Privacy Notice — Personal Data Processing
Issued pursuant to arts. 13 and 14 of Regulation (EU) 2016/679 ("GDPR") — Strongers Events Portal, events.strongers.org
Version: privacy-v2-2026-07-29 · Last updated: 29 July 2026 · Controller: Strongers Social Club ETS
1. Data Controller
The Data Controller is:
Strongers Social Club ETS Via Ruggero Fiore 38, 00136 Roma Tax code (Codice Fiscale): 96564050589 — VAT no.: 17380961007 Registered in RUNTS (Order no. Rep. 122206 of 30 October 2023, section "Other Third Sector Entities") Email: privacy@strongers.org — PEC: strongersc@pec.it
2. Data Protection Contact
Strongers Social Club ETS is not subject to the obligation to appoint a Data Protection Officer (DPO) under art. 37 GDPR and has not appointed one. The point of contact for all data protection enquiries is the Controller, in the person of the President pro tempore, reachable at:
Email: privacy@strongers.org — PEC: strongersc@pec.it
3. Categories of Personal Data Processed
Depending on the event, the sport discipline and the role of the data subject, the Controller may process:
- identification and personal details: first name, last name, date and place of birth, sex/sport category;
- contact data: email, phone number, and optionally postal address;
- sport data: discipline, race category, bib number, club or sport group, membership/licence where required, times, rankings, penalties, participation status;
- health data (special category, art. 9 GDPR): medical certificate of sport fitness required for participation;
- image: photographs, video footage and audiovisual recordings depicting the participant during the event;
- tax code and date/place of birth solely for registration via the ENDU platform: collected exclusively for relay-format registrations under a single registrant, and only if the data subject grants the relevant mandate (see §4.10);
- payment data: amount, status and transaction identifier, payment method within the limits communicated by the provider, reconciliation data (full card data are neither processed nor stored by the Controller);
- data of the parent or legal guardian for the participation of minors (see §4.6 and §9);
- technical and log data: IP address, timestamp of operations, user agent, technical identifiers, selected language, version and hash of the texts (privacy notice, rules, authorisations) displayed, status of optional consents.
4. Purposes of Processing, Legal Bases and Retention
4.1 Management of Registration and Participation
Data: personal details, contact data, race category, discipline, bib number, qualifications, club/group if provided, event data. Purpose: manage registration, verify requirements, organise the competition, assign bib numbers and categories, send service communications, handle changes, withdrawals, substitutions and refunds. Legal basis: art. 6.1.b GDPR (contract/pre-contractual measures). Provision: mandatory — without the necessary data it is not possible to register or participate.
4.2 Acceptance of the Rules
Data: acceptance declaration, event identifier, version/hash of the text, timestamp. Purpose: make registration conditional on acceptance of the participation conditions. Legal basis: art. 6.1.b GDPR. Provision: mandatory.
4.3 Medical Certificate of Sport Fitness (health data — art. 9)
Data: medical certificate of competitive or non-competitive sport fitness in accordance with applicable regulations. May contain health data (art. 9 GDPR). Purpose: verify and document physical fitness and comply with health protection obligations for sporting activities (including Ministerial Decree of 18/2/1982 for competitive sport, Ministerial Decree of 24/4/2013, Ministerial Decree of 8/8/2014 for non-competitive sport, and applicable rules).
Legal basis: art. 6.1.c GDPR (legal obligation, where certification is required) + art. 9.2.h GDPR (purposes of medicine/assessment of sport fitness by authorised health professionals) and, where applicable, art. 9.2.g (public interest in sporting health protection). The certificate is a statutory requirement: the processing is NOT based on consent and is NOT revocable; at registration the data subject (or the parent/guardian for minors) simply acknowledges this.
Strongers does not carry out diagnoses or clinical assessments: it only verifies the presence, formal validity and relevance of the certificate. Medical reports, ECGs, case histories, prescriptions or clinical records must not be uploaded; if uploaded in error, Strongers will request their replacement and delete the excess data. The certificate is stored in a restricted, non-public area, accessible only to authorised persons. Provision: mandatory for events/disciplines that require it. Retention: as a rule up to 5 years from the conclusion of the event (aligned with the limitation period for tort liability, art. 2947 of the Italian Civil Code), unless otherwise required by law, sport regulations, insurance requirements or litigation.
