fsresults

Privacy Policy

Last updated: 2026-07-14

This policy explains what personal data the fsresults figure skating results archive (the "Service", published at bios.fsresults.info) processes, why, on what legal basis, and what rights you have. It is written to satisfy Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).

1. Who is responsible (the "controller")

Controller Defency OÜ
Address Kirsi tn 8, Tallinn, Estonia
Contact for data-protection matters [email protected]

We have not appointed a Data Protection Officer, as we are not legally required to. All data-protection requests go to the contact address above.

2. What this Service is

fsresults is a searchable archive of figure skating competition results: events, categories, start lists, final placements, judges' protocols (per-element and per-component scores), skater and official profiles, clubs and venues. It is an informational and historical record of a publicly conducted, judged sport.

3. Whose data we process, and where it comes from

We do not collect data directly from the people described in the archive. With limited exceptions (account holders — section 8), all personal data in the archive is obtained from already-public sources — we mirror, structure and index information that governing bodies, national federations and event organisers have themselves published. Our sources include:

Categories of data subjects and data

Data subject Personal data we hold
Athletes / competitors name; competition entries, results, rankings and per-judge scores; club and nationality. For athletes with an official ISU bio, additionally: date of birth, gender, place of birth, height, hometown, profession/hobbies, coach/choreographer, social-media/website links, and personal-best/record statistics.
Officials (judges & technical panel) name; nationality; official function; per-season appointments (from ISU communications and national lists); the per-judge marks they awarded, and analysis derived from them.
Federation / club contacts contact details (website, e-mail, phone, address, social media) as published by the ISU or the federation for its official points of contact.
Registered members first and last name, optional nickname, verified e-mail, date of birth, country of residence, language, optional avatar, notification preferences, followed events, consent records, and (for minors) a parent/guardian e-mail. Provided by the member at sign-up — see section 8.
Site administrators account username, display name, WebAuthn passkey credentials, session records (see section 8).

We do not process any special-category data (no health, biometric, religious, political, sexual-orientation or trade-union data). Nationality is recorded as a sporting representation code and is not used as, and does not denote, racial or ethnic origin.

4. Why we process it, and our legal basis

For everything in the public archive (that is, everything except account holders, whose basis is described in section 8), our legal basis is legitimate interests — GDPR Article 6(1)(f). We rely on legitimate interests rather than consent because the Service is a comprehensive public record: it cannot function if it must ask tens of thousands of athletes and officials for permission, and consent that could be withdrawn field-by-field would make an accurate historical archive impossible.

Our legitimate interests, and those of the public and the skating community, are:

This processing is also supported by the GDPR provisions for freedom of expression and information (Article 85) and for archiving in the public interest, and scientific, historical-research and statistical purposes (Articles 89 and 5(1)(b)) — a sports-results archive is both a journalistic / informational activity and an archival one.

We have carried out and documented a Legitimate Interests Assessment and a Data Protection Impact Assessment for this processing. You may request a summary using the contact in section 1.

Why "the data is already public" matters — and its limit. Because our data comes from sources the governing bodies chose to publish, the intrusion into your privacy is incremental and within your reasonable expectations as a competitor or official. That strengthens — but does not by itself establish — our legal basis: republishing public data is still our own processing, for which we take responsibility under Article 6(1)(f).

5. Children (data subjects under 18)

Many competitors are children, and GDPR (Recital 38) requires their data to be given specific protection. We apply the following safeguards:

When someone registers an account, we check their age against the digital age of consent in their country — using both the country they select and the country their connection appears to come from, applying whichever is stricter, so the protection cannot be side-stepped by choosing a different country. If they are below it, the account cannot be activated until a parent or guardian confirms consent by e-mail. Accounts for anyone under 18 are treated as a minor's for safeguarding purposes regardless of the consent age.

If you are a parent or guardian and have concerns about a specific profile or account, contact us (section 1) and we will review it promptly.

6. Automated processing

Some upcoming-event announcements are summarised by an automated (AI) text extraction to draft structured facts (deadlines, venue, contacts). A human reviews and confirms every extraction before anything is published. We do not make any decision that produces legal or similarly significant effects about you by solely automated means (GDPR Article 22 does not apply).

7. Who we share it with, and international transfers

We do not sell personal data and do not share it for advertising. The Service runs on Cloudflare infrastructure (Workers, D1 database, R2 storage, and Workers AI), which processes data on our behalf as a processor under a data processing agreement. This may involve transfers outside the European Economic Area; such transfers are covered by the appropriate GDPR safeguards (Standard Contractual Clauses and/or an adequacy mechanism) in Cloudflare's terms.

Where you hold an account and have enabled notifications, delivery also involves processors: Cloudflare Email Sending for e-mail, and your device's push service — Apple Push Notification service and/or Google Firebase Cloud Messaging — for push. See section 8.

Because the archive is public, the information on it is also visible to, and may be indexed by, anyone on the internet (subject to the child-profile safeguards in section 5).

8. Accounts: registered members and administrators

Account data is not part of the public archive and is processed on a different basis from section 4.

Registered members. Anyone may create an account to follow events and receive notifications. For a member we process the data listed in section 3: first and last name, optional nickname, verified e-mail, date of birth, country of residence, language, an optional avatar, notification preferences, the events you follow, your consent records, and — for an applicant below the age of digital consent — a parent/guardian's e-mail. At sign-up we also record the country your connection appears to come from, derived from your IP at country level only (we do not store your IP address), to apply the correct age-of-consent rules and to detect abuse.

Administrators. A small number of authenticated administrators maintain the archive. For them we process an account identifier, display name, WebAuthn passkey credential and session/login records. The legal basis is the performance of our arrangement with them (Article 6(1)(b)) and our legitimate interest in securing the Service (Article 6(1)(f)).

Support access. To investigate a problem you report, an administrator may temporarily view the Service as your account. Such access is limited, expires automatically, and is recorded in an audit log; administrators cannot change your passkeys or e-mail, or delete your account, while doing so.

9. How long we keep it

Because the Service is a historical record, competition results and the associated athlete and official data are retained indefinitely as an archive in the public interest (Article 89). Raw source documents are retained for provenance, accuracy and correction. Session data and one-time e-mail links are short-lived. Member-account data is kept for as long as the account exists and is deleted when you delete the account; consent and approval records are retained as long as needed to evidence the consent given.

10. Your rights

Under the GDPR you have the right to:

How erasure and objection work here. When you object or ask for erasure, we assess your request individually. For genuine competition-record data we may continue to process it where that is necessary for the exercise of the right to freedom of expression and information, or for archiving in the public interest (GDPR Articles 17(3)(a) and 17(3)(d)) — this is the same public-record interest described in section 4. But we will always correct inaccuracies, and we will remove or de-index data that is not necessary for the record (for example enrichment details, or search-engine visibility of a profile) where your interests warrant it. We aim to respond within one month.

If you have an account, you can exercise access and erasure yourself, straight away, from your account page — export your data or delete your account and its data — and change or withdraw your notification consents there. For anything else, or for data in the public archive, contact us at [email protected].

11. Notice where we could not contact you directly

Because we obtain data from public sources rather than from you, and given the number of people in the archive, individually notifying each person would involve disproportionate effort (GDPR Article 14(5)(b)). This policy is our public notice instead, and we keep it easy to find. If you believe you are in the archive and want to know exactly what we hold, contact us and we will tell you.

12. Changes

We may update this policy; the "last updated" date above tracks changes.