Privacy Policy
Privacy Policy
Sports Evolution Bay o.z.
Version: 2.0 | Effective from: 1 July 2026
1. Controller
The controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (GDPR) is:
| Item | Value |
|---|---|
| Name | Sports Evolution Bay o.z. |
| Legal form | civic association under Act No. 83/1990 Coll. |
| Registered seat | Čajkovského 6332/44, 917 08 Trnava, Slovakia |
| ID No. | 57541591 |
| Statutory body | Chair – acts individually on behalf of the association |
| Contact e-mail | hello@sportsevolutionbay.org |
| Data protection e-mail | gdpr@sportsevolutionbay.org |
| Website | www.sportsevolutionbay.org |
Sports Evolution Bay o.z. (the "controller" or the "association") processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and with Act No. 18/2018 Coll. on the protection of personal data, as amended.
This Privacy Policy informs visitors of the website and everyone who communicates with the association about how their personal data is processed. The website is primarily presentational in nature.
2. What data we process, for what purpose and for how long
2.1 Website operation and server logs
Data: IP address, browser type, access time, page visited, referrer.
Purpose: ensuring the functionality, security and stability of the website and protecting it against abuse (DDoS, bot attacks).
Legal basis: Article 6(1)(f) GDPR – legitimate interest in the secure operation of the website.
Retention period: up to 6 months in the server logs of our hosting provider (Cloudflare).
2.2 Communication via the contact e-mail
Data: name, e-mail address, message content and any further information you voluntarily share with us.
Purpose: handling your question or request.
Legal basis: Article 6(1)(f) GDPR – legitimate interest in handling correspondence, or Article 6(1)(b) GDPR – pre-contractual steps.
Retention period: 1 year after the end of communication, unless another legal basis for further processing arises.
2.3 Contact form on the website (Formspree)
Data: name, e-mail address, message content and any further data entered in the form.
Purpose: receiving and handling enquiries submitted through the contact form on the website.
Legal basis: Article 6(1)(f) GDPR – legitimate interest in handling correspondence; or Article 6(1)(b) GDPR – pre-contractual steps, where the enquiry is aimed at entering into a contractual relationship.
Retention period: submissions are delivered to the association's e-mail via Formspree; they are stored within Formspree only for as long as strictly necessary for delivery and technical processing. After that, the retention period under section 2.2 applies.
The form is technically processed by Formspree (USA) – see section 3.2 and section 4.
2.4 Registration and contact forms (Tally)
Data: depending on the specific form (typically first name, surname, e-mail address and any additional details related to the registration or enquiry).
Purpose: collecting registrations and enquiries for the association's activities (sports programmes, events, educational programmes, registration of applicants).
Legal basis: Article 6(1)(b) GDPR – performance of a contract or pre-contractual steps; or Article 6(1)(a) GDPR – consent, where the form explicitly asks for it.
Retention period: for as long as the purpose lasts (registration, event), followed by 5 years to cover any potential limitation of claims; where consent is the basis, until it is withdrawn.
Forms are technically operated through Tally (Tally NV, Belgium) – see section 3 below.
2.5 Photographs and videos from public events of the association
Data: image and audio recordings from events at which the association acts as organiser or co-organiser.
Purpose: documenting the association's activities and promoting them in annual reports, on the website and on social media.
Legal basis: for reporting and documentary footage from public events, Article 6(1)(f) GDPR and Section 12(2) and (3) of the Slovak Civil Code; for identified portrait photographs, Article 6(1)(a) GDPR – consent.
Retention period: 10 years for documentary purposes; where consent is the basis, until it is withdrawn. Following an objection under Article 21 GDPR we will remove the photograph without undue delay.
2.6 Compliance with legal obligations
Data: to the extent required by law (registration of the association with the Ministry of the Interior of the Slovak Republic, accounting and tax records, 2% tax assignment).
Purpose: compliance with obligations owed to public authorities.
Legal basis: Article 6(1)(c) GDPR – legal obligation (Act No. 83/1990 Coll., Act No. 431/2002 Coll., Act No. 595/2003 Coll.).
Retention period: 10 years for accounting records (Section 35 of Act No. 431/2002 Coll.); other records as required by law.
2.7 Traffic measurement
The website does not use any traffic-measurement or analytics tools (Google Analytics, Matomo, Cloudflare Web Analytics and similar are not deployed). Only operational server logs described in section 2.1 are processed.
