Privacy Policy
Effective date: 12 August 2026
1. Introduction
PLATT Performance Oy ("we", "us", "our") respects your privacy and protects your personal data. This policy explains what personal data we collect, why we collect it, the legal grounds we rely on, how long we keep it, who else sees it, and what rights you have. It is written under the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (Tietosuojalaki 1050/2018).
Some of the information we hold about coaching clients is sensitive. Section 5 explains how we handle it. Some of our clients are under 18. Section 11 explains what that means for players and guardians.
2. Who is responsible for your data
The controller of your personal data is:
PLATT Performance Oy
Pohtosillankuja 6, 33400 Tampere, Finland
Business ID (Y-tunnus): 3627391-6
VAT: FI36273916
Email: contact@plattperformance.com
Phone: +358 45 147 6816
​
We have not appointed a Data Protection Officer. We are not required to. For any privacy question, write to the email above and Geoff Platt will answer personally.
3. What personal data we collect
If you visit the website or contact us
Your name and email address.
Anything you choose to write in a contact form or email.
Limited technical information about how you use the site, collected through cookies and analytics. See Section 9.
If you book or receive coaching
Contact details for the client and, where the client is under 18, for the guardian.
Booking and scheduling information.
Billing information: invoices, payments, and what is needed for our accounts.
Information about the client's sport, training, goals and situation, shared by the client or by the guardian.
Written session notes. After a session we write a short record of what was covered, what the client identified, and what was agreed for next time. Clients receive a written summary. We keep a copy.
We collect only what we need. You do not have to give us personal data, but without it we may not be able to answer you or provide coaching.
4. Why we process your data, and the legal grounds
The GDPR requires a lawful ground for every use of personal data. Ours are:
​
Answer enquiries and contact-form messages — Our legitimate interest in replying to people who contact us, and steps taken at your request before a contract
Schedule and manage sessions — Performance of a contract
Provide coaching and keep session notes — Performance of a contract, and, for the sensitive parts, your explicit consent — see Section 5
Invoice, keep accounts, meet tax obligations — Compliance with a legal obligation
Establish, exercise or defend a legal claim — Our legitimate interest, and Article 9(2)(f) where sensitive data is involved
Analytics and non-essential cookies — Your consent
Where we rely on consent, you can withdraw it at any time. Withdrawal does not make earlier processing unlawful.
We do not sell or rent personal data. We do not use it for automated decisionmaking or profiling.
5. Sensitive information, and why we ask for separate consent
Coaching touches on how a person is doing: stress, sleep, recovery, confidence, pressure, and sometimes injury. Under the GDPR this counts as data concerning health, which is a special category of personal data under Article 9. Health data covers mental as well as physical health, and it does not need to come from a doctor to count.
Special category data needs a second, separate legal ground on top of the one in Section 4. We rely on Article 9(2)(a), explicit consent.
That is why the coaching agreement contains a separate, clearly marked consent statement, signed by the client and, where the client is under 18, by the guardian. It is separate from agreeing to the coaching terms, and you can decline it or withdraw it and still be coached.
If you withdraw that consent, tell us by email. We will stop keeping written session notes from that point, and we will delete the notes we hold, unless we are required to keep something by law or need it to defend a legal claim. Coaching can continue without written notes if you prefer.
​
We do not provide healthcare and we are not a healthcare provider. Coaching is not therapy or medical treatment, and these records are not patient records.
6. Who else sees your data
We share personal data only with service providers who help us run the business, and only as far as needed. They act on our instructions, or as independent controllers under their own policies.
Wix — website hosting and site analytics.
Google — business email and file storage.
Calendly — appointment scheduling.
Apple (iCloud) — session notes are written and stored on a passcode-protected, encrypted iPad in a folder used only for PLATT Performance. That folder syncs to iCloud.
Otter.ai — used at times to transcribe spoken notes made after a session. Where this is used, the recording and transcript are deleted once the written note is made.
Alttum Oy and Procountor — bookkeeping and accounting. They see invoicing and payment data. They do not see session notes.
Session notes are never shared with a club, a team coach, an agent, or a sponsor.
We do not share your data with anyone for their own marketing.
​
We may disclose information if the law requires it, or if there is a serious risk to the safety of the client or another person. Section 12 explains this.
