RacqI — Racquet Sports Intelligence
Legal

Privacy Policy

RacqI (Racquet Sports Intelligence) Provided by RacqI S.r.l.s. (in formation), Pavia, Italy www.racqi.cloud Version 1.1 — Last updated: August 2026

This Privacy Policy explains how RacqI (Racquet Sports Intelligence) ("we", "us", or "our"), a SaaS product provided by RacqI S.r.l.s., a company in formation based in Pavia, Italy, collects, uses, stores, and protects your personal data when you use RacqI (the "Service").

The Service is currently provided as a beta. The privacy practices described here apply to the beta phase. Where material changes occur after the beta phase, we will notify you in advance and, where appropriate, request renewed consent before the changes take effect.

We are committed to protecting your privacy and processing your data in accordance with the EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, and other applicable data protection laws.

By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with these practices, please do not use the Service.

1. Data Controller

The data controller responsible for processing your personal data is:

RacqI S.r.l.s. (in formation — in costituzione)

Società a responsabilità limitata semplificata

Registered office: Via Montebello della Battaglia 4, 27100 Pavia (PV), Lombardy, Italy

Share capital: EUR 1,000

VAT / Codice Fiscale: [to be assigned upon incorporation]

Company registration / REA number: [to be assigned upon incorporation]

Legal representative: Rachele Gaebel (Founder & CEO)

General contact: support@racqi.cloud

Website: www.racqi.cloud

Note on legal form and company structure: RacqI S.r.l.s. is a società a responsabilità limitata semplificata currently in the process of incorporation (in costituzione) in Italy. RacqI S.r.l.s. is an independent company that owns the RacqI platform, its data, and the RacqI brand, and it is the entity responsible for providing the Service and acting as data controller. RacqI S.r.l.s. builds on, but is legally distinct from, the Racquet Sports Institute — an established domain-knowledge body that contributes curated industry expertise to the RacqI knowledge base under a defined arrangement; the Racquet Sports Institute does not process the personal data of users of the Service. As the company is currently in formation, certain registration details (VAT / Codice Fiscale and company registration / REA number) will be finalised upon incorporation, and we will publish an updated version of this Privacy Policy reflecting the completed registration details. As a company built for a global market, we also anticipate a future conversion to an EU Inc. (the EU's planned 28th-regime company form) once that form is legally finalised and applicable. None of these steps will change the location of data processing, the categories of data processed, the purposes of processing, the processors involved, or your rights under the GDPR.

2. What Data We Collect

2.1 Account Data

When you register for the Service, we collect:

Email address

Password (stored in hashed form only)

Name (if provided)

Account creation and authentication is handled through Clerk, a third-party identity provider. We receive only the data necessary for authentication and account management from this provider.

2.2 Profile Data

You may provide profile information to improve the relevance of the Service, including:

Primary and secondary sport (Badminton, Padel, Pickleball, Squash, or Tennis)

Facility type (e.g. Commercial, Non-Profit/Club, School/University, Member Club, Add-on)

Project phase (Idea, Planning, Construction, Operating, Expansion)

Location (city, country, or street address)

Project name and free-text project notes

Response preferences (answer format, communication tone)

Providing profile data is voluntary in the sense that you decide whether and what to enter. Where you do provide it, the core parameters (sport, facility type, project phase, location) are processed to deliver the analysis you have requested and are therefore necessary for the performance of our contract with you; free-text project notes and response preferences are processed on the basis of your consent. You can view, edit, or delete all profile data at any time via the settings area (Memory + Privacy) of the Service.

2.3 Conversation Data

When you use the Service, we process:

Your prompts, questions, and messages

AI-generated responses

Documents and files you upload for analysis

Follow-up selections (Clarifier responses)

PDF export requests

2.4 Memory Data

The Service includes an optional memory feature that stores contextual information across sessions to improve answer quality. Memory data may include:

Facts, preferences, and project details extracted from your conversations (if "Auto-extract from conversations" is enabled)

Information you add manually to the "What the Agent Knows About Me" section

Each memory entry is labelled with a category (Preference, Fact, Context, Project, or Other) and a source indicator showing whether the entry was provided directly by you or extracted automatically from a conversation. You have full control over memory data and can view, edit, or delete any entry at any time.

