Scope & Who We Are
Optirox provides AI-powered football match analysis. We install smart cameras at football pitches, record full matches, and use artificial intelligence to extract player tracking, tactical patterns, and performance reports that are delivered through our mobile apps and web interfaces.
This policy applies to all users of the Service, including club administrators, coaches, players, parents or legal guardians of youth players, staff, and visitors to our website. Where Optirox provides the Service to a football club, academy, or federation (each a “Customer”), that Customer acts as the data controller for player-related data processed on its behalf, and Optirox acts as the data processor. For account, billing, device, and website data, Optirox acts as the controller.
Data We Collect
Account & Identity Data
Name, email address, phone number (optional), role (e.g. coach, analyst, club admin, player, parent), organization or club affiliation, preferred language, password hash, and authentication tokens.
Usage Data
Pages viewed, features used, reports opened, clips watched, time spent in sessions, search queries, and in-app interactions. We use this to operate and improve the Service.
Device & Technical Data
IP address, approximate location derived from IP, operating system and version, device model, browser type, app version, crash logs, performance diagnostics, and identifiers needed to authenticate the device.
Match Video
Full-match footage captured by Optirox cameras installed at pitches operated by our Customers. Footage may incidentally include players, coaches, staff, officials, and spectators present during the match.
Player & Performance Data
Data extracted by our AI from the match footage, including player positions over time, speed, distance covered, sprints, heatmaps, tactical patterns, event detections (passes, shots, pressing actions), and derived metrics such as xG (expected goals), possession, and PPDA. Where jersey numbers, names, or roster information are provided by the Customer, extracted data may be linked to an identified player.
AI-Derived Analytics
Reports, tags, classifications, and insights produced by our AI models based on the match footage and roster information provided by the Customer.
Support & Communications
Messages you send to us, support ticket contents, and feedback you voluntarily submit.
Match Footage & AI Processing
Recording match video is core to the Service. You should understand clearly how we handle it:
- Recording. Cameras installed at pitches operated by our Customers record matches in HD from fixed angles for the purpose of analysis.
- AI processing. After a match ends, the footage is uploaded to our secure processing pipeline. Our models detect and track players, referees, and the ball; extract movement, speed, and tactical patterns; and generate structured performance data and a full match report.
- Extracted data. The structured outputs (player tracking, speed, heatmaps, tactical events, reports) are made available to the Customer inside our apps. Access to identified-player data is restricted to the Customer and the individuals they authorize.
- Model improvement. We may use footage and derived data in an anonymized or aggregated form to train, evaluate, and improve our AI models — for example, by measuring detection accuracy or refining tactical recognition. Anonymization removes names, jersey links, roster identifiers, and any other fields that could re-identify an individual. Where local law requires opt-in consent for AI training use, we rely on the Customer to obtain that consent from players or their legal guardians, and we will not use that data for training without it.
- No biometric identification. Optirox does not use facial recognition to identify individuals. Player identity is linked only to jersey-based detections that the Customer maps to a roster.
How We Use Your Data
- To operate the Service — record matches, process footage, generate reports, and deliver them to the Customer.
- To authenticate users, enforce access controls, and secure accounts.
- To provide customer support and respond to your requests.
- To improve the Service — fix bugs, measure performance, and develop new features.
- To train and refine our AI models using anonymized or aggregated data, subject to the constraints in Section 3.
- To send service-related communications (e.g. account notices, security alerts, and product updates).
- To comply with legal obligations and enforce our Terms of Service.
Legal Bases (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Contract. To provide the Service you or your organization has subscribed to.
- Legitimate interests. To secure the Service, prevent abuse, and improve our products, balanced against your rights and expectations.
- Consent. For non-essential cookies, marketing communications, and any use of identified player data for AI training where consent is required.
- Legal obligation. To comply with applicable laws, court orders, and regulatory requests.
Data Storage & Security
We apply industry-standard technical and organizational measures to protect your data, including:
- Encryption in transit (TLS 1.2+) and at rest for match footage, derived data, and account information.
- Access controls based on least-privilege, role-based permissions, and audit logging for sensitive operations.
- Segregated environments for production, staging, and training.