Reuse and access. The certificate is linked to the data subject's athlete profile and may cover several registrations while it remains valid: it does not have to be uploaded for every race. Only the data subject and, for minors, whoever holds parental responsibility may access it; authorised staff consult it solely to verify eligibility. Whoever purchased or completed the registration on the data subject's behalf — the team captain, for example — cannot view or download it. For minors no reusable athlete profile is created.
4.4 Publication of Start Lists, Rankings and Results
Data: full name and surname, bib number, club/group if provided, category, discipline, times, rankings, penalties, participation status. Purpose: prepare and publish official start lists, rankings and results; ensure sporting transparency and fairness; document and archive the event.
Legal basis (cumulative): art. 6.1.b GDPR (performance of contract, where publication of name and result is necessary for the competition and ranking) and art. 6.1.f GDPR — legitimate interest of the Controller in documentation, transparency and maintenance of the sports archive, as recorded in the Legitimate Interest Assessment (LIA) held on file.
Right to object and anonymisation. The data subject (or the parent/guardian for minors) may object to processing based on legitimate interest (art. 21 GDPR) and request anonymisation of their name in results published by Strongers, on legitimate grounds relating to their particular situation, by writing to privacy@strongers.org. If the request is upheld, the full name is replaced by an anonymised form or technical identifier on pages and archives under the Controller's control. Anonymisation cannot be guaranteed for printed materials, cached copies, third-party copies, screenshots or publications by independent third parties (federations, sport bodies, results platforms, timekeepers). Retention: sports archive with no predetermined term, subject to an upheld anonymisation request or different obligations.
4.5 Publication of the Minor's Name
For minors, publication of the full name in start lists and results takes place in the context of participation authorised by the parent/guardian, on the same cumulative basis (art. 6.1.b + 6.1.f), with balancing conducted with enhanced caution (Recital 38 GDPR; LIA on file). The parent/guardian authorises the registration, acknowledges publication of the minor's full name and is informed of the right to request anonymisation as set out in §4.4.
4.6 Parental Authorisation for a Minor's Registration
Data: first name, last name and contact details of the parent/guardian, relationship to the minor, statement of entitlement, authorisations given on behalf of the minor. Purpose: collect and document authorisation for registration and manage the minor's participation. Legal basis: art. 6.1.b GDPR in conjunction with art. 8 GDPR and with the provisions on parental responsibility (arts. 316 and 320 of the Italian Civil Code). Provision: mandatory for minors. Retention: duration of the event and then up to 10 years, to document the legitimacy of participation.
4.7 Photographic and Video Documentation (Image)
Data: images, photos, videos and recordings depicting the participant during the event. Purpose: document the event and communicate/promote the institutional activities of Strongers Social Club ETS on strongers.org, events.strongers.org, official social media channels and institutional materials. Legal basis: art. 6.1.a GDPR — consent (for minors: consent/authorisation of the parent or guardian — dedicated consent), also taking into account arts. 10 of the Italian Civil Code and 96-97 of Law 633/1941 (Italian copyright law).
Consent is optional, with a default-off setting (default OFF), and may be withheld without any consequence for registration or participation. Images are not transferred to third parties for independent commercial campaigns or used for profiling. Withdrawal: at any time (privacy@strongers.org or tools in the personal area), with prospective effect; Strongers will not make further use of material under its control, but cannot guarantee removal of materials already printed, distributed, republished by third parties or cached. For minors, the use of recognisable images requires specific authorisation from the parent/guardian (dedicated consent, default OFF); panoramic or group images in which the individual is not the main subject are excluded. Retention: until withdrawal of consent for future uses.
4.8 Tax, Accounting and Administrative Obligations
Data: personal details, tax code, fiscal data, payments, receipts, invoices, refunds, fees/donations where applicable. Purpose: issue and retain receipts/invoices, accounting management, compliance with civil and tax obligations. Legal basis: art. 6.1.c GDPR (legal obligations). Retention: 10 years from the accounting entry or for the different statutory period.
4.9 Payments
Data: amount, status, transaction identifier, date/time, payment method within the limits communicated by the provider, reconciliation data. Purpose: manage payment of the registration fee, any donations and related services, refunds/chargebacks. Legal basis: art. 6.1.b GDPR and art. 6.1.c for accounting/tax obligations. Strongers does not store full card data. Payments in the Strongers ecosystem are processed through the strongers.org circuit/edge; providers act, as the case may be, as processors or independent controllers. Retention: time necessary for the transaction and, for accounting data, up to 10 years.