2.5 Usage and Technical Data

We may collect limited technical data necessary for operating the Service, such as:

IP address (for security and abuse prevention)

Timestamps of access and interactions

Error logs and performance metrics

Hashed user identifiers attached to error reports (used for correlating bug reports without revealing your identity)

2.6 Location Data

If you provide a location (city or address) as part of your profile or within a question, the Service uses it to query external public-data APIs for location intelligence (competitor mapping, transport access, climate data, economic context). The location is processed for this purpose only and is not shared with third parties for any other purpose. No personal data beyond location coordinates is transmitted to these APIs.

2.7 Cookies and Local Browser Storage

We use the following browser storage mechanisms, all classified as strictly necessary under the ePrivacy Directive (no consent required):

Authentication cookies (set by Clerk): session management and login state. Lifetime: until logout or session expiry.

Rate-limiting tokens (browser localStorage): anti-abuse tracking on your local device only — these tokens are never transmitted to our servers and exist purely to slow down repeated interactions from the same browser. Lifetime: up to 90 days, automatically rotated.

UI preferences (browser localStorage): language preference, theme. Lifetime: until you clear browser storage.

We do not use third-party tracking cookies, advertising cookies, or analytics that track behaviour across websites. We do not use cookies for advertising or behavioural tracking.

2.8 Website Analytics

To understand which pages of this website are read and how visitors find us, we use Matomo, an open-source analytics tool that we host ourselves. It runs on our own server at www.racqi.cloud/analytics in Italy. There is no Google Analytics on this site and no analytics provider receives your data.

No cookies. Matomo is configured in cookieless mode: it sets no cookies and writes nothing to your browser storage. That is why this site shows no cookie banner.

IP addresses are anonymised. The last two bytes of every IP address are masked before the visit is stored, so no full IP address is ever written to our database. Location is therefore only approximate (country or region level).

What is recorded: pages visited, the page that referred you, approximate region, browser and device type, and the time of the visit.

Where it stays: entirely on our own hosting in the EU. The data is not shared, sold, or transferred to any third party, and never leaves the EU.

Legal basis: our legitimate interest in understanding and improving this website (Art. 6(1)(f) GDPR). Because the measurement is cookieless and anonymised, no consent is required.

The same Matomo instance also measures our partner site racquetsports.institute, under identical settings. If you would rather not be counted at all, you can opt out here:

3. How We Use Your Data

We process your personal data for the following purposes:

Purpose Legal Basis (GDPR) Providing the Service (processing prompts, generating AI responses, PDF exports) Performance of contract (Art. 6(1)(b)) Account creation and authentication Performance of contract (Art. 6(1)(b)) Handling withdrawal, cancellation, and refund requests Performance of contract (Art. 6(1)(b)); compliance with legal obligations (Art. 6(1)(c)) Storing core profile parameters (sport, facility type, project phase, location) to deliver the analysis you request Performance of contract (Art. 6(1)(b)) Storing memory entries, project notes, and response preferences to personalise responses across sessions Consent (Art. 6(1)(a)) — you control these settings Location intelligence queries (competitor mapping, transport, climate, economic data) Performance of contract (Art. 6(1)(b)) Web research queries (with your explicit consent per query) Consent (Art. 6(1)(a)) Security, abuse prevention, and fraud detection Legitimate interest (Art. 6(1)(f)) Service operation monitoring (error tracking, performance metrics, aggregated technical metrics — no User Content) Legitimate interest (Art. 6(1)(f)) Compliance with legal obligations Legal obligation (Art. 6(1)(c))

4. What We Do NOT Do with Your Data

This section describes commitments that are fundamental to how we operate:

We do NOT use your conversations, project data, uploads, or any information you share to train or improve any AI models — neither our own nor those of our AI model providers (Anthropic, Mistral AI, Perplexity). This is a permanent policy, not a setting that can be changed. The specific contractual commitments from our AI providers are set out in Section 5.3.

We do NOT share your data with other users of the Service. Your project information, competitive assessments, and business plans remain strictly confidential.

We do NOT sell, rent, or trade your personal data to third parties.

We do NOT engage in behavioural tracking, profiling for advertising purposes, or cross-service data sharing.

