PRIVACY POLICY
Version: June 2026
Data Controller
The controller responsible for the processing of personal data in connection with the NextLegend App, the NextLegend Web App and the related online services is: NextLegend GmbH, Wangibadstrasse 6, 8914 Aeugst am Albis, Schweiz.
Company Identification Number (UID): CHE-293.635.977.
Authorized Representatives: Roger Claus, Shareholder and Chairman of the Management Board, and Sandra Isabel Claus-Schmid, Shareholder and Managing Director; each with sole signatory authority.
E-Mail: [email protected].
Phone: +41 79 209 84 84.
Privacy Contact and EU Representative
Privacy-related inquiries may be directed to [email protected].
Representative in the European Union pursuant to Article 27 GDPR: Rechtsanwaltsburo Andrea Muller, Fleischergasse 6, 01662 Meissen, 03521-456733, [email protected].
Subject Matter and User Groups
NextLegend is a digital platform for youth sports teams, particularly in football (soccer). It consists of a mobile app for iOS and Android as well as a web app.
The platform is intended for youth football players aged 9 to 17, as well as parents, coaches, co-coaches and administrators.
Its features include, in particular, team management, training and event organization, attendance management, TeamBoard and TeamTicker, chats, challenges, awards, skills and levels, virtual gamification values, NextLegend Coins (NLC), a virtual luxury shop, media features, as well as optional premium and rewarded ads features.
As the service is aimed directly at children and young people, in addition to this comprehensive Privacy Policy, a short, age-appropriate privacy notice is provided during onboarding and permanently within the app.
It explains, in simple language, in particular visibility, chats, media, advertising, deletion and available help options.
Applicable Data Protection Law
As NextLegend is based in Switzerland, Swiss data protection law applies in particular.
Where the service is offered to individuals in the European Union, the General Data Protection Regulation (GDPR) also applies.
The GDPR legal bases referred to in this Privacy Policy apply insofar as the GDPR is applicable to the respective processing activity.
Categories of Personal Data Processed
5.1 Account, Master and Contact Data: First and last name, username, date of birth and age; telephone number and, where applicable, e-mail address; user role, team and club affiliation, season assignment; profile picture, account status and the association between parents and minor players; invitation, registration and verification data.
5.2 Team, Training and Event Data: training, match and event data; registrations, cancellations and confirmed attendance; team memberships, organisational communications and team-related statistics.
5.3 Performance and Gamification Data: challenges and challenge results; skills, XP values and levels; awards and MVP awards; Virtual Market Value; NLC balance, virtual items and activities in the Luxury Shop.
The Virtual Market Value and NLC are used exclusively for in-app gamification purposes. They do not represent any real market value, transfer value, monetary value or official sporting performance assessment.
5.4 Communication and Media Data: chat messages and TeamBoard/TeamTicker content; messages between coaches, players and parents; comments, likes and reports within the Wall of Action / Hall of Fame; profile pictures, challenge photos and videos, team photos and training content; author, timestamp, assignment to the respective content and technical metadata.
5.5 Contract, Payment and Technical Data: selected premium module, contract and season duration, purchase status and transaction references; IP address, device and operating system information, app version and browser type; login timestamps, session and security tokens, push notification tokens; server, application, security, SMS delivery and transmission logs.
Registration, Age Verification and Parental Consent
The coach creates a team and invites players and additional coaches, in particular via SMS link, QR code or personal invitation code.
For the purpose of setting up and assigning an account, the user's name, telephone number, user role, team assignment, date of birth, as well as invitation and verification status are processed.
The date of birth is used to determine the user's age.
For users under the age of 16, the parental consent process is initiated automatically and is mandatory. Registration cannot be completed without successful parental approval; until then, these users have no access to the app, to content or to individual functions.
For this purpose, the parent's name and telephone number, the association with the child, the date and status of the approval, as well as technical proof of the approval process are processed.
The parental confirmation enables the activation of the account and documents the involvement of the legal guardian. It does not automatically constitute the legal basis for all processing activities.
Where processing requires consent, particularly for optional team-wide media sharing or certain advertising and additional features, such consent is obtained separately, for the specific purpose, on a voluntary basis and may be withdrawn at any time.
Phone Number Verification and OTP Login
NextLegend uses SMS one-time passwords (OTP) for phone number verification and login.
