Back to list

Privacy policy

Last updated: 7 August 2026 1. DATA CONTROLLER Ludwig S.r.l.s. VAT no.: IT06332200829 Registered office: Italy Omniathlon is a service provided and operated by Ludwig S.r.l.s. (hereinafter also "Omniathlon" or the "Controller"). Contact, including privacy matters: use the contact form linked from the site footer. 2. DATA PROCESSED AND PURPOSES a) Public browsing (unauthenticated visitor): - IP address and standard request headers — used only to run the site, prevent abuse and suggest the language on first visit. Not stored persistently for mere browsing. Public writing is the exception: see letter f). - Local preferences (language, cookie consent) stored only in your browser. Legal basis: legitimate interest (Art. 6.1.f GDPR) in security and continuity of the service. b) Directory administrators: - Sign-in credentials — used only to verify your identity during the session. Legal basis: contract performance (Art. 6.1.b) or consent. c) Registered organizers: - Email, hashed password, public name and link to claimed races. - Content uploaded to event pages (text, photos). Legal basis: contract performance (Art. 6.1.b). d) Technical logs: - Application and request logs for debugging and security, retained for the minimum necessary time (approximately 30 days). e) Contact form: - Name, email address, subject and message text - processed only to read your request and reply to you. - One attached image, if you choose to upload one. Attach only what the request needs: if the image shows people or contains other people's data, consider first whether it is necessary. Legal basis: legitimate interest (art. 6.1.f GDPR) in replying to those who write to us. f) Content written in public (race comments, missing-race reports, crossings): - IP address and country of the request, stored alongside the content — they defend the site against bots and repeat abuse, where knowing "which account" is not enough because an account can be opened again. - We do not use them to profile you or for advertising, and they appear nowhere on the site: only service administrators can see them. Legal basis: legitimate interest (art. 6.1.f GDPR) in service security and abuse prevention. 3. NO PROFILING We do not use analytics or advertising pixels. If we ever add any, the consent banner will require an explicit choice for the relevant category. 4. THIRD PARTIES AND TRANSFERS - Cloud infrastructure provider (USA/EU) with adequate data-transfer safeguards (standard contractual clauses). - Authentication provider for organizer sign-in. - Language-processing services used to extract public race data from third-party sites (no user data is sent). - Travel partner content (accommodation, experiences, restaurants): fetched by OUR servers via partner APIs and rendered directly on our pages — your browser never contacts the partners and none of your data is sent to them. - Stay22 (Canada) accommodation map: embedded ONLY after your explicit click on the dedicated button, which constitutes the request to load the third-party content. See https://stay22.com/privacy - Affiliate links to external partners (stays, flights, experiences, gear): plain links — no data is shared with the partner until you open them; from then on the destination site's privacy policy applies. - Contact form anti-bot check (Cloudflare Turnstile): active only when you attach an image; it receives your IP address and technical browser signals in order to tell a person from a script. No profiling (see https://www.cloudflare.com/privacypolicy/). 5. RETENTION - Local preferences (language, consent): until you clear your browser. - Sessions: until logout or browser clearing. - Organizer account: until cancellation request or prolonged inactivity (24 months). - Technical logs: approximately 30 days. - IP address and country stored with public content: 12 months, then deleted automatically. - Contact form messages: for as long as needed to handle the request. - Images attached to the contact form: one year from receipt, then deleted automatically. 6. YOUR RIGHTS (Art. 15-22 GDPR) You have the right to access, rectify, delete your data, request restriction or portability, and object to processing. Exercise these rights via the contact form linked from the site footer; we will respond within 30 days. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or your local DPA. 7. MINORS The service is not intended for children under 14. We do not knowingly collect data from minors. 8. CHANGES Any substantial change to this policy will be notified via the consent banner (version bump) and with an updated date at the top of this document. 9. CONTACTS For any request, please use the contact form linked from the site footer.