UWR Portal Privacy Policy
This UWR Portal Privacy Policy (hereinafter the "Policy") is intended to inform you in compliance with the General Data Protection Regulation 679/2016 ("GDPR") and its respective obligations about the way we collect and use your Personal Data as well as your rights when you use UWR Portal owned by Atlantis Sports, a Colorado Not-For-Profit Organization of the United States, PO Box 740233 Arvada, CO 80006 ("Atlantis", "we", "us") contactable at data@atlantissports.org. The website https://uwrportal.com and the mobile application UWR Portal, are the online gateways to the digital platform UWR Portal (hereinafter the "Platform").
Please note that the terms used in this Policy reflect the meaning bestowed in GDPR. While conforming specifically to GDPR, this Policy also follows the consumer privacy precepts as described in the California Consumer Privacy Act (“CCPA”) even though the business nature of Atlantis exempts us from actually being governed by the CCPA. It is of the utmost importance for Atlantis to protect our users' privacy rights and to put the control over their personal data into our users' hands.
2.1. This Policy applies to any person (a “user”) that navigates or opens an Account in the Platform irrespective of their role in an Event (e.g. Tournament Owner, Contributor, Event Helper, Tournament Referee, Referee Helper, Team Organizer, Team Manager, Player, Referee, Time and Score Keeper, Spectator) or Program/Club (e.g. Admins, Leaders, Helpers, Participants, Spectators) and the processing of their Personal Data by Atlantis Sports with its role as a Data Controller.
2.2. This Policy does not include and does not refer to the processing of data carried out by the persons or entities that use the Platform to organize Events as Tournament Organizers or Team Organizers of Events or Admins of Programs/Clubs as Data Controllers (e.g. T-Shirt size, Dietary restrictions etc) under which we act as Data Processor (on behalf of the specific criteria set out by the respective entity according to the needs of the terms of the Event/Program and the configurations that the Platform makes regarding the Events or Programs). Each of the said entities bears the liability for the lawful processing of your Personal Data and you need to address to the respective Tournament Owner, Team Organizer or Admin for the Event or Program/Club led by them. In any case we do not collect or process health data as Data Controllers.
2.3. Personal Data means any information that relates to you as a natural person that you provide or that we collect about you related to the use of the Platform and/or its provided services. All other information regarding legal persons is not considered as Personal Data and this Privacy Policy does not apply to them.
Atlantis Sports does not permit self-registration by minors. If the individual is under 18, a parent or legal guardian must first create their own account and then add the minor as a dependent. We collect parental/guardian consent, confirm via email, and maintain timestamped consent records (guardian identity, email address, dependent linkage, IP/time). Guardians may withdraw consent at any time by deleting their dependent's profile and/or their own profile; at which point we will disable the dependent's profile and delete the dependent's personal data, subject to legal retention requirements. For jurisdictions with specific age thresholds (e.g., U.S. COPPA <13; GDPR child-consent age 13-16), we apply the stricter rule in addition to our global under-18 requirement.
If you are underaged, your guardian shall introduce your Personal Data on your behalf in the respective forms. By filling in your Personal Data, you and your guardian state that you have read this Policy. In case you participate in UWR Events or Programs/Clubs, you need to first sign the Waiver.
4.1. Atlantis Sports acts as the Data Controller solely regarding the processing of your Personal Data as set out in this Policy and restrictively for the respective purposes as referred in the table below.
4.2. When we act as the Data Controller, as above, we determine the purposes and means of the processing of your Personal Data i.e. the why and how of the processing.
4.3. Contact: You may communicate with us anytime by using the Contact us form introduced in the footer of the Platform or by sending us an e-mail to data@atlantissports.org regarding any issue or question regarding the processing of your Personal Data or this Policy.
We collect your Personal Data:
- From you when you:
- Introduce them in the forms provided in the respective steps you take to create your Account as necessary or optional;
- Accept an Invite and the Admin/Organizer necessitates more Personal Data according to the Event/Program/Club requirements based on the respective terms;
- Update them through the respective tools we provide you or when you accept an invitation to an Event/Program;
- Log in to your Account;
- Communicate with us by using the Contact us form or by sending us an e-mail.
