissioner (FDPIC).
No automated decision-making
We do not take any decision based solely on automated processing, including profiling, that produces legal effects concerning you.
Security
We implement appropriate technical and organisational measures to protect your data: encrypted connection (HTTPS), access restricted to those who need it, strong passwords and multi-factor authentication where available, and selection of providers offering sufficient guarantees.
Changes
We may update this policy. The date of the last update is shown at the top of the page. If we make significant changes, we will inform our clients by email.