The phone number, OTP code, time of dispatch, sending and delivery status and technical log data are processed for this purpose. This serves secure identification and protection of user accounts.
The service provider is Twilio Ireland Limited, 70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland.
Twilio is used exclusively for verification and OTP dispatch; no marketing, newsletter or advertising SMS messages are sent.
SMS Pumping Protection is activated and the permitted destination countries are restricted.
Twilio is operated with standard data region settings. Processing by affiliated companies or subprocessors outside Switzerland or the EEA can therefore not be completely excluded.
Where required, statutory transfer mechanisms and contractual safeguards are used for this purpose.
Team Management, Training Sessions, Matches and Events
Coaches can manage teams, training sessions, matches and events.
For this purpose, in particular team memberships, schedules, invitations, registrations and cancellations, attendance, organisational communications and team-related statistics are processed.
The processing serves the organisation and administration of team activities and training operations.
Role and Visibility Logic
The platform is generally not public. There are no public player profiles, no public player search and no public community.
Visibility is determined by the user's role and team membership.
Players can view the information intended for members of their team.
Parents generally have access to information relating to their own child and to the team and chat areas that are available to parents.
Coaches have access to the information required for team management and player supervision.
Administrators are granted access only to the extent necessary for the operation of the platform, support, security and the prevention of misuse.
Administrator roles are restricted, and relevant administrative activities are logged.
Chat and Communication Features
NextLegend provides team chats, player-to-coach chats, parent-to-coach chats, as well as direct communication between coach and player and between coach and parents.
Private direct messaging between individual players is not provided.
The coach is an integral part of the intended player and team communication.
Chat and communication data are processed in order to deliver messages, enable team communication, prevent misuse and investigate reported violations.
Administrators do not have regular operational access to chat content.
Technically necessary access is permitted only in exceptional cases where required for security, troubleshooting, legal enforcement or the investigation of misuse.
Wall of Action / Hall of Fame, Comments and Moderation
A coach may add selected challenge photos or videos to the Wall of Action or Hall of Fame.
These contents are visible to the players of the respective team and the responsible coaches.
Other players can like and comment on the content. Comments are not public.
Players can delete their own comments.
A reporting function is available next to every comment. Reports are forwarded to the responsible coach.
Coaches can delete reported or inappropriate comments.
When processing a report, information relating to the user, the comment, the time of the report and the processing status may be processed and, where necessary, logged.
If a video is deleted or removed from the Hall of Fame, all associated comments and likes are automatically deleted as well.
Photos, Videos and Media Sharing
Players can upload challenge photos and videos; coaches can provide, among other things, TeamBoard content, team photos, as well as training, award and challenge content.
Challenge submissions are generally visible only to the respective player and the responsible coaches.
Rejected submissions are deleted.
Successfully completed challenge submissions may be stored and may be approved by the coach for publication in the Wall of Action / Hall of Fame.
Before an account is activated, parents are transparently informed about the team-internal media and commenting features.
Where photos or videos of a minor player are made available for extended team-internal visibility in the Wall of Action / Hall of Fame and such processing requires consent, that consent must be obtained separately, for the specific purpose and in a manner that allows it to be withdrawn at any time.
The use of the other core features must not be made conditional upon consent to the optional publication in the Wall of Action / Hall of Fame.
Any publication outside the closed team environment takes place only on the basis of a separate legal basis.
Players may delete media they have uploaded themselves.
Upon deletion, any version published in the Wall of Action / Hall of Fame, together with all associated likes and comments, will also be deleted.
Challenges, Awards, Skills, Levels, Market Value and NLC
NextLegend processes challenge assignments and challenge results, awards, skills, XP values, levels, Virtual Market Value, NLC balances and virtual Luxury Shop items for the purpose of providing the platform's motivation and gamification features.
NLC are not legal tender, have no real monetary value and cannot be redeemed for cash, converted into real money, transferred or traded between users.
The Virtual Market Value is a purely in-app career and gamification value and does not represent any real market value or transfer value.
Premium Modules and Payment Processing
NextLegend offers optional premium modules, in particular Co-Coach and Player Agent.
The core features remain available without a premium module.
The modules are offered for the respective current season and expire on 31 July; automatic renewal is not provided.
At launch, payments are processed via the Apple App Store, Google Play or, for web purchases, Stripe.
