Privacy Policy

Last updated: 24 July 2026

SerbiaRun is dedicated to protecting privacy and personal data. This Privacy Policy explains how we collect, use, store, share, and protect information when you use the SerbiaRun public website and related services (the “Service”).

It is drafted with practical alignment to principles found in the EU General Data Protection Regulation (GDPR) and applicable rules in the Republic of Serbia. It does not replace advice from a qualified lawyer or a formal data-protection assessment.

By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service. Read this together with our Terms of Use and Cookie Policy.

1. Who we are

For platform operations, SerbiaRun acts as operator of the Service. For registration data submitted for a specific event, the event Organizer typically acts as controller (or joint controller) of that registration data, while SerbiaRun processes it as platform provider to deliver registration, lists, and related features.

This Policy covers personal data obtained through the SerbiaRun public website (event discovery, registration, public lists, results, Organizer pages, and account flows). It does not govern how independent Organizers process data in their own systems after export, except as described here for platform sharing.

Contact for privacy requests: serbiarun.info@gmail.com.

2. Interpretation

“Personal Data” means any information relating to an identified or identifiable natural person (for example name, email, or online identifiers).

“You” means the individual who uses the Service as a visitor, account holder, or (prospective) Participant.

“Organizer” means the person or organization managing an event on SerbiaRun.

“Service Providers” means third parties that process data on our behalf (for example hosting, database, and authentication providers such as infrastructure used with Supabase).

3. Categories of personal data we acquire

We acquire personal data from you directly, automatically, and — where applicable — from Organizers or authentication providers, and we may combine sources.

3.1 Information you provide directly

Account and authentication data: email address and profile fields needed to create and maintain a sign-in session (for example display name supplied via authentication).

Registration data: fields on an event form, which may include personal details (first name, last name, date of birth), contact details (email, phone), and other Organizer-defined fields (club, category, emergency contact, preferences, etc.).

Support communications: content of emails or messages you send to serbiarun.info@gmail.com.

Preference choices: language and theme selections.

3.2 Information collected automatically

Technical and usage data such as IP address, browser type and version, device type, pages viewed, timestamps, approximate session diagnostics, and security logs.

Strictly necessary / functional cookies and local storage for authentication and for language/theme preferences, as described in the Cookie Policy. These preference cookies are inherent to expected Service behaviour and are not used for advertising.

3.3 Information from other sources

Authentication providers may supply identifiers needed to sign you in.

Organizers may configure which registration fields exist and which are publicly visible; they instruct the platform on event-specific collection.

4. Public visibility of certain Participant data

After entry into the system, fields the Organizer marks as publicly visible (commonly name fields, and any other enabled public fields) may be shown on public registration lists, results, and related event pages inside SerbiaRun.

This mirrors common practice for start lists and race results. By registering, you understand that those Organizer-enabled public fields may be publicly displayed.

SerbiaRun does not sell personal data and does not distribute registration data to parties for whom it was not intended at entry.

5. How we use personal data and legal bases

We may process personal data to: operate and secure the Service; create and authenticate accounts; enable event discovery; receive and store registrations; share registrations with the relevant Organizer; display public lists and results where published; remember language and theme; diagnose errors; respond to requests; improve reliability; and comply with law.

Depending on context, legal bases include: performance of a contract or steps prior to a contract (Art. 6(1)(b) GDPR principles); legitimate interests in running a secure sporting-events platform (Art. 6(1)(f)); consent where required (Art. 6(1)(a)), for example if optional analytics cookies are introduced later; and legal obligation (Art. 6(1)(c)) where applicable.

Where we rely on consent, you may withdraw it without affecting the lawfulness of prior processing.

6. How we disclose personal data

Organizers: receive registration data for events you register for, so they can administer participation.

Service Providers: hosting, database, authentication, email delivery, and similar processors acting on our instructions.

Legal and safety disclosures: when required by law, or where reasonably necessary to protect rights, safety, or integrity of users, Organizers, or the Service.

Business transfers: if SerbiaRun is involved in a merger, acquisition, or asset transfer, data may transfer to a successor with appropriate notice where required.

With your direction or consent: any other sharing only when you ask for it or agree to it.

We do not sell personal data as a product.

7. International transfers

SerbiaRun is oriented to users in Serbia. Infrastructure providers may process data on servers in the EU or other countries.

Where legally required for transfers outside jurisdictions deemed adequate, we rely on appropriate safeguards available through providers (for example contractual clauses).

8. Retention

We retain personal data only as long as reasonably necessary for the purposes above, including event administration support, security, dispute handling, backups, and legal retention.

Account data is kept while the account is active and then deleted or minimized after a validated deletion request, subject to lawful backup cycles.

Registration and results data may remain visible or archived for historical sporting records where published; Organizers may apply their own retention rules after they receive data.

Technical logs are typically rotated on shorter cycles unless needed for security or law.

Exact timelines may evolve as the product matures; material changes will be reflected in updates to this Policy.

9. Security

We implement reasonable technical and organizational measures appropriate to a portal of this kind (access controls, encrypted transport where standard, provider security features, and minimization where practical).

No method of transmission or storage is 100% secure. Measures do not cover force majeure, sabotage, or failures outside our reasonable control.

10. Your rights

Subject to applicable law (including GDPR-style rights where they apply to you), you may have rights to: be informed; access; rectify; erase (“right to be forgotten”); restrict processing; data portability; object; withdraw consent; and lodge a complaint with a supervisory authority.

These rights may be limited in some cases (for example where we must retain data for legal claims or mandatory retention).

To exercise rights related to SerbiaRun platform data, email serbiarun.info@gmail.com. For deletion, state which event and/or account the request concerns.

For registration data held primarily by an Organizer, contact that Organizer as well; we will help route requests where appropriate.

11. Children

The Service is not directed at children without appropriate adult involvement. We do not knowingly collect personal data from children in violation of applicable law.

Where a minor is registered, a parent or guardian should submit the data and confirm they are authorized to do so. For EU-style rules, verifiable parental consent may be required below the applicable digital-consent age.

12. Cookies and similar technologies

We use cookies and local storage as described in our Cookie Policy. Currently we use strictly necessary / functional technologies for authentication and language/theme preferences. We do not currently require a marketing-cookie banner because we do not deploy optional advertising analytics by default.

If we add optional analytics or advertising cookies later, we will update the Cookie Policy and Privacy Policy and obtain consent where required before enabling them.

13. Links to other websites

The Service may link to third-party sites (including other SerbiaRun products or Organizer pages). Their privacy practices are their own; review their policies separately. We assume no responsibility for third-party privacy compliance beyond our own Service.

14. Automated decision-making

We do not use personal data for solely automated decisions that produce legal or similarly significant effects about you within the meaning of GDPR Art. 22, except as may be required for basic fraud/security filtering of abusive traffic.

15. Changes to this Privacy Policy

We may update this Policy from time to time. The updated version will be posted on the Service with a new “Last updated” date. We invite you to review it regularly. Significant changes that require consent will be handled as required by law.

Continued use of the Service after an update constitutes acknowledgment of the updated Policy where permitted by law.

16. Contact

Privacy questions, complaints, or rights requests: serbiarun.info@gmail.com.

We aim to respond as soon as possible and within applicable statutory timeframes (commonly up to one month for access-style requests, subject to complexity and identity verification).

If issues remain unresolved, you may lodge a complaint with the competent supervisory authority in your country of residence or in Serbia, as applicable.