Privacy policy

This is a translation for convenience. The German version is the legally binding one.

Controller

Thomas Dylla
Herbststraße 29
01139 Dresden
Germany
Email: thomas.dylla@mg-airsports.de

No data protection officer has been appointed, and none is required under Art. 37 GDPR in conjunction with § 38 BDSG: only one person is permanently concerned with the processing. Enquiries go to the address given above.

What we process, and why

When visiting the site

The web server records technically necessary details: IP address, time, the address requested, the volume of data transferred and the browser identification. The basis is the legitimate interest in secure operation (Art. 6(1)(f) GDPR). These logs are deleted after seven days.

The site sets no cookies for statistics or advertising and embeds no external services, no fonts from third-party servers and no third-party map services. A session cookie is only created when you log in to an account.

With a user account

Username, email address, encrypted password, the time of registration and of the last login. The basis is performance of the usage relationship (Art. 6(1)(b) GDPR).

With the pilot profile

Every account has a pilot profile. Processed are first name, surname, email address, date of birth, gender, country, state or region, club, regional association, FAI licence and, if desired, the transmitter frequencies used.

The date of birth is needed for age categories (juniors, seniors). The age category itself is calculated and not stored. Publicly visible in participant lists are only name, club, country and class — not the date of birth, not the address.

When entering a competition

Stored are the classes chosen, team, caller and supervisor, payment status, position and list status, and the answers to the organiser's additional questions. If an organiser requires proof — such as a licence, insurance or parental consent — those files are held in an area that is not publicly accessible and can only be retrieved by the administration and by the organiser of the competition concerned.

The basis is performance of the entry relationship (Art. 6(1)(b) GDPR), supplemented by consent (Art. 6(1)(a) GDPR), which is given in the first step of the entry — both with an account and without one.

With entries made for other people

Anyone entering another person — a parent for a child, say, or a club for a member — is recorded as managing that person. For this it is stored which account may act for which person, and whether the person or their guardian agreed to it.

When creating a person without an account of their own, whoever enters them declares that they are entitled to do so and that they have informed the person or their legal guardians. This declaration is stored against the person with its time and with the account of the person declaring.

Consent: what exactly is stored

Wherever this site requires consent, it is recorded so that it can be demonstrated. Three details are stored:

  • The time — date and time of the agreement.
  • The version of the consent text, as a date. Without it one would know that somebody consented, but not to what; if the wording changes, the version increases.
  • For details about other people, additionally who made the declaration.

This concerns these places:

  • Entering a competition — against the entry.
  • Creating an account, at registration and when accepting an organiser invitation — against the account.
  • Feedback through the form — against the feedback.
  • Creating a person without an account of their own — against that person.

Consent can be withdrawn at any time, for the future and without giving reasons — through the feedback form or the address given below. Withdrawal leads to the deletion of the data concerned, unless a retention obligation stands in the way. Entries that, before the withdrawal, belonged to a competition that has already started are kept so that the results remain traceable.

Accounts from the old site carry no record of consent: they were taken over before such a record existed. Their basis is the continuation of the existing usage relationship; at the first entry to a competition, consent is given and stored from then on.

Who sees the data

  • The organiser of the competition an entry belongs to, and the deputies they have registered: they see the entry data of their own competition, not that of other competitions.
  • The site's administration, as far as necessary for operation and fault-finding.
  • Scoring programs: organisers can output start lists as a file. Such an output link has a time limit, is logged, and names at set-up which personal columns it contains.
  • Public are participant lists with name, club, country and class, provided the organiser makes the list public. They can also restrict it to logged-in users or hide it entirely.

Hosting

The site runs on a rented server from STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin. The servers are located in Germany. STRATO processes the data solely on instruction and on our behalf; a data processing agreement under Art. 28 GDPR is in place for this.

No transfer to countries outside the European Union takes place from this site. The only exception is described in the following section, and it only arises if you click a payment link yourself.

Payment: bank transfer and PayPal

This site does not take money. There is no payment process here, no payment account and no payment service provider acting for this site. The entry fee is paid directly to the organiser.

The organiser can give two routes for this, and both appear as their details on the competition page:

  • Bank details — recipient, IBAN, BIC and payment reference. The transfer runs between you, your bank and the organiser. This site learns nothing about it; whether payment was made is entered by the organiser by hand.
  • The organiser's PayPal.Me link — an ordinary link to paypal.com. PayPal is a separate company (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg) and processes your details on its own responsibility, under its own terms and partly outside the European Union.

An important point about the PayPal link, because it is the most common misunderstanding: it is not an embedded payment window and not a script from PayPal. As long as you do not click, nothing is transmitted to PayPal — no IP address, no cookie, no tracking pixel. Only with the click do you leave this site; from then on PayPal's privacy policy applies. In return, this site learns nothing from PayPal: no payment status, no name, no account details. The amount that is already filled in when the page opens comes from the competition's rate and is passed through the link.

Anyone who does not want to use PayPal can make a bank transfer — or ask the organiser for another route. There is no obligation to use PayPal, and it creates no disadvantage when entering.

Emails

The site sends confirmations, notices about moving up from the waiting list, withdrawal confirmations, messages from the organiser to their participants and, on request, a daily report to organisers. A log entry is kept for every send so that it remains traceable whether a message went out. Address and subject are removed from this log after 90 days; the time of sending, the type of message and the outcome remain.

Backups

Backups of the database and files are created daily. They are encrypted before they leave the server (GnuPG, AES-256); only the controller holds the key.

  • On the server at the host, for 14 days.
  • At a second location off the server, so that a failure of the server does not take the backup with it.
  • An encrypted copy of the database additionally goes to a mailbox belonging to the controller. The provider of that mailbox (Google Ireland Ltd., with processing also in the USA) thereby stores ciphertext that it cannot read.

A deletion on request takes effect immediately in the running application. In the backups, data remains until they expire — it is not removed from them individually, because interfering with a backup destroys its purpose. If a backup is restored, a deletion that was granted is carried out again.

How long we store data

  • Account and pilot profile: until deleted by the person or on request.
  • Entries and their change history: three years after the end of the competition. For that long they are needed for rankings across several seasons and for queries about results; after that they are deleted.
  • Proof and attachments to entries (licence, insurance, parental consent): until 31 December of the year in which the competition took place. The proof is needed for participation, and not afterwards.
  • Send log: personal reference for 90 days, anonymised after that.
  • Records of consent (time and version): as long as the data they belong to exists. They are deleted along with it — a record without the data it applies to would itself be surplus.
  • Server logs: seven days.

Your rights

You have the right of access (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object (Art. 21). You can withdraw consent you have given at any time; processing up to the withdrawal remains unaffected.

A lot can be done without an enquiry: profile details can be changed in your own area, an entry can be withdrawn using the link in the confirmation email, and the management of other people can be ended at any time. For access and deletion, a message to thomas.dylla@mg-airsports.de is enough.

You can also lodge a complaint with a supervisory authority. The competent authority is that of the controller's federal state:

Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17
01067 Dresden
www.datenschutz.sachsen.de

Changes

This policy is adapted when the processing changes. Version of 30 July 2026.