Privacy Policy
Last updated: September 2, 2026
1. Overview
This Privacy Policy explains how NEXTON INTERACTIVE LIMITED trading as Teloframe collects, uses, shares, and protects personal data when you use Teloframe, our websites, applications, AI features, support channels, and related services.
This policy should be read together with our Terms of Service, our Cookie Policy, and, for organizational customers using the Service to process team, player, club, or other customer content, our Data Processing Addendum.
2. Who We Are and Our Roles
NEXTON INTERACTIVE LIMITED is the operator of Teloframe. We act as a data controller for our own business and platform operations, including account administration, subscription and billing administration, security, fraud prevention, support, legal compliance, direct marketing preferences, and service analytics where permitted.
When a club, academy, school, team, coach, analyst, educator, or other organization uses Teloframe to upload or manage player records, evaluations, plans, sessions, photos, health-related workflows, or other customer content, that organization is typically the controller for that customer content and we act as its processor or service provider. The Data Processing Addendum governs that relationship unless a separate written agreement says otherwise.
3. Age, Children, and Minor Player Records
Teloframe is available only to users who are at least 13 years old. If you are under the age of majority in your jurisdiction, you may use the Service only with the involvement and permission of a parent, guardian, school, club, or other authorized adult organization representative.
Teloframe is marketed primarily to coaches, analysts, clubs, academies, schools, educators, and other users who are 16 or older or adults in their jurisdiction. Children under 13 may not create accounts directly.
Minor player data may still be managed through adult staff accounts when a club, academy, school, coach, or other authorized adult user has the required lawful basis, permissions, notices, and authority to upload and use that information. Customers are responsible for determining whether they are permitted to upload children's data and for limiting access to authorized staff.
Some data-protection laws set a higher threshold than 13. In Kenya, where NEXTON INTERACTIVE LIMITED is established, a person under 18 is treated as a child and their personal data generally requires parental or guardian consent. Customers are responsible for meeting whichever standard applies to them and to the children whose data they upload.
If we learn that a direct account was created for a child under 13, we may disable that account and take steps appropriate to the circumstances.
Our Safeguarding and Children's Data page sets out the controls we provide, the limits of what the Service does, and how to raise a concern.
4. Player and Parent Portal Accounts
Teloframe includes a portal that lets a club invite a player, or a player's parent or guardian, to see selected information about that player, such as their development plan, goals, reports, explainers, fixtures, and notifications.
Portal invitations are issued by the customer, not by us, and are sent to an email address the customer provides. The customer decides whether to invite a player directly or only a parent or guardian, and is responsible for making that choice lawfully, including where the player is a child. Accepting an invitation creates a link between an account and that player record, which the customer can revoke at any time.
A linked portal account sees information about the player it is linked to. It does not receive club-wide staff access, other players' records, or internal staff notes that the customer has not chosen to share. A family calendar feed may also be offered through a private subscription link, which works for anyone who has that link until it is regenerated or revoked.
5. Photos, Video, and Likeness
Customers can upload player photos and, in matchday workflows, match photos and video clips. Media items can carry captions and can be tagged to identify the players who appear in them. This content can depict children.
Player profile photos and development-plan evidence files are stored with private access and are served through controlled retrieval. Match gallery media, club crests, board branding images, and similar presentation assets are stored at unguessable public storage URLs so they can be rendered in galleries, exports, shared pages, and printed materials. A person who has one of those URLs can open the file without signing in, and a match gallery item can also be surfaced on a public match page if the customer publishes one.
Customers are responsible for holding the media, image, and likeness permissions required for any photo or video they upload, tag, or publish, for honouring any player or family who has withheld or withdrawn media consent, and for removing media when consent is withdrawn. Teloframe provides consent records and per-item removal so customers can operate that process, but it does not verify permissions on their behalf.
6. Notifications and Browser Push
We send in-app and email notifications about activity in your workspace, such as fixtures, sessions, announcements, and availability requests. You can change what you receive in your notification preferences.