- From third parties when:
- You sign in to the Platform with your Google, Facebook, or Apple account;
- You are underaged/Dependent and your guardian introduces the respective Personal Data on your behalf;
- Your Personal Data is introduced as an emergency contact.
- From automated means:
- Cookies are installed on your devices after you create an account. Our website uses only the minimum necessary Cookies to ensure its smooth operation.
In order to inform you about the purposes of processing your Personal Data, the respective categories necessary, the legal basis (legal grounds) of their processing and your respective rights activated we have introduced the table below to facilitate you.
Purpose of processing - Processing activities | Categories of Personal Data | Legal Basis | Rights | |
---|---|---|---|---|
1 | Prospect entities that show interest on underwater hockey | |||
Communication When you:
| Identification data (First name, Last name) Question/Comment | Consent We process your Personal Data when you communicate with us at your initiative to learn more information or express your interest by completing the Contact us form in order to respond to you based on your consent. Our response completes the purpose of processing. | Access Rectification Erasure Restriction Portability Withdrawal of consent | |
2 | Event organizers - Other participants | |||
Account creation to the Platform Public Account When you:
| Identification data (First name, Last name, Username/Nickname, Profile QR Code) Birth - year Log in Credentials Country of residence | Performance of contract We process your Personal Data when you create an Account on our platform. In addition, you need to create an Account to organize or participate in an Event/Program in order to fulfill our contractual obligations towards you according to the TCs to provide our services as presented through the Platform and to allow you to access and use them. In case you want to delete your Account, you can delete it and remove all your personal data by using the mobile app or request to have your account deleted at any time through our Contact form or by e-mail to data@atlantissports.org. | Access Rectification Erasure Restriction Portability | |
Account Picture (for the app) Access to Pictures in mobile Access to Documents in mobile | Consent If you choose to, you can upload a profile (avatar) picture, using your likeness or otherwise; we shall collect and process it in order to be displayed in your Account. Additionally, when you use the app, we shall ask you for your consent for the app to have access to Pictures and Documents in your mobile. You can use the settings of your mobile to withdraw consent. You can choose to delete your (avatar) picture at any time by using the respective tool. Until that time, we process it for the said purpose lawfully. | Access Rectification Erasure Restriction Portability Withdrawal of consent | ||
3 | Legal Age Verification | Birth - year | Legal Obligation We process your personal data in order to verify whether you are an adult or not and can be classified in adults' or underaged' based on our obligation to complete legal contracts. | Access Rectification Restriction |
4 | Age classification | Birth-year | Performance of contract We process your personal data in order to classify you according to your competitive age in order to provide you with the chance to participate in an appropriate team with your age according to UWH terms. | Access Rectification Erasure Restriction Portability |
5 | Security of access and use of the Platform When we:
| Credentials Activities' Logs Distinctive Role of the user | Legitimate interest We process your Personal Data to safeguard the access and use of your Account by the appropriate persons as well as to ensure the proper operation of the services of the Platform in order to prevent fraud and security breaches and to maintain the Platform's functionality as efficiently as possible. | Access Rectification Erasure Restriction Object |
6 | Communication of the Platform with the user When we: send You communication regarding notifications during Events or Programs/Clubs by using the notification tools of your Account | Username Event name Team name | Performance of contract We will communicate with you to notify about the Event/Program/Club information through the notifications tool incorporated in your Account. | Access Rectification Erasure Restriction Portability |
7 | Investigation of the incident of breach, provision of information and recording of the incident Should a data breach incident occur, we need to: a) investigate the incident and assess whether you were affected; b) communicate to inform you (if needed); c) In order to record the incident in the relevant internal registry. d)In order to inform the relevant data protection authority (if needed) and/or other competent authorities | Identification Data Communication Data (Telephone number) Data involved in the data breach incident | Compliance with legal obligation We Process your Personal Data to comply with our obligations with GDPR in case of a data breach in order to assess if the incident has affected you or there is a necessity to communicate with you individually to provide you guidance or to inform you regarding it, if it is necessary under the respective provisions. Also, we process them in order to record it internally. | Access Rectification Restriction |
Please note that:
- In your public Account the only Personal Data that appears before being invited in an Event is your Username and, if you choose to provide one, your (avatar) picture.
