Skip to content

Privacy notice

Last updated: July 21, 2026

This notice explains what personal data Calciopoly collects, why, how long it is kept and who it is shared with. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

1. Who processes your data

The data controller is the party that decides the purposes and means of the processing, and the one to contact about anything concerning your data.

Data controller

Fictilis S.r.l.

Area PIP 113 snc, 83047 Lioni (AV), Italia

03254170644 · AV - 315508

calciopoly@fictilis.it

2. What data we collect

Account data: email address, name, and a password we do not know — it is encrypted by our authentication provider and is readable neither by us nor by anyone with access to the database.

Tournament content: everything you enter as an organiser — tournament details, teams, players, fixtures, results, live commentary, rules, sponsors, notices, and any images you upload.

Payment data: when you buy a tournament, payment is handled by Stripe. Your card details never pass through our servers and we never store them: we only receive the outcome of the payment and a transaction identifier.

Technical data: IP address, browser type and request logs, generated automatically by the server that serves the pages. They keep the site running and protect it from abuse.

3. Players' data (and who answers for it)

This is the most important section of this notice, and the one nobody usually reads.

When an organiser adds the players of a tournament, they are uploading other people's personal data: first name, surname, position, possibly more. In respect of that data, the organiser is the data controller and Calciopoly is merely the processor (Art. 28 GDPR): we store it and display it on their behalf, we do not use it for purposes of our own.

It follows that the organiser must inform their players that their data will be published on a public page indexable by search engines, and must have a legal basis for doing so. A player asking for erasure should contact the tournament organiser; if they get no answer, they can write to us and we will step in.

Minors: if a tournament involves under-age players, publishing their data requires the consent of whoever holds parental responsibility. That is the organiser's call, and must be made before publishing.

4. Why we process it, and on what legal basis

Providing the service (creating the account, running and publishing the tournament): the legal basis is performance of the contract you are party to (Art. 6(1)(b) GDPR).

Taking payment and issuing tax documents: performance of the contract and a legal obligation (Art. 6(1)(b) and 6(1)(c)).

Security of the service (technical logs, abuse prevention): the controller's legitimate interest in protecting the platform (Art. 6(1)(f)).

Answering your requests by email: performance of the contract or legitimate interest.

We do not profile you, we take no automated decisions concerning you, and we never sell or hand your data to anyone for marketing purposes.

5. How long we keep it

Account: as long as the account exists. If you close it, the data is deleted, except what we are required by law to keep.

Tournament content: as long as the tournament exists. A finished tournament is archived automatically 7 days after its end date and remains readable; you can ask for its deletion at any time.

Accounting and tax records (invoices, proof of payment): 10 years, as Italian law requires.

Technical logs: a limited period set by the hosting provider, and in any case no longer than security requires.

6. Who it is shared with

Your data is processed by us and by a small number of providers, acting as processors on our behalf and bound by a contract under Art. 28 GDPR. There are no others: this list is not a template, it is taken from the site's source code.

ProviderWhat it doesData processedPrivacy notice
SupabaseDatabase, authentication and file storageEmail, password (encrypted), name, tournament content, uploaded images
StripeCollecting the one-off paymentEmail, card details (handled by Stripe directly: they never pass through our servers and we never store them)
VercelWebsite hosting and page deliveryIP address and technical request logs

7. Transfers outside the European Union

Some of the providers above are based in, or run infrastructure in, the United States. Where a transfer outside the European Economic Area takes place, it is covered by the safeguards of Chapter V GDPR: Standard Contractual Clauses approved by the European Commission and, where applicable, the provider's certification under the EU-U.S. Data Privacy Framework. Write to us for a copy of the safeguards in place.

8. Your rights

You have the right to: access your data and obtain a copy; have it rectified if inaccurate; have it erased; restrict the processing; object to processing based on legitimate interest; and receive your data in a machine-readable format and transfer it to another controller (portability).

To exercise them, just write to the address above: we reply within one month.

If you believe the processing breaches the GDPR, you have the right to lodge a complaint with the supervisory authority.

9. How we protect the data

Traffic to the site is encrypted (HTTPS). Passwords are stored in plain text nowhere. Access to data in the database is governed by rules enforced by the database itself (row level security), not just by the interface: a request with no right to a piece of data does not get it, even if someone bypassed the screen that hides it.

No system is absolutely secure. Should a breach occur that poses a risk to your rights, we will tell you and notify the supervisory authority within the deadlines of Art. 33 GDPR.

10. Changes to this notice

If the service changes in a way that affects how data is processed (for instance if one day we added an analytics tool), we will update this page and the date above. Substantial changes will be notified to you by email.