This Privacy Policy explains how RacqI (Racquet Sports Intelligence) ("we", "us", or "our"), a SaaS product provided by RacqI S.r.l.s., a company in formation based in Pavia, Italy, collects, uses, stores, and protects your personal data when you use RacqI (the "Service").
The Service is currently provided as a beta. The privacy practices described here apply to the beta phase. Where material changes occur after the beta phase, we will notify you in advance and, where appropriate, request renewed consent before the changes take effect.
We are committed to protecting your privacy and processing your data in accordance with the EU General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, and other applicable data protection laws.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with these practices, please do not use the Service.
The data controller responsible for processing your personal data is:
RacqI S.r.l.s. (in formation — in costituzione)
Società a responsabilità limitata semplificata
Registered office: Via Montebello della Battaglia 4, 27100 Pavia (PV), Lombardy, Italy
Share capital: EUR 1,000
VAT / Codice Fiscale: [to be assigned upon incorporation]
Company registration / REA number: [to be assigned upon incorporation]
Legal representative: Rachele Gaebel (Founder & CEO)
General contact: support@racqi.cloud
Website: www.racqi.cloud
Note on legal form and company structure: RacqI S.r.l.s. is a società a responsabilità limitata semplificata currently in the process of incorporation (in costituzione) in Italy. RacqI S.r.l.s. is an independent company that owns the RacqI platform, its data, and the RacqI brand, and it is the entity responsible for providing the Service and acting as data controller. RacqI S.r.l.s. builds on, but is legally distinct from, the Racquet Sports Institute — an established domain-knowledge body that contributes curated industry expertise to the RacqI knowledge base under a defined arrangement; the Racquet Sports Institute does not process the personal data of users of the Service. As the company is currently in formation, certain registration details (VAT / Codice Fiscale and company registration / REA number) will be finalised upon incorporation, and we will publish an updated version of this Privacy Policy reflecting the completed registration details. As a company built for a global market, we also anticipate a future conversion to an EU Inc. (the EU's planned 28th-regime company form) once that form is legally finalised and applicable. None of these steps will change the location of data processing, the categories of data processed, the purposes of processing, the processors involved, or your rights under the GDPR.
When you register for the Service, we collect:
Email address
Password (stored in hashed form only)
Name (if provided)
Account creation and authentication is handled through Clerk, a third-party identity provider. We receive only the data necessary for authentication and account management from this provider.
You may provide profile information to improve the relevance of the Service, including:
Primary and secondary sport (Badminton, Padel, Pickleball, Squash, or Tennis)
Facility type (e.g. Commercial, Non-Profit/Club, School/University, Member Club, Add-on)
Project phase (Idea, Planning, Construction, Operating, Expansion)
Location (city, country, or street address)
Project name and free-text project notes
Response preferences (answer format, communication tone)
Providing profile data is voluntary in the sense that you decide whether and what to enter. Where you do provide it, the core parameters (sport, facility type, project phase, location) are processed to deliver the analysis you have requested and are therefore necessary for the performance of our contract with you; free-text project notes and response preferences are processed on the basis of your consent. You can view, edit, or delete all profile data at any time via the settings area (Memory + Privacy) of the Service.
When you use the Service, we process:
Your prompts, questions, and messages
AI-generated responses
Documents and files you upload for analysis
Follow-up selections (Clarifier responses)
PDF export requests
The Service includes an optional memory feature that stores contextual information across sessions to improve answer quality. Memory data may include:
Facts, preferences, and project details extracted from your conversations (if "Auto-extract from conversations" is enabled)
Information you add manually to the "What the Agent Knows About Me" section
Each memory entry is labelled with a category (Preference, Fact, Context, Project, or Other) and a source indicator showing whether the entry was provided directly by you or extracted automatically from a conversation. You have full control over memory data and can view, edit, or delete any entry at any time.
We may collect limited technical data necessary for operating the Service, such as:
IP address (for security and abuse prevention)
Timestamps of access and interactions
Error logs and performance metrics
Hashed user identifiers attached to error reports (used for correlating bug reports without revealing your identity)
If you provide a location (city or address) as part of your profile or within a question, the Service uses it to query external public-data APIs for location intelligence (competitor mapping, transport access, climate data, economic context). The location is processed for this purpose only and is not shared with third parties for any other purpose. No personal data beyond location coordinates is transmitted to these APIs.