- In your Events/Programs Account appear the necessary information for you to participate in the Event/Program. If the event asks for your name and/or photo, you may choose to hide them from being displayed on the Platform if you do not wish for them to appear.
- When the processing of your Personal Data is based on your Consent, you may at any time withdraw it. The withdrawal of consent is valid for the future. The processing operations carried out up to the point in time of the withdrawal shall be deemed to be lawful in all respects.
- When we process your Personal Data on the legal basis of our Legitimate Interest, you may opt-out at any time (object), requesting that access to Personal Data is ceased for this purpose introducing your special condition that prevails their processing. We shall then fairly balance between our legitimate interest and the user's own interests in the protection of their Personal Data according to his/her compelling reasons.
- In case Atlantis Sports needs to support or defend against any legitimate claim, it may process your Personal Data based on its overriding Legitimate Interest, that has been fairly balanced against your privacy.
- Some of your Personal Data may be processed on the basis of our Legitimate Interest and our compliance with our legal obligation for other purposes, such as when we receive documents, requests, orders, writs/lawsuits, warrants, etc. from legal authorities or bodies, such as supervisory, prosecution, judicial, tax authorities, for the investigation of crimes and your protection against fraud or the fight against all forms of criminality and infringement of legal rights.
- When you register with third-party platforms' accounts as Google, Facebook, or Apple, the respective privacy policies for the protection of your Personal Data apply.
- You have the ability to edit or update your Personal Data through your Account.
Note: If you have lost your passwords or suspect that they are being used by a third not-authorized person, we would like you to change them immediately.
7.1. We will retain your Personal Data stored for the necessary period to fulfill the purposes for which they were collected. The retention periods for data may vary based on the specific purposes of collection and processing, taking into consideration factors such as the nature of the Personal Data, quantity, purpose, and security protocols, among others.
7.2. Among the rights you have according to GDPR is the right to request the deletion of your data. If you object to their processing or withdraw your consent, where those legal bases apply, we are obligated to delete the data and not retain it. However, we reserve the right to withhold your respective rights as analyzed in section 8 below.
7.3. Account: Your Account shall be retained until you request to close/delete it.
In order to exercise your rights, you need to send us an e-mail to data@atlantissports.org. To make it easier for you to exercise your rights, we provide below a detailed table of your rights and their respective explanations:
RIGHT of | WHAT IS IT? |
---|---|
Access | You have the right to request from us:
|
Rectification | You can request from us to rectify your false or inaccurate Personal Data or update them. In this context we have the right to verify the accuracy of the data before it rectifies them and is obliged to inform the recipient to whom Personal Data are notified, unless this proves impracticable or involves a disproportionate effort. |
Erasure | You can request the deletion of your Personal Data under the following circumstances:
However, we retain the right to deny this request if data processing is necessary for a) the original purpose of collection, b) compliance with a legal obligation, or c) establishing, exercising, or defending legal claims. Data deletion will occur once the specified conditions are met. |
Restriction | You can ask from us to exercise the right of restriction of the processing i.e. your Personal Data to be retained but not to be used when:
|
Portability | You have the right to ask us to provide you with your Personal Data in a structured form or you can request that they be transmitted directly to another data controller. A prerequisite is that your Personal Data must have been provided with consent and that they must be retained by automated means and not in paper form. A further condition is that the data have been provided by you; this term does not apply in case the data have been inferred by us based on data provided by you. |
Objection | You have the right to object to the processing of your personal data based on legitimate interest at any time. If you choose to exercise this right, we must provide compelling and legitimate reasons that outweigh your rights and freedoms, or are necessary for the establishment, exercise, or defense of legal claims, in order to continue the processing. |
Withdrawal of consent | You have the right to withdraw your consent, where consent is the basis of processing. You can withdraw your consent freely at any time with a request at the Contact us form or the e-mail data@atlantissports.org. The withdrawal of consent is valid for the future. |
