Privacy policy
What data we process, what for, how long we keep it and how to have it deleted. No small print other than this.
Last updated: 10 August 2026.
Who processes your data
AI4Padel is a product of KAIX LABS. The company responsible is KAIX SECURITY AND ARTIFICIAL INTELLIGENCE LABS, S.L., Spanish tax ID (NIF) B88664305, based in Madrid, Spain, and its website is www.kaixlabs.com.
For anything to do with data protection — including asking us to delete your data — write to [email protected]. That is the privacy mailbox and a person reads it. For everything else, [email protected].
Two very different situations
Almost everything below depends on which one is yours, because it changes who decides about your data:
- You contact us through this website, or your club is our customer. Here we decide: we are the data controller and answer for your data directly.
- You are a player or member of a club that uses AI4Padel. Here the club decides: it is the controller and we are a processor. We process your data on the club's behalf, on its instructions, under a processing agreement compliant with art. 28 GDPR. We do not use it for anything of our own.
If you contact us through this website
The demo form collects two required things —your club's name and a contact email— and two optional ones: a phone number and a message. We do not ask for your name, and there is no hidden field collecting anything else.
- What for: to reply, prepare the demo and, if there is interest, send you pricing and terms.
- Legal basis: the pre-contractual steps you yourself request by submitting the form (art. 6.1.b GDPR).
If you email us instead of using the form, we process what you tell us for the same purpose and on the same basis.
If your club subscribes to AI4Padel
- What data: account and authorised staff details — name, work email, role — and the club's billing data.
- What for: to give access to the service, support you, invoice and meet our accounting and tax obligations.
- Legal basis: performance of the contract (art. 6.1.b GDPR) and, for invoicing and accounting, compliance with legal obligations (art. 6.1.c GDPR).
If you are a player at a club that uses AI4Padel
Your data comes from your club, out of its booking software or its spreadsheet: name, phone number, playing level, court position, availability and match history, plus any WhatsApp conversations you have with the club's number. It is used for one thing only: putting your club's matches together — offering you a spot in one that is short of players, confirming you are coming and reminding you.
The legal basis for that processing is set by your club, not by us: usually the performance of your membership or of the booking itself, and consent where the message is a commercial one. If you want to know exactly which applies to you, or to exercise your rights, your club is the one to talk to; below is what we do if you write to us instead.
Stopping the messages is immediate and needs no justification. Just reply to the club's WhatsApp saying you do not want any more: it is understood in your own words, there is no keyword to get right. From then on you get no further notices, it is recorded on your file and you drop out of the suggestions.
Cookies and measurement
If you accept nothing, this website does not measure you and sets no cookies. No third-party script is loaded, and the fonts are served from our own domain. Until you decide, not even the fact that you are reading this leaves here.
If you accept, we use Google Analytics to see which pages get read
and which channels people arrive through. It sets the _ga and
_ga_* cookies, which expire after two years and identify a browser, not a
person. The legal basis is your consent (art. 6.1.a GDPR) and, unlike
almost everyone else, we send nothing to Google — not even a cookieless signal —
before you give it.
We use no advertising or profiling cookies: Google's ad signals are switched off for good, and this measurement is never combined with product data or with any club's player data.
You can change your mind at any time from the “Cookies” link in the footer: it reopens the notice and lets you reject what you accepted before. Withdrawing is as easy as granting, and clearing your browser cookies also stops the measurement.
Who else is involved
We do not sell data, we do not share it with third parties for their advertising, and we do not use it to train artificial-intelligence models. Only the providers we need in order to run the service are involved, as our processors and under contract:
- Cloudflare, Inc. — hosting for this website and for the service that receives the form.
- Resend, Inc. — delivery of the email carrying your demo request.
- Meta Platforms Ireland Ltd. — sending and receiving the club's messages through the WhatsApp Business Platform. Meta's own processing of those messages is additionally governed by its terms.
- A language-model provider — drafts the messages the club approves. We only contract providers that contractually undertake not to use the data to train their models.
- Google Ireland Ltd. — measurement of this website, and only if you accept it. Collection happens on European Union servers. It plays no part in the product and never sees a single player's data.
Beyond that, we disclose data only where the law requires it: to public authorities, to courts or to law enforcement acting on a legitimate request. You can ask the privacy mailbox for the current list of providers.
Where it is processed
Service data is hosted and processed in the European Union. Some of the providers above are US companies and may access data from outside the European Economic Area; where that happens, the transfer relies on a European Commission adequacy decision — the EU-US Data Privacy Framework — or, failing that, on the Commission's standard contractual clauses (art. 46 GDPR), with the risk assessment Chapter V requires.