7. Data outside the EU
Some of the providers above, including Wix, Google, Calendly, Apple and Otter.ai, may store or process data outside the European Economic Area, including in the United States. Where that happens the transfer is covered by safeguards recognised under the GDPR, such as the European Commission's Standard Contractual Clauses or the provider's certification under the EU-U.S. Data Privacy Framework. Write to us if you want details of the safeguards for a particular provider.
8. How long we keep data
Enquiries that do not become an engagement — 12 months, then deleted
Contact and booking details of clients — 2 years after the last session, then deleted
Written session notes — 2 years after the last session, then deleted
Audio recordings and transcripts used to make a note — Deleted as soon as the written note is made
Accounting and invoicing records — At least six years from the end of the financial year, as required by Finnish accounting law
Analytics — According to the settings of the tools we use
The two-year period reflects the general three-year limitation period for claims under Finnish law, kept shorter because we should hold no more than we need. We review and clear old records at least every two years. You can ask us to delete session notes sooner. See Section 10.
9. Cookies and analytics
-
Essential cookies make the site work. They do not need consent.
-
Analytics and other non-essential cookies help us understand how the site is used. These are set only with your consent, asked for through a cookie banner.
You can change or withdraw your cookie choices at any time, and control cookies through your browser.
10. Your rights
Under the GDPR you have the right to:
-
See the personal data we hold about you.
-
Have inaccurate or incomplete data corrected.
-
Have your data deleted.
-
Have processing restricted in certain situations.
-
Object to processing based on our legitimate interests.
-
Receive your data in a portable, machine-readable format.
-
Withdraw consent at any time, where we rely on consent.
To use any of these rights, email contact@plattperformance.com. We answer within one month, as the GDPR requires.
You also have the right to complain to the Finnish supervisory authority: Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
11. Clients under 18
Some of our clients are under 18. Here is how that works.
-
The guardian agrees to the coaching. The coaching agreement and the consent in Section 5 are signed by a guardian as well as the player. The guardian knows the coaching is taking place and pays for it.
-
The player is the person the data is about. The rights in Section 10 belong to the player, and a player can use them.
-
What is said in session stays in session. A young person's sessions are held in confidence in the same way as an adult's. We do not report on sessions to a guardian as a matter of course. The written summary after a session goes to the client.
-
The limit is safety. If there is a serious risk to the young person's wellbeing or safety, or where the law or child protection requires it, we will involve the guardian or the appropriate people.
-
A guardian's right of access. A guardian may ask to see the data we hold about their child. We weigh that against the young person's own right to confidentiality, taking account of the young person's age and maturity, and we will talk to the young person before releasing session notes.
-
Age 13. Under the Finnish Data Protection Act, 13 is the age from which a young person can consent independently to online services. That rule is about signing up to online services. It does not replace the guardian's role in agreeing to coaching for a person under 18.
If you believe we hold a young person's data without proper consent, contact us and we will deal with it promptly.
12. Confidentiality and its limits
What you share in a session stays between you and your coach. We will not talk about your sessions with anyone else without your agreement.
The limits are safety and the law. If there is a serious risk to you or to someone else, or where the law requires it, we may have to share what is necessary. Where it is safe and appropriate, we will tell you that we are doing this and why.
Where sessions take place at a club facility, physical work done in the open may be discussed with the club’s coaches, so that it fits the player’s training. What is spoken about in a session is not shared with the club. Written session notes are never shared with a club, a team coach, an agent, or a sponsor.
This matches section 6 of the PLATT Performance Coaching Agreement.
13. Security
Session notes are written and kept on a passcode-protected, encrypted iPad, in a folder used only for PLATT Performance. Accounts are protected by strong passwords and two-factor authentication where the provider offers it. Access is limited to Geoff Platt. Notes are not kept in shared folders.
If a data breach happens that is likely to be a risk to you, we will tell the supervisory authority within 72 hours and tell you directly where the GDPR requires it.
14. Changes to this policy
We may update this policy. The current version is always on this page with its effective date at the top. If we make a change that materially affects coaching clients, we will tell them directly.
15. Contact
PLATT Performance Oy
Pohtosillankuja 6, 33400 Tampere, Finland
Business ID: 3627391-6 · VAT: FI36273916
contact@plattperformance.com ·
+358 45 147 6816