Privacy notice
About Ludi and this notice
Ludi is a software platform for sport psychologists. It supports assessment, planning, record keeping and other tasks in professional practice. Practitioners remain responsible for their professional judgement, decisions and services.
This notice explains how we process personal data when you visit our website, create an account, use Ludi or contact us. Information about athlete records is provided under “Athlete data” below and in our Privacy information for athletes.
Controller
The controller for the processing described in this notice is Ludi GbR, Burnitzstraße 7, 60596 Frankfurt am Main, Germany, a civil-law partnership represented by its partners Nelson von Groll and Shezaf Yarden (“Ludi”, “we”, “us”).
For all data protection matters, contact us at nelson@ludisp.com.
For athlete records processed on behalf of a practitioner or their organisation, responsibility is described under “Athlete data”.
Information we collect
Depending on how you use Ludi, we process:
- Account information: your email address, authentication information, acceptance of our terms and communication preferences. If you use Google sign-in, we receive your email address, name and profile picture. We do not receive your Google password. Passwords created for Ludi are stored as hashes rather than readable text.
- Optional profile information: your professional role, sport, country and how you heard about Ludi.
- Usage information: library cards you open and when you open them.
- Pilot enquiries: your name, professional role, contact details and any optional information you provide, such as gender.
- Communications: information you provide when contacting us.
- Technical information: information processed when your browser requests our website, including request logs used to operate and secure the service.
An email address is required to create an account. Profile responses and marketing consent are optional.
Purposes and legal bases
We use account information to provide access to Ludi and administer the service, including notices about changes to our terms. This processing is necessary to perform our agreement with you (Article 6(1)(b) GDPR).
We process pilot enquiries to respond to your request and take steps towards providing the service (Article 6(1)(b) GDPR).
We use technical information to maintain the security and operation of the website. Our legal basis is our legitimate interest in providing a secure, reliable service (Article 6(1)(f) GDPR).
We use library activity and optional profile information to understand use of the service, improve Ludi and identify potential pilot participants. Our legal basis is our legitimate interest in developing and evaluating the service (Article 6(1)(f) GDPR). You may object to this processing as explained below.
We send optional news and updates with your consent (Article 6(1)(a) GDPR). You can withdraw that consent at any time by contacting us. Withdrawal does not affect earlier lawful processing or your access to the service.
Athlete data
The practitioner or the organisation responsible for their practice determines why athlete data is collected and how it is used in their professional work. This includes selecting an appropriate legal basis, providing privacy information and meeting applicable professional confidentiality requirements.
Ludi processes athlete records on that controller’s behalf, in accordance with their documented instructions and the applicable data processing agreement. Practitioners remain responsible for interpreting assessments, selecting interventions and deciding what action to take.
Separately, Ludi uses pseudonymised athlete data for its own research in sport psychology, including research that follows athletes over time. For this use Ludi is the controller, not the practitioner. Practitioners agree to it in the terms of use.
Purpose and legal basis: research in sport psychology, on the athlete’s explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), accepted from athletes of any age. Where the law permits research without consent (Art. 9(2)(j) GDPR with § 27 BDSG), Ludi may rely on that instead, but only after athletes have been told and with a right to object at any time.
Data and safeguards: answers and scores from individual questionnaires, check-ins and team questionnaires, with questionnaire, version and form, the injury phase an injury check-in was set up for, and for team questionnaires the team, round and kind of leader rated; the practitioner’s assessments (construct scores, items ticked in an observation, constructs marked as reviewed, kind and status); injury periods and, at each questionnaire and assessment, injured or not and the injury phase; intervention plan tools and their status; completed sessions (type, duration, focus constructs, tools used, plan); sport where it is on Ludi’s list, type of sport and gender, and at each questionnaire and assessment age in whole years and squad level. No date of any entry: each entry carries a day number counted from the athlete’s first entry; the only date released is the study’s release date, and no entry dated after it is used; the status of plans, tools and assessments, current injury details and squad membership are as they stand on the day of extraction. A research consent given to a notice older than version 2026-09-29.2 covers only the questionnaire data, without any injury phase; an injury check-in is such a questionnaire, and its instrument shows the athlete was injured. Never names, contact details, dates of birth, free text (practitioner notes, summaries, session notes, goals), practitioner-made tools, a typed-in sport, the names given in questions about teammates, mental health screens or team questionnaires promised to count only in the team’s total. A research identifier replaces the athlete’s identity, and the key is stored separately. Each study is recorded with its purpose, approver, release date and end date and has its own codes. Research data cannot be reached from the website, no researcher has a database login, and only the partners of Ludi GbR have access. Every extract is logged: who, which record type, how many rows, when. Results are published only in aggregated form. No study has started yet.
