MASProLegal

Privacy

Privacy policy

Last updated: 22 August 2026

This English version is provided for convenience. In case of discrepancies, the German version prevails.

In short: MASPro is an administration and communication platform for clubs. The operator is the controller for the platform account, contract, security and support. For data relating to members, leads and booking contacts, the respective club is regularly the controller and MASPro acts as its processor.

1. Controller

Ausbildungszentrum für Selbstverteidigung und Kampfkunst SportUnion, register number (ZVR) 1561748312, Erikaweg 4, 9241 Wernberg, Austria, represented by its chairman Raimund Pock. Email: info@masvillach.at. Data protection contact for MASPro: office@pock.biz.

2. Roles under data protection law

We are the controller for the administration of MASPro accounts, user permissions, contracts, billing, platform operations, abuse prevention, security logs and support. Clubs generally determine the purposes and means of processing their member, lead, appointment, message, payment and form data. To that extent we process data as a processor on their documented instructions. Affected end customers should contact the club concerned first; we support the club in handling such requests.

A public booking form may additionally contain a privacy notice specific to that club. That notice governs the booking in question and supplements this platform information.

3. Categories of data processed

  • Account and organisation: name, email address, phone number, club, roles, permissions, sign-in and OAuth account information.
  • Members and leads: core and contact data, memberships, notes, documents, attendance and communication in line with the club’s configuration.
  • Bookings and forms: the service selected, appointment, location, form entries, consent status as well as technical request and security data.
  • Communication: sender, recipient, content, attachments as well as delivery and error status for activated email, SMS or messaging channels.
  • Payments and accounting: transaction, invoice and payment status; full card details are processed by the payment providers used and are not stored by MASPro.
  • Integrations: connection status, provider IDs, encrypted access tokens and the data requested through the integration.
  • Usage and security: IP address, browser/device information, timestamps, audit, diagnostic and error data.

4. Purposes and legal bases

  • Providing and administering the platform, performance of the contract and pre-contractual measures (Art. 6(1)(b) GDPR).
  • Compliance with statutory retention, tax and record-keeping obligations (Art. 6(1)(c) GDPR).
  • IT security, prevention of fraud and misuse, error analysis and needs-based improvement (Art. 6(1)(f) GDPR).
  • Optional functions or integrations on the basis of consent (Art. 6(1)(a) GDPR) or on the instruction of the club acting as controller.

Where we act as a processor, the club determines the specific legal basis.

5. Optional integrations

MASPro provides configurable connections, for example to Google services, payment processing, email, SMS, messaging, document dispatch, maps, error analysis or AI-assisted functions. Data is transferred to a provider only where the function has been activated and is used, or where this is technically necessary. Each club is responsible for its selection, configuration, legal basis and the information provided to end customers. AI functions must not be used with special categories of personal data without prior review.

6. Google API Services and Google user data

When an authorised user establishes a Google connection, MASPro uses — depending on the function expressly selected — basic profile data (OpenID, email, profile), Google Drive and Google Sheets for selected files and spreadsheets, Gmail for the shared inbox and message workflows, and Google Data Manager for authorised conversion events.

  • Google Drive and Google Sheets: the drive.file scope limits MASPro to files opened with or created by MASPro. MASPro uses it to select, import and process the files designated by the user. For expressly configured spreadsheets, MASPro can read and write values through Google Sheets. MASPro does not request access to all other files in the connected Drive account for this purpose.
  • Gmail: a separately enabled Gmail connection uses gmail.modify. This scope technically permits reading, composing and sending messages and modifying message labels. MASPro uses it solely to make incoming messages, including senders, recipients, subject, body and attachments, available in the shared inbox or message workflow enabled by the user; to send messages initiated by the user or a configured automation to the selected recipients; and to mark successfully processed incoming messages as read. MASPro does not permanently delete Gmail messages, alter unrelated messages or account settings, or use Gmail content for advertising. Configured workflows may transfer attachments to document processing or invoice import. If the club expressly enables AI-assisted reply analysis, the subject and message body may be transferred to the configured AI service provider solely to provide that function; use for training general-purpose AI models is excluded.
  • Conversion tracking: if a club activates conversion tracking, MASPro may send a booking event to the Google Ads destination it has configured. This event may contain the destination and transaction identifier, timestamp, consent status, value and currency, any Google click identifiers present (gclid, gbraid or wbraid) and — only where configured and legally permissible — the email address and phone number in SHA-256 hashed form.
  • Storage: the OAuth email address, technical connection data, granted scopes and encrypted refresh tokens are stored for as long as the connection is needed. Imported Gmail messages and attachments, sent content, provider message identifiers and imported or exported business data are processed according to the customer contract, configured workflow and the general retention rules in section 9. Click identifiers and the associated conversion attribution are retained only until the end of the attribution window configured by the club and are then deleted on a regular cycle.
  • Transfer and disclosure: Gmail content is retrieved through the Google Gmail API or sent to recipients selected by the user or the enabled workflow. Where conversion tracking is enabled, conversion data is transmitted to Google Data Manager or the configured Google Ads destination. Google user data is not sold, not used by MASPro for personalised advertising, not passed on to data brokers and not used to train general-purpose AI models. Any other disclosure takes place only to the connected club, to necessary technical service providers, on the user’s documented instruction, or where required by law.
  • Withdrawal and deletion: the connection can be disconnected in MASPro and additionally revoked in the Google Account, which ends further API access. Users may then request deletion of remaining data using the procedures described under Deletion & data subject rights.
Google Limited Use: MASPro’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve user-facing features that the user has explicitly enabled.

7. Recipients and processors

We use hosting, storage, database, communication, payment, monitoring and integration providers. Depending on the functions activated, these may include in particular Hetzner, self-hosted Supabase technologies, Google, Microsoft, Meta, Stripe, Resend, Bird/MessageBird, Vonage, Sentry, Mapbox as well as selected document or AI providers. The current overview, including purpose and the conditions under which each is used, is available under Security & providers. Authorities or advisers receive data only where there is a legal basis or for the defence of legal claims.

8. Transfers to third countries

Some providers may process data outside the European Economic Area. Where no adequacy decision applies, we base transfers in particular on the European Commission’s standard contractual clauses and assess additional safeguards. The specific processing depends on the provider’s region, product and configuration.

9. Retention

We store personal data only for as long as it is needed for the respective purpose, the customer relationship, legitimate security and record-keeping interests or statutory obligations. Statutory invoicing and accounting records are regularly retained for seven years. Operational data follows the contract, the club configuration and any deletion request. Security logs, backups and event data are overwritten or deleted according to staggered technical periods; deleted data may remain in backups until the regular overwrite cycle and is not restored for other purposes.

10. Security

We use risk-based technical and organisational measures, including TLS transport encryption, role-based access, separate environments, logging, secured secrets, updates, backups and incident handling procedures. No system is absolutely secure; security reports can be submitted in line with our vulnerability disclosure policy.

11. Rights of data subjects

Where the statutory conditions are met, data subjects have the right to access, rectification, erasure, restriction, data portability, objection and withdrawal of consent with effect for the future. There is also a right to lodge a complaint with the Austrian Data Protection Authority. For club data, the request should first be addressed to the club concerned. Details can be found under Deletion & data subject rights.

12. Contact and changes

Data protection enquiries: office@pock.biz. We update this policy in the event of material changes and indicate the current version date. Where a change requires renewed consent, this is obtained separately.