- Today's match list
- Basic fixture information
- Selected public market views
- Limited analysis detail
- No official Best Single
- No Global Best Single
Privacy & Cookies
How personal data and cookies/similar technologies are intended to be handled under Swedish and EU data-protection rules.
Last updated: 8 September 20261. Controller
The data controller for Scorestatix must be identified before production use.
| Controller | [INSERT LEGAL ENTITY] |
|---|---|
| Organisation number | [INSERT ORG. NO.] |
| Address | [INSERT ADDRESS] |
| Privacy contact | [INSERT PRIVACY EMAIL] |
| Data Protection Officer | If legally required: [INSERT DPO DETAILS OR STATE NOT APPOINTED] |
2. Personal data we may process
- Account data: name, email, username and account settings if accounts are introduced.
- Contact data: information you submit when contacting support or exercising rights.
- Technical/security data: IP address, timestamps, device/browser information, security logs and request metadata where necessary to operate and secure the service.
- Subscription/payment metadata: plan, invoice and transaction identifiers if paid services are introduced. Full card details should be handled by the payment provider, not stored by Scorestatix unless strictly necessary and compliant.
- Usage/analytics data: only where enabled and where a valid legal basis and, when required, prior cookie/terminal consent exists.
- Marketing preferences: where marketing is introduced and legally permitted.
3. Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Provide an account or paid service requested by you | Performance of a contract / steps requested before entering a contract |
| Security, fraud prevention, abuse prevention and service integrity | Legitimate interests, balanced against your rights; in some cases legal obligation |
| Customer support and responding to enquiries | Contract, legitimate interests or legal obligation depending on the request |
| Accounting, tax and mandatory record keeping | Legal obligation |
| Optional analytics, personalisation or advertising | Consent where required; such processing must remain off until valid consent is obtained |
| Direct electronic marketing | Consent or another lawful basis only where permitted, with applicable opt-out rights |
The actual legal basis must be determined and documented before each processing activity begins.
4. Recipients and processors
Personal data may be shared only where necessary with vetted service providers such as hosting, security, email, payment or AI/infrastructure providers, or where disclosure is required by law. Processor agreements and appropriate confidentiality/security obligations must be in place where required.
A production version of this policy should identify categories of recipients and, where appropriate, material named providers.
5. International transfers
If personal data is transferred outside the EU/EEA, Scorestatix must use a lawful transfer mechanism where required, such as an adequacy decision or appropriate safeguards, and assess supplementary measures where necessary. The production policy should identify relevant transfer destinations and safeguards.
6. Retention
Personal data is kept only for as long as necessary for the stated purpose, legal obligations, dispute handling and security. Production retention schedules must be documented per data category.
- Security logs: retained only for a proportionate operational/security period.
- Support enquiries: retained for the time needed to resolve and document the matter.
- Account data: retained while the account is active and for a justified period afterwards where necessary.
- Accounting records: where applicable, Swedish accounting records are generally retained for the statutory period.
7. Your GDPR rights
Depending on the circumstances, you may have rights to information, access, rectification, erasure, restriction, data portability, objection and to withdraw consent at any time where processing relies on consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY): www.imy.se.
8. Cookies and similar technologies
This current frontend build does not intentionally enable optional analytics, advertising or personalisation cookies. Necessary technologies may be used only where strictly required to provide a feature requested by the user.
If optional cookies or similar terminal-storage/access technologies are added, users must receive clear information and, where required, be able to accept or reject them before they are used. Refusal must not be treated as consent, and consent must be capable of withdrawal.
Cookie inventory — current frontend build
| Category | Status | Purpose |
|---|---|---|
| Necessary | Only if technically required | Requested site functionality/security |
| Analytics | Off | Not currently enabled |
| Advertising/personalisation | Off | Not currently enabled |
9. Automated analysis and AI
Scorestatix may use automated systems and AI to analyse football-model candidates. These outputs concern football analytics, not legal or similarly significant decisions about individual users. If future features introduce automated decision-making about users with legal or similarly significant effects, the privacy information and safeguards must be updated before launch.
10. Security and changes
Appropriate technical and organisational security measures should be applied according to risk. No internet service can promise absolute security. Material changes to this policy should be communicated in a clear manner and the effective date updated.
IP-based language localisation
When the language selector is set to Auto, the current static frontend may request country-level Geo-IP information from ipapi.co to choose a default interface language. This necessarily exposes the visitor's IP address to that provider. A manually selected language overrides automatic detection. This temporary frontend lookup should be replaced by the Scorestatix backend before production launch and the production privacy notice must reflect the final provider and data flow.