How long we keep each thing
- Demo requests that do not lead to a contract: 12 months from the last contact. Then deleted.
- Customer club data: for as long as the contract lasts.
- Invoices and accounting records: 6 years, because art. 30 of the Spanish Commercial Code requires it; those with tax effect, at least 4 years under the General Tax Act.
- Security logs and the record of who approved each send: up to 24 months. They evidence who authorised what, and they are what we investigate incidents with.
- Player data: set by your club, which is the one that decides. If a club stops being a customer, it takes its data with it and we can delete the rest.
How to ask us to delete your data
Write to [email protected] with the subject “Borrado de datos” (Spanish for “data deletion” — in English it works just as well). That is enough for the clock to start.
Tell us only what we need in order to find you:
- The email or phone number you contacted us with, or the one your club has for you.
- If you are a player or member, the name of your club.
You do not have to explain why, and you do not have to attach an ID document. Only if what you send does not let us tell who you are will we ask for anything further, and then the bare minimum (art. 12.6 GDPR). It is free of charge (art. 12.5 GDPR).
Deadline: one month from receiving your request, as art. 12.3 GDPR requires. If the case is particularly complex we may need up to two months more, and if so we tell you within the first month and explain why. We always reply in writing, even when the answer is that we cannot do it: in that case we tell you the reason and that you can complain.
What happens next depends on your case:
- You contacted us through this website, or you are a contact at a customer club. We delete your contact details and the history of the commercial conversation.
- You are a player or member of a club. The controller is your club, so we cannot delete on our own initiative data that is not ours: what we do is pass your request to your club without delay and tell you we have done so and who is now handling it, so you are not left waiting. When the club acts on it, your name, phone number and email are removed, pending messages are dropped, and you are permanently excluded from the suggestions, with no later sync putting you back. If all you want is to stop the messages, none of this is needed: reply to the club's WhatsApp and you are done.
What we cannot delete, and why. Invoices and accounting entries are kept for the years the Commercial Code and tax rules require. That data is blocked in the sense of art. 32 of the Spanish Data Protection Act: held solely at the disposal of courts, the Spanish Data Protection Agency and public authorities, used by no one for anything else, and deleted as soon as the period expires.
This page covers the website and your dealings with us. Inside the product, the club handles opt-outs and deletions from its own panel, without having to write to us.
Your other rights
Through the same mailbox — [email protected], same one-month deadline, also free — you can exercise the rest of your GDPR rights:
- Access: know what data we hold about you and what we do with it.
- Rectification: correct anything wrong or incomplete.
- Objection: ask us to stop processing it.
- Restriction: ask us to keep it but not use it while a disagreement is resolved.
- Portability: receive the data you gave us in a readable format, or have us pass it to someone else.
- Withdraw consent where the processing rests on it; as easy to withdraw as it was to give, with no retroactive effect.
And if you think we have got it wrong, you can complain to the Spanish Data Protection Agency (AEPD), the competent supervisory authority. You do not have to come to us first, though we would appreciate the chance to put it right.
Automated decisions
AI4Padel proposes: it looks at which matches are short of players, suggests who would fit, and drafts the message. Sending is always decided by a person at the club, and who authorised it and when is recorded. We make no automated decisions with legal effect on you and do not profile you within the meaning of art. 22 GDPR.
Children
This website is not aimed at children and we do not collect their data through it. A club may have members who are minors: in that case it is the club, as controller, that must have the appropriate legal basis — in Spain, parental or guardian consent below the age of 14 (art. 7 of the Spanish Data Protection Act). If you find we have processed a child's data without that cover, write to us and we will fix it.
Security
We apply technical and organisational measures proportionate to the risk: individual access with separated roles, strict separation between each club's data, encryption of communications and credentials, backups, and an activity log that cannot be altered. If there ever were a breach that could affect you, we comply with arts. 33 and 34 GDPR: we notify the authority within 72 hours and tell you if the risk to you is high.
Changes to this policy
If we change it, we update the date at the top. When a change genuinely affects how we treat your data, we tell customer clubs before it takes effect. Earlier versions are kept and we will send you one if you ask.
This policy is governed by Regulation (EU) 2016/679 and by Spanish Organic Act 3/2018 on the protection of personal data and the guarantee of digital rights. This English text is a translation for convenience: the Spanish version is the authoritative one and prevails in case of discrepancy. The terms of service are here.