4.10 Registration via the ENDU Platform under Mandate (relay only)
When this applies: exclusively for relay-format registrations under a single registrant, where the data subject requests Strongers to carry out registration on the ENDU platform. For all other formats athletes register on ENDU independently and this processing does not take place. Data communicated to ENDU: tax code and date/place of birth only, solely for the purpose of registration. Purpose: execute the mandate. In this processing Strongers acts as agent/intermediary of the data subject for the transmission of the minimum data; ENDU processes the data as an independent controller for the management of registration on its own platform, in accordance with its own privacy policy. Legal basis: art. 6.1.b GDPR (service requested by the data subject). Minimisation (art. 5.1.c): the tax code is collected only if the data subject grants the mandate. Provision: optional as a precondition; if the mandate is granted, tax code and date/place of birth are required.
(Feature currently deactivated; it will be active only for relay events that provide for ENDU registration, with a link to ENDU's privacy policy.)
4.11 Strongers Newsletter
The portal may display a link to the Strongers newsletter. Newsletter subscription does NOT take place through the event registration form, but via a separate (single opt-in) flow managed on strongers.org, with a dedicated notice and consent. Non-subscription has no effect on event registration/participation. Legal basis: art. 6.1.a GDPR (consent), withdrawable at any time.
4.12 Technical Data, Logs and Proof of Operations (Accountability)
Data: IP, timestamp, user agent, technical identifiers, application logs, language, version/hash of texts displayed, declarations and consents given, event identifier. Purpose: portal operation and security, abuse prevention, demonstration of the correct collection of declarations, authorisations and consents (accountability, art. 5.2 GDPR), internal audits. Legal basis: art. 6.1.f GDPR (legitimate interest in security and compliance). Retention: technical/security logs as a rule up to 12 months; proof of declarations/consents as a rule up to 10 years, subject to litigation.
4.13 Cookies and Similar Tools
The portal may use technical cookies necessary for operation and, where provided, measurement tools or third-party services. Details in the Cookie Policy. The use of non-technical cookies or tools occurs, when required, only upon prior consent of the user.
5. Mandatory or Optional Nature of Data Provision
| Processing | Nature | Consequence of refusal |
|---|---|---|
| Registration and participation (§4.1) | Mandatory | Impossible to register/participate |
| Acceptance of Rules (§4.2) | Mandatory | Impossible to complete registration |
| Medical certificate (§4.3) | Mandatory by law; not consent-based, not withdrawable | Impossible to participate |
| Name in rankings (§4.4–4.5) | Necessary/legitimate interest; not consent-based. Right to object/anonymisation | No preclusion; case-by-case assessment |
| Parental authorisation (§4.6) | Mandatory for minors | Impossible to register the minor |
| Photos/videos (§4.7) | Optional (consent, default OFF) | No consequence |
| Tax obligations (§4.8) | Mandatory where applicable | Impossible to issue tax documents |
| ENDU mandate (§4.10) | Optional as a precondition | Without mandate ENDU registration is not performed; no collection of tax code |
| Newsletter (§4.11) | Optional, separate flow | No consequence |
6. Source of Data
Data are as a rule provided directly by the data subject (art. 13 GDPR). In some cases they are provided by a third party managing registration on behalf of the participant (art. 14 GDPR): in team/relay registrations (the registrant provides data of the members) and for minors (data provided by the parent/guardian). Anyone registering third parties is required to inform them of this processing.
7. Retention Periods (Summary)
| Purpose | Retention |
|---|---|
| Registration and participation | Duration of event and, for essential administrative data, up to 10 years, subject to litigation |
| Operational event data | Up to 24 months, except data incorporated into rankings/archives/accounting |
| Medical certificate | As a rule 5 years from the conclusion of the event (art. 2947 of the Italian Civil Code), unless otherwise required |
| Start lists, rankings, results | Sports archive with no predetermined term, subject to an upheld anonymisation request |
| Photos and videos | Until withdrawal of consent for future uses |
| Parental authorisations | Duration of event and then up to 10 years |
| Tax code for ENDU mandate | For the time necessary to prove the mandate/execution, subject to different obligations |
| Tax and accounting data | 10 years from the accounting entry |
| Payment data | Duration of transaction and, for accounting data, up to 10 years |
| Technical and security logs | As a rule 12 months |
| Proof of declarations and consents | As a rule up to 10 years |
Upon expiry, data are deleted, anonymised or aggregated, unless retention is necessary for legal obligations, defence of rights or compatible statistical/archival purposes.
