Privacy Policy

Last updated: August 2026

1. Data controller

The controller for data processing on this platform is:

Ramsey Albayati Nordring 16 64807 Dieburg Germany

Email: [email protected] Phone: +49 173 2594195

No data protection officer has been appointed; the conditions of § 38 BDSG (German Federal Data Protection Act) do not apply. For data protection enquiries, please use the contact details above.

2. Who is responsible for which data

There are two distinct roles on this platform, and the difference matters for your rights.

The respective organiser is responsible for tournament and participant data. They decide that an event takes place, which data is collected for it and how long it is stored. We process this data on their behalf and on their instructions (processing on behalf of a controller under Art. 28 GDPR). For access or erasure requests concerning your tournament registration, please contact the organiser first; we support them in responding.

We are responsible for the platform itself — that is, your user account, your profile, technical provision, logs and everything that exists independently of a single event.

3. Overview of processing activities

Processing activityLegal basisRetention period
Accessing the platform, server logsArt. 6(1)(f)30 days
Strictly necessary cookiesArt. 6(1)(f)session or expiry of the token
User account and profileArt. 6(1)(b)until the account is deleted
Tournament registration by clubsorganiser's instruction, Art. 2812 months after the end of the event
Publication of results (only after release by the organiser)Art. 6(1)(f)12 months after the end of the event
Annual rankingArt. 6(1)(f)until you object
Profile picture in the annual rankingArt. 6(1)(a)until you withdraw consent
Athlete identityArt. 6(1)(f)until the athlete profile is deleted
Tournament chatArt. 6(1)(f)90 days after the end of the event
News postsArt. 6(1)(f)until deleted by the publisher
Comments on news postsArt. 6(1)(f)until deleted by you or with the post
Push notificationsArt. 6(1)(a)until you withdraw consent
Email deliveryArt. 6(1)(b) and (f)see the respective purpose
PaymentsArt. 6(1)(b) and (c)statutory retention periods
Participant passesorganiser's instructionwith the pass or the profile
Club and membership administrationclub's instruction, Art. 28until deleted by the club
Help assistantArt. 6(1)(f)not stored permanently by us
Map displayArt. 6(1)(f)not stored by us
Contacting usArt. 6(1)(b) and (f)until the enquiry is settled

4. Processing activities in detail

4.1 Accessing the platform

Each time the platform is accessed, technical data is stored in log files: IP address, browser type, time of access, the address requested and the outcome of the request. This data is required to keep the service running, detect faults and defend against attacks.

The legal basis is our legitimate interest in secure and functional operation (Art. 6(1)(f) GDPR). Logs are deleted after 30 days. Logging is handled by Grafana Cloud with storage in the European Union.

4.2 Cookies

We use strictly necessary cookies only:

  • Session cookies for sign-in — without them, signing in is not possible. They are deleted when the session ends or the token expires.
  • NEXT_LOCALE — stores the language you selected.

We set no cookies for tracking, analytics or advertising. No data is transmitted to Google Analytics, Facebook or comparable services.

The legal basis is Art. 6(1)(f) GDPR in conjunction with § 25(2) no. 2 TTDSG. Strictly necessary cookies do not require consent — which is why you will not see a consent banner on this platform.

4.3 User account

For an account we process your email address, first and last name, and your password in encrypted form. You may optionally add: phone number, date of birth, grade, gender, nationality, profile picture and your affiliation with one or more clubs.

Signing in via Apple or Google is also possible. In that case we receive your email address and name from them.

The legal basis is performance of the user agreement (Art. 6(1)(b) GDPR). The data is stored until you delete your account, which you can do yourself at any time in the settings.

Important: deleting the account also deletes the tournament registrations made through it. While you are registered for an ongoing event, you should not delete the account.

4.4 Tournament registration

Registrations are made through club or federation accounts, not by the athletes themselves. For each registered competitor we process: first and last name, age, gender, grade, the chosen disciplines, a competitor number and — where the event's rule set provides for weight classes — the weight. The registering club may optionally add an email address.

No date of birth is collected for tournament registration.

We process this data on behalf of the respective organiser. They are the controller; we act on their instructions. The basis is a data processing agreement under Art. 28 GDPR.

The tournament and its registration data are deleted automatically twelve months after the end of the event, unless the organiser sets a shorter period. Until then they remain fully accessible to the organiser.

4.5 Publication of competition data

A competition is a public event. So that participants, clubs, spectators and the press can follow what happened, certain data is publicly accessible.

Results. Whether an event's results are public is decided by the organiser alone. They release them explicitly; releasing the draw does not do so. New events start without public results.

Once released, the following can be accessed without signing in: first and last name of placed participants, club or nation, and the discipline. The discipline name indicates age class, gender and grade.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in making sporting results verifiable: a placement can only be checked if it is attributed to a person. In competition, therefore, the actual name is always used; a pseudonym is not possible there. The assessment takes into account that publication is not an automatic consequence of running the competition but rests on a separate decision by the organiser, which they can withdraw at any time. Who makes it and when is recorded.

