Comment Compteam respecte la loi andorrane sur la protection des données pour votre salle, et ce que vous, admin de section, devez faire pour rester conforme.
Under the Andorran data-protection law — Llei 29/2021 (LQPD), closely aligned with the EU GDPR — your gym is the data controller for your athletes' personal data: you decide why and how it is used. Compteam is the data processor: we host the software and process the data only on your instructions, under the Data Processing Agreement you accept at sign-up.
This guide explains what we handle for you, and the few things that remain your responsibility as the controller.
You don't have to build any of this — it's built in:
When you register your branch you get a default Terms & Conditions template. Review and customise it to match how your gym actually operates — it's a starting point, not legal advice. Athletes accept your Terms and the privacy notice when they join, so make sure the text is accurate before you invite them.
Under the LQPD (Art. 8), a person under 16 cannot consent on their own to an online service — a parent or legal guardian must. Compteam enforces this: an under-16 cannot self-register. Instead, you add them as a member through the kids flow, where their guardian gives consent. See the Kids program guide.
Collect and store only the personal data you actually need to run the membership (data minimisation, Art. 5). In particular, don't put health/medical information (injuries, medical conditions) into free-text fields — health data is a special category (Art. 9) that needs a separate, explicit consent. If you need to record it, ask first.
If an athlete asks to access, correct, or delete their data, the in-app tools cover most cases — point them to their profile, or use the admin export. You are the controller, so the request is ultimately yours to honour.
Athletes (and you) can complain to the Andorran supervisory authority, the Agència Andorrana de Protecció de Dades (APDA) — www.apda.ad (Art. 61). Keep your gym's own records of how you handle personal data.