1. Introduction
Gran Fondo Bulgaria Ltd. ("we", "us", or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you:
- Visit our website at www.granfondobulgaria.com
- Register for our cycling events
- Subscribe to our newsletters
- Contact us through any channel
- Participate in our events
Please read this Privacy Policy carefully. By using our services, you consent to the collection and use of your personal data as described in this policy.
This policy is designed to comply with the European Union's General Data Protection Regulation (GDPR) and the Bulgarian Personal Data Protection Act.
2. Data Controller
The data controller responsible for your personal data is:
Gran Fondo Bulgaria Ltd.
National Palace of Culture
1 Bulgaria Square
1463 Sofia, Bulgaria
Company Registration: 123456789
VAT Number: BG123456789
Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions, please contact our DPO:
- Email: privacy@granfondobulgaria.com
- Phone: +359 2 987 6543
- Address: 1 Bulgaria Square, 1463 Sofia, Bulgaria
3. Data We Collect
We collect different types of personal data depending on how you interact with us:
3.1 Information You Provide
Registration Data
- Full name (first name and last name)
- Email address
- Phone number
- Postal address
- Date of birth
- Gender
- Nationality
- Cycling club affiliation (if applicable)
Health & Emergency Data
- Emergency contact name and phone number
- Medical conditions relevant to participation
- Allergies or special medical requirements
- Blood type (optional)
Payment Data
- Billing address
- Payment method details
- Transaction history
We do not store your full credit card numbers. All payment processing is handled by our secure payment partners (Stripe, EasyPay) who are PCI-DSS compliant.
3.2 Information Collected Automatically
Technical Data
- IP address
- Browser type and version
- Device type and operating system
- Time zone setting and location
- Pages visited and time spent on our website
Event Data
- Race timing data
- GPS tracking data (during the event)
- Checkpoint times
- Finishing position and time
3.3 Information from Third Parties
- Timing partners (race results)
- Photography partners (event photos)
- Social media platforms (if you connect your account)
- Cycling federations (license verification)
4. Legal Basis for Processing
Under GDPR, we must have a valid legal basis for processing your personal data. We rely on the following legal bases:
Contract Performance
Processing necessary to fulfill our contract with you (e.g., event registration, providing services you requested).
Consent
Where you have given explicit consent for specific processing activities (e.g., marketing emails, photography).
Legal Obligation
Processing necessary to comply with legal requirements (e.g., tax records, health and safety regulations).
Legitimate Interest
Processing necessary for our legitimate business interests, where not overridden by your rights (e.g., fraud prevention, improving services).
Vital Interests
Processing necessary to protect your vital interests or those of another person (e.g., medical emergencies during events).
Special Category Data
Health data is considered 'special category' data under GDPR. We process this data based on:
- Your explicit consent provided during registration
- Vital interests (medical emergencies)
- Legal obligations for event safety
5. How We Use Your Data
5.1 Event Management
- Processing your registration and entry
- Allocating race numbers and timing chips
- Managing start waves and corrals
- Recording and publishing race results
- Issuing finisher certificates and medals
- Coordinating logistics (race packs, refreshments)
5.2 Communication
- Sending registration confirmations
- Providing event updates and important information
- Responding to your inquiries and support requests
- Sending post-event surveys and feedback requests
- Marketing communications (with your consent)
5.3 Safety & Security
- Ensuring participant safety during events
- Emergency response coordination
- Contacting emergency contacts if needed
- Fraud prevention and detection
- Verifying participant identity
5.4 Legal & Administrative
- Processing payments and refunds
- Maintaining financial records for tax purposes
- Complying with legal obligations
- Handling insurance claims
- Resolving disputes
5.5 Improvement & Analytics
- Analyzing participation trends and demographics
- Improving our events and services
- Developing new features and offerings
- Website analytics and performance optimization
6. Data Sharing & Disclosure
We may share your personal data with the following categories of recipients:
6.1 Service Providers
| Provider Type | Purpose | Data Shared |
|---|---|---|
| Payment Processors | Processing payments | Billing details, transaction data |
| Timing Partners | Race timing & results | Name, race number, timing data |
| Photography Partners | Event photography | Race number, name (for photo matching) |
| Email Service Provider | Sending communications | Email address, name |
| Cloud Hosting | Data storage | All registration data |
6.2 Event Partners
- Event sponsors (only aggregated, anonymized data unless you consent otherwise)
- Local authorities (as required for event permits)
- Medical and emergency services (for safety purposes)
- Insurance providers (for claims processing)
6.3 Public Disclosure
The following information may be made publicly available:
- Race results (name, nationality, age category, time, position)
- Event photographs and videos
- Participant lists (name, nationality, race number)
By participating in our events, you consent to the publication of your race results. If you wish to opt out, please contact us before the event.
