Privacy Policy

GENERAL PRIVACY POLICY
We are committed to protecting the privacy and personal data of our users and partners. This Privacy Policy explains how Hoopit collects, uses, stores and protects personal data when you use our services, and what rights you have regarding your personal data.

Data Controller vs. Data Processor For personal data related to your membership and activity in a specific club/association, the club is the Data Controller, while Hoopit operates as a Data Processor on behalf of the club to deliver the Service. For data we collect for our own purposes (such as improving the platform), Hoopit acts as the Data Controller.

1. WHICH PERSONAL DATA DO WE PROCESS?

We process personal data about our users to the extent necessary to provide and administer the Service and to ensure that users have access to relevant information related to their participation in clubs, teams, and activities managed through Hoopit.

This includes, but is not limited to, the following types of personal data:

  • Name, address, email address, telephone number, and affiliation with a named club/association.
  • Date of birth of children (to indicate affiliation within an age-specific group and membership register).
  • Date of birth of guardians (for use in identification and security).
  • Indication of the relationship between named users (guardians/children/coaches, etc.).
  • Information about events (training sessions, matches, and other events organized by the club/association). This may also include team lineups, etc.
  • Profile pictures and other user-generated content shared within the Service, such as posts, comments, messages, images, or attachments.
  • Technical information such as IP address, device type, operating system, and log information generated through use of the Service
  • When the Service is used to process payments (e.g., membership fees or training fees), we process information necessary to facilitate such payments, including transaction history and invoicing details. Payment card information is processed securely by our payment providers and is not stored in full on Hoopit’s servers.

Hoopit does not intend to collect or process special categories of personal data as defined in Article 9 of the GDPR. The Service is not intended for the storage or sharing of such information, and users and clubs are instructed not to upload or share sensitive personal data through the Service.

2. MINORS AND PARENTAL CONSENT

The Service may be used by organizations whose members include minors. Where a user is below the age of digital consent under applicable law (for example under 16 years of age under the GDPR, or a lower age where permitted by national law), the Customer using the Service is responsible for ensuring that any required consent from a parent or legal guardian has been obtained before the minor is granted access to the Service.

Hoopit does not independently verify parental consent and relies on the organization using the Service to comply with applicable legal requirements.

 

3. WHY DO WE PROCESS YOUR PERSONAL DATA?

The personal data we process will primarily be used to administer and manage the Service on behalf of the association/team and to offer our users the necessary information about activities organized by the club/association.

4. HOW DO WE COLLECT YOUR PERSONAL DATA?

The information we process stems either from information the user provides to us directly in connection with registering as a user of the Service, in addition to information we receive from the club/association. Information can also be generated through the customer’s activity in connection with the customer relationship when the customer communicates with us.

We also retrieve information from the following integrations:

  • NIF: If your club uses the NIF (Norwegian Olympic and Paralympic Committee and Confederation of Sports) integration.

5. WHAT IS THE LEGAL BASIS FOR THE PROCESSING OF YOUR PERSONAL DATA?

We process personal data based on one or more of the following legal bases:

  • Performance of a contract (to deliver the Service to the Customer)
  • Legitimate interests (to operate, secure and improve the Service)
  • Legal obligations (for example accounting and regulatory requirements)
  • Consent where required (for example marketing communications or optional integrations)

6. WHO HAS ACCESS TO YOUR PERSONAL DATA WITH US?

We will limit access to the personal data of our users to those who need such access based on the purposes mentioned in section 1 above. The information will also be available to designated representatives of the club/association with which the user is affiliated.

We may also share this information with our data processors (see section 7), and in case of specific needs, also the company’s advisors, auditors, lawyers, IT consultants, and others. In such cases, we will ensure that all information is processed fully in accordance with the purpose and that our suppliers assume responsibility for maintaining information security.

We explicitly note that parts of the information we store about our users will also be available to other registered users of the Service, for example, to be able to search for team and association members affiliated with the same team/association as the user themselves. The solution also includes an “autocomplete” function for lookups, which will suggest names/associations for initiated searches in the solution. The information available is the user’s name and group affiliation.

