Website: marathonvarna42km.com
Last updated: 24 May 2026
1. Introduction
1.1. This Privacy Policy explains how STS Akademic (the “Controller”, “we”, “us”) — processes personal data when you use the official website and related online services (the “Website”).
1.2. Processing is carried out in accordance with:
Regulation (EU) 2016/679
(GDPR);
the Bulgarian
Personal Data Protection Act
;
other applicable EU and Bulgarian legislation.
1.3. This Policy supplements the Terms of Use and the Participation Terms for the relevant edition. Rules on the race itself (health, liability, media, etc.) are in the Participation Terms.
2. Data controller
Field | Value |
|---|---|
Name | *** |
UIC (EIK) | *** |
Address | *** |
Privacy / general enquiries | info@marathonvarna42km.com |
Registration enquiries | registration@marathonvarna42km.com |
Data Protection Officer (DPO): Bozhidar Iliev
To exercise GDPR rights, contact us using the emails above with the subject “Personal data”.
3. Categories of personal data we process
Depending on how you use the Website, we may process:
Category | Examples | When collected |
|---|---|---|
Identity & contact | First, middle, last name, email, phone, city, country | Registration, contact form |
Participation | Sex, year of birth, distance, team, T-shirt size, bib number, public UID, registration status | Registration and event operations |
Payment | Amount, currency, payment status, transaction reference, method | Online or recorded payment |
Account | Password (hashed), language, time of terms acceptance | Registration and login |
Sports / federation | BFLA registry card (42 km marathon) | Registration for that distance |
Technical | IP address, session, logs, user agent, timestamps | Every visit |
Communication | Message body, topic | Contact form |
Media | Race photos/videos, bib search in gallery | Event, galleries, MyRacePix |
Biometric / facial (selfie) | Face photo for search; face embedding (vector) — at MyRacePix | Only when you voluntarily use “selfie search” in the gallery, after consent |
Special categories (health, biometrics under GDPR Art. 9): we do not require or purposefully collect these via the Website. Health declarations in the Participation Terms are the participant’s responsibility when taking part in the event, not a separate health database on the Website.
Children: online registration is available to persons aged 16 or over. For younger participants, registration should be completed by a parent/guardian outside the standard online flow — please contact us.
3.1. Selfie photo search (facial recognition)
When the “Find your photos with one selfie” feature is enabled for an event gallery, you may voluntarily upload one photo of your face (a selfie) to find race photos you appear in.
Aspect | Description |
|---|---|
What you upload | One image (JPG, PNG or WebP, up to 5 MB) showing your face |
What we do not require | Registration, account or bib number for this feature |
How it works | The image is sent to MyRacePix (processor), which extracts a mathematical face embedding and compares it with faces already indexed from event photos. Matching images are shown in the gallery |
What we do not store on the Site | The selfie is not saved in the marathonvarna42km.com database after the request completes |
Consent | The feature is available only after you tick explicit consent in the form and follow the link to this policy |
Legal basis | Art. 6(1)(a) GDPR — consent (separate from race registration) |
Withdrawal | Do not upload a selfie if you do not want processing; the Site does not retain uploaded selfies. For requests under Section 11 (access, erasure, etc.) — info@marathonvarna42km.com |
Automated decision-making | Results are technical face matches in photos; they do not produce legal or similarly significant effects under Art. 22 GDPR |
Biometric data | Processing may involve biometric data under Art. 9 GDPR (facial recognition). The basis is your explicit consent (Art. 9(2)(a)) via the form checkbox, solely to “find my photos from this event” |
Retention: the selfie and temporary technical data from the request are processed only for the duration of the search (seconds to minutes) and are not kept for marketing or profiling.
Recipients: MyRacePix and its sub-processors (photo hosting, AI/embedder infrastructure — e.g. servers in the EU/EEA or outside with Chapter V safeguards). Details: info@marathonvarna42km.com.
Rate limiting: request limits per IP address apply to prevent abuse (e.g. 10 searches per minute).
