Ice HockeyTourneys

Privacy policy

1. Controller

The controller within the meaning of Article 4(7) GDPR is:

  • Business name: BestArtcic, s. r. o.
  • Registered office: Železničná 19/18, 980 52 Hrachovo
  • Company number: 57716404
  • Tax number: 2122899801
  • Registration: Obchodný register Okresného súdu Banská Bystrica, oddiel Sro, vložka č. 56501/S
  • Email: turnaje@icehockeytournaments.eu
  • Phone: +421 949 409 099

The operator is not required to designate a data protection officer under Article 37 GDPR — it neither processes personal data on a large scale nor systematically monitors data subjects. For data protection matters, write to the email address above.

2. Whose data we process

  • Organisers — people who have applied for a membership or hold one.
  • Team contacts — people who enter a team for an event.
  • Senders of messages — people who write through the contact form.
  • Visitors — to the extent of data from cookies and technical server logs.

3. What data, for what purpose and on what legal basis

3.1 Membership application and running an organiser account

Data: name of the organisation, first and last name of the contact person, email, phone, billing address, company ID, tax ID, VAT ID, chosen plan and payment method, note to the application, IP address and time of submission.

Purpose: reviewing the application, setting up and running the account, communication about the membership.

Legal basis: performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR). IP address and time of submission — legitimate interest in protecting the form from misuse (Art. 6(1)(f) GDPR).

Retention: for the duration of the membership and 3 years after it ends (limitation period). Rejected applications are kept for 24 months.

3.2 Team entry for an event

Data: team name, first and last name of the contact person, email, phone, town, category, number of players, team logo, note, agreement to the terms, IP address and time of submission.

Purpose: passing the entry to the event organiser and informing the team about changes to the event.

Legal basis: pre-contractual steps and performance of a contract between the team and the organiser (Art. 6(1)(b) GDPR); in relation to the operator, legitimate interest in running the portal (Art. 6(1)(f) GDPR).

Retention: 24 months from the date of entry. After that, older entries are automatically anonymised — only non-personal statistics remain.

The organiser’s position: in relation to entries the event organiser is a separate controller. The portal operator makes the entry available to them; what happens with it afterwards is up to the organiser.

3.3 Messages from the contact form

Data: name, email, phone, message text, IP address and time of submission.

Purpose: replying to the message.

Legal basis: legitimate interest in dealing with the enquiry (Art. 6(1)(f) GDPR).

Retention: 24 months.

3.4 Invoices and accounting records

Data: the organiser’s billing details, invoice number, amount, period, date of payment.

Purpose: bookkeeping and meeting tax obligations.

Legal basis: legal obligation (Art. 6(1)(c) GDPR) under Act No. 431/2002 Coll. on accounting and Act No. 595/2003 Coll. on income tax.

Retention: 10 years following the year the record relates to.

3.5 Operational and security logs (audit trail)

Data: IP address, time, type of action and its result (for example a failed login, an event approval, a change of plan). The portal keeps every such audit record in its own table.

Purpose: the security of the portal, protection against misuse and evidence of the changes made.

Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

Retention: as configured in the portal, by default 24 months.

3.6 Cookies and traffic measurement

Legal basis: essential cookies — legitimate interest in the functioning of the portal; analytics and marketing cookies solely your consent (Art. 6(1)(a) GDPR and § 109(8) of Act No. 452/2021 Coll. on electronic communications). Without consent they are not loaded, and you can withdraw consent at any time.

The details are in the Cookie policy.

4. Who we share data with

We do not sell data. We share it only with these recipients and only as far as necessary:

  • The event organiser — the team entries for their event. In relation to those they are a separate controller.
  • Websupport s. r. o., Karadžičova 7608/12, 821 08 Bratislava — as a processor, running the server and backups.
  • The email service provider — delivering emails from the portal, as a processor.
  • The accountant and tax adviser — accounting records, as a processor.
  • Cloudflare, Inc. — protecting the forms against bots (Turnstile), where enabled.
  • Google Ireland Limited and Meta Platforms Ireland Limited — traffic measurement and advertising, only if you have consented.
  • Public authorities — where the law requires it.

5. Transfers outside the European Union

Data is processed in the European Union. The exception is the tools of Google, Meta and Cloudflare, where a transfer to the United States may occur. Such a transfer is safeguarded by standard contractual clauses approved by the European Commission and by the EU–U.S. Data Privacy Framework. Analytics and advertising tools only run with your consent, so without it no such transfer takes place.

6. Your rights

As a data subject you have the right:

  • of access to your data and to a copy of it (Art. 15 GDPR),
  • to rectification of inaccurate data (Art. 16 GDPR),
  • to erasure (Art. 17 GDPR),
  • to restriction of processing (Art. 18 GDPR),
  • to data portability (Art. 20 GDPR),
  • to object to processing based on legitimate interest (Art. 21 GDPR),
  • to withdraw consent at any time where processing is based on it; withdrawal does not affect the lawfulness of processing before it.

It is enough to send a request by email to the operator. We reply within 30 days; in more complex cases we may extend that by a further two months and will let you know.

An organiser can also correct most of their data themselves in their dashboard, and download a copy of it there.

You also have the right to lodge a complaint with the supervisory authority — the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.

7. Is providing the data mandatory?

It is not, but without the fields marked as required in the forms we cannot review a membership application, pass a team entry to the organiser or reply to a message. Filling in a form is voluntary.

8. Automated decision-making

The portal carries out no automated decision-making or profiling with legal effects for data subjects. A person decides on both membership applications and events.

9. Security

Data is transmitted over an encrypted connection (HTTPS). Only authorised people with their own account have access to the administration. The forms are protected against automated misuse. Backups are held with the hosting provider in the European Union.

10. Changes to this document

We may update this document. The current wording is always available on this page. Effective from 4. 9. 2026.