TRIDATA
Privacy Policy
Last updated: 25 September 2026 · English
This notice covers the Tridata public demo at tridata.vyramo.com and its sign-in service at tridata-auth.vyramo.com. Tridata helps people find races, compare results, explore athlete histories and manage their own participation and athlete claims.
Who is responsible
The controller responsible for the processing described here is:
Gotsch Joel JulienPrivate business based in Austria
Hammer-Purgstallgasse 1/12
1020 Wien, Austria
tridata@joelgotsch.com
Information we use
- Account and sign-in information. Our sign-in service, Authentik, handles your email address, account name and authentication information. Tridata stores an account identifier, display name, language preference, role and session information. It also stores membership grants, their validity periods, and administrator grant/revocation reasons and audit records. The sign-in service also records your confirmation that you are at least 18; we do not ask for a date of birth for registration. Email-and-password registration also involves password credentials managed by Authentik.
- Google sign-in. If you choose Google, we receive your Google account identifier and basic profile information, including your name and email address, to create or authenticate your account. We do not request access to your Gmail messages, contacts or Google Drive files. Google sign-in does not prove that an athlete result belongs to you.
- Race results and athlete history. We import race and result records from the previous Tridata service and race-result sources. These can include athlete names, categories, clubs, nationality, race dates, distances, placements, finish and split times, status and points. We retain source records (which may also contain birth year or city) and matching evidence so we can investigate errors and preserve the history of corrections.
- Information you submit. This includes saved races, participation and visibility choices, athlete claims, the evidence you provide, requests to combine athlete records, and messages sent to the operator.
- Technical information. Operating and security logs can include IP addresses, request paths, timestamps, response status and authentication events. Sessions and preferences use cookies or browser storage.
Why we use it
We use account information to provide sign-in, preferences and account features; claim information to check ownership and review duplicate records; and race information to display results, histories and comparisons. Technical records help us operate, troubleshoot and protect the service. Account email may be used for verification, recovery and service messages.
Account registration, eligibility, preferences and requested account features are processed to provide the service under Article 6(1)(b) GDPR. Maintaining and correcting the race archive, reviewing identity links and protecting the service rely on our legitimate interests under Article 6(1)(f) GDPR. Those interests are an accurate, useful sporting record and prevention of misuse. You can object to processing based on legitimate interests, including the publication of your results. Where a specific legal obligation requires processing, Article 6(1)(c) GDPR applies.
What is public
Race results and athlete profiles can be read without an account. An athlete profile can exist even if that athlete has never registered. Public results may also be downloaded as CSV files. Account credentials and claim evidence are not part of those public exports. Participation visibility is separate: items saved as private are restricted to your account and authorized operators.
Services involved
- Self-hosted application, database and Authentik services provide Tridata and sign-in.
- Proton AG (Switzerland) delivers account messages; email providers process the addresses and message content needed for delivery.
- Backups are stored locally, with encrypted offsite copies at Hetzner Online GmbH (Germany) for recovery.
- Course maps request map data from OpenFreeMap and terrain data from Mapterhorn. When a map loads, these providers receive technical connection data such as your IP address and the map tiles requested.
- Google processes sign-in requests when you select Google. Its handling of data is described in the Google Privacy Policy.
These services may process connection or account data outside the European Economic Area. Google describes its international-transfer arrangements, including adequacy decisions and standard contractual clauses, in its data transfer documentation. The linked provider policies explain their own processing. Contact us for information about the providers and safeguards relevant to your request. We do not sell Google account information or use it for advertising or training AI models.
Cookies and browser storage
The Tridata session cookie supports sign-in and expires after eight hours. A language preference cookie can last one year. The interface also remembers its color scheme in browser storage. Authentik uses its own session and sign-in protections on the authentication domain; the public sign-in session lasts seven days. The current Tridata application does not include advertising or audience-tracking integrations.
Retention and corrections
Account and submitted records currently remain in the service until an operator handles a deletion or correction request. Cancelling a claim changes its status; it does not erase the request or evidence. Historical source records and review history are retained to support corrections and trace the origin of results. Backup rotation does not automatically delete primary records. Ordinary central operating logs normally have a 90-day retention period, with longer retention for designated security records. Local database recovery copies are retained for 30 days, or 90 days for the sign-in service. Selected encrypted offsite backups are retained for up to three yearly snapshots; deleting live information does not immediately remove it from those recovery copies. If recovery requires restoring an older backup, the operator must reapply completed deletion and restriction requests before reopening the recovered service.
Your choices and rights
You can change your language in Account → Settings and remove saved participations. Contact the operator to request access to your information, correction, deletion, restriction or an export, or to object to processing. These rights depend on applicable law and the circumstances. We may need to verify your identity without collecting more information than necessary. There is currently no self-service account deletion button.
Removing an account does not by itself determine whether an independently sourced public race result should be removed; we consider requests about those records separately. Where applicable, you can complain to your data protection authority, including the Austrian Data Protection Authority. Scores and suggested athlete links support sports information and review; they are not decisions about access to credit, employment or insurance.
Age requirement
Registration is limited to people aged 18 or over. The sign-up confirmation is a declaration, not an identity-document or age-verification service. Historical race records are imported independently of account registration; the age requirement does not mean every person in those records is an adult. Contact us about an underage account or a concern about a published record.
Changes to this notice
We will update this page when the service or its data handling changes and show the revision date above.