Privacy

What we do with your details

Registering a team means telling us things about real people - who is coming, how to reach them, and sometimes what they cannot eat. This page says exactly what happens to all of it, how long we keep it, and what you can make us do about it.

Version 2026-08-20· Operated by Hellersjo Consulting AB · Contact: privacy@unispect.example

Läs det här meddelandet på svenska

Who is responsible

For a competition registration, the organising club named on the event decides what is collected and why - they are the data controller. Their name and contact details are on the competition's registration page and in your confirmation email.

Unispect, operated by Hellersjo Consulting AB, runs the software on the organiser's behalf as a processor under a written agreement (Art. 28 GDPR). Reach the operator at privacy@unispect.example.

For your Unispect account - your name, email and sign-in - Hellersjo Consulting AB is the controller, because the same account works for every competition on the platform.

What we collect, and why we are allowed to

WhatWhyOur legal basis
Team name, category, ISU member federation Entering your team into the competition Art. 6(1)(b) - the contract you enter into by registering
Contact person's name, email and phone Confirming the registration and reaching you about changes Art. 6(1)(b)
Rooming list - names, countries, phone numbers Telling the hotel who is staying and in which room Art. 6(1)(f) - the organiser's and the hotel's legitimate interest in knowing who is on the premises
Passport or national ID numbers Hotel check-in, which many hotels cannot complete without one Art. 6(1)(f), and Art. 6(1)(c) where local law obliges the hotel to record it
Travel details - flight numbers, arrival and departure times Arranging transfers and shuttles Art. 6(1)(b)
Allergies, dietary needs, accessibility requirements, health notes Feeding people safely, and making the venue and hotel work for them Art. 9(2)(a) - your explicit consent, and nothing else. We ask separately, we never pre-tick it, and you can take it back at any time

We do not use any of this for advertising, we do not sell it, and we do not make automated decisions about anyone with it.

Health information is treated differently

Allergies and dietary requirements are special category data under Art. 9 GDPR - legally the same class as medical records. That means three things in practice:

  • The fields that hold them stay closed until you explicitly consent. You can complete a registration without ever opening them.
  • They are encrypted in our database with a key held outside it, so they are unreadable to anyone who gets at the data without also getting at the key.
  • They are deleted first - well before the rest of the registration - because they stop being needed the moment the last meal is served.

You can withdraw that consent from your registration page at any time. Withdrawing does not just stop future use: it deletes what those fields hold, immediately.

How long we keep it

WhatHow long
Passport and national ID numbersDeleted 14 days after the competition ends
Allergies, dietary needs, accessibility and other health-related notesDeleted 30 days after the competition ends
Your registration, contact details, roster and travel detailsDeleted 180 days after the competition ends
Registrations you started but never submittedDeleted 30 days after they were last edited
The record of who looked at your dataDeleted after 365 days

These periods are read straight from the system that enforces them, so this table cannot drift away from what actually happens. Deletion runs automatically every day.

Who else sees it

  • The hotel named in the registration - rooming list including passport or ID numbers, for check-in
  • The catering supplier at the venue - dietary requirements, in aggregate where possible
  • Hellersjo Consulting AB (Unispect) - operates the registration system on the organiser's behalf as a processor under Art. 28
  • Microsoft Azure (EU regions) - hosting, database and storage, as a sub-processor
  • Microsoft Entra External ID - the sign-in directory, holding the email address and display name of account holders, as a sub-processor
  • The hotel named in the registration - rooming list including passport or ID numbers, for check-in
  • The catering supplier at the venue - dietary requirements, in aggregate where possible
  • Hellersjo Consulting AB (Unispect) - operates the registration system on the organiser's behalf as a processor under Art. 28
  • Microsoft Azure (EU regions) - hosting, database and storage, as a sub-processor
  • Microsoft Entra External ID - the sign-in directory, holding the email address and display name of account holders, as a sub-processor

Registrations, rosters and every other competition record are stored in Microsoft Azure's EU regions and never leave the EU/EEA. The sign-in directory (Microsoft Entra External ID) that holds account holders' email addresses and display names is currently located in the United States. That transfer relies on Microsoft's certification under the EU-US Data Privacy Framework and on the standard contractual clauses in Microsoft's data processing terms.

Your rights

You can exercise most of these yourself, straight away, from your registration page:

  • See it all (Art. 15, 20). "Prepare my copy" gives you a JSON file with everything held, why, and for how long.
  • Correct it (Art. 16). Every wizard step stays editable until the change deadline.
  • Delete it (Art. 17). "Delete our details" removes every personal field from the registration and its rooming list.
  • Withdraw consent (Art. 7(3)). One checkbox, as easy to untick as it was to tick, and it deletes the data it covered.
  • Object or restrict (Art. 18, 21). Contact us and we will act within one month.

Account holders can do the same from their account settings, or by contacting us.

If you are not satisfied with how we handle a request, you can complain to Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy@imy.se.

Cookies

We set two cookies, both strictly necessary, so neither needs your consent under the ePrivacy rules: one keeps you signed in, and one remembers the language you chose in the footer. Dates and numbers follow your browser's own region settings and are not stored anywhere. There is no analytics, advertising or tracking on this site - which is why there is no cookie banner asking you to agree to any.

Security

Health-related notes, passport numbers, phone numbers and travel details are encrypted in the database. A registration is reached only by signing in with the email address it was made under - there is no link that opens it on its own, so a forwarded email discloses nothing. Every read and write is tied to a signed-in person. We keep a record of every access to personal data so we can tell you who looked at yours if you ask.

Ett fel har uppstått. Sidan kan behöva laddas om för att fungera igen. Ladda om 🗙