Last updated
Security and data handling
Short answer
Data is processed in the EU and delivered into accounts the club owns. Credentials sit in an encrypted secrets manager with read-only access where providers allow it. Each club’s data is separate; we sign a DPA, delete working copies within 30 days on disconnect, and exclude medical/health AMS data during the 2026/27 founding program. We do not claim security certifications yet.
Access model
Every source uses the club’s own credentials under the club’s licence. The Hockey Brain processes on your behalf and does not resell or pool data across clubs. Sources without an API use CSV/Excel uploads with defined templates.
Security & control (commitments)
- Data processed in the EU; working copies on EU-hosted infrastructure
- Credentials encrypted in a secrets manager — never in code, spreadsheets or email
- Read-only access wherever the provider offers it; no writes back to source systems
- Club-by-club separation — nothing pooled between clubs
- No medical or health records from AMS in 2026/27 founding program
- GDPR: data processing agreement with your club; The Hockey Brain as processor
- On disconnect: revoke access; we delete working copies within 30 days and confirm in writing
- Honest status: early-stage company without security certifications yet — we answer IT/legal questionnaires
- Disconnect anytime and keep every table already delivered
Frequently asked questions
Is our data safe?
Data is processed in the EU and delivered into your club’s own accounts. Credentials are stored encrypted, access is read-only where possible, and nothing is shared between clubs.
Where are API keys stored?
In a secrets manager, accessible only to named members of our team for operations — never in email or shared drives.
Do you process medical data?
Not during the 2026/27 founding program. Athlete management health fields are out of scope until the setup is mature.
Get a free map of your club’s data stack
30 minutes · hello@thehockeybrain.com