We do NOT build hidden profiles or collect data beyond what is described in this Privacy Policy.

5. Data Sharing and Third-Party Processors

We use a limited number of third-party service providers ("processors") to operate the Service. These processors act on our instructions and are contractually bound — through Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs) where required — to process data only for the purposes we specify, in compliance with GDPR.

5.1 Categories of Processors

AI Model Provider — Anthropic PBC (USA)

Purpose: Processing prompts and generating AI responses via API

Data processed: Prompts, conversation context (no persistent storage by provider, not used for model training)

Data location: USA — protected by DPA with EU SCCs

AI Model Provider — Mistral AI SAS (France)

Purpose: Processing prompts and generating AI responses via API

Data processed: Prompts, conversation context (not used for model training)

Data location: European Union (France) — no transfer outside the EEA

AI Research Provider — Perplexity AI (USA)

Purpose: Web research for specific research-eligible queries (only with explicit user consent per query)

Data processed: Research query derived from user prompt, sport and country context

Data location: USA — protected by DPA with EU SCCs

Cloud Hosting — Render, Weaviate, Vercel

Purpose: Application servers, databases, knowledge base, frontend delivery

Data processed: All Service data

Data location: European Union (Frankfurt, Germany). These providers are US-incorporated companies; any incidental access from outside the EEA (e.g. technical support) is covered by DPAs with EU SCCs

Authentication Provider — Clerk (Clerk.com, Inc., USA)

Purpose: Account creation, login, identity verification

Data processed: Email, name (if provided), authentication tokens, session metadata

Data location: USA — protected by DPA with EU SCCs

Error Monitoring — Sentry

Purpose: Application error tracking and performance monitoring to identify and fix bugs

Data processed: Error stack traces, hashed user identifiers, request context (no prompt content, no User Content)

Data location: European Union (Sentry EU region)

Payment Processor — Stripe (Stripe Payments Europe, Limited)

Purpose: Secure processing of subscription payments on our behalf (RacqI S.r.l.s. is the seller and Merchant of Record)

Data processed: Name, email, billing details, and a payment-card token — we do not store full card numbers

Data location: European Economic Area (Ireland)

External Public-Data APIs (e.g. Eurostat, World Bank, OpenStreetMap, national census bureaus, transport and climate services)

Purpose: Location intelligence, demographic data, economic context. The list of providers may evolve over time as the Service grows.

Data processed: Location coordinates and query parameters — no personal data beyond location is transmitted

Data location: Various (EU and global public-data sources)

We may add, replace, or discontinue AI model providers in order to maintain and improve the quality and availability of the Service. Where a new provider would involve a transfer of personal data outside the EEA, or a materially different retention practice, we will update this Privacy Policy and notify you before the change takes effect.

5.2 International Data Transfers

The majority of your data is stored and processed within the European Union (Frankfurt, Germany). However, certain processing operations require the transfer of data to countries outside the European Economic Area (EEA):

AI prompt processing (Anthropic): When your query is routed to Anthropic PBC (USA), the text of your prompt and relevant conversation context are transmitted to their API for processing. Anthropic processes this data solely to generate a response and does not retain it after the response is generated. This transfer is protected by EU Standard Contractual Clauses (SCCs) incorporated into our Data Processing Agreement with Anthropic.

AI prompt processing (Mistral AI): Where your query is routed to Mistral AI SAS, processing takes place within the European Union. No transfer outside the EEA occurs for these queries.

Web research (with consent): For certain research-eligible queries, and only with your explicit consent, a research query derived from your prompt may be sent to Perplexity AI (USA) for web-based research. This transfer is protected by the same contractual safeguards (DPA with SCCs).

Authentication: Account and session data are processed by Clerk (USA). This transfer is protected by a DPA with EU SCCs.

Error monitoring: Error reports are transmitted to the EU region of Sentry and remain within the European Union. Error reports do not contain prompt content or AI Outputs.

Payment processing: Payments are processed by Stripe (Stripe Payments Europe, Limited), which is established in Ireland and processes payment data within the European Economic Area. To the extent any data is transferred outside the EEA in connection with global card-network processing, such transfers are subject to appropriate safeguards, including Standard Contractual Clauses where applicable.