Retention: the data is used while the athlete’s research consent stands and the record exists. A study’s data is deleted or anonymised when the study ends. Erasing an athlete deletes their research identifier.
Withdrawal: an athlete may withdraw research consent at any time with the Withdraw from research button on their booking page, or by writing to nelson@ludisp.com. From then on no further data of theirs is released for research; data already given to a study stays in it until the study ends. Withdrawal does not affect the lawfulness of processing carried out before it.
Service providers and international transfers
We use service providers to operate Ludi. These include Supabase for database and authentication services, Cloudflare for hosting and security, Resend for session-related emails, and Anthropic for optional AI-assisted categorisation of text submitted by a practitioner.
| Provider | Purpose and data | Location | Safeguard |
|---|---|---|---|
| Supabase, Inc., USA | Database, authentication and file storage. Holds all data stored in Ludi, including athlete records. | Our project is hosted in Frankfurt, Germany (eu-central-1). Supabase is a company based in the USA. | Supabase data processing agreement, including the EU standard contractual clauses: supabase.com/legal/dpa. Copy: at the link above or on request from nelson@ludisp.com. |
| Cloudflare, Inc., USA | Hosting, content delivery and protection against attacks. Handles all requests to the website. Request logs are kept for 3 days on our current plan. | Cloudflare is a company based in the USA. | Cloudflare data processing agreement, including the EU standard contractual clauses: cloudflare.com/cloudflare-customer-dpa. Copy: at the link above or on request from nelson@ludisp.com. |
| Plus Five Five, Inc. (Resend), San Francisco, USA | Emails about booked sessions: names and email addresses, session date, time and format, and any booking note. | Emails from our sending domain are sent through Amazon SES in Ireland (eu-west-1). Resend is a company based in the USA. | Resend data processing agreement, including the EU standard contractual clauses (Module Two): resend.com/legal/dpa. Sub-processors: resend.com/legal/subprocessors. Copy: at the link above or on request from nelson@ludisp.com. |
| Anthropic, PBC, USA | Only free text that a practitioner chooses to submit to the AI-assisted assessment, for categorisation. Anthropic deletes inputs and outputs within 30 days of receipt or generation. Its published retention terms provide for longer retention in specific cases, in particular where content is flagged for a breach of its Usage Policy (inputs and outputs up to 2 years, safety classification scores up to 7 years) and where the law requires it: privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data. Its Commercial Terms do not permit training on this content. | Processed in the USA. | Anthropic data processing addendum with the EU standard contractual clauses (Module Two), incorporated by reference in Anthropic’s Commercial Terms. Sub-processors: anthropic.com/subprocessors. Copy: on request from nelson@ludisp.com. |
All four providers are companies based in the USA. Where personal data is transferred to them outside the European Economic Area, the safeguard shown in the table applies.
Retention
We retain personal data for the purposes described in this notice and apply the following periods or criteria:
| Information | How long we keep it |
|---|---|
| Account and profile information | Until you delete your account or ask us to delete it |
| Library activity | Kept with your account |
| Pilot enquiries | Until the enquiry has been dealt with. If you then open an account, it is kept with your account; otherwise we delete it once it is no longer needed for the enquiry. |
| Communications | Until the matter has been dealt with, then deleted, unless we are legally required to keep it. |
| Consent records | For as long as your account exists, and afterwards for as long as we may need to demonstrate that consent was given, generally until the statutory limitation period ends (§§ 195, 199 German Civil Code, BGB). |
| Security logs | 3 days (Cloudflare request logs) |
| Pseudonymised research data (athletes) | For as long as the athlete’s research consent remains in place and the record exists; a study’s data is deleted or anonymised when the study ends. See “Athlete data”. |
To request account deletion, contact nelson@ludisp.com. Athlete records are handled in accordance with the responsible controller’s instructions and applicable retention requirements.
Your rights
Subject to the applicable legal conditions, you may request access to your personal data, correction, deletion, restriction of processing and data portability.
You may object, on grounds relating to your particular situation, to processing based on our legitimate interests. You may object to direct marketing at any time. Where processing relies on consent, you may withdraw that consent without affecting the lawfulness of processing before withdrawal.
Send requests concerning your Ludi account to nelson@ludisp.com. Requests concerning athlete records should be directed to the responsible practitioner or organisation; we assist that controller where required.
We respond to requests for which we are responsible within the periods required by data protection law, normally one month. If a permitted extension is necessary, we will explain the reason within that month.
You may lodge a complaint with a data protection supervisory authority, including the authority where you live or work. The authority for our location is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit).
Automated decision-making
Ludi supports professional decision-making. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects within the meaning of Article 22 GDPR.
Updates
We update this notice when our processing changes. The date above identifies the current version. Where required, we will bring material changes to your attention.