8. Recipients of Data
- authorised personnel of Strongers Social Club ETS, within the limits of their functions;
- IT service providers (hosting, maintenance, security, transactional email, storage and portal management) — generally data processors under art. 28 GDPR;
- other components of the Strongers technical ecosystem (identity services and org portal), within the limits necessary for accounts, authentication and payments — processors or, where acting for their own purposes, independent controllers;
- payment providers — processors or independent controllers as the case may be;
- timing, results and results-platform providers — often independent controllers;
- the ENDU platform — limited to the relay registration mandate (§4.10), as an independent controller for the management of registration on its own platform;
- federations, sport promotion bodies, organising committees, race officials — where necessary, generally as independent controllers;
- tax, administrative, legal or technical advisors, within the scope of their respective engagements;
- public authorities and judicial/administrative authorities, when required by law.
Entities that process data on behalf of Strongers are appointed as processors under art. 28 GDPR; at present there are no additional internal staff with data access beyond the authorised personnel indicated above. The updated list of appointed processors is available on request at privacy@strongers.org. Data are not sold or transferred to third parties for independent commercial purposes.
9. Minors
Participation by minors is permitted only upon authorisation of the parent or legal guardian (arts. 316 and 320 of the Italian Civil Code; art. 8 GDPR). Majority of age is calculated as at the date of the event. For minors: registration is authorised by the parent/guardian (§4.6); the medical certificate is uploaded/confirmed by the parent/guardian (acknowledgement, statutory requirement); publication of the name occurs on the basis of 6.1.b+6.1.f with acknowledgement and right to anonymisation (§4.5); the use of recognisable images requires dedicated consent from the parent/guardian (default OFF); no additional data (contacts, residence, school, family relationships) are published beyond those necessary for the ranking.
10. Transfers to Third Countries
Data are processed predominantly within the European Union. Some providers or platforms (technical services, email, payments, social media, content publication) may involve transfers outside the EU or access from outside the EU: in such cases the transfer takes place only on the basis of one of the safeguards set out in arts. 44–49 GDPR (adequacy decision, standard contractual clauses, supplementary measures or other permitted instruments). Publication of images/content on official social media channels is subject to the respective platforms' privacy policies.
11. Rights of the Data Subject (arts. 15–22 GDPR)
The data subject has the right to: access their data (art. 15); request rectification (art. 16); erasure in the cases provided for (art. 17); restriction (art. 18); portability in the cases provided for (art. 20); object, on grounds relating to their particular situation, to processing based on legitimate interest (art. 21), including publication of their name in the ranking with anonymisation upon reasoned request; withdraw consents given at any time (photos/videos, newsletter), without prejudice to the lawfulness of prior processing.
Withdrawal of consent applies only to consent-based processing and does not apply to processing necessary for registration, statutory health protection obligations in sport (medical certificate), tax obligations or documentation for the protection of the Controller's rights.
To exercise rights: privacy@strongers.org — PEC strongersc@pec.it. Strongers may request information to verify the identity of the requester.
12. Right to Lodge a Complaint
The data subject has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali — www.garanteprivacy.it) if they consider that processing is taking place in breach of applicable law.
13. Absence of Automated Decision-Making and Profiling
Data are not subject to automated decision-making, including profiling, which produces legal effects or similarly significantly affects the data subject (art. 22 GDPR).
14. Security Measures
Strongers implements appropriate technical and organisational measures, with particular attention to medical certificates and confidential data: restriction of access to authorised persons only, authentication, storage of certificates in non-public areas, data minimisation, reasonable measures against unauthorised access, loss, alteration or unlawful disclosure.
15. Changes to This Notice
This notice may be updated to reflect regulatory, technical, organisational or event-related changes. In the event of material changes, Strongers will provide notice via events.strongers.org or other appropriate channels.
Version: privacy-v2-2026-07-29 — Last updated: 29 July 2026 · Strongers Social Club ETS — privacy@strongers.org — strongersc@pec.it