LudiLog in

Data processing agreement

Version 2026-10-04.1 · The German text is binding

Contents

  1. Parties
  2. Subject matter and duration
  3. Nature and purpose
  4. Types of personal data
  5. Categories of data subjects
  6. Your instructions
  7. Ludi’s own research
  8. Confidentiality
  9. Professional secrecy
  10. Security
  11. Sub-processors
  12. Requests from athletes
  13. Help with your other duties
  14. Data breaches
  15. Deletion or return at the end
  16. Information and audits
  17. Liability
  18. Term and termination
  19. Order of precedence
  20. Governing law
  21. Annex: technical and organisational measures

Parties

This agreement is concluded between you, the practitioner who holds a Ludi account, as controller, and Ludi GbR, Burnitzstraße 7, 60596 Frankfurt am Main, Germany, represented by its partners Nelson von Groll and Shezaf Yarden (“Ludi”), as processor (Art. 28 GDPR).

You accept it together with the terms of use, in the same step. It is concluded in electronic form (Art. 28(9) GDPR).

The German text is binding. The English text is a translation.

Subject matter and duration

Ludi stores and processes the athlete data you enter in your Ludi account, so that you can use Ludi in your work.

This agreement runs as long as your account does.

Nature and purpose

Ludi stores the data, scores questionnaires, shows readings and suggested interventions, creates the links you send to athletes, sends emails about sessions and, when you choose to, sends free text to an AI service to sort it into categories.

The purpose is to operate Ludi for you. Ludi does not use your athletes’ data for its own purposes, with one exception: its own research with pseudonymised copies, described in the section Ludi’s own research.

Types of personal data

  • Health data (Art. 9 GDPR): questionnaire answers, scores and answering times, results of the mental health screen, injury records, your observations and noted tendencies, session records, intervention plans, notes, uploaded files and voice memos.
  • Answers athletes give about teammates.
  • Basic details: name, date of birth, photo, sport, position, squad and language, and, where given, gender, phone number, hobbies and interests.
  • Bookings: session times and mode, the athlete’s note, your availability, and the athlete’s email address.
  • Access links, consent records and a log of changes to athlete records.

Categories of data subjects

  • Your athletes, including athletes under 18.
  • Teammates named in an athlete’s answers.
  • People you invite to work with you on a squad.

Your instructions

You instruct Ludi through the platform. What you enter, send, change and delete are your instructions. You can give further instructions in writing, including by email to nelson@ludisp.com.

Ludi processes the data only on your instructions, including any transfer outside the EU, unless EU or German law requires otherwise. In that case Ludi tells you before it processes, unless that law forbids it.

If Ludi thinks an instruction breaks data protection law, it tells you straight away.

Ludi’s own research

Ludi’s research with pseudonymised athlete data is not processing on your behalf. Ludi is an independent controller for it (Art. 4(7) GDPR), and this agreement does not apply to it. It is governed by the section Research with pseudonymised athlete data of the terms of use.

By accepting this agreement you instruct Ludi to make pseudonymised copies of the data named in that section, including the assessments, injury periods, intervention plans and sessions you create, available to its research (Art. 28(3)(a) GDPR). Beyond that, Ludi does not use your athletes’ data for purposes of its own.

Requests from athletes about Ludi’s research are Ludi’s to answer as controller. Ludi answers them itself.

Confidentiality

At Ludi, only the partners Nelson von Groll and Shezaf Yarden have access to your data. Both are bound to confidentiality by this agreement, and that duty continues after it ends.

Professional secrecy

If you are bound by professional secrecy under § 203 StGB, for example as a psychologist, Ludi contributes to your professional work in the sense of § 203(3) StGB.

Ludi commits to keeping your athletes’ secrets and knows that disclosing them without authority is a criminal offence (§ 203(4) StGB). It learns only what it needs to run Ludi for you, and it binds the sub-processors it engages to confidentiality.

