Skip to content
Language: en

Personal data processing notice — Panka application

Last updated: 28 August 2026

Panka is an application for managing a football team and for playing a fantasy game internal to that team. The service therefore involves the processing of data relating to natural persons: the composition of the squad, call-ups, performance ratings, medical certificate expiry dates and the payment of dues.

This document sets out the data processed, the purposes and legal bases, the retention periods and the parties who have access to the data. It is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”).

1. Data controller

The data controller is Panka S.r.l., with registered office at Viale Aldo Moro 16, 40127 Bologna, Italy, VAT and tax code 04398091209, registered with the Bologna Companies Register under no. REA BO-590392.

Any request may be addressed to privacy@panka.app. Certified electronic mail: pankasrl@pec.it.

The Controller is also answerable for data entered by the team’s staff, having assumed sole controllership rather than allocating it to the individual managers of each group. It follows that every request may be addressed to a single party.

2. Persons to whom this notice is addressed

This document is addressed to three categories of data subject, whose positions within the application differ.

CategoryAccountParty entering the data
Users of the application: players, coaches, club officersYesThe data subject, together with the data entered by the staff
Persons listed in a squad without having registeredNoThe team’s staff. For those persons this document constitutes the notice required under Article 14 GDPR; see §11
Persons attending a trial or a training session as guestsNoThe staff, who record their name and a contact detail

3. Categories of data processed

CategoryData
Identification and contact dataFirst name, surname, email address, nickname, date of birth, image
Login credentialsProcessed in protected form by the authentication service provider
Health data (special category, Article 9 GDPR)Only the issue and expiry dates of the sports medical certificate are processed. The document itself is not uploaded or stored and remains with the sports club and the certifying doctor
Financial dataDues owed, instalments and recorded payments. No payment card or bank account data are processed; these records do not constitute accounting entries
Sporting activity and contentCall-ups, line-ups, training attendance, goals, the coach’s ratings and comments, game scores and standings
Technical identifiersNotification tokens, device type, language
Location dataThe team’s home ground and the pitches used for matches and training; the device’s location is not processed
Web version usage statistics (subject to consent, once enabled)Installation identifier, screens viewed and application usage events — such as the opening of a feature, the completion of a guided procedure or the outcome of an operation — application version, operating system, device type, language and the IP address in anonymised form. No data capable of revealing health status, no payment data and no content entered by the user are processed. No advertising purposes and no profiling activities are involved
Data received from the authentication provider, where access is obtained through Google, Apple, Facebook or XName, email address and, where available, profile image. The password is not transmitted and the Controller is not able to publish content on the user’s behalf

The application does not collect the device’s geographical location at any time.

4. Purposes and legal bases

PurposeLegal basis
Creation of the account and provision of the servicePerformance of a contract (Article 6(1)(b) GDPR)
Management of the squad, matches, call-ups, ratings and the gameLegitimate interest of the Controller in the operation of the team and of the game (Article 6(1)(f) GDPR)
Retention of the multi-season record of the team’s activityLegitimate interest in preserving a record of past sporting activity (Article 6(1)(f) GDPR)
Processing of medical certificate datesExplicit consent (Article 9(2)(a) GDPR) and/or the obligation, connected with sporting activity, to establish who may take part in matches
Management of dues and paymentsPerformance of a contract or of the membership relationship
Sending push notificationsThe permission granted to the device, revocable at any time
Sending marketing communications by emailConsent of the data subject, given by means of a separate, non-pre-ticked box
Measurement of web version usage statisticsConsent of the data subject

Where the legal basis is legitimate interest, the right to object applies, as set out in §12.

5. Minors

An account may be created only by persons who have reached the age of fourteen, in accordance with the threshold set in Italy pursuant to Article 8 GDPR. For that reason the date of birth is a mandatory item at registration: without it the threshold could not be verified.

Children under the age of fourteen do not have an account and may nonetheless be part of the squad: their record is entered and managed by the staff, as set out in §11.

The publication of a minor’s image on a shareable card is excluded in all cases, without exception.

6. Shareable cards

The application allows images to be generated for sharing in the team’s chat: the match result, the standings, the line-up, an individual player’s card. This is the only feature that involves a name and an image leaving the perimeter of the application and it is therefore subject to specific rules.

Cards show the nickname and not the first name and surname. Where no nickname is set, the first name and the initial of the surname are shown; where the data subject has objected, the wording “Player” is shown.

Cards containing an image may be generated only in respect of adults and only within teams that have declared that they have obtained the relevant releases. The data subject may in any event share their own card, that being a decision concerning themselves.

A card link is valid for twenty days, after which it ceases to work; the image is deleted from the Controller’s servers after thirty days. Cards already forwarded to third parties cannot be recovered: expiry operates on the link generated by the Controller and not on copies already distributed.

