Privacy Policy and Data Policy

This covers how your data is used along with what we will, and what we wont, do with it.

In this document, "we" or "our" refers to Athlete Manager, "you" refers to you and your account and "group" and "club" can be used interchangeably to mean any organisation or charitable cause that is associated with Special Olympics GB.


Interactions with Athlete Manager

  1. Upon Login or Failed Login
    1. Your IP address will be recorded.
    2. A fingerprint of your browser will be taken.
  2. Interacting with the API
    1. Each interaction with the API is logged.
    2. The date, time, origin IP, endpoint, result (success, fail, other) will be recorded.
  3. We may will store a finger print of your device.

Cookie Use

  1. Upon Login
    1. Cookies will be set for the duration of the session.
    2. An additional cookie will be set if you select 'Remember Me'.
      1. Upon returning to the website, you will be logged back in automatically so long has the cookie has not expired or been remotely frozen or deleted.
      2. If you select to logout when you have previously selected 'Remember Me', you will be logged out but will only be required to enter your password when you return. This will also display the first letter of your email and the domain.
  2. Social Cookies
    1. No social cookies or social media plugins will be used.

Information and Data

  1. Sensitive data on the system is encrypted.
    1. Sensitive data is defined is defined by us as any data that would lead to distress or discomfort to an individual if disclosed.
    2. Sensitive data may fall under Special Category Data under GDPR; in the case of Athlete Manager this is because some data is likely to be relevant to health.
    3. Our condition for processing special category data is legitimate interest.
      1. The legitimate interest of processing it to enable the day to day functioning of clubs whilst ensuring that the relevant information to protect individuals can be collected, stored and used appropriately.
      2. Some information, such as information relating to disabilities, is required so groups can be sure they have the complete picture when it comes to those involved in their group.
      3. Some medical questions are required, this ensures that the individual can be protected and that the most up to date information is held.
        1. For example, information about allergies would need to be collected so mitigations can be put in place for the individual.
      4. Under our terms and conditions, groups cannot create forms that are excessive. It is unlikely a group would collect excessive data as it would not benefit the group in any way.
  2. You will not try to access the data of others except for Whitehat testing. Even so, explicit access to sensitive data is forbidden
  3. Your information can be accessed by groups you are part of as long as they have a reasonable need to access the information. For example, if you are a volunteer at a club they will be able to see your contact details**.
  4. You can read our Data Protection Impact Assessment.

Sharing Data

  1. We don't share data with other companies with the exception of Twilio for SMS purposes and Stripe for payment purposes.
  2. We don't allow social plugins on Athlete Manager.
  3. You accept that aggregated data about regions is available to regional level volunteers and national level volunteers.
  4. You accept that aggregated data about groups may be made available to regional and national level volunteers.
  5. Personal contact details will never be shared widely unless an individual is the public point of contact for a group or region and has chosen to share that information.
  6. We will never share your email address or phone number. If this changes, it will be an explicit opt-in process for others to view your contact details.

Deleting Data

  1. Your data is automatically deleted when your account with a club is closed.
  2. Deleted files may take 24 hours to be removed from the system.

External Sites

  1. Athlete Manager does not take responsibility for the content of external sites.

Security

  1. All communication with Athlete Manager will use HTTPS.
  2. Individuals are responsible for ensuring that their devices are virus free.
  3. Individuals should use the Two Factor Authentication feature that is provided.
  4. We will retain logs of interactions with the API as well as with connections made to the servers.
    1. This information will be analysed to identify suspicious activity.
    2. 'Machine Learning' may be used to identify trends in the data.

      Access Rights

      1. We will use access rights in order to protect access to the more sensitive functions and data on Athlete Manager.

      Athlete Manager Data Access

      1. Athlete Manager reserves the right to access the data of clubs in order to provide support.
      2. Athlete Manager reserves the right to access the data of individuals in order to provide support.

      Forms

      1. Groups can create their own forms for use within the group or for events.
        1. The forms must be marked sensitive if they are sensitive.
        2. Volunteers, and those with access to the forms, must not disclose the data within the forms to those without a valid 'need-to-know'.
      2. The data within forms can be queried to return only those who gave a specific answer to a question.
      3. The data from any forms that were filled out is deleted if that individual is removed from the group.
      4. If you feel like a form is too broad or not appropriate, you can report it - you'll be kept anonymous.

      System Location, Backups & Breaches

      1. We will use computers hosted in Europe.
      2. Backups will be taken at least once a day.
      3. Backups may be encrypted and uploaded to the cloud.
      4. Backups may be kept on a USB so long as the USB is encrypted.
      5. Data breach
        1. We will restore from a known clean backup.
        2. We will never pay a ransom.
        3. We may contact government agencies, such as the NCSC and ICO, for assistance.
        4. You will be notified as soon as possible about a breach.