Privacy Policy

How we process personal data on the site — registration, payments, cookies, and your GDPR rights.

Website: marathonvarna42km.com

Last updated: 24 May 2026

1. Introduction

1.1. This Privacy Policy explains how STS Akademic (the “Controller”, “we”, “us”) — processes personal data when you use the official website and related online services (the “Website”).

1.2. Processing is carried out in accordance with:

  • Regulation (EU) 2016/679

    (GDPR);

  • the Bulgarian

    Personal Data Protection Act

    ;

  • other applicable EU and Bulgarian legislation.

1.3. This Policy supplements the Terms of Use and the Participation Terms for the relevant edition. Rules on the race itself (health, liability, media, etc.) are in the Participation Terms.

2. Data controller

Field

Value

Name

***

UIC (EIK)

***

Address

***

Privacy / general enquiries

info@marathonvarna42km.com

Registration enquiries

registration@marathonvarna42km.com

Data Protection Officer (DPO): Bozhidar Iliev

To exercise GDPR rights, contact us using the emails above with the subject “Personal data”.

3. Categories of personal data we process

Depending on how you use the Website, we may process:

Category

Examples

When collected

Identity & contact

First, middle, last name, email, phone, city, country

Registration, contact form

Participation

Sex, year of birth, distance, team, T-shirt size, bib number, public UID, registration status

Registration and event operations

Payment

Amount, currency, payment status, transaction reference, method

Online or recorded payment

Account

Password (hashed), language, time of terms acceptance

Registration and login

Sports / federation

BFLA registry card (42 km marathon)

Registration for that distance

Technical

IP address, session, logs, user agent, timestamps

Every visit

Communication

Message body, topic

Contact form

Media

Race photos/videos, bib search in gallery

Event, galleries, MyRacePix

Biometric / facial (selfie)

Face photo for search; face embedding (vector) — at MyRacePix

Only when you voluntarily use “selfie search” in the gallery, after consent

Special categories (health, biometrics under GDPR Art. 9): we do not require or purposefully collect these via the Website. Health declarations in the Participation Terms are the participant’s responsibility when taking part in the event, not a separate health database on the Website.

Children: online registration is available to persons aged 16 or over. For younger participants, registration should be completed by a parent/guardian outside the standard online flow — please contact us.

3.1. Selfie photo search (facial recognition)

When the “Find your photos with one selfie” feature is enabled for an event gallery, you may voluntarily upload one photo of your face (a selfie) to find race photos you appear in.

Aspect

Description

What you upload

One image (JPG, PNG or WebP, up to 5 MB) showing your face

What we do not require

Registration, account or bib number for this feature

How it works

The image is sent to MyRacePix (processor), which extracts a mathematical face embedding and compares it with faces already indexed from event photos. Matching images are shown in the gallery

What we do not store on the Site

The selfie is not saved in the marathonvarna42km.com database after the request completes

Consent

The feature is available only after you tick explicit consent in the form and follow the link to this policy

Legal basis

Art. 6(1)(a) GDPR — consent (separate from race registration)

Withdrawal

Do not upload a selfie if you do not want processing; the Site does not retain uploaded selfies. For requests under Section 11 (access, erasure, etc.) — info@marathonvarna42km.com

Automated decision-making

Results are technical face matches in photos; they do not produce legal or similarly significant effects under Art. 22 GDPR

Biometric data

Processing may involve biometric data under Art. 9 GDPR (facial recognition). The basis is your explicit consent (Art. 9(2)(a)) via the form checkbox, solely to “find my photos from this event”

Retention: the selfie and temporary technical data from the request are processed only for the duration of the search (seconds to minutes) and are not kept for marketing or profiling.

Recipients: MyRacePix and its sub-processors (photo hosting, AI/embedder infrastructure — e.g. servers in the EU/EEA or outside with Chapter V safeguards). Details: info@marathonvarna42km.com.

Rate limiting: request limits per IP address apply to prevent abuse (e.g. 10 searches per minute).