These providers process payment data partly under their own responsibility as independent data controllers.
NextLegend processes, in particular, the selected module, purchase and activation date, subscription period, purchase status and technical transaction references.
Complete credit card information is generally processed by the respective payment provider.
Where a premium module includes additional NLC or virtual benefits, these form an integral part of the respective module.
NLC are not sold separately in exchange for real money.
Push-Notifications
NextLegend uses exclusively Firebase Cloud Messaging (FCM) by Google for push notifications.
Other Firebase services such as Authentication, Analytics, Crashlytics, Remote Config, Firestore or Realtime Database are not used.
Depending on the user's role, push notifications may relate, among other things, to chats, TeamBoard announcements, awards, challenges, level-ups and Luxury Shop activities.
In particular, push tokens, device and app information, notification type, delivery timestamp and technical delivery information are processed.
Push notifications require permission within the user's operating system and can be completely disabled there.
It is currently not possible to disable individual notification categories within the app.
Rewarded Video Ads and Google AdMob
NextLegend offers voluntary Rewarded Video Ads through Google AdMob.
By voluntarily watching an advertisement, users may receive exclusively virtual, in-app benefits.
The core features of the platform remain fully usable without watching advertisements, and no entitlement to real money, physical goods or cash payouts arises.
The age determined during registration is used for age-based advertising configuration.
Before the app is released, Google's current Age Treatment configuration will be implemented using the latest versions of the Google Mobile Ads SDK and the Google User Messaging Platform (UMP) SDK.
Users aged 9 to 12 receive exclusively non-personalised and child-appropriate advertisements.
Users aged 13 to 15 are treated as users below the age of consent and receive exclusively non-personalised advertisements.
Additional restrictions on sensitive advertising categories and age-appropriate content ratings are applied for all minor users.
For users aged 16 and above, the Google UMP consent dialogue is used in accordance with the applicable legal requirements.
Hosting, Database and Technical Service Providers
17.1 DigitalOcean: Hosting and media storage are provided through DigitalOcean in Frankfurt am Main, Germany. In particular, user, platform, media, server, security and log data are processed for this purpose. The Data Processing Agreement forms part of the contractual relationship.
17.2 MongoDB Atlas: The database is operated through MongoDB Atlas in Frankfurt am Main, Germany. The data required for user, team, communication, media, gamification and administrative functions are stored there. The MongoDB Data Processing Agreement and the applicable data transfer mechanisms form part of the contractual relationship.
Website, Cookies and Local Storage Technologies
The website and web app use only storage technologies that are functionally necessary.
Cookies for authentication and session management.
Local Storage for authentication tokens, the selected team or team context, temporary application states and user-related data required for the operation of the app.
Standard server and application logs for operation, security and error analysis.
Session Storage is currently not used.
At present, neither the website nor the web app uses analytics, profiling, advertising or any other tracking technologies.
A separate consent via a cookie banner is therefore currently not required for these exclusively technically necessary storage technologies.
Should non-essential technologies be introduced in the future, this will only take place in compliance with the applicable information and consent requirements.
Support, Feedback and Abuse Prevention
When users contact NextLegend for support or submit feedback or support requests, NextLegend processes contact details, user role, the content of the request, technical and account-related information, as well as the communication history.
For security and abuse prevention purposes, data may be processed to investigate unauthorised access, manipulation, insults, bullying, discrimination, harassment, unlawful content or violations of the Terms of Use.
Following an individual review, content may be removed, functions may be restricted or user accounts may be suspended.
Legal Bases under the GDPR
Where the GDPR applies, personal data are processed on the following legal bases, depending on the purpose of the processing.
Article 6(1)(b) GDPR, in particular for registration, account management, team, chat, challenge, gamification and premium features, where such processing is necessary for the performance of the respective user or premium contract.
Article 6(1)(c) GDPR, for compliance with legal obligations, in particular obligations under commercial, tax, regulatory or record-keeping laws.
Article 6(1)(f) GDPR, for the purposes of the legitimate interests in ensuring the secure, reliable and abuse-free operation of the platform, providing support and troubleshooting, moderating content and protecting minors, as well as establishing, exercising or defending legal claims.
Where data relating to minors are processed, their interests and rights are given particular consideration.
Article 6(1)(a) GDPR, where consent is required, in particular for optional advertising or tracking activities and optional media sharing.