These pages are accessible to search engines and may be found through them.

If the organiser withdraws the publication, the results are no longer publicly accessible through the platform. Search engines may still hold them for some time; we have no direct influence over that. Withdrawal is not deletion — the results remain available internally to the organiser, and the retention period below applies unchanged.

If you would like your name, or your child's, removed from a published results list, please contact the organiser of the event concerned; they decide on publication. You can also reach us at [email protected] and we will put you in touch.

Schedules and bout lists are likewise accessible without signing in and contain names and competitor numbers. They are not indexed by search engines. Displays in the competition hall are reachable only via a link that is not publicly known.

Annual ranking. A public ranking is maintained across individual events. For each athlete it contains the name, age, gender, grade, club and the medals achieved.

Included is anyone who was recorded with an email address in a registration and achieved a placement. When entering the email address, the registering club confirms that the person concerned, or their legal guardians, agree to this.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in a comprehensible overview of performance reaching beyond a single event, as is customary in competitive sport.

You may object to inclusion at any time (Art. 21 GDPR). If you have confirmed your athlete profile, you can switch the ranking off directly in the settings and also choose a pseudonym instead of your name. Otherwise an informal message to [email protected] is sufficient — no account is required. We will then remove you from the ranking.

A profile picture appears in the ranking only if you have expressly released it. The default is "no picture". In that respect the legal basis is your consent under Art. 6(1)(a) GDPR, which you may withdraw at any time.

These settings affect the annual ranking only. The results of individual events remain unaffected. The same applies in reverse: if an organiser withholds the results of their event, the annual ranking is unaffected. It only carries medals and points across the season and names no individual event; you decide on your own visibility there.

4.6 Athlete identity and athlete profile

If a club records an email address during registration, a cross-event identifier is created. It allows you to view your own registrations and results over the years and to object to the annual ranking.

As long as the identifier has not been confirmed by you, no data is released through it to the requesting user. Your data becomes visible only after confirmation via a link sent to your email address.

The identifier is not tied to a single tournament and is therefore not deleted with it. You can delete your athlete profile yourself at any time.

4.7 Tournament chat

A chat is available for coordination during an event. We process message contents, sender, time and uploaded attachments. Attachments are held in a non-public area and can only be retrieved via time-limited links.

The legal basis is Art. 6(1)(f) GDPR. Messages and attachments are deleted automatically 90 days after the end of the event.

4.8 News and comments

Dojos, federations and we ourselves publish news posts that are publicly visible on the platform. If a club has a news feed on file, we regularly fetch its publicly available address and take over title, date, link and a short excerpt. We do not take over the full text; it stays with the club. Personal data arises only insofar as the club has published it itself. This also includes a cover image, if the feed provides one: we copy it to our server and deliver it from there. If the club's image server refuses us the copy, we embed the image directly from there as an exception — in that case your browser connects to that server and transmits your IP address. We do not pass on which page you are reading. If the website has no feed, we instead read its public content index and the details it provides for link previews — the same data, just from a different source. We respect a machine-readable prohibition on the website.

Comments on these posts can be written by signed-in users. We process the text, your display name, your profile picture and the time. Comments are public — anyone can read them, including without signing in, and search engines may index them. Please do not post anything there that you do not want to be public.

We do not store an IP address with comments.

The legal basis is our legitimate interest in an exchange between the clubs and their members (Art. 6(1)(f) GDPR).

You can delete your comments yourself at any time. If replies are attached, a placeholder remains without your name and without your text so that the replies of others stay comprehensible. Deleting your account removes your comments entirely; deleting a post also removes the comments below it.

For moderation, the publisher of a post can hide comments below it; only you and we as the operator can delete them permanently. If a comment is reported several times, we hide it provisionally until it has been reviewed. For a report we store the reason, the time and the reporting person; the author is not told who reported.

4.9 Notifications

Push notifications to your device require your express consent in the browser or app. A device-side identifier is stored for this purpose and transmitted to the push service of the respective manufacturer — to Apple for Apple devices, to the browser vendor's service for browsers. These services are located outside the European Union.

You can withdraw consent at any time in your device settings. The legal basis is Art. 6(1)(a) GDPR.

Emails are sent to perform the user agreement (confirmations, invitations, access details) and on the basis of legitimate interest (reminders for events you have bookmarked). You can switch reminders off in your settings.

4.10 Payments

Where an organiser processes payments through the platform, card payment, PayPal, bank transfer and cash are available.

Card and SEPA payments are handled by Stripe. We do not see payment data — it is processed exclusively by Stripe. We receive the amount, the status and a transaction reference. Payouts go directly to the organiser.

With bank transfer and cash, no payment service provider is involved; only what the organiser needs for allocation is processed.

The legal basis is performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR). Payment records are subject to statutory retention periods and therefore cannot be deleted early.

4.11 Participant passes

For passes we process name, club or nation, competitor number, role and — where available — a photograph.

