Privacy notice for the KLL registration system
This notice explains which personal data are used in the registration system, for which purposes and for how long.
Version: 28 July 20261. Controller
König Ludwig Lauf e. V.Turnerweg 6a · 82487 Oberammergau · Deutschland
Telefon: +49 (0) 8822 3990
E-Mail: office@koenig-ludwig-lauf.com
2. Website operation and security
When the system is accessed, technically necessary connection data such as IP address, time, requested resource, browser information and security events may be processed. This is necessary to deliver and protect the service (Art. 6(1)(f) GDPR).
The service is provided using OpenAI Ireland Limited and its documented infrastructure and hosting subprocessors, including Cloudflare. Where providers process data on our behalf, processing is governed by Art. 28 GDPR. International transfers are made only in accordance with Art. 44 et seq. GDPR, for example on the basis of an adequacy decision or the EU Standard Contractual Clauses.
3. Registration and event delivery
We process the data required for registration and event delivery: identity and contact data, date of birth, address, nationality, selected race, team or club details, sports identifiers where needed, extras, size, registration and bib number, payment status and voluntary messages. Required fields are marked.
The legal basis is performance of the participation contract (Art. 6(1)(b) GDPR), compliance with legal obligations (Art. 6(1)(c) GDPR) and, for security and fraud prevention, our legitimate interests (Art. 6(1)(f) GDPR). The mandatory checkbox records that the privacy information was made available; it is not consent to the contractually necessary processing.
Free-text fields must not be used for diagnoses, ID copies, card details or other particularly sensitive information.
4. KLL account
The KLL account stores profile data and previous registrations to provide secure self-service and reuse of details. Passwords are stored only as salted password verifiers. In the account, consent can be withdrawn, a copy of the stored data can be downloaded and a data protection request can be submitted.
5. Public entry and result lists
For event delivery, the public entry list may show first name, surname, year of birth, club, race and, after finalisation, bib number. It never shows addresses, full dates of birth, email addresses, telephone numbers or payment data. Adults can object during registration or later. Minors are hidden by default and are displayed only after separate permission by a legal guardian.
For adults, the legal basis is our legitimate interest in transparent sporting event delivery (Art. 6(1)(f) GDPR). The right to object under Art. 21 GDPR remains unaffected.
6. Payment providers
Depending on the selected payment method, the necessary registration reference, amount, name, email address and transaction data are sent to TeleCash/Fiserv, PayPal or SumUp. Full card details are not stored in the KLL system. The legal basis is Art. 6(1)(b) GDPR. The provider's privacy information also applies.
7. Contractual email and participant messages
Registration confirmations, payment information, reminders, safety notices and replies are sent as necessary for the contract. Open payments receive one reminder after ten days. If payment is still outstanding after 20 days, the registration is removed from the active list and kept in a restricted recovery area for no more than 90 days.
Email delivery may use Resend. Delivery records are restricted to error handling and accountability.
8. Newsletter and WhatsApp
Newsletter and WhatsApp messages are voluntary and are sent only on the basis of separate consent (Art. 6(1)(a) GDPR and applicable direct marketing law). Newsletter consent is activated only after confirmation by email. Consent text, version, time, status and withdrawal are recorded. Every marketing email contains an unsubscribe link. WhatsApp consent can be withdrawn immediately in the KLL account.
WhatsApp is provided by WhatsApp Ireland Limited. Use of Meta infrastructure may involve transfers to third countries under the provider's applicable safeguards.
9. Recipients and administration
Access is limited by role and event. Only authorised persons receive the data needed for their tasks. Sensitive full exports and database exports are restricted to specially authorised roles and are logged. Data may also be shared, where necessary, with payment, timing, results, tax, legal, insurance or public bodies.
10. Retention
| Data category | Regular period |
|---|---|
| Open, unpaid registration | 20 days active, then no more than 90 days in the restricted recovery area |
| Public entry list | no more than four weeks after the event |
| Participant messages | six months after archiving |
| Registration data | generally three years after the event; then anonymised unless a legal duty prevents this |
| Payment and accounting evidence | for the applicable statutory retention period |
| Marketing and delivery evidence | generally three years |
| Technical sessions | until expiry; expired sessions are removed daily |
| Encrypted backups | no more than 30 days |
A daily deletion process removes or anonymises data when its purpose and retention period have ended. If statutory duties or a concrete legal claim require longer retention, the data are restricted instead.
11. Your rights
Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction, data portability and objection, and may withdraw consent at any time for the future. Contact the controller above. You may also complain to the Bavarian Data Protection Authority (BayLDA).
12. Necessary storage and automated decisions
Only technically necessary security and session cookies are used. No analytics or advertising cookies are set. The fixed 10/20-day payment rule is an administrative schedule, not profiling or an automated decision within Art. 22 GDPR; a human review can be requested at any time.