Where Article 8 GDPR applies, consent is given or authorised by the person legally entitled to provide such consent.
Consent may be withdrawn at any time with effect for the future. The lawfulness of any processing carried out before the withdrawal remains unaffected.
Required and Voluntary Information
The user's name, telephone number, date of birth, user role and the information required for registration, age verification, authentication and team assignment are mandatory for creating an account.
Without this information, the account cannot be created or used.
Profile pictures, optional media uploads, comments and certain additional features are voluntary, unless they are required for a specific feature actively chosen by the user.
Data Sources and Recipients
Data originate in particular from the users themselves, parents or legal guardians, coaches in the context of an invitation, other team members through comments or reactions, app stores, payment providers and technical service providers.
Recipients may include, in particular, hosting, database, SMS, push notification, advertising, payment, IT, support and security service providers, as well as coaches, parents and team members in accordance with the applicable role and visibility logic.
Service providers receive only the data necessary for the performance of their respective tasks and, where they act as processors, are contractually bound accordingly.
International Data Transfers
Certain service providers, affiliated companies or subcontractors may be located outside Switzerland, the European Union (EU) or the European Economic Area (EEA).
Transfers of personal data to countries that do not provide an adequate level of data protection will take place only where permitted by law, for example on the basis of adequacy decisions, Standard Contractual Clauses (SCCs) or other appropriate safeguards.
Storage Period and Deletion
23.1 Challenge and Media Content: Rejected challenge submissions are deleted. If a user's own media content is deleted or removed from the Hall of Fame, the associated Hall of Fame version, likes and comments are also deleted.
23.2 Chat Messages: Chat messages are stored during the current season. After the end of the season on 31 July, chat histories remain archived for two months and are available exclusively to the coach with read-only access. From 1 October, all chat messages from the expired season are automatically deleted from the production system.
Individual messages may, by way of exception, be stored for longer with restricted access if this is necessary to investigate a reported abuse case, to protect a user or to establish, exercise or defend legal claims.
23.3 Accounts, Season Archiving and Inactivity: After the end of a season, team and usage data are archived. If a user remains inactive in the following season, the data are initially archived for a further twelve months. After a total of approximately 14 months of continued inactivity, personal data are deleted or anonymised, unless statutory retention obligations or other legitimate reasons prevent this.
Users can initiate account deletion in the app or on the website using their registered telephone number and OTP verification. As a rule, the account is deleted within 14 days; during this period, accidental deletion may be revoked.
23.4 Backups: After deletion from the production database, data may still be included in automated MongoDB Atlas snapshots until the expiry of the current backup retention period of approximately eight days. These backups are used exclusively for disaster recovery and are automatically deleted thereafter.
Data Security
NextLegend implements appropriate technical and organisational measures to protect personal data.
These include, in particular, role-based access controls, the need-to-know principle, administrator logs, OTP verification, SMS Pumping Protection, restrictions on SMS destination countries, closed team and visibility areas, as well as age-based advertising and content settings.
Rights of Data Subjects
Data subjects have the rights granted under the applicable data protection laws, including in particular the right of access, rectification, erasure, restriction of processing, objection, withdrawal of consent, data portability and the right to lodge a complaint with a supervisory authority.
Requests may be submitted to [email protected].
To protect users, proof of identity may be required.
Parents and legal guardians may, in particular, request access to, rectification or deletion of their child's personal data, withdraw previously granted consent, and request the termination of the use or deletion of media, comments and accounts, provided that the applicable legal requirements are met.
Right to Lodge a Complaint
In Switzerland, complaints may in particular be lodged with the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland.
Where the GDPR applies, data subjects also have the right to lodge a complaint with the competent data protection supervisory authority in the European Union.
No Solely Automated Decision-Making with Significant Effects
Skills, levels, awards, Market Value and NLC are used exclusively for in-app motivation and entertainment purposes.
They are not used as the basis for any solely automated decisions that produce legal effects or similarly significantly affect users.
In particular, they do not determine any real sporting selection, contracts, club membership or medical assessments.
Changes to this Privacy Policy
NextLegend may amend this Privacy Policy if its features, service providers, legal requirements or data processing activities change.
Users will be informed of any material changes in an appropriate manner.
Where renewed consent is required, the relevant feature will only be used after such consent has been obtained.