Skip to content
Language: en

Notice for persons listed in a squad without an account

Last updated: 7 August 2026

Your team uses Panka, an application for managing the group and for playing an internal fantasy game. You do not have an account, but data concerning you is held in the application: it was entered by the staff when you were added to the squad.

This document sets out which data are processed, for which purposes and which rights may be exercised. It is provided pursuant to Article 14 of Regulation (EU) 2016/679 (the “GDPR”), which applies where the data have not been obtained from the data subject.

1. Data controller

The data controller is Panka S.r.l., Viale Aldo Moro 16, 40127 Bologna, Italy — VAT and tax code 04398091209, REA BO-590392. Certified electronic mail: pankasrl@pec.it.

The Controller is also answerable for data entered by the team’s staff, having assumed sole controllership rather than allocating it to the individual managers of each group. It follows that every request may be addressed to a single address: privacy@panka.app.

2. Data entered by the team

CategoryData
Identification dataFirst name, surname, any nickname, date of birth and, where uploaded, an image
Sporting activityPosition, call-ups, attendance, goals and the ratings given by the coach
Medical certificateOnly the issue and expiry dates. The certificate itself is not uploaded or stored and remains with the sports club and the certifying doctor
DuesAmount owed, instalments and recorded payments. No payment card or bank account data are processed; these records do not constitute accounting entries

The last two categories arise only where the team uses the corresponding modules, which can be enabled individually.

3. Legal bases

The processing is based on the group’s legitimate interest in organising itself (Article 6(1)(f) GDPR): in order to function, a team must be able to establish who is in the squad, who has been called up, who may take part in matches and who has paid their dues. The data are not used for advertising purposes nor disclosed to third parties.

The medical certificate dates are health data and are therefore subject to Article 9 GDPR: they are accessible to the staff alone, they do not leave the application, and the person managing the team has declared that they obtained what was required in order to record them.

4. Access to the data

Within the application the team’s staff have access to all the data. Other members have access to group data — squad, call-ups, ratings, attendance — and have no access to dues or to medical certificate dates, which are reserved to the staff.

No access is provided outside the team, save for what is shared by means of the cards, dealt with in the following paragraph.

5. Shareable cards

The application generates images intended for sharing in the team’s chat: the match result, the standings, an individual player’s card. Those images may show the nickname, the rating and the image of the data subject.

The data subject may object to appearing. From the moment the objection is raised, cards concerning them are no longer generated and group cards show the wording “Player”; membership of the team is unaffected. The objection may be raised with the staff, who record it with the same effect, and it results in the immediate deletion of cards already generated.

For data subjects who are minors, publication of the image is excluded in all cases: this is not a preference left to the user but a control applied server-side, which the application cannot override.

6. Retention periods

Data relating to the activity of the game are retained for the period determined by the team and in any event for no longer than five years from the close of the season. Medical certificate dates can no longer be consulted six months after expiry and are deleted twenty-four months after expiry. Shared cards are deleted after thirty days.

Where membership of the squad ends, the team may delete the record at any time; at the data subject’s request the Controller will do so.

7. Rights of the data subject

The data subject may exercise the rights of access, rectification, erasure, restriction of processing, portability and objection provided for in Articles 15 to 22 GDPR.

Requests are to be sent to privacy@panka.app and are answered within one month of receipt. Exercising those rights does not require installing the application or holding an account, and does not have to go through the team; where the data subject prefers to approach the staff, the staff are required to forward the request to the Controller.

The right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, www.garanteprivacy.it) applies in any event.

8. Full text

This document is the short version. The full notice for the application — purposes, suppliers receiving the data and retention periods in full — is published at panka.app/en/legal/app-privacy, together with the other documents.

← Legal documents

https://panka.app/en/legal/roster/

Any request concerning the processing of personal data may be sent to privacy@panka.app. A reply is provided within one month of receipt.