We use the following browser storage mechanisms, all classified as strictly necessary under the ePrivacy Directive (no consent required):
Authentication cookies (set by Clerk): session management and login state. Lifetime: until logout or session expiry.
Rate-limiting tokens (browser localStorage): anti-abuse tracking on your local device only — these tokens are never transmitted to our servers and exist purely to slow down repeated interactions from the same browser. Lifetime: up to 90 days, automatically rotated.
UI preferences (browser localStorage): language preference, theme. Lifetime: until you clear browser storage.
We do not use third-party tracking cookies, advertising cookies, or analytics that track behaviour across websites. We do not use cookies for advertising or behavioural tracking.
To understand which pages of this website are read and how visitors find us, we use Matomo, an open-source analytics tool that we host ourselves. It runs on our own server at www.racqi.cloud/analytics in Italy. There is no Google Analytics on this site and no analytics provider receives your data.
No cookies. Matomo is configured in cookieless mode: it sets no cookies and writes nothing to your browser storage. That is why this site shows no cookie banner.
IP addresses are anonymised. The last two bytes of every IP address are masked before the visit is stored, so no full IP address is ever written to our database. Location is therefore only approximate (country or region level).
What is recorded: pages visited, the page that referred you, approximate region, browser and device type, and the time of the visit.
Where it stays: entirely on our own hosting in the EU. The data is not shared, sold, or transferred to any third party, and never leaves the EU.
Legal basis: our legitimate interest in understanding and improving this website (Art. 6(1)(f) GDPR). Because the measurement is cookieless and anonymised, no consent is required.
The same Matomo instance also measures our partner site racquetsports.institute, under identical settings. If you would rather not be counted at all, you can opt out here:
We process your personal data for the following purposes:
This section describes commitments that are fundamental to how we operate:
We do NOT use your conversations, project data, uploads, or any information you share to train or improve any AI models — neither our own nor those of our AI model providers (Anthropic, Mistral AI, Perplexity). This is a permanent policy, not a setting that can be changed. The specific contractual commitments from our AI providers are set out in Section 5.3.
We do NOT share your data with other users of the Service. Your project information, competitive assessments, and business plans remain strictly confidential.
We do NOT sell, rent, or trade your personal data to third parties.
We do NOT engage in behavioural tracking, profiling for advertising purposes, or cross-service data sharing.
We do NOT build hidden profiles or collect data beyond what is described in this Privacy Policy.
We use a limited number of third-party service providers ("processors") to operate the Service. These processors act on our instructions and are contractually bound — through Data Processing Agreements (DPAs) with Standard Contractual Clauses (SCCs) where required — to process data only for the purposes we specify, in compliance with GDPR.
AI Model Provider — Anthropic PBC (USA)
Purpose: Processing prompts and generating AI responses via API
Data processed: Prompts, conversation context (no persistent storage by provider, not used for model training)
Data location: USA — protected by DPA with EU SCCs
AI Model Provider — Mistral AI SAS (France)
Purpose: Processing prompts and generating AI responses via API
Data processed: Prompts, conversation context (not used for model training)
Data location: European Union (France) — no transfer outside the EEA
AI Research Provider — Perplexity AI (USA)
Purpose: Web research for specific research-eligible queries (only with explicit user consent per query)
Data processed: Research query derived from user prompt, sport and country context
Data location: USA — protected by DPA with EU SCCs
Cloud Hosting — Render, Weaviate, Vercel
Purpose: Application servers, databases, knowledge base, frontend delivery
Data processed: All Service data
Data location: European Union (Frankfurt, Germany). These providers are US-incorporated companies; any incidental access from outside the EEA (e.g. technical support) is covered by DPAs with EU SCCs
Authentication Provider — Clerk (Clerk.com, Inc., USA)
Purpose: Account creation, login, identity verification
Data processed: Email, name (if provided), authentication tokens, session metadata
Data location: USA — protected by DPA with EU SCCs
Error Monitoring — Sentry
Purpose: Application error tracking and performance monitoring to identify and fix bugs
Data processed: Error stack traces, hashed user identifiers, request context (no prompt content, no User Content)
Data location: European Union (Sentry EU region)
Payment Processor — Stripe (Stripe Payments Europe, Limited)
Purpose: Secure processing of subscription payments on our behalf (RacqI S.r.l.s. is the seller and Merchant of Record)
Data processed: Name, email, billing details, and a payment-card token — we do not store full card numbers
Data location: European Economic Area (Ireland)
External Public-Data APIs (e.g. Eurostat, World Bank, OpenStreetMap, national census bureaus, transport and climate services)
Purpose: Location intelligence, demographic data, economic context. The list of providers may evolve over time as the Service grows.
