FISSI REGS · PRIVACY

PRIVACY AND REGISTRY NOTICE

This combined privacy and registry notice explains how FISSI Regs processes personal data relating to athletes, coaches, managers and other users in connection with user accounts, race registrations, payments and service administration.

Updated: 2026-08-22

1. Data Controller

AI Sport Solutions (AISS)

Business ID: 3193654-9

Vantaa, Finland

Email: info@fissi.fi

Registry matters: info@fissi.fi

Phone: +358 40 465 8788

2. Register Name and Contact

The name of the register is the user register of the online service.

Questions related to privacy and personal data can be sent to the controller at info@fissi.fi.

3. Purposes of Processing

  • creating user accounts, identifying users, managing access rights and maintaining accounts
  • receiving, managing, confirming and cancelling race registrations
  • managing athletes, coaches, managers and groups in the service
  • handling payments for paid registrations and tracking payment transactions
  • ensuring service security, logging, abuse prevention and technical maintenance
  • communicating with users, for example in verification, login and password reset situations

4. Legal Bases for Processing

  • performance of a contract or steps taken before entering into a contract when a user creates an account, participates in a test event or registers for a race
  • legitimate interests of the controller in operating, securing, logging and developing the service
  • legal obligations, for example in relation to payment and accounting records
  • consent where processing is specifically based on consent

5. Personal Data Processed

  • name, username, email address, phone number, club and role
  • athlete data such as birth year or date of birth, nationality, FIS code or SHLID code, club and gender when relevant for the event
  • registration and event data such as race or test event, discipline, timing, status, verification details, cancellations and group information
  • payment-related data such as payment service provider, payment status, transaction identifier and the contact email linked to the registration
  • the password created by the user in strongly encrypted form, the registration date, and IP address or other identifiers such as the latest login
  • technical data related to sessions, logins, audit logs and service protection

6. Regular Sources of Data

Data is mainly obtained from the data subject, the athlete's coach or manager, the controller's customer or partner organisation, and from data generated while using the service.

Some athlete details may also be retrieved from public sources such as sports federations or results services when used to support registrations, verify information or identify results.

7. Recipients and Disclosures

Personal data is processed only by persons and parties who need access based on their role or duties.

  • the controller's authorised administrators and technical support
  • designated users involved in event operations, such as coaches, managers and administrators, to the extent necessary for organising the event
  • payment service providers Paytrail and Stripe for payment processing
  • hosting, maintenance and possible email service providers acting on behalf of the controller

Data is not disclosed for external marketing purposes. Participant information related to an event or test event may be shown to those users who need it for the operation of the service or under the applicable event rules.

8. Transfers Outside the EEA

As a rule, personal data is not transferred outside the EU or EEA. If a service provider processes data outside the EEA, the controller will ensure that an appropriate legal basis and safeguards are in place for the transfer.

9. Retention Periods

  • user account data is retained while the account is active and for no longer than 24 months after the latest login or other latest activity, unless longer retention is required by law, security needs or an investigation request
  • race registration and test-event data is retained for the time needed to organise the event, report results and handle possible follow-up issues
  • payment and accounting data is retained for the period required by applicable accounting and tax laws
  • log and audit information is retained only for as long as needed to protect the service, investigate incidents or prevent misuse

10. Security and Cookies

Personal data is stored in electronically protected systems. Access rights are limited to persons who need the data for their work duties.

The service uses access control, password protection, technical logging and other organisational and technical safeguards to protect personal data. The service uses necessary session and functional cookies to support login, language selection and secure operation.

11. Rights of the Data Subject

  • the right to know whether personal data is being processed and to access personal data
  • the right to request rectification of inaccurate or incomplete data
  • the right to request erasure or restriction of processing where the legal conditions are met
  • the right to object to processing based on legitimate interests
  • the right to lodge a complaint with a supervisory authority

Requests related to these rights can be sent to info@fissi.fi or fissi@fissi.fi. The controller may request additional information to verify identity before responding.

12. Supervisory Authority

Office of the Data Protection Ombudsman

Lintulahdenkuja 4, FI-00530 Helsinki, Finland

P.O. Box 800, FI-00531 Helsinki, Finland

Email: tietosuoja@om.fi

Phone: +358 29 566 6700

Registry office: +358 29 566 6768

13. Automated Decision-Making, Profiling and Updates

The service does not make legally significant decisions about a data subject based solely on automated decision-making, and personal data is not used for profiling for such purposes.

This notice may be updated when the service, personal data processing or legal requirements change. The current version is published on this page and in the PDF generated from the same source data.