All employees at Hoopit have signed confidentiality agreements.

7. TO WHOM DO WE DISCLOSE YOUR PERSONAL DATA?

We may use suppliers (data processors) who assist us with the processing of personal data. This includes, among others, suppliers of storage services, payment processing, and operation and maintenance services. A complete and continually updated overview of our sub-processors can be found here: hoopit.io/data-processors/.

Our data processors may be located abroad (both inside and outside the EU/EEA). In the event of any transfers of personal data outside the EU/EEA, we ensure that the transfer is subject to valid transfer mechanisms approved by the EU Commission, such as Standard Contractual Clauses (SCCs) or a formal adequacy decision.

Information about name, address, age, and club affiliation will also be made available to the Norwegian Olympic and Paralympic Committee and Confederation of Sports (NIF) to establish and maintain the mandatory connection to their central register. Otherwise, the information will not be made available to outside parties for any purpose

8. HOW AND FOR HOW LONG DO WE STORE YOUR PERSONAL DATA?

Personal data is stored for as long as it is needed based on the purpose of the processing. When your relationship with the club ends, your general profile information will be deleted or anonymized within a reasonable time. However, information related to payments and transactions will be stored for up to 5 years to comply with statutory requirements for accounting documentation under the Bookkeeping Act.

Personal data we collect in connection with the use of our services is mainly stored de-identified or encrypted. You may at any time ask us to delete information related to you, unless there is a statutory requirement to retain the information for a certain period.

9. MARKETING AND COMMUNICATIONS

We want to keep you informed about relevant updates and make sure you get the most out of Hoopit. All such communications are carried out in accordance with applicable marketing legislation or based on your explicit consent.

Opting out: You can unsubscribe from our marketing list or withdraw your consent at any time by using the “Unsubscribe” link in any of our emails or contact us directly at kontakt@hoopit.io.

10. DATA SUBJECT RIGHTS

We are committed to keeping you informed about how we process your personal data. Under the applicable data protection legislation, you have the right to:

  • obtain access to the personal data we process about you,
  • demand that incorrect, unnecessary, deficient, or outdated personal data be corrected or removed,
  • receive the personal data about yourself that you have provided to us and transmit it to another data controller (data portability),
  • withdraw any consents you have given (e.g., for marketing),
  • contact us with any questions or concerns regarding the processing of your personal data
  • request restriction of processing
  • object to certain types of processing based on legitimate interests
  • lodge a complaint to the Norwegian Data Protection Authority (Datatilsynet), or to the national data protection supervisory authority in the EU/EEA country where you live or work, if you believe that the processing of your personal data violates applicable legislation.

 

11. HOW DO WE PROTECT YOUR PERSONAL DATA?

We have implemented a comprehensive set of technical and organisational measures to ensure that your personal data is processed securely and in accordance with applicable legislation. These measures operate at multiple levels and include regular risk assessments, technical safeguards and physical security procedures to prevent unauthorised access, loss or misuse of personal data.

We have also established a dedicated process for identifying, assessing and handling data breaches and security incidents. This ensures that any breach is detected promptly, contained and reported in accordance with applicable obligations.

12. HOW CAN YOU CONTACT US?

Customers and users who have questions or claims associated with our processing of personal data can contact us via:

Club United AS (Hoopit)
Business Reg. No.: 917 100 179
Address: Solheimsgata 18
2000 Lillestrøm
Norway
Email: kontakt@hoopit.io

13. CHANGES TO THIS PRIVACY POLICY

We may update this privacy notice from time to time. Any significant changes will be communicated clearly on our website, or by email to affected parties.

14. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar technologies to operate the website, improve the user experience, and analyze usage of our services.

Cookies are small text files stored on your device when you visit a website. They allow the website to recognize your device and remember certain information.

Cookies may be used for:

  • ensuring that the Service functions properly
  • remembering user preferences
  • analyzing usage and performance of the Service

Where required by law, we will obtain your consent before storing or accessing non-essential cookies on your device.

For more information about the cookies, we use and how to manage them, please see our Cookie Policy.

Last updated: 2026-03-12