Data processed: Location coordinates and query parameters — no personal data beyond location is transmitted
Data location: Various (EU and global public-data sources)
We may add, replace, or discontinue AI model providers in order to maintain and improve the quality and availability of the Service. Where a new provider would involve a transfer of personal data outside the EEA, or a materially different retention practice, we will update this Privacy Policy and notify you before the change takes effect.
The majority of your data is stored and processed within the European Union (Frankfurt, Germany). However, certain processing operations require the transfer of data to countries outside the European Economic Area (EEA):
AI prompt processing (Anthropic): When your query is routed to Anthropic PBC (USA), the text of your prompt and relevant conversation context are transmitted to their API for processing. Anthropic processes this data solely to generate a response and does not retain it after the response is generated. This transfer is protected by EU Standard Contractual Clauses (SCCs) incorporated into our Data Processing Agreement with Anthropic.
AI prompt processing (Mistral AI): Where your query is routed to Mistral AI SAS, processing takes place within the European Union. No transfer outside the EEA occurs for these queries.
Web research (with consent): For certain research-eligible queries, and only with your explicit consent, a research query derived from your prompt may be sent to Perplexity AI (USA) for web-based research. This transfer is protected by the same contractual safeguards (DPA with SCCs).
Authentication: Account and session data are processed by Clerk (USA). This transfer is protected by a DPA with EU SCCs.
Error monitoring: Error reports are transmitted to the EU region of Sentry and remain within the European Union. Error reports do not contain prompt content or AI Outputs.
Payment processing: Payments are processed by Stripe (Stripe Payments Europe, Limited), which is established in Ireland and processes payment data within the European Economic Area. To the extent any data is transferred outside the EEA in connection with global card-network processing, such transfers are subject to appropriate safeguards, including Standard Contractual Clauses where applicable.
We do not transfer personal data to countries outside the EEA unless appropriate safeguards are in place, as described above. We regularly review the data protection practices of our processors and the legal frameworks governing international transfers.
When you submit a prompt, the text of your prompt and relevant context are sent to an AI model provider for processing. Under the terms of our Data Processing Agreements, the AI model providers:
Process the data solely to generate a response to your query
Do not use your data to train or improve their models
Do not retain your data beyond the generation of the response, save for any limited retention period strictly necessary for abuse monitoring and security under the applicable Data Processing Agreement, after which the data is deleted
Are contractually prohibited from selling, sharing, or using your data for any purpose other than providing the Service
Have implemented appropriate technical and organisational security measures
The prohibition on model training applies without exception and to all of our AI model providers.
Primary data storage is located exclusively in European data centres (Frankfurt, Germany). This includes:
Application servers and backend infrastructure (Render, EU region)
PostgreSQL database — account data, profiles, conversation logs, memory entries (Render, EU region)
Weaviate vector database — knowledge base and document embeddings (EU region)
Frontend delivery infrastructure (Vercel, EU region)
Uploaded documents and files
Processing outside the EU:
As described in Section 5.2, where your query is routed to Anthropic PBC (USA), the text of your prompt is transmitted there for processing. Where your query is routed to Mistral AI SAS, processing remains within the European Union. For research-eligible queries where you have given explicit consent, a derived research query may additionally be sent to Perplexity AI (USA). Account and session data are processed by Clerk (USA). Error reports are transmitted to the EU region of Sentry. Transfers outside the EEA are transient processing operations — no personal data is permanently stored outside the EU — and all such transfers are protected by Standard Contractual Clauses and Data Processing Agreements that ensure GDPR-equivalent protection.
Your data at rest — your account, profile, conversations, memories, and uploaded files — remains exclusively within the European Union at all times.
