FADP transparency

Data protection notice

This notice explains which personal data RallyCore processes for Critérium Jurassien, why it is used, who may receive it and how long it is retained.

Version: 2026-08-28 — effective 2026-08-28

Controller

Critérium Jurassien
Case Postale 265, 2800 Delémont, Suisse
info@criterium-jurassien.ch

To exercise your rights or ask a question about your data:

info@criterium-jurassien.ch

1. Data processed

We only process information needed to operate the portal and organize the event. Depending on your role and the features used, this may include:

2. Purposes

Data is used to receive and review registrations, verify eligibility, organize event resources, provide personal areas, communicate with participants, manage payments, publish authorized official information, protect the system and establish or defend legal claims. Optional features such as Push notifications can be disabled.

3. Source and necessity

Data mainly comes from you or from a person legitimately registering a crew, and from authorized organizers reviewing the case. Required fields are necessary for processing or security; without them, the case may not be processed. RallyCore does not buy personal-data lists.

4. Recipients and providers

Access is restricted by role to authorized Critérium Jurassien personnel. Where necessary, data may be shared with sporting bodies, officials, timekeepers, insurers, safety services or relevant logistics providers. Hosting is currently provided by Infomaniak in Switzerland. Email delivery uses the SMTP service configured by the organization, which must be recorded in its provider register. Data is not sold or used for targeted advertising.

5. Push notifications and foreign transfers

In the audited configuration, the core service is hosted in Switzerland. The location of the configured SMTP service must be verified in the provider register. If you enable Push notifications, your browser or device provider may route them from abroad under its own terms; only technical information necessary for delivery is sent. Any transfer must rely on adequate protection or appropriate safeguards.

6. Cookies and local storage

The audited version only uses cookies and storage required for sessions, CSRF protection, authentication and technical preferences. They are not used for advertising or profiling. Session cookies are protected by HTTPS and the Secure attribute. Any future non-essential analytics must be announced and, where required, enabled only after your choice.

7. Your rights

You may ask whether we process data about you, obtain the information required by the FADP, correct inaccurate data or request deletion when there is no longer a reason to retain it. You may object to optional processing where applicable. Send your request by email or post to the controller above. Proportionate identity verification may be required. We normally respond within 30 days. You may also contact the Federal Data Protection and Information Commissioner (FDPIC).

8. Security and breaches

Technical and organizational measures protect data, including HTTPS, secure cookies, role-based access, private document storage, backups and security checks. No system can provide absolute security. A breach likely to create a high risk is assessed and reported in accordance with applicable requirements.

9. Changes

The version and effective date appear at the top. A new version will be published before material changes to purposes, recipients or technologies. The version shown for a new registration is recorded with the case without presenting that information as consent to necessary processing.

Retention periods

Periods normally run from the end of the relevant edition. A legal duty, proceeding or documented legal hold may justify longer retention.

Data Target period Final action
Sporting IDs, licences, vehicle documents, PDFs and private documents 12 months Delete files and records
Messages, checks, logistics, commissioners and staff 24 months Delete; minimize competitor data
Minimal competitor financial evidence up to 10 years Delete at accounting expiry
Participant accounts without an active case Review after 24 months Delete after role review
Stored notifications 12 months Delete
Imports, exports and error data 30 days Delete files and records
Inactive sessions 30 days Delete
Password-reset tokens 24 hours Delete
Disabled Push subscriptions or ended edition 90 days Delete subscription and keys
Rotating application logs 90 days Delete; separate security/audit logs: 12 months
Local deployment backups 90 days Delete after manual review
Provider backups and email logs Verified contract period Confirm rotation and deletion with provider