We do not transfer personal data to countries outside the EEA unless appropriate safeguards are in place, as described above. We regularly review the data protection practices of our processors and the legal frameworks governing international transfers.

5.3 AI Model Providers — Specific Commitments

When you submit a prompt, the text of your prompt and relevant context are sent to an AI model provider for processing. Under the terms of our Data Processing Agreements, the AI model providers:

Process the data solely to generate a response to your query

Do not use your data to train or improve their models

Do not retain your data beyond the generation of the response, save for any limited retention period strictly necessary for abuse monitoring and security under the applicable Data Processing Agreement, after which the data is deleted

Are contractually prohibited from selling, sharing, or using your data for any purpose other than providing the Service

Have implemented appropriate technical and organisational security measures

The prohibition on model training applies without exception and to all of our AI model providers.

6. Data Storage and Hosting

Primary data storage is located exclusively in European data centres (Frankfurt, Germany). This includes:

Application servers and backend infrastructure (Render, EU region)

PostgreSQL database — account data, profiles, conversation logs, memory entries (Render, EU region)

Weaviate vector database — knowledge base and document embeddings (EU region)

Frontend delivery infrastructure (Vercel, EU region)

Uploaded documents and files

Processing outside the EU:

As described in Section 5.2, where your query is routed to Anthropic PBC (USA), the text of your prompt is transmitted there for processing. Where your query is routed to Mistral AI SAS, processing remains within the European Union. For research-eligible queries where you have given explicit consent, a derived research query may additionally be sent to Perplexity AI (USA). Account and session data are processed by Clerk (USA). Error reports are transmitted to the EU region of Sentry. Transfers outside the EEA are transient processing operations — no personal data is permanently stored outside the EU — and all such transfers are protected by Standard Contractual Clauses and Data Processing Agreements that ensure GDPR-equivalent protection.

Your data at rest — your account, profile, conversations, memories, and uploaded files — remains exclusively within the European Union at all times.

7. Data Retention

Data Type Retention Period Account data Retained while your account is active. Deleted upon account deletion request. Profile data Retained while your account is active. You can edit or delete individual fields at any time. Conversation data Retained while your account is active, with automatic deletion of conversations inactive for more than 90 days. You can manually delete specific conversations or all conversations at any time via the Privacy tab. Support chat history Subject to the same retention rules as Conversation data above. Support chats are stored in the same conversation tables and are included in data export and deletion. Memory entries Retained until you delete them or delete your account. You can delete individual entries at any time. Uploaded documents Retained while your account is active. You can delete individual files at any time. Technical and usage logs Retained for up to 90 days for security and debugging, then automatically deleted or anonymised. Administrative audit logs Records of administrative actions on the Service (e.g. configuration changes, user-management actions). These are operational logs, do not contain User Content, and are retained for up to 12 months for security and operational purposes. Error monitoring data (Sentry) Retained per Sentry retention defaults (typically up to 90 days). Contains no User Content; identifiers are hashed. Backups Encrypted backup copies of the production database and of uploaded files are retained on a rolling basis for up to 35 days and are then automatically overwritten. Backups are stored within the European Union, are access-restricted, and are used solely for disaster recovery. Where you delete data or your account, the data is removed immediately from the live systems; residual copies within existing backups are not separately restored, accessed, or used for any other purpose, and are erased when the backup in which they are contained expires.

When you request account deletion, all associated data (profile, conversations, memories, uploads, support chat history) is permanently deleted from our live systems without undue delay. As described in the table above, residual copies may persist in encrypted backups until those backups expire; during that period the data is not processed for any purpose other than disaster recovery. Some anonymised, aggregated technical metrics that cannot be linked to you may be retained for service improvement.

8. Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data:

Right of access (Art. 15) — You can request a copy of all personal data we hold about you. The "Export Data" function in the Privacy tab provides this in JSON format.

Right to rectification (Art. 16) — You can correct inaccurate data via your profile settings or by contacting us.

Right to erasure (Art. 17) — You can request deletion of your account and all associated data. The "Delete All Data" function in the Privacy tab provides this. Deletion is permanent and cannot be undone.

Right to restriction of processing (Art. 18) — You can request that we restrict the processing of your data in certain circumstances.