When you request account deletion, all associated data (profile, conversations, memories, uploads, support chat history) is permanently deleted from our live systems without undue delay. As described in the table above, residual copies may persist in encrypted backups until those backups expire; during that period the data is not processed for any purpose other than disaster recovery. Some anonymised, aggregated technical metrics that cannot be linked to you may be retained for service improvement.
Under the GDPR, you have the following rights regarding your personal data:
Right of access (Art. 15) — You can request a copy of all personal data we hold about you. The "Export Data" function in the Privacy tab provides this in JSON format.
Right to rectification (Art. 16) — You can correct inaccurate data via your profile settings or by contacting us.
Right to erasure (Art. 17) — You can request deletion of your account and all associated data. The "Delete All Data" function in the Privacy tab provides this. Deletion is permanent and cannot be undone.
Right to restriction of processing (Art. 18) — You can request that we restrict the processing of your data in certain circumstances.
Right to data portability (Art. 20) — You can export your data in a structured, machine-readable format (JSON) via the Privacy tab.
Right to object (Art. 21) — You can object to processing based on legitimate interest.
Right to withdraw consent (Art. 7(3)) — Where processing is based on consent (e.g. memory features, project notes, web research), you can withdraw consent at any time by disabling the relevant settings or deleting your data. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, you can:
Use the built-in data management tools in the Service (Profile settings, Privacy tab)
Contact us at support@racqi.cloud
We will respond to your request without undue delay and in any event within one month, as required by GDPR (Art. 12(3)). This period may be extended by two further months where necessary, taking into account the complexity and number of requests.
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
The Service generates AI Outputs — analyses, estimates, benchmarks, and recommendations — in response to your queries. These outputs are decision-support material only. They are addressed to you, they do not determine any outcome affecting you, and no decision about you is taken by us on their basis. As set out in the Terms of Service, you remain solely responsible for reviewing, validating, and applying AI Outputs.
Where you have enabled profile and memory features, we use the information you provide to tailor the relevance and format of responses. This personalisation serves only to improve the usefulness of the answers you receive and can be disabled or deleted at any time in the settings area (Memory + Privacy).
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
Encryption of data in transit (TLS/HTTPS)
Encryption of data at rest where technically feasible
Encryption of backup copies
Secure authentication mechanisms
Access controls limiting data access to authorised personnel only
Server-side rate limiting and request throttling to prevent abuse
Sanitised error responses to administrators that do not expose internal system details
Regular security reviews and updates
Separation of operational data and facility knowledge data across independent database systems
No system is completely secure. While we take reasonable precautions, we cannot guarantee absolute security. If we become aware of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by GDPR (Art. 33–34).
The Service is a professional decision-support tool intended exclusively for individuals who have reached the age of 18. We do not knowingly collect personal data from persons under 18. If we become aware that a person under 18 has provided us with personal data, we will take steps to delete that data promptly. This requirement corresponds to the eligibility rules in Section 2 of our Terms of Service.
The Service is operated from Italy and primarily hosted in European data centres (Frankfurt, Germany). If you access the Service from outside the European Economic Area, your data will be transferred to and processed within the European Union as part of providing the Service to you (Art. 49(1)(b) GDPR — necessary for the performance of a contract). The EU provides a high level of data protection under the GDPR.
For details on data transfers outside the EU that occur as part of AI prompt processing, please refer to Section 5.2.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Update the version number and the "Last updated" date at the top of this document
Provide notice within the Service or by email where appropriate
Where the changes are material to your rights, request renewed acknowledgement before continued use of the Service
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy, subject to any renewed-acknowledgement requirement we communicate.
If you believe that we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for RacqI S.r.l.s. is:
Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma, Italy
Website: www.garanteprivacy.it
You may also contact the supervisory authority in your own EU/EEA member state.
If you have any questions about this Privacy Policy or our data practices, please contact us:
RacqI S.r.l.s. (in formation — in costituzione)
Registered office: Via Montebello della Battaglia 4, 27100 Pavia (PV), Lombardy, Italy
Privacy and data-protection enquiries: support@racqi.cloud
Website: www.racqi.cloud
This Privacy Policy should be read together with our Terms of Service and Refund Policy Imprint. All three documents are available at www.racqi.cloud.
RacqI S.r.l.s. — Privacy Policy — v1.1, August 2026Racquet Sports Intelligence. The connected data space for the racquet sports ecosystem — five sports, 220+ countries. Sourced, calculated, or named. Never guessed.