If you turn on browser push notifications, your browser issues a push endpoint and a pair of encryption keys, which we store with the user-agent string of that device so we can send and manage notifications for it. Delivery passes through the push service operated by your browser vendor. You can turn push off in the app or revoke notification permission in your browser, which stops future messages to that device.
7. Personal Data We Collect
- Account and identity data - Name, email address, password hash, profile image, account identifiers, authentication provider details, security settings, and login or session metadata.
- Club, team, and workspace data - Club names, team names, rosters, roles, permissions, invitations, workspace membership, collaboration room data, and organizational settings.
- Player and athlete records - Names, positions, jersey numbers, dates of birth if uploaded, squad assignments, evaluations, development plans, goals and reflections, notes, training or performance records, match statistics and awards, photos, and related customer content.
- Guardian, family, and portal access data - Parent or guardian names, contact details, relationship to a player, portal invitations, accepted portal accounts, family calendar subscription tokens, and records of which portal accounts are linked to which player.
- Photos, video, and other match media - Match and training photos, video clips, captions, the identity of the person who uploaded an item, and any player tags applied to that media. This media can depict minors when customers choose to upload it.
- Attendance, availability, and participation records - Session attendance, event responses, per-event RSVP records, availability status, lineups and squad selections, minutes played, and related participation history.
- Consent records - Records of consents a customer has captured for a player, such as media, data-processing, medical, or travel consent, including whether consent was granted, when, its source, and any expiry.
- Sensitive health data - Injury status, injury episodes, rehabilitation progress, expected return dates, return-to-training and return-to-play information, and notes that reveal physical or mental health status.
- AI feature data - Prompts, supporting context, AI outputs, and related usage metadata for tactics, session planning, evaluation, performance, communication, or other AI-enabled workflows.
- AI usage, credit, and feature-metering data - AI credit balances and ledgers, per-feature usage counts, quota and rate-limit counters, cost-control records, and records of which product variant or experimental feature configuration an account was shown.
- Notification and device data - Notification preferences per channel, notification and delivery history, and, if you enable browser push, the push endpoint URL issued by your browser, the encryption keys your browser generates, and the user-agent string of the registering device.
- Activity and audit records - Records of significant actions taken in a club or workspace, such as who created, changed, shared, published, invited, or deleted something, and when, kept for accountability, security, and dispute resolution.
- Billing and subscription data - Subscription tier, cadence, customer identifiers, order identifiers, subscription status, renewal or end dates, billing contact data, and related merchant-of-record records from Polar.
- Communications and support data - Support requests, feedback, launch-update subscriptions, marketing consent records, unsubscribe status, suppression status, and message-delivery metadata.
- Technical, cookie, and device data - IP address, browser and device metadata, route names, diagnostics, optional analytics data if you consent, and browser storage or cookie preference records.
8. How We Collect Personal Data
We collect personal data in several ways, including:
- Directly from you when you sign up, log in, purchase a subscription, contact us, request support, use AI tools, create content, or change settings.
- From your organization or other authorized adult users who add you or upload player, guardian, health, or team records into the Service.
- From third-party identity, billing, collaboration, hosting, monitoring, AI, and email-delivery providers that support the Service.
- From fixture files you import, such as CSV or calendar files, and from fixture text you paste.
- Automatically from your browser, device, and use of the Service, including logs, diagnostics, cookies, local storage, and analytics if you consent.
9. How We Use Personal Data
We use personal data to deliver the Service, run customer workflows, secure the platform, communicate with users, and operate our business. Depending on the context and applicable law, our legal bases may include performance of a contract, legitimate interests, consent, and compliance with legal obligations.
- Provide and secure the Service, including authentication, account management, exports, sharing, billing, and support.
- Operate club, team, coach, analyst, educator, and player workflows, including evaluations, planning, collaboration, and reporting.
- Run injury, availability, rehabilitation, return-to-training, and return-to-play workflows chosen by customers.
- Provide AI features and generate responses, drafts, suggestions, or analysis when users invoke those tools.
- Operate the player and parent portal, including invitations, account linking, family calendar feeds, and the read access a linked portal account has to that player's information.