4. Purposes and legal bases (GDPR Art. 6)
Purpose | Legal basis | Notes |
|---|---|---|
Online registration and performance of the participation contract | Art. 6(1)(b) — contract | Registration fields, account, confirmations |
Online fee payment | Art. 6(1)(b) and Art. 6(1)(c) — legal obligation (accounting) | Payments, invoicing/reporting where applicable |
Public participant list (name, bib, distance, country) | Art. 6(1)(e) — public interest task / Art. 6(1)(b) — contract | Sporting transparency; limited fields |
Gallery selfie photo search | Art. 6(1)(a) — consent; Art. 9(2)(a) — explicit consent for biometric data | nly to show your photos from the event; no registration required |
Email notices (registration, reminders, payment confirmation) | Art. 6(1)(b) | Necessary to perform registration |
Contact form | Art. 6(1)(b) or Art. 6(1)(f) — legitimate interest / pre-contract steps | Answering enquiries |
Security and abuse prevention (rate limits, honeypot, logs) | Art. 6(1)(f) — legitimate interest | Protecting the Website and participants |
Content administration (Filament admin panels) | Art. 6(1)(b) and Art. 6(1)(f) | Authorised staff only |
Promoting the event (photos, names in media) | Art. 6(1)(a) — consent / Art. 6(1)(f) — legitimate interest | Per Participation Terms and separate consent where required |
Legal compliance | Art. 6(1)(c) | e.g. accounting, authority requests |
Profiling and automated decisions with legal or similarly significant effects under GDPR Art. 22: we do not use these.
Direct marketing: we do not send promotional newsletters through the Website. Emails are transactional (registration, payment) unless you explicitly opt in elsewhere.
5. Sources of data
Directly from you
— registration form, contact form, account login.
Automatically
— technical logs, session/cookies (see § 9).
Payment operators
— transaction status and reference (not full card data).
MyRacePix
(if configured) — photos linked to bib number when searching the gallery.
Administrative staff
— manual corrections, bib assignment, race-pack check-in notes.
Directly from you (gallery) — selfie and consent checkbox when using “search by selfie”.
6. Recipients and processors
Data may be disclosed to:
Recipient | Role | Data |
|---|---|---|
KBC Bank / UPC (online payment) | Independent controller / payment operator | Card and transaction data — only with them |
Borica AD (if enabled) | Payment operator | As above |
Hosting provider | Processor under contract | Website content, database, logs |
Email provider (SMTP) | Processor | Email address, message content |
MyRacePix | Processor / independent controller for photos | Bib number for bib search; selfies, face embeddings and matches for selfie search; photo hosting and AI infrastructure |
YouTube / Google | When playing embedded video | Technical data when the player runs |
Authorised administrators (Filament CMS & marathon panel) | Internal | Data needed to run the event |
Public authorities | Where required by law | As mandated |
Processors are bound by Art. 28 GDPR agreements (or appropriate safeguards for transfers outside the EEA).
Publicly available data: after payment and bib assignment, the “Participants” list shows bib number, name, distance, country — not email, phone, or address.
7. Transfers outside the EEA
Primary processing is in the EU/Bulgaria. If services use servers outside the EEA (e.g. email, MyRacePix, YouTube), transfers rely on:
an adequacy decision, or
EU Standard Contractual Clauses
, or
other GDPR Chapter V mechanisms.
You may request details at info@marathonvarna42km.com.
8. Retention periods
Data | Period (indicative) |
|---|---|
Registration for active edition | Until the edition ends + accounting/claims period (often up to 5 years after the financial year unless law requires longer) |
Unpaid/expired registrations | Until cancellation + short technical archive/log period |
Payments and accounting records | Under the Bulgarian Accounting Act (min. 5 years) |
Contact messages | Until the thread is closed + up to 2 years unless disputed |
Server logs | Usually 30–90 days unless investigating an incident |
Sessions | Until session expiry (default up to 120 minutes inactive) or logout |
Gallery/media photos | Per Participation Terms and legitimate interest in promotion; deletion requests assessed where no legal basis remains |
Selfie submitted for gallery search | Not stored on the Site after the request; at MyRacePix — per their policy (typically short-lived processing for the search) |
After retention expires, data is deleted or anonymised.
9. Cookies and similar technologies
9.1. What we use
Type | Name / mechanism | Purpose | Consent |
|---|---|---|---|
Strictly necessary | Laravel session (laravel_session, etc.) | Login, registration, CSRF, locale | Not required (ePrivacy — essential) |
Functional (local) | localStorage — marathon-theme | Light/dark theme preference | Does not identify you |
Admin panel | Filament cookies | Administrators only | Not applicable to visitors |
YouTube embed | Google cookies when playing | Video content | Inform users; embed via youtube-nocookie.com where possible |
Analytics and marketing cookies (Google Analytics, Google Ads, Facebook Pixel): used only after explicit consent from the user via Klaro Consent Manager. See sections 9.2–9.4 for details.
