Policy version 2026.06.20

Privacy Policy and Safeguarding Responsibility Statement

This application is used for competition administration. It records privacy and safeguarding responsibility acknowledgement, but it does not replace the organiser's safeguarding checks, DBS checks where applicable, training, supervision, lawful-basis assessment, or legal responsibilities. The event organiser and authorised administrators remain responsible for how the application is configured, validated, and used.

1. Purpose of this application

The Competition Management application is used to manage registrations, event administration, stage allocation, judging, timing, results, appeals, certificate writing, certificate distribution, public result display, and related event workflows.

The application is an administrative support tool. It must be configured, checked, and operated by authorised administrators in line with the event organiser's rules, policies, safeguarding procedures, privacy requirements, and legal responsibilities.

2. Responsible organisation and administration responsibility

The event organiser and authorised organisation administrators using this application are responsible for deciding what personal data is collected, why it is collected, how it is used, who may access it, how long it is kept, and when it is deleted or exported.

The responsibility for correct administration, safeguarding compliance, privacy compliance, lawful data use, role assignment, registration validation, result publication, appeal handling, certificate handling, and day-to-day use of the application rests with the event organiser and the authorised administrators using the application.

The application is not responsible for the event organiser's decisions, data entered by users, role assignments, safeguarding checks, publication choices, retention decisions, or operational decisions made through the system.

3. Personal data processed

The application may process participant, parent/guardian, emergency contact, registration, judging, timing, result, appeal, certificate, uploaded document, audit, and system access information.

  • Participant name, date of birth, category, church/area/region or other organisational unit.
  • Registration number, chest number, selected items, group/team member details.
  • Parent/guardian and emergency contact details where collected.
  • Medical or allergy notes where provided and needed for event administration or emergency response.
  • Photo/video consent and public result display preferences where collected.
  • Judge, stage coordinator, time keeper, certificate, appeal, and administrator records.
  • Marks, timing records, ranks, results, appeals, certificate records, uploaded files, logs, and audit records.

4. Why the data is used

Data is used to create and manage registrations, check category eligibility, assign items and stages, manage event-day flow, submit marks and timings, calculate and publish results, manage appeals, prepare certificates, support safeguarding and emergency contact processes, maintain audit records, and protect the integrity of the competition.

5. Lawful basis for processing

The event organiser is responsible for identifying and documenting the appropriate lawful basis for processing personal data before using the application. Depending on how the organiser uses the application, the lawful basis may include one or more of the following:

  • Legitimate interests: to organise and administer the competition, manage registrations, stages, judging, timing, results, appeals, certificates, and event operations.
  • Contract or participation agreement: where registration or participation is provided under agreed event rules or conditions.
  • Consent: where the organiser asks for specific consent, such as photo/video consent, optional media use, or optional public display preferences.
  • Legal obligation: where information must be kept or shared to meet a legal or regulatory requirement.
  • Vital interests: where information must be used or shared in a genuine emergency to protect someone's life or immediate safety.
  • Safeguarding or substantial public interest, where applicable: where information is processed or shared to protect children, young people, or vulnerable persons.

The application records the information entered into it, but the organiser remains responsible for ensuring that the chosen lawful basis is appropriate for the event and for the way the data is used.

6. Special category and sensitive information

Some information may be more sensitive, such as medical notes, allergy information, disability-related information, safeguarding notes, or information connected to a child or vulnerable person. This information must be handled with extra care.

Where special category data is collected or used, the organiser must ensure that there is both an appropriate lawful basis and, where required, an additional special category processing condition before collecting, accessing, using, sharing, or retaining that information.

7. Children and young people

Many participants may be children or young people. Their information must be handled with extra care. The organiser must ensure that privacy information is clear and appropriate, and that parents, guardians, or authorised persons are informed where required.

Private contact details, medical notes, safeguarding notes, date of birth, and parent/guardian details must not be shown on public pages, public results, Big TV screens, judge screens, or general event displays.

8. Parent/guardian and emergency contact information

Parent/guardian and emergency contact details are collected to support event administration, communication, safeguarding, and emergency response. These details must only be viewed by authorised users who need them for their event role.