Purpose

Legal basis

Notes

Online registration and performance of the participation contract

Art. 6(1)(b) — contract

Registration fields, account, confirmations

Online fee payment

Art. 6(1)(b) and Art. 6(1)(c) — legal obligation (accounting)

Payments, invoicing/reporting where applicable

Public participant list (name, bib, distance, country)

Art. 6(1)(e) — public interest task / Art. 6(1)(b) — contract

Sporting transparency; limited fields

Gallery selfie photo search

Art. 6(1)(a) — consent; Art. 9(2)(a) — explicit consent for biometric data

nly to show your photos from the event; no registration required

Email notices (registration, reminders, payment confirmation)

Art. 6(1)(b)

Necessary to perform registration

Contact form

Art. 6(1)(b) or Art. 6(1)(f) — legitimate interest / pre-contract steps

Answering enquiries

Security and abuse prevention (rate limits, honeypot, logs)

Art. 6(1)(f) — legitimate interest

Protecting the Website and participants

Content administration (Filament admin panels)

Art. 6(1)(b) and Art. 6(1)(f)

Authorised staff only

Promoting the event (photos, names in media)

Art. 6(1)(a) — consent / Art. 6(1)(f) — legitimate interest

Per Participation Terms and separate consent where required

Legal compliance

Art. 6(1)(c)

e.g. accounting, authority requests

Profiling and automated decisions with legal or similarly significant effects under GDPR Art. 22: we do not use these.

Direct marketing: we do not send promotional newsletters through the Website. Emails are transactional (registration, payment) unless you explicitly opt in elsewhere.

5. Sources of data

  • Directly from you

    — registration form, contact form, account login.

  • Automatically

    — technical logs, session/cookies (see § 9).

  • Payment operators

    — transaction status and reference (not full card data).

  • MyRacePix

    (if configured) — photos linked to bib number when searching the gallery.

  • Administrative staff

    — manual corrections, bib assignment, race-pack check-in notes.

  • Directly from you (gallery) — selfie and consent checkbox when using “search by selfie”.

6. Recipients and processors

Data may be disclosed to:

Recipient

Role

Data

KBC Bank / UPC (online payment)

Independent controller / payment operator

Card and transaction data — only with them

Borica AD (if enabled)

Payment operator

As above

Hosting provider

Processor under contract

Website content, database, logs

Email provider (SMTP)

Processor

Email address, message content

MyRacePix

Processor / independent controller for photos

Bib number for bib search; selfies, face embeddings and matches for selfie search; photo hosting and AI infrastructure

YouTube / Google

When playing embedded video

Technical data when the player runs

Authorised administrators (Filament CMS & marathon panel)

Internal

Data needed to run the event

Public authorities

Where required by law

As mandated

Processors are bound by Art. 28 GDPR agreements (or appropriate safeguards for transfers outside the EEA).

Publicly available data: after payment and bib assignment, the “Participants” list shows bib number, name, distance, country — not email, phone, or address.

7. Transfers outside the EEA

Primary processing is in the EU/Bulgaria. If services use servers outside the EEA (e.g. email, MyRacePix, YouTube), transfers rely on:

  • an adequacy decision, or

  • EU Standard Contractual Clauses

    , or

  • other GDPR Chapter V mechanisms.

You may request details at info@marathonvarna42km.com.

8. Retention periods

Data

Period (indicative)

Registration for active edition

Until the edition ends + accounting/claims period (often up to 5 years after the financial year unless law requires longer)

Unpaid/expired registrations

Until cancellation + short technical archive/log period

Payments and accounting records

Under the Bulgarian Accounting Act (min. 5 years)

Contact messages

Until the thread is closed + up to 2 years unless disputed

Server logs

Usually 30–90 days unless investigating an incident

Sessions

Until session expiry (default up to 120 minutes inactive) or logout

Gallery/media photos

Per Participation Terms and legitimate interest in promotion; deletion requests assessed where no legal basis remains

Selfie submitted for gallery search

Not stored on the Site after the request; at MyRacePix — per their policy (typically short-lived processing for the search)

After retention expires, data is deleted or anonymised.

9. Cookies and similar technologies

9.1. What we use

Type

Name / mechanism

Purpose

Consent

Strictly necessary

Laravel session (laravel_session, etc.)

Login, registration, CSRF, locale

Not required (ePrivacy — essential)

Functional (local)

localStorage — marathon-theme

Light/dark theme preference

Does not identify you

Admin panel

Filament cookies

Administrators only

Not applicable to visitors

YouTube embed

Google cookies when playing

Video content

Inform users; embed via youtube-nocookie.com where possible

Analytics and marketing cookies (Google Analytics, Google Ads, Facebook Pixel): used only after explicit consent from the user via Klaro Consent Manager. See sections 9.2–9.4 for details.