Right to data portability (Art. 20) — You can export your data in a structured, machine-readable format (JSON) via the Privacy tab.

Right to object (Art. 21) — You can object to processing based on legitimate interest.

Right to withdraw consent (Art. 7(3)) — Where processing is based on consent (e.g. memory features, project notes, web research), you can withdraw consent at any time by disabling the relevant settings or deleting your data. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, you can:

Use the built-in data management tools in the Service (Profile settings, Privacy tab)

Contact us at support@racqi.cloud

We will respond to your request without undue delay and in any event within one month, as required by GDPR (Art. 12(3)). This period may be extended by two further months where necessary, taking into account the complexity and number of requests.

9. Automated Decision-Making and Profiling

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

The Service generates AI Outputs — analyses, estimates, benchmarks, and recommendations — in response to your queries. These outputs are decision-support material only. They are addressed to you, they do not determine any outcome affecting you, and no decision about you is taken by us on their basis. As set out in the Terms of Service, you remain solely responsible for reviewing, validating, and applying AI Outputs.

Where you have enabled profile and memory features, we use the information you provide to tailor the relevance and format of responses. This personalisation serves only to improve the usefulness of the answers you receive and can be disabled or deleted at any time in the settings area (Memory + Privacy).

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

Encryption of data in transit (TLS/HTTPS)

Encryption of data at rest where technically feasible

Encryption of backup copies

Secure authentication mechanisms

Access controls limiting data access to authorised personnel only

Server-side rate limiting and request throttling to prevent abuse

Sanitised error responses to administrators that do not expose internal system details

Regular security reviews and updates

Separation of operational data and facility knowledge data across independent database systems

No system is completely secure. While we take reasonable precautions, we cannot guarantee absolute security. If we become aware of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by GDPR (Art. 33–34).

11. Age Requirement

The Service is a professional decision-support tool intended exclusively for individuals who have reached the age of 18. We do not knowingly collect personal data from persons under 18. If we become aware that a person under 18 has provided us with personal data, we will take steps to delete that data promptly. This requirement corresponds to the eligibility rules in Section 2 of our Terms of Service.

12. International Users

The Service is operated from Italy and primarily hosted in European data centres (Frankfurt, Germany). If you access the Service from outside the European Economic Area, your data will be transferred to and processed within the European Union as part of providing the Service to you (Art. 49(1)(b) GDPR — necessary for the performance of a contract). The EU provides a high level of data protection under the GDPR.

For details on data transfers outside the EU that occur as part of AI prompt processing, please refer to Section 5.2.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

Update the version number and the "Last updated" date at the top of this document

Provide notice within the Service or by email where appropriate

Where the changes are material to your rights, request renewed acknowledgement before continued use of the Service

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy, subject to any renewed-acknowledgement requirement we communicate.

14. Supervisory Authority

If you believe that we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for RacqI S.r.l.s. is:

Garante per la protezione dei dati personali

Piazza Venezia 11, 00187 Roma, Italy

Website: www.garanteprivacy.it

You may also contact the supervisory authority in your own EU/EEA member state.

15. Contact

If you have any questions about this Privacy Policy or our data practices, please contact us:

RacqI S.r.l.s. (in formation — in costituzione)

Registered office: Via Montebello della Battaglia 4, 27100 Pavia (PV), Lombardy, Italy

Privacy and data-protection enquiries: support@racqi.cloud

Website: www.racqi.cloud

This Privacy Policy should be read together with our Terms of Service and Refund Policy Imprint. All three documents are available at www.racqi.cloud.

RacqI S.r.l.s. — Privacy Policy — v1.1, August 2026
RacqI

Racquet Sports Intelligence. The connected data space for the racquet sports ecosystem — five sports, 220+ countries. Sourced, calculated, or named. Never guessed.

Site Overview Evidence base For whom What it delivers About Request access
Legal Privacy Policy Terms of Service Refund Policy
Your data Fully compliant with European data protection law. Your data stays under your control, removed on request. RacqI never learns from users' questions or documents.
Contact info@racqi.cloud
RacqI S.r.l.s. · Pavia, Italy · racqi.cloud Ecosystem know-how: RacquetSports.Institute