Emergency contact information must not be displayed publicly. It should only be used where necessary and proportionate for administration, safeguarding, or emergency response.

9. Photo and video consent

The application may record photo or video consent preferences. The event organiser remains responsible for ensuring photography, videography, media publication, and public display activity follows the organisation's safeguarding and privacy policies.

Recording a preference in the application does not by itself make photography, video recording, or publication lawful or appropriate. The organiser must ensure that the correct process is followed at the event.

10. Public results and public display

The application may display results through public result pages or display screens. Public result settings must be configured carefully. Private information such as date of birth, phone number, parent/guardian details, emergency contact details, medical notes, and safeguarding notes must not be shown on public displays.

The organiser is responsible for deciding what information is appropriate to publish and for checking results before publication.

11. AI-assisted development and functionality

The application and some of its functionality, content, code, design, or configuration may have been created, generated, reviewed, or improved with the assistance of artificial intelligence tools.

AI assistance does not replace human review, testing, approval, legal review, safeguarding review, privacy review, or operational checks. The event organiser and authorised administrators remain solely responsible for verifying that the application is suitable for their event, that the configured rules are correct, that outputs are checked before use, and that the application is used lawfully and appropriately.

12. Safeguarding responsibility

The application does not verify whether a person is legally or organisationally suitable to work with children, young people, or vulnerable persons. It is the responsibility of the event organiser, authorised administrators, safeguarding lead, and relevant organisation to ensure that all safeguarding policies, safer recruitment checks, DBS checks where applicable, training, supervision arrangements, and approvals are completed outside the application before assigning any person to a role.

By assigning users, judges, coordinators, volunteers, time keepers, certificate users, or other helpers within the application, the authorised administrator confirms that they have followed the organisation's safeguarding policy and that the assigned person is suitable for the role. The application records administrative actions and acknowledgements only; it does not approve, certify, or guarantee safeguarding suitability.

13. Safeguarding information sharing

Safeguarding concerns may need to be shared with the safeguarding lead, relevant organisation leaders, local authority safeguarding services, emergency services, police, or other appropriate authorities where necessary.

The organiser is responsible for deciding when safeguarding information should be shared and for ensuring that any sharing is necessary, proportionate, appropriate, and lawful.

14. User responsibilities

  • Use the application only for authorised event purposes.
  • Access only the information needed for the user's role.
  • Keep login details secure.
  • Do not share participant data outside authorised event processes.
  • Do not copy, download, screenshot, or export data unless required for the user's role.
  • Report data issues, safeguarding concerns, or unauthorised access to the organiser or authorised administrator.
  • Follow the event organiser's safeguarding and privacy policies.

15. Data sharing

Personal data may be shared only where necessary with authorised event administrators, registration teams, stage coordinators, judges, time keepers, certificate teams, safeguarding leads, appeal review teams, system administrators, relevant organisational leaders, emergency contacts, or authorities where required.

Data must not be shared publicly unless it is part of an approved public result, certificate, announcement, or event communication process configured and authorised by the organiser.

16. Data retention

The event organiser decides how long registration, result, appeal, certificate, audit, and uploaded document records are retained. Data should not be kept longer than necessary for event administration, reporting, safeguarding, appeals, certificates, audit, or legal requirements.

The organiser is responsible for periodically reviewing retained data and deleting, anonymising, or exporting information where appropriate.

17. Individual rights and data requests

Individuals may have rights over their personal data, including rights to access, correction, deletion, restriction, objection, and complaint, depending on the circumstances and the lawful basis for processing.

Requests about personal data, corrections, removal, access, privacy concerns, or complaints should be raised with the event organiser or authorised administrator responsible for the event.

18. Issues, concerns, and support

Registration issues, appeal issues, result queries, certificate queries, safeguarding concerns, data corrections, privacy requests, complaints, or questions about how information is used must be raised with the event organiser, authorised administrator, or safeguarding lead for the event.

Technical issues should also be reported to the event organiser or authorised administrator. They may contact their technical support route if required.