Right to human intervention | We do not make decisions solely by using automated technical means to process your Personal Data that produce legal effects against you or similarly significantly affect you. Nor do we make your profiling through automated processing of Personal Data without human intervention. You have the right to request human intervention in decision-making through automated processing and to express your point of view on the decision. |
Supervisory authority/Alternative forms of dispute resolution | You have the right to submit your complaints or accusation to the local supervisory authority about your processing of Personal Data. Since the protection of your privacy is a priority for us, you can communicate with us at any time and for any issue or complaint regarding the processing of your Personal Data by using the Contact us form or the e-mail data@atlantissports.org. In addition, we suggest that you choose alternative dispute resolution - mediation as a more flexible means of resolving disputes between you and us. |
Aspect | Details |
---|---|
Verification | As we keep strict confidentiality of Personal Data, if you wish to exercise your rights, we may request certain information to confirm your identity in order to protect other users' rights. |
Specific Requests | In order to respond to you effectively, your request should contain accurate and truthful information. Requests lacking valid details may be refused if they are unfounded, excessive, abusive, or illegal. |
Timelines | We aim to address your valid and accurate requests within one (1) month of receipt, unless they are exceptionally complex or multiple requests have been submitted simultaneously. If we require more time to respond, we will notify you within the month and fulfill your rights within three (3) months. |
Charges | Exercising your rights related to Personal Data is generally free of charge. However, in specific cases where your access request is unfounded or excessive under the law, we may levy a reasonable fee. We will inform you of any charges before proceeding with your request. |
Contact | Feel free to reach out to us using Contact us form or the e-mail data@atlantissports.org. You can share your comments, questions, concerns, or complaints about this Policy and the overall collection and processing of your Personal Data. |
10.1. In case you register to your Account through your Google, Facebook, or Apple account, we process your Personal Data received by any of the said third parties acting both as Independent Controllers. This transfer is based on your consent to receive those Personal Data through Google, Facebook, or Apple and their privacy policies apply too.
10.2. We may share Your Personal Data through our Platform with third parties involved in the Events or Programs/Clubs you participate in. It is noted that your Personal Data can be disclosed only to the respective participants of each Event/Program and only such Personal Data that you choose to provide them.
10.3. We engage third-party suppliers as subcontractors (such as our hosting provider, website developers, etc.), after concluding the appropriate data processing agreements according to their role in the processing of your Personal Data.
10.4. Additionally, your Personal Data could be disclosed to law enforcement agencies and other administrative authorities under their request or mandate according to relevant laws.
When we need to transfer your Personal Data to a third country outside EU/EEA or to a country that has no adequacy decision or an entity that is not included in the Data Privacy Framework list, we adhere to GDPR obligations linked to transfers and take all appropriate safeguards regarding transfers of your Personal Data according to GDPR, such as the conclusion of the appropriate Standard Contractual Clauses (SCCs) and implement all necessary contractual, technical, and organizational measures to fulfill these obligations. Authorized personnel may remotely access EU-hosted data under least-privilege, MFA, and access logging.
We implement and employ a range of suitable technical and organizational measures to secure your Personal Data against unauthorized access, use, alteration, or destruction. If and when applicable, we indicatively use pseudonymization or anonymization. In any case privacy by design and by default measures are applied on the function of the Platform.
13.1. We retain the right to modify this Policy at our discretion, primarily in response to new legal obligations or adjustments in our procedures concerning the processing of your personal data (e.g. when we introduce new services on our Platform or refine its scope, functions, or features).
13.2. If you continue to navigate our Platform or use its services, you acknowledge your acceptance of all such modifications. We encourage you to carefully review this Policy and periodically check for updates to stay informed about the protection of your Personal Data in accordance with this Policy.
13.3. Feel free to communicate with us if you require clarification, information, or have any reservations or questions taking into account that any information or clarification regarding changes to this Policy, provided as described above, does not serve as a replacement or an amendment to this Policy.