Skip to main content

Privacy & Data Protection

Last updated: July 2026

Who controls your data (controller identity)

TestMi operates as a joint data controller arrangement. Your club or coaching organisation ("the Club") and Set Point Ltd (trading as TestMi), company number: 17299890, ICO registration: ZC183254 are both data controllers for athlete data collected through the TestMi platform.

Under this arrangement, the Club determines the purpose and manner of data collection (coaching and development), and TestMi provides the technical platform. A joint-controller agreement under UK GDPR Article 26 governs the responsibilities of each party. A summary is available on request.

To exercise your data rights, contact your Club's TestMi administrator in the first instance, or contact TestMi directly at: privacy@testmi.fitness.

If a data protection officer (DPO) has been appointed, their contact details will be provided by your Club.

What data we collect and why

We collect two categories of personal data, each processed under a different lawful basis.

1. General performance data — processed under UK GDPR Article 6(1)(b)

This data is necessary to provide the coaching service (contract performance basis). It is collected as soon as an athlete is registered, without requiring separate explicit consent.

  • Identity data — first name, last name, date of birth, and gender
  • Membership data — sport, club, and squad
  • Performance results — test results (sprint, jump, agility, endurance, and other sport-specific metrics), T-scores, percentiles, and normative comparisons
  • Training load — training activity type, duration, RPE (perceived exertion), and weekly load summaries
  • Coach notes and reports — performance notes, corrective notes, and recommendations
  • Consent records — consent status, the name and relationship of the consenting person, and date of consent
  • Consent contact email (optional) — an email address stored by the coach, used solely to send the GDPR consent request link to the athlete or their parent/guardian. For athletes aged 13 and over this is the athlete's own email; for under-13s it is the parent or guardian's email. It is not used for marketing. To deliver the consent link we share it with our email delivery provider, who acts as a data processor on our instructions and does not use it for its own purposes; it is not otherwise shared with third parties. Retained while the athlete record is active; cleared when the athlete record is anonymised or erased.
  • Audit logs — records of who accessed or changed data, for security and accountability

2. Special-category health and biometric data — processed under UK GDPR Article 9(2)(a)

This data is classified as special-category data under UK GDPR Article 9 because it reveals health information. Its collection requires your explicit, separate consent. Declining this consent does not prevent general performance testing from proceeding.

  • Biometric measurements — height (cm), weight (kg), sitting height (cm)
  • Maturity and growth data — biological age, maturity offset (years from peak height velocity), predicted adult height, and growth phase
  • Menstrual health data — cycle day, phase, flow, symptoms, and perceived cycle impact (only if cycle tracking is enabled by the athlete or guardian)
  • Daily wellness data — sleep quality, perceived fatigue, perceived soreness, and perceived stress
  • Parent height data — mother's and father's height in centimetres, used for Khamis-Roche predicted adult height calculation
  • Heritage data — parental heritage country (used for ethnicity-adjusted growth norms where applicable) — marked for DPO review
  • Age at menarche and related reproductive health fields

Lawful bases for processing

  • Article 6(1)(b) — Contract performance: general coaching and performance data is necessary to deliver the TestMi service.
  • Article 9(2)(a) — Explicit consent: special-category health and biometric data requires your explicit, freely-given, informed, and specific consent. You can withdraw this at any time without penalty.

What happens if you withdraw special-category consent: General performance data previously collected lawfully under Article 6(1)(b) is retained (it was processed on a different lawful basis). Biometric and health data collection stops immediately. Existing special-category data is hidden internally and will not be exported or shared. You can request erasure of special-category data separately.

Children's data

TestMi is specifically designed to work with data belonging to children and young people. We recognise the additional protections required under GDPR Article 8 and the UK Data Protection Act 2018.

  • For athletes under 13, a parent or guardian must provide consent before any data is recorded. Athletes aged 13 and over may provide their own consent in line with UK data protection law.
  • If consent is not obtained, or if it is withdrawn, general performance testing can continue under Article 6(1)(b); biometric and health data will not be collected.
  • Athletes' data is only accessible to authorised coaches and administrators within the same organisation. Shared report links are view-only and do not expose login credentials.

Profiling and automated decision-making

TestMi calculates T-scores and percentile rankings by comparing individual results against aggregated, anonymised platform data. This constitutes profiling for performance-monitoring purposes under UK GDPR Article 22. These scores do not produce legally significant decisions or similarly significant effects on athletes — they are informational tools for coaches. We consider this profiling to be compatible with Article 22 (it does not involve automated decision-making with significant legal effects).

Data retention

We retain data for the following periods (provisional — subject to DPO confirmation):

  • General performance data — retained while the organisation account is active, plus 12 months after an athlete becomes inactive or the account closes.
  • Special-category data (biometric and health) — retained for 6 months after an athlete becomes inactive, or until explicit consent is withdrawn, whichever occurs first.
  • Audit logs — retained for 7 years (84 months) for legal accountability and security purposes.
  • Anonymised normative data — aggregated, anonymised performance data used for T-score and percentile calculations may be retained indefinitely as it cannot be linked to an individual.

Data storage and security

  • All data is encrypted at rest and in transit using industry-standard protocols.
  • The platform enforces role-based access controls — coaches can only access athletes within their organisation.
  • Authentication is handled via secure magic-link emails — passwords are not required for sign-in, reducing the risk of credential-based attacks.
  • The application is hosted on secure, managed infrastructure with regular security updates.

Processors: TestMi uses the following categories of third-party processors under Data Processing Agreements: (1) hosting/infrastructure provider; (2) magic-link email delivery service. No athlete data is sold or shared for marketing purposes. Full processor details are available on request.

Your rights under UK GDPR

As a data subject (or parent/guardian of a data subject), you have the right to:

  • Access — request a copy of the personal data we hold (Subject Access Request)
  • Rectification — ask us to correct inaccurate data
  • Erasure — request deletion of personal data ("right to be forgotten")
  • Portability — receive your data in a machine-readable format (CSV export available via the platform)
  • Withdraw explicit consent — revoke Art 9 special-category consent at any time without penalty; general data collected under Art 6(1)(b) is unaffected
  • Object — object to processing in certain circumstances
  • Lodge a complaint — if you are unsatisfied with how we handle your data, you can contact the Information Commissioner's Office (ICO) at ico.org.uk or by post: ICO, Wycliffe House, Water Lane, Wilmslow, SK9 5AF.

To exercise any of these rights, contact your organisation's TestMi administrator or email privacy@testmi.fitness.

Contact

If you have questions about how your data is handled, or wish to exercise your data protection rights, please contact your organisation's administrator in the first instance, or email privacy@testmi.fitness.