6.4 Legal Requirements
We may disclose your data when required by law, including:
- Responding to court orders or legal processes
- Cooperating with law enforcement investigations
- Protecting our legal rights
- Complying with regulatory requirements
7. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place:
7.1 Safeguards
- EU adequacy decisions for countries with adequate data protection
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules for transfers within corporate groups
- Certification schemes (e.g., EU-US Data Privacy Framework)
7.2 Countries
We may transfer data to service providers in:
- United States (cloud services, payment processing)
- Other EU/EEA countries (timing partners, sponsors)
You may request a copy of the safeguards used for international transfers by contacting our Data Protection Officer.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Type | Retention Period | Reason |
|---|---|---|
| Registration Data | 7 years after last participation | Legal and tax requirements |
| Race Results | Indefinitely | Historical records, rankings |
| Payment Records | 10 years | Tax and accounting obligations |
| Health Data | 1 year after event | Insurance claims, legal compliance |
| Marketing Preferences | Until consent withdrawn | Your preferences |
| Website Analytics | 26 months | Performance analysis |
After the retention period, we will securely delete or anonymize your data. Anonymized data may be retained for statistical purposes.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or misuse:
9.1 Technical Measures
- SSL/TLS encryption for all data transmissions
- Encrypted data storage
- Secure password hashing
- Regular security updates and patches
- Firewall and intrusion detection systems
- Regular security audits and penetration testing
9.2 Organizational Measures
- Access controls and role-based permissions
- Staff training on data protection
- Confidentiality agreements with employees and contractors
- Data protection impact assessments
- Incident response procedures
9.3 Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours
- Inform affected individuals without undue delay if there is a high risk
- Document the breach and our response
10. Your Rights
Under GDPR, you have the following rights regarding your personal data:
Right of Access
You have the right to obtain confirmation of whether we process your personal data and to request a copy of that data.
Right to Rectification
You have the right to request correction of inaccurate personal data or completion of incomplete data.
Right to Erasure
You have the right to request deletion of your personal data in certain circumstances ("right to be forgotten").
Right to Restriction
You have the right to request restriction of processing of your personal data in certain circumstances.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that significantly affect you.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time.
How to Exercise Your Rights
To exercise any of these rights, please contact our Data Protection Officer:
- Email: privacy@granfondobulgaria.com
- Mail: Data Protection Officer, Gran Fondo Bulgaria Ltd., 1 Bulgaria Square, 1463 Sofia, Bulgaria
We will respond to your request within one month. This period may be extended by two months for complex requests, in which case we will inform you.
Right to Lodge a Complaint
If you believe we have violated your data protection rights, you have the right to lodge a complaint with a supervisory authority. In Bulgaria, this is:
Commission for Personal Data Protection
2 Prof. Tsvetan Lazarov Blvd.
1592 Sofia, Bulgaria
Website: www.cpdp.bg
Email: kzld@cpdp.bg
12. Children's Privacy
Our events are generally intended for participants aged 18 and over, or 16-17 with parental consent.
12.1 Age Requirements
- Participants must be at least 16 years old
- Participants aged 16-17 require written parental/guardian consent
- We do not knowingly collect data from children under 16
12.2 Parental Consent
For participants aged 16-17, a parent or legal guardian must:
- Provide written consent for participation
- Agree to these privacy terms on behalf of the minor
- Serve as the primary contact for communications
If you believe we have collected personal data from a child without appropriate consent, please contact us immediately at privacy@granfondobulgaria.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
13.1 Notification of Changes
When we make changes:
- We will update the "Last Updated" date at the top of this policy
- For significant changes, we will notify you by email or website notice
- We will obtain fresh consent if required for material changes
13.2 Your Continued Use
Your continued use of our services after changes become effective constitutes acceptance of the revised policy. We encourage you to review this policy periodically.
13.3 Previous Versions
Previous versions of this Privacy Policy are available upon request. Please contact our Data Protection Officer.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Protection Officer
Email: privacy@granfondobulgaria.com
Phone: +359 2 987 6543
Address:
Gran Fondo Bulgaria Ltd.
Attn: Data Protection Officer
1 Bulgaria Square
1463 Sofia, Bulgaria
General Inquiries
Email: granfondobulgaria@gmail.com
Phone: +359 2 987 6543
Website: www.granfondobulgaria.com
We aim to respond to all privacy-related inquiries within 5 business days.
Your Privacy Matters
We are committed to protecting your personal data and respecting your privacy rights. If you have any concerns about how we handle your data, please don't hesitate to contact us.
This Privacy Policy is effective as of December 15, 2024.