Security

Ludi takes the measures Art. 32 GDPR requires. They are listed in the annex at the end of this agreement. Ludi may improve them, and does not lower the level of protection.

Sub-processors

You give Ludi general authorisation to engage these sub-processors:

  • Supabase: database, sign-in and file storage. Servers in Frankfurt, Germany.
  • Cloudflare: hosts and protects the website and runs scheduled jobs. Request logs are kept for 3 days.
  • Resend: sends emails about sessions, from servers in Ireland.
  • Anthropic: sorts free text you choose to send into categories. Processing in the United States under the EU standard contractual clauses. Inputs and outputs are deleted within 30 days, except where Anthropic’s published retention terms provide for longer retention, in particular for content flagged under its Usage Policy or where the law requires it (privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data). Never used to train AI.

Ludi tells you by email at least 30 days before it adds or replaces a sub-processor. You can object within that time. If Ludi cannot meet your objection, you can end this agreement before the change takes effect.

Ludi binds each sub-processor to the same data protection obligations as this agreement and remains liable to you for them (Art. 28(4) GDPR).

Requests from athletes

If an athlete asks Ludi to see, correct, delete or copy their data, or objects to its use, Ludi passes the request to you without undue delay and does not answer it itself. Requests about Ludi’s own research are the exception: Ludi answers those itself.

Ludi helps you answer. In the platform you can see and edit an athlete’s record and erase it. For a copy in a portable form, write to nelson@ludisp.com.

Help with your other duties

Ludi gives you the information it has to help you with security, data breach notifications, data protection impact assessments and consulting the supervisory authority (Art. 32 to 36 GDPR). Ludi’s own impact assessment of the platform is available on request.

Data breaches

If Ludi becomes aware of a breach affecting your data, it tells you without undue delay, and within 48 hours at the latest, by email to your account address.

It tells you what happened, which data and roughly how many athletes are affected, the likely consequences, and what Ludi has done and proposes to do. What is not yet known follows as soon as it is.

Deletion or return at the end

When your account ends, Ludi deletes the personal data it processes for you, and any copies, unless the law requires them to be kept.

Before that you can ask for a copy of your data. To have your account and its data deleted, write to nelson@ludisp.com.

While this agreement runs, you delete an athlete with the platform’s erase function.

Information and audits

Ludi makes available the information you need to show that this agreement is kept: this agreement, the annex, the sub-processor list and answers to your written questions.

Where that is not enough, Ludi allows and contributes to audits by you or an auditor you appoint. An inspection on site takes place only where the law requires it, with reasonable notice.

Liability

Liability follows the section Liability of the terms of use. Art. 82 GDPR is not affected.

Term and termination

This agreement begins when you accept it and ends with your account. Ending the terms of use ends this agreement.

Each version of the terms of use comes with the version of this agreement shown at the top. You accept both together.

Order of precedence

Where this agreement and the terms of use differ on data protection, this agreement applies.

Governing law

German law applies. The place of jurisdiction follows the terms of use.

Annex: technical and organisational measures

  • Hosting in the EU: Supabase stores the database and files in Frankfurt, Germany.
  • Row-level security on every database table. Each practitioner reaches only their own athletes.
  • Athlete links are long random codes, checked in the database on every use. The code sits after the # in the link, so it is not sent to the server or kept in logs. Registration, invite and questionnaire links expire, and a booking link can be reset at any time.
  • One exception: the calendar feed has its code in the address, because calendar apps drop what follows the #. The feed shows only initials and times.
  • Encryption in transit: every connection uses HTTPS.
  • Access to the production systems is limited to the partners of Ludi GbR.
  • Signed-in parts of the platform need a session. The interface behind them refuses requests without one.
  • Audio and uploaded files are stored privately and opened only through short-lived links.
  • A log records changes to athlete records.
  • Cloudflare’s request logs are kept for 3 days.
  • Transcription of voice memos stays switched off until a provider has been assessed.
Ludi
ImpressumPrivacyTerms of useDPA© 2026 Ludi