Policy
Privacy Notice
This notice explains how we handle personal data on World Rugby Player Profile in line with the UK GDPR and the Data Protection Act 2018.
Last updated: 7 August 2026
1. Who we are
Kaiviti Rugby Academy UK of London is the data controller for personal data processed through this service. ICO registration number: C2005186.
Data protection enquiries: kaivitirugbyacademy@yahoo.com.
2. What personal data we process
- Account data — email address, password credentials and sign-in timestamps, handled by our authentication provider.
- Player profile data — name, date of birth, nationality, position, height and weight, club and career history, match statistics, strength and conditioning results (bench press, deadlift, squat, Bronco time), availability status and profile photographs.
- Membership and billing data — subscription tier, status and renewal date, invoices, billing name, address and contact details. Card details are entered directly with our payment processor and are never stored on our systems.
- Technical data — data needed to keep the service secure and working, such as session cookies and error logs.
This service is for adult players only. We do not knowingly collect data about anyone under 18. See our Safeguarding Policy.
3. Why we process it and our lawful basis
- Contract — to create accounts, provide roster and profile features, and take payment for memberships.
- Legitimate interests — to publish player profiles for recruitment and scouting purposes, to secure the service and to prevent fraud and misuse.
- Consent — for any optional cookies and for publishing a player's photograph and profile where the player has asked us to rely on consent. Consent can be withdrawn at any time.
- Legal obligation — to keep financial and tax records.
We do not process special category data (such as health or medical records) and ask that none is entered into free-text fields. Performance figures should be recorded without clinical or injury detail beyond the availability status.
4. Who we share data with
We use trusted processors who act only on our instructions: our cloud hosting and database provider (data stored in the UK/EEA), our authentication provider, and our payment processor for subscriptions and invoices. We do not sell personal data or share it for advertising.
Player profiles marked as publicly viewable can be seen by anyone with the link. Only administrators can create or edit player records.
5. International transfers
Where a processor transfers data outside the UK, the transfer is covered by UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses, with appropriate supplementary safeguards.
6. How long we keep it
- Account and player profile data — for as long as the profile is active, then deleted within 12 months of a deletion request or account closure.
- Billing records and invoices — 6 years, to meet UK tax and accounting requirements.
- Security and error logs — up to 12 months.
7. How we protect data
Access is controlled by row-level security policies in the database, with write access limited to verified administrator accounts. Data is encrypted in transit (TLS) and at rest. Card data is handled entirely by our PCI-DSS compliant payment processor. Access rights are reviewed and revoked when a person's role ends.
8. Your rights
Under UK GDPR you have the right to be informed and to access, rectify, erase, restrict, port, or object to the processing of your personal data, and to withdraw consent where we rely on it. To exercise a right, email kaivitirugbyacademy@yahoo.com. We respond within one month.
If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
9. Cookies
We set strictly necessary cookies for sign-in sessions and payment processing; these do not require consent. Any optional cookies are only set after you accept them in the cookie banner. You can change your choice by clearing your browser storage for this site.
10. Data breaches
We investigate suspected personal data breaches immediately and report qualifying breaches to the ICO within 72 hours, notifying affected individuals without undue delay where there is a high risk to their rights and freedoms.
11. Changes to this notice
We may update this notice as the service changes. Material changes will be highlighted on this page with a new "last updated" date. See also our Terms of Service.