- Run matchday workflows chosen by customers, including fixtures, lineups, live match logging, attendance and event responses, awards, debriefs, and match photo or video galleries.
- Send transactional messages such as verification, password reset, security notices, receipts, billing messages, and service updates.
- Send in-app, email, and browser push notifications according to the notification preferences you choose.
- Meter AI credits, feature quotas, and rate limits, control costs, and evaluate product variants so we can improve the Service.
- Keep activity and audit records so clubs can see who did what in their workspace, and so we can investigate security or misuse.
- Send opt-in marketing communications, launch updates, product news, or offers where permitted by law and where you have subscribed or otherwise consented.
- Monitor performance, detect abuse or failures, troubleshoot incidents, enforce our terms, and comply with law.
10. Sensitive Health Data
Some customer workflows in Teloframe can involve sensitive health data, not just a generic availability flag. For example, customers may use the Service to record injury status, injury episodes, rehabilitation progress, expected return dates, return-to-training or return-to-play tracking, and notes that reveal physical or mental health status.
We process this information only to support the customer workflows chosen by the customer, such as player availability management, welfare tracking, rehabilitation administration, training and squad planning, reporting, and player development context. We do not use customer health data to provide consumer advertising or behavioral profiling.
Teloframe is not a medical device, healthcare provider, emergency service, or clinical records system. AI outputs are not medical advice and must not be used as a substitute for clinical judgment, diagnosis, treatment, or emergency response.
Customers are responsible for determining their lawful basis for sensitive health-data processing, providing required notices, obtaining any permissions or consents required by law, limiting uploads to relevant and necessary information, and restricting internal access to authorized staff with a legitimate need to know.
11. AI Features
Teloframe includes AI-powered tools across tactics, planning, evaluation, performance, and communication workflows. When you use an AI feature, the prompt, surrounding context, and resulting output may be processed by OpenAI, Anthropic, and related service infrastructure to generate the requested response.
Depending on the feature and what you choose to submit, AI processing can include player details, session notes, evaluations, club context, guardian information, or health- related content. You should not submit unnecessary sensitive data to AI tools.
We do not use customer content to train our own models, and we access AI providers through commercial API arrangements rather than consumer AI products. We do keep AI usage and credit records so we can meter features, apply quotas and cost controls, and troubleshoot problems.
If you choose to use AI features with player, minor, guardian, or health-related data, you remain responsible for ensuring you have the lawful basis, permissions, notices, and authority required by applicable law. Details about our supporting providers are available on our Subprocessors page and in the Data Processing Addendum.
12. How We Share Personal Data
We may share personal data in the following circumstances:
- With service providers and subprocessors that help us host, secure, monitor, bill, collaborate, and operate the Service.
- With your organization, team administrators, or other users who are authorized to access the relevant workspace, content, club, or player records.
- With payment, identity, collaboration, AI, or email vendors when you use the related features.
- If required to comply with law, enforce our terms, protect the Service, investigate abuse, or respond to valid legal process.
- In connection with a reorganization, financing, merger, sale, or similar transaction, subject to appropriate confidentiality and legal safeguards.
A current public provider list is available on our Subprocessors page. The providers currently disclosed there are:
- Neon - Managed PostgreSQL database hosting for account records, saved content, club data, and operational application data.
- Vercel - Application hosting, content delivery, blob storage used by some uploads and exports, and optional Vercel Analytics when you consent.
- OpenAI - AI processing when you use AI coaching tools across the platform.
- Anthropic - AI processing for selected AI features, including AI-generated coaching content.
- Liveblocks - Real-time collaboration infrastructure for shared board presence, room state, and live co-editing features.
- Sentry - Operational error monitoring and performance diagnostics used to detect and troubleshoot failures.
- Resend - Transactional and opt-in marketing email delivery for verification, password reset, account communications, launch updates, and product announcements.
- Polar - Subscription checkout, billing, customer portal, and related subscription records.
- Browser push delivery services - Your browser vendor's push service (for example Google, Apple, or Mozilla) delivers web push notifications to your device if you enable them.
