fsresults

Privacy Policy

Last updated: 2026-10-04

This policy explains what personal data the fsresults figure skating results archive (the "Service", published at bios.fsresults.info) processes, why, on what legal basis, and what rights you have. It is written to satisfy Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).

1. Who is responsible (the "controller")

Controller Defency OÜ
Address Kirsi tn 8, Tallinn, Estonia
Contact for data-protection matters [email protected]

We have not appointed a Data Protection Officer, as we are not legally required to. All data-protection requests go to the contact address above.

2. What this Service is

fsresults is a searchable archive of figure skating competition results: events, categories, start lists, final placements, judges' protocols (per-element and per-component scores), skater and official profiles, clubs and venues. It is an informational and historical record of a publicly conducted, judged sport.

3. Whose data we process, and where it comes from

We do not collect data directly from the people described in the archive. With limited exceptions (account holders — section 8), all personal data in the archive is obtained from already-public sources — we mirror, structure and index information that governing bodies, national federations and event organisers have themselves published. Our sources include:

Categories of data subjects and data

Data subject Personal data we hold
Athletes / competitors name; competition entries, results, rankings and per-judge scores; club and nationality. For athletes with an official ISU bio, additionally: date of birth, gender, place of birth, height, hometown, profession/hobbies, coach/choreographer, social-media/website links, and personal-best/record statistics.
Officials (judges & technical panel) name; nationality; official function; per-season appointments (from ISU communications and national lists); the per-judge marks they awarded, and analysis derived from them.
Federation / club contacts contact details (website, e-mail, phone, address, social media) as published by the ISU or the federation for its official points of contact.
Registered members the SkateID subject identifier your account is bound to, verified e-mail, first and last name, optional nickname, language, optional avatar, notification preferences, push subscriptions, followed events, consent records, and session records (including the SkateID ID token and refresh token). Provided via SkateID at sign-in — see section 8.
Site administrators the same data as a registered member (above), plus their admin role grant(s); during a documented one-release rollback (AUTH_MODE=passkey) also a WebAuthn passkey credential. See section 8.

We do not process any special-category data (no health, biometric, religious, political, sexual-orientation or trade-union data). Nationality is recorded as a sporting representation code and is not used as, and does not denote, racial or ethnic origin.

4. Why we process it, and our legal basis

For everything in the public archive (that is, everything except account holders, whose basis is described in section 8), our legal basis is legitimate interests — GDPR Article 6(1)(f). We rely on legitimate interests rather than consent because the Service is a comprehensive public record: it cannot function if it must ask tens of thousands of athletes and officials for permission, and consent that could be withdrawn field-by-field would make an accurate historical archive impossible.

Our legitimate interests, and those of the public and the skating community, are:

This processing is also supported by the GDPR provisions for freedom of expression and information (Article 85) and for archiving in the public interest, and scientific, historical-research and statistical purposes (Articles 89 and 5(1)(b)) — a sports-results archive is both a journalistic / informational activity and an archival one.

We have carried out and documented a Legitimate Interests Assessment and a Data Protection Impact Assessment for this processing. You may request a summary using the contact in section 1.

Why "the data is already public" matters — and its limit. Because our data comes from sources the governing bodies chose to publish, the intrusion into your privacy is incremental and within your reasonable expectations as a competitor or official. That strengthens — but does not by itself establish — our legal basis: republishing public data is still our own processing, for which we take responsibility under Article 6(1)(f).

5. Children (data subjects under 18)

Many competitors are children, and GDPR (Recital 38) requires their data to be given specific protection. We apply the following safeguards:

Account sign-in is gated by SkateID, not by us. We no longer run our own registration form, so we never ask for or collect a date of birth, a country of residence, or a guardian's e-mail from an account holder. The digital-age-of-consent check and any parent/guardian verification a minor needs happen at SkateID (auth.skateid.me) before an account can sign in at all — see the SkateID privacy policy for how it handles that. This Service relies on that check and applies no separate age gate of its own.

If you are a parent or guardian and have concerns about a specific profile or account, contact us (section 1) and we will review it promptly.

6. Automated processing

Some upcoming-event announcements are summarised by an automated (AI) text extraction to draft structured facts (deadlines, venue, contacts). A human reviews and confirms every extraction before anything is published. We do not make any decision that produces legal or similarly significant effects about you by solely automated means (GDPR Article 22 does not apply).