Type

Name / mechanism

Purpose

Consent

Analytics

Google Analytics (_ga, _ga_*, _gid)

Anonymous visit statistics — number of visitors, session duration, traffic sources

Required — loaded only after explicit consent via Klaro

Marketing

Google Ads (_gcl_*, _gac_*)

Conversion tracking and remarketing via Google Ads

Required — loaded only after explicit consent via Klaro

Marketing

Facebook Pixel (_fbp, _fbc)

Conversion tracking and remarketing via Meta/Facebook

Required — loaded only after explicit consent via Klaro

Consent

Klaro (klaro)

Stores the user's cookie consent preferences

Not required (Art. 5(3) ePrivacy — strictly necessary)

9.2. Analytics and Marketing Cookies

The Website uses Google Analytics 4 to collect anonymous visit statistics (number of visits, session duration, geographic region, device and traffic sources). The data is used solely to improve content and user experience. Google Analytics does not collect personal data without your explicit consent.

For advertising purposes we use Google Ads and Facebook Pixel (Meta). These services track conversions (e.g. successful registrations) and enable remarketing — showing ads to users who have already visited the Website.

All analytics and marketing cookies are loaded only after explicit consent on your part via the cookie banner (Klaro Consent Manager). You can change your preferences at any time using the 🍪 icon in the bottom-left corner of the screen.

The Website uses Google Consent Mode v2, which ensures that:

  • Before consent: no data is sent to Google or Meta

  • Upon decline: cookies of the respective services are automatically deleted

  • Upon acceptance: only the categories you have selected are activated

For users in the European Economic Area (EEA), the United Kingdom and Switzerland, all marketing and analytics cookies are denied by default until explicit consent is obtained, in accordance with GDPR and the ePrivacy Directive.

The klaro cookie stores your consent preferences (which services you have accepted and which you have declined). It is valid for 365 days and is strictly necessary for the operation of the cookie consent mechanism, therefore it does not require consent (Art. 5(3) of the ePrivacy Directive).

9.5. Control

You can delete cookies in your browser settings. Blocking strictly necessary cookies may prevent registration and payment.

10. Security

We apply appropriate technical and organisational measures, including:

  • HTTPS encryption;

  • password hashing;

  • restricted admin access (roles);

  • rate limiting on forms;

  • honeypot and timing checks on the contact form;

  • signed temporary profile links (magic links);

  • backups and software updates.

In a personal data breach, we will notify the supervisory authority and affected individuals when required by GDPR.

11. Your rights

Subject to GDPR and Bulgarian law, you have the right to:

1. Access (Art. 15) — a copy of your data.

2. Rectification (Art. 16) — inaccurate or incomplete data.

3. Erasure (Art. 17) — “right to be forgotten” where no legal basis to retain remains.

4. Restriction (Art. 18) — while accuracy is contested or processing is unlawful.

5. Portability (Art. 20) — structured format where processing is automated and contract-based.

6. Object (Art. 21) — to processing based on legitimate interests, including the public list where applicable.

7. Withdraw consent (Art. 7(3)) — without affecting lawfulness before withdrawal.

8. Lodge a complaint with a supervisory authority.

How to exercise rights: email info@marathonvarna42km.com or registration@marathonvarna42km.com with your request and identification details. We respond within 1 month (extendable by 2 months in complex cases).

Supervisory authority in Bulgaria:

Commission for Personal Data Protection (CPDP)

2 Prof. Tsvetan Lazarov Blvd., Sofia 1592

www.cpdp.bg | kzld@cpdp.bg

12. Automated decision-making

We do not make automated decisions with legal effects on you. Bib assignment and statuses follow system rules and/or administrator action.

Selfie search uses automated face matching in photos but does not result in refusal of entry, scoring or any other decision with legal or similar significant effect — only a list of gallery photos.

  • Passwords

    are stored encrypted; we do not store them in plain text.

  • Magic links

    (signed URLs) provide temporary account access without a password until a set expiry (linked to registration/event end). Do not share the link.

  • For

    forgotten passwords

    , contact registration@marathonvarna42km.com (a self-service flow may be added on the Website).

14. Contact form and anti-spam

We process: name, email, topic, message.

We use a honeypot field, minimum completion time, and rate limiting. Suspicious submissions are blocked and may be logged without sending email.

15. Changes to this Policy

Updates are published on this page with a new date. Material changes may be highlighted on the Website.

16. Contact

info@marathonvarna42km.com — privacy and general enquiries

registration@marathonvarna42km.com — registrations and account

With the support of