3. Who we share your data with
We do not share your personal data with third parties for commercial purposes. We work with the following trusted providers (processors under Article 28 GDPR):
3.1 Hosting and infrastructure
Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.
Purpose: website hosting (Cloudflare Pages), CDN, DNS, TLS certificates and protection against automated attacks.
Contract: Cloudflare Customer Data Processing Addendum, available at https://www.cloudflare.com/cloudflare-customer-dpa/
Sub-processors: the current list is published at https://www.cloudflare.com/gdpr/subprocessors/
Cloudflare, Inc. is based in the USA – see section 4.
3.2 Form services
Tally NV, Outer Ring Brussels 4, 1090 Jette, Belgium.
Purpose: technical processing of submitted forms and temporary storage of responses.
Contract: Data Processing Agreement available at https://tally.so/help/data-processing-agreement
Form responses may then be stored in a downstream system – we will list the specific provider here once selected: [TO BE ADDED – e.g. Google Sheets, Airtable, Notion, own database].
Formspree (USA) – contact form on the website.
Purpose: technical processing and delivery of submitted contact forms to the association's e-mail.
Contract: Data Processing Agreement available at https://formspree.io/legal/
Data location: Amazon Web Services infrastructure in the USA – see section 4.
[TO BE ADDED – exact corporate name and registered seat of Formspree per their DPA.]
3.3 Other recipients
- The association's accountant or accounting firm – to the extent necessary for bookkeeping.
- Public authorities (Ministry of the Interior of the Slovak Republic, the Slovak Financial Administration, the Office for Personal Data Protection of the Slovak Republic, courts, law-enforcement authorities) – to the extent required by law.
4. Transfers of data outside the European Union
Some of our processors are based in the USA. As a result, personal data (in particular IP addresses, technical identifiers and data submitted via the contact form) is transferred to the United States of America.
4.1 Cloudflare, Inc. (hosting, CDN)
Data transferred: IP address, technical identifiers, server log data.
Safeguards: Cloudflare, Inc. is a certified participant in the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection). In addition, the Cloudflare Customer DPA incorporates the Standard Contractual Clauses (SCCs) adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
4.2 Formspree (contact form)
Data transferred: name, e-mail address, message content, sender IP address.
Safeguards: the Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914. Framework list available at https://www.dataprivacyframework.gov/list.
4.3 Tally NV
Tally NV is based in Belgium (EU). No transfer to third countries occurs in connection with this service.
The current list of entities certified under the EU–US Data Privacy Framework is available at https://www.dataprivacyframework.gov/list.
A copy of the safeguards in place will be provided on request sent to the e-mail address in section 1.
5. Your rights
Under Articles 15 to 22 GDPR you have the right:
- to access your personal data (Article 15)
- to rectification of inaccurate data (Article 16)
- to erasure ("right to be forgotten", Article 17)
- to restriction of processing (Article 18)
- to data portability (Article 20)
- to object to processing based on legitimate interest (Article 21)
- not to be subject to automated decision-making (Article 22)
- to withdraw consent at any time (Article 7(3)) – withdrawal does not affect the lawfulness of processing before it was withdrawn
You can submit a request by e-mail to the address listed in section 1, or by post to the association's registered seat. We will respond within one month in line with Article 12(3) GDPR; in complex cases the period may be extended by a further two months, and we will let you know if this happens.
6. Right to lodge a complaint
If you believe that we are processing your data in breach of the law, you have the right to lodge a complaint with the supervisory authority:
Office for Personal Data Protection of the Slovak Republic
Hraničná 12, 820 07 Bratislava 27, Slovakia
E-mail: statny.dozor@pdp.gov.sk
7. Data security
We apply appropriate technical and organisational measures under Article 32 GDPR, including encrypted transmission (HTTPS/TLS), access-rights management and regular system updates. Our processors (Cloudflare, Formspree, Tally) commit to protecting data in transit and at rest and safeguarding it against unauthorised access.
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, we will notify the Office for Personal Data Protection of the Slovak Republic without undue delay, at the latest within 72 hours (Article 33 GDPR), and, where the risk is high, we will also inform the affected data subjects (Article 34 GDPR).
8. Automated decision-making and profiling
The association does not carry out automated decision-making with legal effects for data subjects, nor profiling within the meaning of Article 22 GDPR.
9. Changes to this Policy
The association may update this Policy from time to time. The current version is always published on the website with the effective date. We will inform data subjects of any material changes in an appropriate way (e-mail, notice on the website).
This Policy takes effect on 1 July 2026 and replaces any previous version.