To exercise your rights or ask a question about your data:
1. Data processed
We only process information needed to operate the portal and organize the event. Depending on your role and the features used, this may include:
- identity, contact details, user account and authentication data;
- registration, sporting licence, crew, vehicle and supporting documents;
- availability and logistics such as transport, accommodation, meals or a special need you disclose;
- messages, administrative decisions, acknowledgements and necessary case history;
- payment amount, status and date, but not full payment-card data;
- technical security data such as IP address, browser, session, error and system logs;
- if you enable Push notifications: subscription identifier, technical keys, browser and selected edition.
2. Purposes
Data is used to receive and review registrations, verify eligibility, organize event resources, provide personal areas, communicate with participants, manage payments, publish authorized official information, protect the system and establish or defend legal claims. Optional features such as Push notifications can be disabled.
3. Source and necessity
Data mainly comes from you or from a person legitimately registering a crew, and from authorized organizers reviewing the case. Required fields are necessary for processing or security; without them, the case may not be processed. RallyCore does not buy personal-data lists.
4. Recipients and providers
Access is restricted by role to authorized Critérium Jurassien personnel. Where necessary, data may be shared with sporting bodies, officials, timekeepers, insurers, safety services or relevant logistics providers. Hosting is currently provided by Infomaniak in Switzerland. Email delivery uses the SMTP service configured by the organization, which must be recorded in its provider register. Data is not sold or used for targeted advertising.
5. Push notifications and foreign transfers
In the audited configuration, the core service is hosted in Switzerland. The location of the configured SMTP service must be verified in the provider register. If you enable Push notifications, your browser or device provider may route them from abroad under its own terms; only technical information necessary for delivery is sent. Any transfer must rely on adequate protection or appropriate safeguards.
6. Cookies and local storage
The audited version only uses cookies and storage required for sessions, CSRF protection, authentication and technical preferences. They are not used for advertising or profiling. Session cookies are protected by HTTPS and the Secure attribute. Any future non-essential analytics must be announced and, where required, enabled only after your choice.
7. Your rights
You may ask whether we process data about you, obtain the information required by the FADP, correct inaccurate data or request deletion when there is no longer a reason to retain it. You may object to optional processing where applicable. Send your request by email or post to the controller above. Proportionate identity verification may be required. We normally respond within 30 days. You may also contact the Federal Data Protection and Information Commissioner (FDPIC).
8. Security and breaches
Technical and organizational measures protect data, including HTTPS, secure cookies, role-based access, private document storage, backups and security checks. No system can provide absolute security. A breach likely to create a high risk is assessed and reported in accordance with applicable requirements.
9. Changes
The version and effective date appear at the top. A new version will be published before material changes to purposes, recipients or technologies. The version shown for a new registration is recorded with the case without presenting that information as consent to necessary processing.
Retention periods
Periods normally run from the end of the relevant edition. A legal duty, proceeding or documented legal hold may justify longer retention.
| Data | Target period | Final action |
|---|---|---|
| Sporting IDs, licences, vehicle documents, PDFs and private documents | 12 months | Delete files and records |
| Messages, checks, logistics, commissioners and staff | 24 months | Delete; minimize competitor data |
| Minimal competitor financial evidence | up to 10 years | Delete at accounting expiry |
| Participant accounts without an active case | Review after 24 months | Delete after role review |
| Stored notifications | 12 months | Delete |
| Imports, exports and error data | 30 days | Delete files and records |
| Inactive sessions | 30 days | Delete |
| Password-reset tokens | 24 hours | Delete |
| Disabled Push subscriptions or ended edition | 90 days | Delete subscription and keys |
| Rotating application logs | 90 days | Delete; separate security/audit logs: 12 months |
| Local deployment backups | 90 days | Delete after manual review |
| Provider backups and email logs | Verified contract period | Confirm rotation and deletion with provider |