- Perplexity - Search and answer engine queried by our internal brand-visibility tracking. It does not receive customer content.
- Google OAuth - Optional social sign-in provider if you choose to authenticate with Google.
13. International Transfers
We and our providers may process personal data outside Kenya, including in the United States and other countries where our hosting, AI, billing, monitoring, collaboration, identity, and email vendors operate. Those countries may have data-protection laws that differ from the laws in your home jurisdiction.
Where applicable, we use contractual, technical, and organizational safeguards intended to protect transferred personal data. Organizational customer transfers are also addressed in the Data Processing Addendum.
14. Marketing and Communications
We send transactional and service messages when necessary to run the Service, including verification, password reset, billing, security, subscription, and operational notices.
We may also send launch updates, product news, and other marketing communications where permitted by law and where you have joined a waitlist, requested updates, opted in, or otherwise given permission for those messages. Marketing emails include an unsubscribe method, and you may also contact us at contact@teloframe.com to object to direct marketing.
15. Retention
We keep personal data for as long as reasonably necessary for the purposes described in this policy, including to provide the Service, maintain records, comply with law, resolve disputes, enforce agreements, and protect the platform.
Retention periods vary depending on the type of data, the account or workspace status, and legal or operational requirements. Deletion from the live product does not always mean immediate removal from temporary files, caches, logs, generated exports, or backups, which may persist for a period of time until ordinary deletion or overwrite cycles run.
Some retention behaviour is built into specific features. Portal invitations expire on the date set when they are sent. Files we generate for a self-serve data export are held behind a private, time-limited link and expire automatically. When you delete your account, we delete or disassociate the account data we hold as controller, subject to the backup, log, and legal-retention caveats above; content that belongs to a club workspace remains with that club, which controls it.
For organizational customer content, deletion and return terms are described more specifically in the Data Processing Addendum.
The periods below describe how long we keep the main categories of data. Where a customer deletes something sooner, the shorter period applies. Where the law requires us to keep something longer, for example for tax or a legal claim, we keep it for that longer period.
| Data | Retention |
|---|---|
| Account and profile data | For as long as the account is open. Deleting your account removes the personal-scope records held under it straight away. |
| Club and team workspace data after a subscription ends | 90 days after the subscription lapses or is cancelled, then deleted, unless the workspace is reactivated first. |
| Inactive free accounts | Kept until you delete the account. We do not automatically delete accounts for inactivity. |
| Players and teams you delete | Recoverable for 90 days, then permanently removed. Clubs can be restored for 30 days. |
| Match photos, video, and gallery media | Kept until the club removes the item or the workspace itself is deleted. Media is not deleted on a timer. |
| Club audit and activity records | 24 months. |
| Notification records and delivery history | 12 months. |
| AI prompts, outputs, and generation records | 12 months. AI credit balances and usage counters are kept while the account is open for billing and quota purposes. |
| Push notification subscriptions | Removed 30 days after the subscription is disabled or your browser stops accepting it. |
| Invitations and revoked portal links | Invitations expire after 14 days. Expired and revoked invitation and link records are removed after 90 days. |
| Data export files | The download link and the generated file expire 24 hours after the export is prepared. |
| Support requests and feedback | 24 months. |
| Marketing contacts after unsubscribe | The suppression record is kept indefinitely so we can keep honouring your unsubscribe. Other marketing data is deleted. |
| Billing, subscription, and tax records | 7 years, to meet tax and accounting record-keeping requirements. |
| Operational error diagnostics and monitoring data | Held by our monitoring provider under the retention configured for our plan, and not used beyond security and reliability. |
| Database backups | Held on our database provider's rolling backup and point-in-time recovery window. Deleted data can persist in a backup until that window rolls past it. |
16. Your Rights
Depending on your location and the role in which we process your data, you may have some or all of the following rights:
- Access - Ask whether we process your personal data and request a copy of relevant information.
- Correction - Ask us to correct inaccurate or incomplete personal data.
- Deletion - Ask us to delete personal data where the law gives you that right.
- Restriction or objection - Ask us to restrict certain processing, object to processing based on legitimate interests where applicable, or object to direct marketing at any time.