An objection to appearing on any card may be raised from the personal profile or, where there is no account, to the team’s staff. The objection takes effect immediately and results in the deletion of cards already generated.

7. Access to data within the team

Access to data varies according to role. The restriction is not left to the interface: it is configured at database level.

RoleData accessible
PlayerSquad, matches, ratings and standings of the team. As regards dues and certificates, only their own
CoachThe above, together with the dues and certificates of the entire squad, given their organisational role
Club officer (administrator)The above, together with management of the squad, invitations and team settings
Panka S.r.l.The technical personnel appointed, authorised to process the data under written instructions and solely for the operation and maintenance of the service

A team may disable the medical examination and dues modules entirely; where it does so, the corresponding data are not processed.

8. Recipients of the data

The Controller relies on suppliers that process the data on its behalf as processors, appointed pursuant to Article 28 GDPR. The data are not sold or otherwise disclosed to any other party.

Google, Apple, Meta (Facebook) and X are a separate case: where access is obtained through their authentication services, those parties do not act on behalf of the Controller but as independent controllers. They learn that Panka is being used and transmit to the Controller the name, the email address and any profile image; their own terms apply to that processing. Registration by email address is available as an alternative.

SupplierActivity carried outPlace of processing
SupabaseDatabase, authentication and file storageIreland (European Union)
Google (Firebase)Push notifications on the web versionUnited States
ExpoPush notifications on the iOS and Android applicationsUnited States
ResendSupport messages and, where consent is given, marketing communicationsUnited States
Komoot (Photon)Suggestion of towns and pitch addressesGermany (European Union)
Google (Analytics)Usage statistics on the web version, subject to consent, once enabledUnited States

9. Transfers to third countries

The majority of the data is processed within the European Union: the database, files and authentication are hosted in Ireland. Identification data, certificate dates, dues, ratings, images and cards therefore remain there.

The data transferred outside the European Economic Area, to the United States, are the content and recipient of push notifications, email messages and, once enabled, usage statistics. Those transfers take place on the basis of the Standard Contractual Clauses and/or of the EU-US Data Privacy Framework, with the safeguards provided for in Articles 44 et seq. GDPR.

Where access is obtained through Google, Apple, Facebook or X, authentication involves United States companies, which in that context act as independent controllers (§8).

10. Retention periods

DataRetention period
Account and profileUntil deletion, carried out within thirty days of the request. An account inactive for 24 months is deleted after prior notice
Medical certificate dates6 months after expiry the record can no longer be consulted; 24 months after expiry the dates are deleted. Those periods are brought forward where membership of the team ends
Dues and payments24 months from the close of the season
Training sessions and attendance5 years from the close of the season. For persons attending a trial only: 12 months
Ratings, line-ups and standingsFor the duration of membership of the team, as a record of the game
Notifications12 months
Shared cardsLink 20 days, image 30 days
Web version usage statistics14 months
Registration through an authentication provider left incompleteDeleted immediately where the registration is cancelled and within 24 hours in any other case: without the date of birth an account cannot be maintained

Deleted data may persist in backup copies until those copies expire.

11. Data entered by the team

Where the data subject is listed in a squad without having registered, the data concerning them — name, date of birth, image, certificate dates, dues, attendance — are entered by the staff. The source of the data is the team; the purposes and legal bases are those set out in §3 and §4 and this document constitutes the notice required under Article 14 GDPR.

Those data subjects have the same rights as set out in the following paragraph; their exercise does not require an account and is effected by writing to privacy@panka.app.

An objection to appearing on cards may also be raised with the team’s staff, who record it, with the same effect.

12. Rights of the data subject

The data subject may exercise the rights of access, rectification, erasure, restriction of processing, portability and objection provided for in Articles 15 to 22 GDPR. Where processing is based on consent, that consent may be withdrawn at any time, without prejudice to the lawfulness of processing carried out before withdrawal.

Deletion of the account may be requested from within the application or, without installing it, from the “Account deletion” page published on this website.

Consent to marketing communications is withdrawn through the unsubscribe link at the foot of every message.

The right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) applies in any event.

It is specified that a player record created within a team belongs to that team: deletion of the account does not remove it. Such a request must be addressed to the person managing the team; the Controller will assist.

13. Amendments to this notice

The Controller reserves the right to amend this notice, recording any amendment by updating the date shown above. Where an amendment concerns material elements — for example the introduction of a new measurement tool — consent is sought again.

← Legal documents

https://panka.app/en/legal/app-privacy/

Any request concerning the processing of personal data may be sent to privacy@panka.app. A reply is provided within one month of receipt.