Last reviewed: May 2026
Data protection
GDPR (EU General Data Protection Regulation)
Stactiq complies with GDPR obligations applicable to its role as a data processor for EU-based Customers. A Data Processing Addendum incorporating Standard Contractual Clauses for international transfers is available at /legal/dpa.
UK GDPR
Stactiq's GDPR compliance posture extends to UK GDPR. UK-based Customers may execute the DPA as applicable to UK law.
CCPA (California Consumer Privacy Act)
Stactiq does not sell personal data. CCPA-compliant data handling is described in the Privacy Policy at /legal/privacy.
AI governance
Stactiq's AI Usage Policy at /legal/ai-policy defines the boundaries of AI output use, model limitations, human review obligations, and prohibited AI-assisted conduct. These provisions are aligned with emerging EU AI Act obligations for governance-layer AI infrastructure.
Customer Content is never used to train foundation AI models. This commitment is contractually enforceable under the Terms of Service and DPA.
Football governance contexts
Stactiq's Methodology DNA system is designed to support compliance with league and governing body documentation requirements, including:
- MLS NEXT: Academy curriculum documentation and methodology alignment standards.
- USSF: Coaching education and academy licensing documentation requirements.
- ECNL: Development pathway and curriculum structure requirements.
- UEFA: Club licensing methodology documentation where applicable.
Stactiq does not certify compliance with any governing body standard. Customers are responsible for ensuring that their use of Stactiq-generated documentation satisfies the specific requirements of their governing body.
Security certification
| Standard | Status | Expected |
|---|---|---|
| SOC 2 Type II | In progress | Q4 2026 |
| ISO 27001 | Roadmap | 2027 |
| Penetration test (third party) | Scheduled | Q3 2026 |
Security overview is at /security.
Contact
Compliance enquiries: legal@stactiq.ai