7. Who we share it with, and international transfers

We do not sell personal data and do not share it for advertising. The Service runs on Cloudflare infrastructure (Workers, D1 database, R2 storage, and Workers AI), which processes data on our behalf as a processor under a data processing agreement. This may involve transfers outside the European Economic Area; such transfers are covered by the appropriate GDPR safeguards (Standard Contractual Clauses and/or an adequacy mechanism) in Cloudflare's terms.

Where you hold an account, signing in involves SkateID (fs-sso), operated by the same controller as this Service on its own cluster, which acts as our processor for your identity data — your credentials, your verified e-mail (and phone, where SkateID offers it), and the birthdate it uses for its own age gate. We do not receive your birthdate from SkateID. See section 8. If you have also enabled notifications, delivery involves further processors: Cloudflare Email Sending for e-mail, and your device's push service — Apple Push Notification service and/or Google Firebase Cloud Messaging — for push.

Because the archive is public, the information on it is also visible to, and may be indexed by, anyone on the internet (subject to the child-profile safeguards in section 5).

8. Accounts: sign-in, members and administrators

Account data is not part of the public archive and is processed on a different basis from section 4.

Sign-in. We do not run our own registration form, password, or passkey enrolment for a new account any more. You sign in through SkateID (auth.skateid.me, operated by the same controller as this Service, on its own infrastructure), which authenticates you with a passkey or a one-time code and acts as our processor for that identity data. SkateID — not this Service — verifies your e-mail (and phone, where it offers that), holds your credentials, and runs the digital-age-of-consent check and any parent/guardian verification a minor needs, before an account can sign in at all; see the SkateID privacy policy for that processing. Because of this, we never collect a date of birth, a country of residence, or a guardian's e-mail for an account — the only age-related safeguard on accounts happens at SkateID, before sign-in ever reaches us. (This is separate from the date-of-birth safeguards for skater profiles in section 5, which are about people in the results archive, not about accounts.) Accounts created before the switch to SkateID may still carry the legacy registration fields (date of birth, country, guardian e-mail) until a follow-up schema clean-up removes them; these fields are no longer read or used for anything.

What we store. Once you sign in, for your account we process: the SkateID subject identifier it's bound to; your verified e-mail; first and last name, optional nickname and language as given by SkateID; an optional avatar; the events you follow and your notification preferences; any push subscription you register; your consent records (this policy and the Terms of Service, each versioned); and session records — including the SkateID ID token (used to also sign you out of SkateID on logout) and refresh token (used to re-check your SkateID claims roughly hourly) — for as long as the session lasts. An administrator's account additionally carries their role grant(s) (see /admin/users).

Support access. To investigate a problem you report, an administrator may temporarily view the Service as your account. Such access is limited, expires automatically, and is recorded in an audit log; administrators cannot change your e-mail or delete your account while doing so.

9. How long we keep it

Because the Service is a historical record, competition results and the associated athlete and official data are retained indefinitely as an archive in the public interest (Article 89). Raw source documents are retained for provenance, accuracy and correction. Session data is short-lived. Account data is kept for as long as the account exists and is deleted when you delete the account; consent records are retained as long as needed to evidence the consent given, and role-grant history is retained for the administrator audit trail.

10. Your rights

Under the GDPR you have the right to:

How erasure and objection work here. When you object or ask for erasure, we assess your request individually. For genuine competition-record data we may continue to process it where that is necessary for the exercise of the right to freedom of expression and information, or for archiving in the public interest (GDPR Articles 17(3)(a) and 17(3)(d)) — this is the same public-record interest described in section 4. But we will always correct inaccuracies, and we will remove or de-index data that is not necessary for the record (for example enrichment details, or search-engine visibility of a profile) where your interests warrant it. We aim to respond within one month.

If you have an account, you can exercise access and erasure yourself, straight away, from your account page — export your data or delete your account and its data — and change or withdraw your notification consents there. For anything else, or for data in the public archive, contact us at [email protected].

11. Notice where we could not contact you directly

Because we obtain data from public sources rather than from you, and given the number of people in the archive, individually notifying each person would involve disproportionate effort (GDPR Article 14(5)(b)). This policy is our public notice instead, and we keep it easy to find. If you believe you are in the archive and want to know exactly what we hold, contact us and we will tell you.

12. Changes

We may update this policy; the "last updated" date above tracks changes.