For participants with an account, the photograph is their profile picture. It belongs to their account, not to the event; they upload it and delete it themselves. For guests without an account — such as medical staff or external helpers — a passport photo is stored separately in a non-public area and removed together with the pass.

4.12 Club and membership administration

Clubs can administer their members on the platform. Depending on use, the following is processed: name, date of birth, gender, grade, training attendance, examinations and contact details of legal guardians.

The respective club is the controller for this data; we process it on their behalf. It is deleted when the club deletes it or gives up the club account.

4.13 Help assistant

The interface contains an assistant that answers questions about how to use the platform. Your question and the user manual are transmitted to Anthropic in the United States. Participant data is not transmitted.

You can hide the assistant permanently in your settings. The legal basis is Art. 6(1)(f) GDPR.

4.14 Map display

On public event pages the venue is shown via Google Maps. Your IP address is transmitted to Google in the process. Participant data is not transmitted. The legal basis is Art. 6(1)(f) GDPR.

4.15 Contacting us

For messages sent via the contact form or by email, we process your details in order to handle the enquiry. The legal basis is Art. 6(1)(b) or (f) GDPR. Messages are deleted once the enquiry has been settled and no retention obligations apply.

5. Recipients of the data

We use the following service providers. Where they process on our behalf, data processing agreements under Art. 28 GDPR are in place. Payment service providers act as controllers in their own right for parts of their processing; their own privacy notices apply in that respect.

Service providerPurposePlace of processing
DigitalOceanOperation of the applicationFrankfurt am Main
SupabaseDatabase, authentication, file storage, backupsFrankfurt am Main (eu-central-1)
Cloudflare, Inc.Delivery, name resolution, attack protection, email forwardingUSA; delivery via the nearest location
BrevoSending emailsFrance and Belgium; sub-processors in the USA and India
Grafana LabsLogging and monitoringEuropean Union
StripePayment processingIreland and USA
PayPal (Europe)Payment processingLuxembourg
GoogleMap display, inboxUSA
AnthropicHelp assistantUSA
Apple and browser vendorsPush notificationsUSA

Backup copies of the database are additionally stored on our own storage system in Dieburg, Germany. This is our own infrastructure, not a service provider.

On Cloudflare specifically: Cloudflare decrypts traffic in order to process it and is therefore not a mere cache. Requests from Germany are served from locations within the European Union.

6. Transfers to third countries

Some of the service providers named above process data outside the European Union, in particular in the United States.

These transfers take place on the basis of the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR or — where the provider is certified — on the basis of the adequacy decision for the EU-US Data Privacy Framework under Art. 45 GDPR. Which basis applies in each case is recorded in the data processing agreement with the respective provider; we make these agreements available to organisers on request.

These transfers can be avoided for:

  • Payments — if the organiser chooses bank transfer or cash, no payment service provider is involved.
  • Map display — can be switched off at the organiser's request.
  • Help assistant — can be switched off for each account individually.
  • Push notifications — only after express consent.

7. Retention periods

DataPeriod
Server logs30 days
Tournament with registrations, draws and results12 months after the end of the event
Tournament chat and attachments90 days after the end of the event
News posts and commentsuntil deleted; comments additionally with the post and with your account
User account and profileuntil you delete it
Athlete identityuntil the athlete profile is deleted
Database backups7 days at the provider, 30 days on our own storage
Payment recordsstatutory retention periods

Note on backups: deletion does not apply retrospectively to backups already created. A deleted record disappears for good once the last backup containing it has expired — after about a month at the latest.

8. Your rights

You have the right to:

  • Access the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a commonly used format (Art. 20 GDPR)
  • Object to processing based on legitimate interests (Art. 21 GDPR)
  • Withdraw consent with effect for the future (Art. 7(3) GDPR)
  • Lodge a complaint with a supervisory authority (Art. 77 GDPR)

The authority responsible for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit Postfach 3163, 65021 Wiesbaden, Germany [email protected]

You may, however, contact any supervisory authority, in particular the one where you habitually reside.

On the right to object in particular: you may object to inclusion in the public annual ranking at any time. If you have an athlete profile, you can do this directly in the settings. Otherwise an informal message to [email protected] is sufficient — no account is required.

If your rights concern data from an event, please contact the organiser first. They decide on the matter; we support them.

9. Obligation to provide data

Name, email address and password are required for a user account. Without them, no account can be created.

For a tournament registration, the details required by the organiser are necessary; without them, participation is not possible. All other details — phone number, date of birth, profile picture, nationality — are voluntary.

10. No automated decision-making

Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place. Assignment to age and performance classes follows the rules of the respective federation and is the responsibility of the competition management.

11. Security

We take technical and organisational measures to protect your data, including encrypted transmission (TLS version 1.2 or higher), a tiered role and permission model, access restrictions at database level and regular backups. We provide an overview to organisers on request.

12. Changes to this policy

We adapt this policy when processing changes. The version published here at any given time is the applicable one.