Courtesy translation. In case of any discrepancy between versions, the Brazilian Portuguese version prevails.
Privacy Policy
DataVoga · Last updated: 6 August 2026
This Policy explains how we process personal data on the DataVoga platform, in accordance with the Brazilian General Data Protection Law (Law 13,709/2018, the LGPD).
1. Who we are (platform operator)
The DataVoga platform is operated and maintained by DATAVOGA TECNOLOGIA E SERVICOS LTDA, a company registered in Brazil under CNPJ 67.564.430/0001-07 (“DataVoga”, “we”).
The platform is made available to clubs, federations and other rowing institutions (“Institutions”), which use it to manage their athletes, crews, training and competitions. For athlete data entered and managed by the Institution, the Institution is the Controller and DataVoga acts as Processor, processing the data on behalf of and according to the Institution’s instructions. For the account data of people who register directly (for example, the athlete or the manager), DataVoga processes it to enable access and the provision of the service.
2. Data Protection Officer
Questions, requests or complaints about your data: Fernando Turatti, e-mail dpo@datavoga.com.
3. What data we process
- Athletes and rowers: name, date of birth, sex, weight, rowing side, contact details (e-mail and phone), photo (optional) and, where applicable, para-rowing classification. We also process performance and rowing telemetry data (distance, time, pace, power, stroke rate and heart rate), both in the boat and on the indoor rower (Concept2 / PM5 ergometer), as well as the history of workouts, sessions and challenges.
- Institution staff and managers: name, e-mail, phone, access credentials and usage records (actions on the platform, for security and audit purposes).
- Technical data: access logs and identifiers required for security and operation.
4. Why we use it (purposes) and legal basis
- To provide the rowing management service (athlete and crew records, training telemetry, challenges, competitions and rankings): performance of a contract and legitimate interest (article 7, items V and IX of the LGPD); for athletes, also consent where applicable.
- Public display of an athlete profile: only with the athlete’s explicit opt-in consent, which can be withdrawn at any time.
- Communication with athletes and managers (e-mail) about access, training and events.
- Security, fraud prevention and audit: legitimate interest and compliance with legal obligations.
5. Sharing
Athlete data is accessible within the Institution’s hierarchy (club and, where authorised, federation), according to the sharing consent set by the athlete or the Institution. We use sub-processors (cloud infrastructure and e-mail delivery providers) that process data on our behalf, under contract and confidentiality. If you choose social login (Google), authentication takes place with that provider, under its own policies. We do not sell personal data. Anonymised telemetry data (detached from any identifiable person, under article 12 of the LGPD) may be used and shared in aggregated form for studies, statistics and improvement of the platform, as set out in section 6 of the Terms of Service.
6. Storage and security
We apply technical and organisational measures to protect the data (role-based access control, hashed passwords, transmission over secure HTTPS channels and audit logging). Sensitive data is not made public without consent.
7. Retention
We keep the data for as long as necessary for the purposes above and for legal obligations, or while the account or the link to the Institution is active. Once the link ends, or a deletion request is fulfilled, the data is deleted or anonymised, unless a legal retention obligation applies.
8. Your rights (LGPD, article 18)
You may request: confirmation that processing takes place, access, correction, anonymisation or deletion, portability, information about sharing, and withdrawal of consent. To exercise them, contact the Data Protection Officer (section 2) or use the Data deletion page.
9. Cookies and social login
The platform uses strictly necessary cookies (authentication and session handling) and Google Analytics, for aggregated and anonymous usage metrics (pages visited, traffic source), with no sale or commercial sharing of data. We do not use advertising cookies. If you use social login (Google), that provider may set its own cookies, governed by its policies, only when you choose that way in.
10. Data deletion
You may request the deletion of your data at any time on the Data deletion page (form) or by e-mail to the Data Protection Officer (dpo@datavoga.com).
11. Changes
We may update this Policy; the version in force is always on this page, with the date of the update. Continued use after a change means acceptance of the version in force.