- Regular backups, monitoring, and vulnerability management.
- Security reviews of our third-party service providers.
No method of transmission or storage is 100% secure. While we work hard to protect your data, we cannot guarantee absolute security. If we become aware of a security incident that materially affects your personal data, we will notify affected users and the relevant authorities as required by applicable law.
Data Retention
- Account data is retained while your account is active and for a limited period afterwards to comply with legal obligations, resolve disputes, and enforce agreements.
- Match footage and derived data are retained according to the retention period agreed with the Customer. Customers can request earlier deletion of specific matches.
- Anonymized or aggregated data used for model improvement and analytics may be retained indefinitely, as it can no longer be linked to an individual.
- Support and billing records are retained as long as required by applicable tax, accounting, and consumer-protection laws.
You or your Customer organization can request deletion of your data at any time by contacting us at info@optirox.com.
Your Rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data, subject to legal retention requirements.
- Restrict or object to certain processing activities.
- Withdraw consent for processing that is based on consent.
- Receive your data in a portable, machine-readable format.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, contact us at info@optirox.com. If your data is processed on behalf of a Customer organization, we will forward your request to that organization and support it in responding.
Children & Youth Players
Optirox is used in youth football, and we understand that many of the players captured on match footage are under 13 years old. Protecting minors is a priority for us.
- Role of the Customer. The club, academy, federation, or similar organization that operates the pitch and instructs Optirox to record matches is responsible for obtaining the consents required by applicable law from parents or legal guardians before minors are recorded and their performance data processed. This includes, where applicable, verifiable parental consent under the U.S. Children’s Online Privacy Protection Act (COPPA) and any national implementation of GDPR rules for children (GDPR-K).
- No direct account for young children. Optirox does not knowingly create individual user accounts for children under 13. Where app access is needed for a minor, it is provided through a parent or guardian, or through the Customer organization.
- No marketing to children. We do not direct advertising or marketing communications to children.
- No behavioral profiling. We do not use minors’ data for behavioral advertising or automated decisions that produce legal or similarly significant effects.
- Parental requests. Parents or legal guardians may contact us at info@optirox.com to review, correct, or delete data relating to their child. We may route the request through the responsible Customer organization where appropriate.
If we learn that we have processed personal data of a child without the consents required by law, we will delete that data promptly.
Third-Party Services
We rely on a small set of vetted service providers to run the Service. These may include:
- Cloud infrastructure and VPS hosting providers for application servers and AI processing.
- Object storage and CDN providers for match footage and static assets.
- Email delivery providers for transactional messages.
- Crash reporting and analytics providers to diagnose issues and improve quality.
- Mobile app platform providers (Apple App Store and Google Play).
Each provider is contractually bound to handle data only on our instructions, implement appropriate security measures, and comply with applicable data-protection laws. A current list of sub-processors is available on request at info@optirox.com.
AI Usage Disclaimer
The AI features in Optirox are designed to assist analysis, not to replace human judgment. You should be aware that:
- AI-generated tracking, events, and metrics can contain errors, especially in low-light, occluded, or unusual gameplay situations.
- Optirox outputs are provided for performance analysis and coaching purposes only. They are not intended for — and must not be used as the basis for — disciplinary action, legal decisions, medical assessments, officiating decisions, or any other high-stakes automated decision-making.
- Optirox does not make automated decisions about individuals that produce legal or similarly significant effects.
- Coaches, clubs, and users remain responsible for how they interpret and act on AI outputs.
International Transfers
Optirox operates internationally. Your data may be processed in countries other than the one in which you live, including in jurisdictions that may not provide the same level of data-protection as your home country. Where required, we implement appropriate transfer safeguards — such as Standard Contractual Clauses approved by the European Commission — to protect your data during international transfers.
Changes to This Policy
We may update this Privacy Policy to reflect changes to our Service, legal requirements, or operational practices. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you through the app, email, or a notice on our website. Your continued use of the Service after the updated policy takes effect means you accept the changes.
Contact Us
If you have questions, requests, or concerns about this Privacy Policy or our data practices, you can reach us at:
We aim to respond to privacy requests within 30 days. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data-protection authority.