Privacy
Privacy Policy
Last updated: 2026-09-23
Explains how we process personal data on the site and in João Rangel football training services. Covers only real processing.
1. Data controller
João Rangel Miguel – Sociedade Unipessoal, Lda. (NIPC 519294610), trading as João Rangel, is the controller of personal data collected via joaorangel.pt and in the course of training services.
Address: Avenida do Colégio Militar 34 A, 1500-185 Lisboa. Contact: joaorangeltreinador@gmail.com · 912 391 386.
2. Categories of data
We process only data needed for the purposes below. Typically:
- Identification and contact details of the parent/guardian / client (name, email, phone/WhatsApp).
- Athlete data needed for the service (name, age band or date of birth once a client, club/sport context, schedule preferences).
- Commercial data (packs, sessions, payments, invoicing).
- Content of site requests (help/diagnosis form answers).
- Minimal technical site data (e.g. cookie preference; hosting security logs).
- Image/video only with specific authorisation.
- Sports analysis data (GPS, technical video, etc.) when included in the contracted service.
3. Purposes and legal bases
We do not rely on consent for everything. Typical bases are:
- Site requests / leads: steps prior to a contract at the data subject’s request and/or legitimate interest in replying (GDPR Art. 6(1)(b) and/or (f)).
- Training contract, packs, bookings and payments: performance of a contract (Art. 6(1)(b)).
- Invoicing and tax/accounting duties: legal obligation (Art. 6(1)(c)).
- Marketing: only with consent (Art. 6(1)(a)), optional and separable.
- Image for marketing: specific consent, independent of the training contract.
- Site security and abuse prevention: legitimate interest (Art. 6(1)(f)).
- Web analytics (Vercel): only if you accept analytics in cookie preferences (consent).
- Internal CRM AI assistance (OpenAI): legitimate interest in supporting management and accompaniment (Art. 6(1)(f)), with a right to object; may coexist with pre-contractual/contractual steps (Art. 6(1)(b)) when context is needed to reply to you.
3A. Artificial intelligence assistance
We use artificial intelligence tools (notably OpenAI services) to support internal CRM management and accompaniment of leads and clients — for example to gather operational historical context, improve reply quality, detect patterns useful for human decisions, and draft replies. Access is broad to the operational/commercial/relational data needed for these purposes, but does not mean sending the entire database with every request.
Relevant decisions (commercial contacts, sending messages, contract changes) remain under human control. We do not take solely automated decisions with legal or similarly significant effects on you in this context (GDPR Art. 22).
Health data and other identified special categories (including Terms health notes and clinical fields) are not sent to these tools. You may object to this legitimate-interest processing by contacting us; that does not erase data needed for the contract or invoicing.
4. Minors
Many athletes are under 18. The parent/guardian is normally the contact and contracting party. On the public form we mainly ask for the responsible adult’s contact and the player’s age band — we do not ask for date of birth on the initial request.
Data about the minor is limited to what is needed to deliver and safely run the service (identification, sport context, bookings, and, when applicable, safety-relevant information provided by the guardian).
5. Forms and leads
The help / diagnosis request on the site collects name, contact channel and category answers. It is used so João Rangel can contact you about that request (transactional). Campaigns only with a separate marketing opt-in, unchecked by default.
6. Clients, athletes, packs, sessions and payments
When there is a commercial relationship, we process data to manage athletes and guardians, packs, sessions, payments and invoicing. The CRM runs with controlled server-side access; we do not expose the backend to the public visitor’s browser.
7. WhatsApp, Instagram and Facebook messaging
We may receive and, when legally allowed and operationally approved, send service messages via WhatsApp Business, Instagram Direct and Facebook Messenger linked to the internal CRM. This covers:
- Message content and technical metadata needed (message identifiers, timestamps, delivery status when available).
- Phone numbers in international format (WhatsApp) and Meta platform conversation identifiers.
- Media files sent by the client (e.g. image, audio) stored privately in our storage with controlled access.
- Audio transcriptions when generated to aid CRM reading (no automated marketing analysis).
- Messages sent manually in the WhatsApp Business app and messages sent via an approved API — both linked to the same service conversation when possible.
8. Image, video and sports analysis
Use of image/video for marketing or social media requires express authorisation, separate from the training contract. Technical analysis with video/GPS/other tools, when contracted or agreed, is for sporting/informational purposes and is not a medical diagnosis.
9. Recipients and processors
The following may process data on our behalf as needed for the service:
- Vercel Inc. — Website hosting and web analytics (aggregated / no first-party analytics cookies from the app)
- Supabase — Database and server-side storage for requests and service data
- Resend / Gmail (quando usados) — Transactional email sending (e.g. Terms and service communications)
- Meta Platforms (WhatsApp / Instagram / Facebook) — Professional messaging channels when a client contacts us or when we send approved service messages (WhatsApp Business, Instagram Direct, Facebook Messenger)
- YCloud (quando usado com WhatsApp) — Technical WhatsApp API provider in coexistence with the WhatsApp Business app
- OpenAI — AI tools that support internal CRM management (operational context, drafts and patterns) under our instructions; health data is not sent
10. International transfers
Some processors (e.g. Vercel, Meta, OpenAI, email providers) may process data outside the EEA. Where that happens, legal safeguards apply (e.g. standard contractual clauses or adequacy decisions), without disclosing internal technical details.
11. Retention
We keep data while needed for the purposes and legal duties (notably tax/accounting). Unused leads are reviewed operationally after about 24 months — our operational practice, not an absolute legal deadline. Cookie preferences stay on your device until you change them. For deletion requests linked to Meta messaging, see also /data-deletion. AI assistance retention is limited to usage metadata and what is needed for the service.
12. Rights
You may request access, rectification, erasure, restriction, objection (including to AI assistance based on legitimate interest) and, where applicable, portability via joaorangeltreinador@gmail.com. You may also lodge a complaint with the Portuguese DPA (CNPD) (https://www.cnpd.pt).
13. Security
We apply technical and organisational measures appropriate to the risk (access control, HTTPS, CRM role segregation). We do not publish architecture details or secrets.