- Portability - Request a machine-readable export of data you provided to us where portability rights apply.
- Withdraw consent - Withdraw consent for optional processing, such as analytics choices or marketing consent, without affecting earlier lawful use.
- Complaint - Lodge a complaint with the Office of the Data Protection Commissioner in Kenya or another competent regulator where applicable.
Account holders can exercise two of these rights directly in the product. Your account settings include a self-serve data export, which prepares a downloadable copy of your account data through a private, time-limited link, and self-serve account deletion. For anything else, contact us using the details at the end of this policy. We aim to respond to rights requests within the period required by the law that applies to you, and we may need to verify your identity first.
If we process data only as a processor for an organizational customer, we may direct your request to that customer because it controls the relevant customer content. For example, a parent asking about a child's player record will usually need to raise that with the club or academy that created it.
17. U.S. State Privacy Rights Where Applicable
If a U.S. state privacy law applies to your relationship with us, you may have additional rights such as access, deletion, correction, portability, and appeal rights. We do not sell personal information, and we do not use personal information for cross-context behavioral advertising.
18. Automated Decision-Making and Profiling
We do not make decisions that produce legal effects or similarly significant effects about you based solely on automated processing. AI features in Teloframe generate suggestions, drafts, summaries, and analysis for a human user to review. Selection, assessment, progression, and welfare decisions about a player are made by the customer's staff, not by us and not by the Service.
We do run limited internal product experimentation, such as showing different feature configurations to different accounts, to evaluate and improve the Service. This does not affect a player's records or a customer's decisions about players.
19. Public Sharing and Visibility
If you create a share link, the linked content can be accessed by anyone who has the URL. We do not include supported share-link pages in our sitemap and we apply noindex signals to those pages, but we cannot prevent recipients, search tools, screenshots, exports, or third parties from redistributing or capturing content once it has been shared.
The same applies to other link-based features, including public match pages and their galleries, shared player explainers, and family calendar subscription links. Anyone holding the link can open it while it remains active. Uploaded media, crests, and branding images are also stored at unguessable public storage URLs as described above.
Separately, you can choose to publish content such as tactics, sessions, or drills to a public library. Published content is visible to anyone, can be viewed, copied, or forked by other users as the feature allows, and may be indexed by search engines. Where a feature offers a choice, you decide whether to publish under your name or anonymously. Unpublishing removes the content from the library going forward but cannot recall copies others already made.
You must not publicly publish or share health information, children's data, guardian data, images of children, or other confidential or sensitive content unless you are clearly authorized to do so.
20. Security
We use measures designed to help protect the Service and the data stored in it, including HTTPS or TLS in transit, authentication safeguards, optional two-factor authentication, role-based access controls for club workflows, private-access file flows for player photos and plan evidence, and operational monitoring for security and reliability. As explained above, some presentation and gallery media is deliberately stored at unguessable public URLs so it can be rendered in shared and exported material. No online service can guarantee absolute security.
If we become aware of a personal-data breach affecting data we control, we will assess it and provide notice where applicable law requires. Where we act as a processor for an organizational customer, we notify that customer without undue delay so it can meet its own obligations, as set out in the Data Processing Addendum.
If you believe you have found a security vulnerability in Teloframe, please report it to contact@teloframe.com rather than disclosing it publicly, and give us a reasonable opportunity to fix it. Our Security page describes the measures in place and what is in scope for a report.
21. Cookies and Local Storage
We use essential cookies for authentication and security, optional analytics when you consent, and browser storage for preferences and client-side functionality. See our Cookie Policy for details.
22. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, our providers, legal requirements, or our data practices. When we do, we will update the date at the top of this page and, where appropriate, provide additional notice.
23. Contact
For privacy questions, complaints, or rights requests, contact NEXTON INTERACTIVE LIMITED at contact@teloframe.com.
P.O BOX 632, 00618 - RUARAKA, NAIROBI, KENYA
If you are not satisfied with our response, you may complain to the Office of the Data Protection Commissioner in Kenya or another regulator with authority over your complaint where applicable.