Type | Name / mechanism | Purpose | Consent |
|---|---|---|---|
Analytics | Google Analytics ( | Anonymous visit statistics — number of visitors, session duration, traffic sources | Required — loaded only after explicit consent via Klaro |
Marketing | Google Ads ( | Conversion tracking and remarketing via Google Ads | Required — loaded only after explicit consent via Klaro |
Marketing | Facebook Pixel ( | Conversion tracking and remarketing via Meta/Facebook | Required — loaded only after explicit consent via Klaro |
Consent | Klaro ( | Stores the user's cookie consent preferences | Not required (Art. 5(3) ePrivacy — strictly necessary) |
9.2. Analytics and Marketing Cookies
The Website uses Google Analytics 4 to collect anonymous visit statistics (number of visits, session duration, geographic region, device and traffic sources). The data is used solely to improve content and user experience. Google Analytics does not collect personal data without your explicit consent.
For advertising purposes we use Google Ads and Facebook Pixel (Meta). These services track conversions (e.g. successful registrations) and enable remarketing — showing ads to users who have already visited the Website.
All analytics and marketing cookies are loaded only after explicit consent on your part via the cookie banner (Klaro Consent Manager). You can change your preferences at any time using the 🍪 icon in the bottom-left corner of the screen.
9.3. Consent Management (Consent Mode v2)
The Website uses Google Consent Mode v2, which ensures that:
Before consent: no data is sent to Google or Meta
Upon decline: cookies of the respective services are automatically deleted
Upon acceptance: only the categories you have selected are activated
For users in the European Economic Area (EEA), the United Kingdom and Switzerland, all marketing and analytics cookies are denied by default until explicit consent is obtained, in accordance with GDPR and the ePrivacy Directive.
9.4. Klaro Cookie
The klaro cookie stores your consent preferences (which services you have accepted and which you have declined). It is valid for 365 days and is strictly necessary for the operation of the cookie consent mechanism, therefore it does not require consent (Art. 5(3) of the ePrivacy Directive).
9.5. Control
You can delete cookies in your browser settings. Blocking strictly necessary cookies may prevent registration and payment.
10. Security
We apply appropriate technical and organisational measures, including:
HTTPS encryption;
password hashing;
restricted admin access (roles);
rate limiting on forms;
honeypot and timing checks on the contact form;
signed temporary profile links (magic links);
backups and software updates.
In a personal data breach, we will notify the supervisory authority and affected individuals when required by GDPR.
11. Your rights
Subject to GDPR and Bulgarian law, you have the right to:
1. Access (Art. 15) — a copy of your data.
2. Rectification (Art. 16) — inaccurate or incomplete data.
3. Erasure (Art. 17) — “right to be forgotten” where no legal basis to retain remains.
4. Restriction (Art. 18) — while accuracy is contested or processing is unlawful.
5. Portability (Art. 20) — structured format where processing is automated and contract-based.
6. Object (Art. 21) — to processing based on legitimate interests, including the public list where applicable.
7. Withdraw consent (Art. 7(3)) — without affecting lawfulness before withdrawal.
8. Lodge a complaint with a supervisory authority.
How to exercise rights: email info@marathonvarna42km.com or registration@marathonvarna42km.com with your request and identification details. We respond within 1 month (extendable by 2 months in complex cases).
Supervisory authority in Bulgaria:
Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd., Sofia 1592
www.cpdp.bg | kzld@cpdp.bg
12. Automated decision-making
We do not make automated decisions with legal effects on you. Bib assignment and statuses follow system rules and/or administrator action.
Selfie search uses automated face matching in photos but does not result in refusal of entry, scoring or any other decision with legal or similar significant effect — only a list of gallery photos.
13. Participant account, magic links, and passwords
Passwords
are stored encrypted; we do not store them in plain text.
Magic links
(signed URLs) provide temporary account access without a password until a set expiry (linked to registration/event end). Do not share the link.
For
forgotten passwords
, contact registration@marathonvarna42km.com (a self-service flow may be added on the Website).
14. Contact form and anti-spam
We process: name, email, topic, message.
We use a honeypot field, minimum completion time, and rate limiting. Suspicious submissions are blocked and may be logged without sending email.
15. Changes to this Policy
Updates are published on this page with a new date. Material changes may be highlighted on the Website.
16. Contact
info@marathonvarna42km.com — privacy and general enquiries
registration@marathonvarna42km.com — registrations and account