Privacy Policy
Last updated: March 2, 2026
1. Data Controller
scoutsland UG (haftungsbeschränkt)
Rähnitzgasse 20b, 01097 Dresden, Germany
E-Mail: info@scoutsland.com
Managing Director: Egle Neumann
2. General Information on Data Processing
We process personal data exclusively in accordance with legal provisions, specifically the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). Personal data encompasses all information relating to an identified or identifiable person (e.g., name, email address, IP address).
3. Types of Data Processed
- Master data (name, email address, company affiliation)
- Contract data (subscription, payment status)
- Usage data (login times, interactions)
- Technical data (IP address, browser, device, operating system)
- Payment data (processed via Stripe)
- Communication data (support requests)
4. Purposes and Legal Bases of Processing
Processing relies on:
- Art. 6 para. 1 lit. b GDPR (contract fulfillment)
- Art. 6 para. 1 lit. c GDPR (legal obligations)
- Art. 6 para. 1 lit. a GDPR (consent, e.g., analytics)
- Art. 6 para. 1 lit. f GDPR (legitimate interest, e.g., IT security)
5. Our Platforms & Systems
5.1 Backend Infrastructure (scoutsland-service)
Central GraphQL API based on NestJS with MongoDB Atlas supporting account management, authentication, scouting data provision, and AI-powered analysis.
5.2 Live Scores Platform (scoutsland-live)
A React web application with server-side rendering that collects technical access information for performance and security assurance.
5.3 Scout Panel (scoutsland)
Professional dashboard for scouts, clubs, and agencies processing personal account information for contractual purposes.
5.4 Marketing & Content Hub (scoutsland-landing)
Marketing site using Sanity CMS collecting technical information for optimization.
6. Third-Party Service Providers
Clerk (Authentication)
We use Clerk for secure user authentication. Clerk may transfer information to third countries using standard contractual clauses.
- Email address
- User ID
- Login information
- Authentication tokens
Stripe (Payment Processing)
Stripe processes payment information, billing details, IP addresses, and payment status. Stripe functions as an independent controller; its privacy policy applies. Legal basis: Art. 6 para. 1 lit. b GDPR.
Sportmonks (Football Data)
Live data is obtained via the Sportmonks API without transmitting personal user information. Only match and statistics data is processed.
Cloudinary (CDN & Media Optimization)
Cloudinary collects IP address, browser type, device information, and time of access for performance optimization, reduced loading times, and scalable media delivery. Legal basis: Art. 6 para. 1 lit. f GDPR.
Google Analytics (Analytics)
Google Analytics is activated only after explicit consent, collecting anonymized IP addresses, browser information, usage behavior, and session duration. Legal basis: Art. 6 para. 1 lit. a GDPR. Consent withdrawal is available at any time.
Sentry (Error Monitoring)
Sentry collects technical error logs, browser information, IP addresses (potentially truncated), and user IDs when logged in for system stability, error correction, and performance optimization. Legal basis: Art. 6 para. 1 lit. f GDPR.
7. One-Stop-Shop & International Users
For EU private customer sales below the legal turnover limit, taxation occurs in Germany. When thresholds are exceeded, the OSS procedure applies.
8. Cookies
We use technically necessary cookies, authentication cookies (Clerk), and analytics cookies (Google Analytics, consent-required). A cookie banner enables consent management. For more details, see our Cookie Policy
9. Data Security
We implement the following security measures:
- TLS/HTTPS encryption
- Role-based access control
- Serverless infrastructure (Netlify)
- Monitoring (Sentry), distributed caching (Redis), background job processing (Bull Queues)
10. Data Transfer to Third Countries
Service providers including Stripe, Clerk, Cloudinary, Google, and Sentry may transfer information to third countries using standard contractual clauses or adequacy decisions.
11. Storage Duration
Personal information is retained only when necessary for contractual fulfillment, legal retention requirements exist, or legitimate interests apply.
12. Rights of Data Subjects
You have the following rights regarding your personal data:
- Right of access — request information about your data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your data
- Right to restriction — limit processing of your data
- Right to data portability — receive your data in a portable format
- Right to withdraw consent — withdraw previously given consent at any time
- Right to lodge a complaint with a supervisory authority
Requests should be directed to: info@scoutsland.com
13. Changes to this Privacy Policy
We reserve the right to modify this privacy policy when services or legal requirements change.
