Loading...

Privacy Policy

Effective Date: 23rd May 2018.

Last updated: 11th Dec 2024

This privacy policy sets out how Alpha Business Systems Limited (“Alpha Timing”) uses and protects any information that you provide when you use this website or the following services: Alpha Race Pro Online Entry System, Alpha Flow booking system, Alpha Timing System, Alpha Scanning System, Alpha Live Timing, Alpha Live Streaming, Alpha Results web applications or Alpha Race Hub mobile application (the "Services"). Alpha Timing is committed to ensuring that your privacy is protected. Should we ask you to provide certain information by which you can be identified when using our services, you can be assured that it will only be used in accordance with this privacy statement.

Data We Collect

Alpha Timing may collect and / or access the following data on behalf of our clients:

  • Name
  • Address
  • Date of birth
  • Email address
  • National governing body licence number(s) (e.g. Motorsport UK licence number)
  • Telephone / mobile phone numbers
  • Parent / Guardian's name, address, telephone numbers and national governing body licence numbers
  • Emergency contact name, address and telephone numbers
  • Race entry information such as race number, team name, entrant name and details about your vehicle(s)
  • Social media identifiers (such as Facebook or Twitter handles)
  • Photos uploaded by users of our services
  • Plus any additional data defined by our clients

Sub-Processors

To provide our services effectively, we rely on trusted third-party service providers (sub-processors) to process personal data on our behalf. These sub-processors include:

  • Heroku (Salesforce): Provides hosting and application infrastructure services. Heroku processes data in accordance with ISO 27001, ISO 27017, ISO 27018, and SOC 1, 2, and 3 certifications. For more information visit: Heroku Security Documentation
  • SendGrid (Twilio): Provides email delivery and analytics services to send transactional and notification emails. SendGrid complies with GDPR and other relevant standards. For more information visit SendGrid PrivacyDocumentation
  • DigitalOcean: Provides hosting and backup services. DigitalOcean processes data in compliance with GDPR and adheres to ISO 27001 certifications. For more information visit DigitalOcean Data Processing Agreement

Each sub-processor processes personal data solely for the purposes outlined in our agreements and only as instructed by us. We ensure that all sub-processors comply with stringent data protection standards and maintain safeguards such as encryption and access control.

Details about our sub-processors, including specific processing instructions and compliance measures, are available upon request. Please contact us at privacy@alphatiming.co.uk for more information.

What Do We Use Your Data For?

We manage the above data on behalf of our clients so they can manage their race entries, bookings, event administration, communications with their clients, timing of events, the publication of event results online, reporting, and safe storage of the data to meet contractual and legal obligations.

In certain circumstances, a client of Alpha may request to merge customer data to improve the accuracy and integrity of their records. In such cases, Alpha may access personal data to determine how best to perform the requested data merge. This ensures that data is combined in a way that is both effective and compliant with data protection obligations.

What Do We Use Your Data For?

We may share personal data with the following third parties when necessary to provide our services, fulfil legal obligations, or meet regulatory requirements:

Sanctioning Bodies and National Governing Bodies

For events licensed by a sanctioning body (e.g., national or regional motorsport organizations), or to comply with broader motorsport regulations overseen by national governing bodies, we may share personal data when required. This includes:

  • Identifying information such as names, license numbers, and contact details.
  • Signed e-waivers or consent forms required for event participation.
  • Aggregated or individual data related to event participation or equipment usage (e.g., barcoded equipment tracking).

This data is shared to comply with the sanctioning body’s regulations, verify participant eligibility and ensure proper administration of events and fulfil oversight and compliance requirements of governing organisations. Data will only be shared for sanctioned events and as instructed by our clients.

Sub-Processors:

We work with trusted third-party service providers (sub-processors) to deliver our services. These include hosting, email delivery, and analytics providers. For more details, see the “Sub-Processors” section of this policy.

Legal Authorities:

Personal data may be shared when required by law, such as in response to valid legal requests, to enforce our terms of service, or to protect our rights or the safety of others.

Legal basis for procesing (EEA individuals only)

If you are from the European Economic Area, our legal basis for collecting and using the personal information described above depends on the personal information concerned and the specific context in which we collect it.

We will collect personal information only where we have your consent to do so, or where processing is in our or our customers’ legitimate interests, which are not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may have a legal obligation to collect the information. If we ask for personal information to comply with a legal requirement, we will make it clear and advise if provision is mandatory and outline the consequences of not providing the information.

Similarly, if we collect and use your personal information in reliance on our or our customers’ legitimate interests, and those interests are not already listed above (in the"What Do We Use Your Data For?" section), we will make clear to you at the relevant time what those legitimate interests are.

How Long Do We Keep Your Data?

The retention period for your personal data varies depending on the type of data and our clients' instructions. For example:

  • Booking and Entry Data: Retained for as long as our clients instruct us to after the last event attended.
  • Race and Event Results: Published indefinitely in the public domain, unless otherwise requested by the client.

Special Processing for Race and Event Results

Our clients may use our timing system for timing of their events. Our timing system may use the following information provided by you via our online entry system on behalf of our clients: Name, Race Number, Class,Town, Club, Engine Name, Chassis Name. Our software will generate information such as position, lap times, session results, overall event results, and championship tables. This generated data, along with the information you provide, may be published online in the public domain on behalf of our clients. This information (race and event results) may be published online indefinitely due to the public and historical interest in the results.

Special Processing for Barcode Scanning

Our clients may use our barcode scanning system for tracking tyre, chassis, engine, and other equipment usage at their events. Barcodes on the side of tyres, engines, chassis or vehicles may be logged against your name, license number, race number, and class at venues/championships using our barcoding software. This information may be shared with national governing bodies to provide aggregated information about tyre usage within their jurisdiction.

Security

We are committed to ensuring your information is secure. To prevent unauthorised access or disclosure, we have put in place suitable physical, electronic, and managerial procedures to safeguard and secure the information we collect.

International Data Transfers

Some of our sub-processors may process personal data outside the European Economic Area (EEA). In such cases, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs), to protect your data in compliance with GDPR. For more information on the specific safeguards, please contact us at privacy@alphatiming.co.uk

How We Use Cookies

A cookie is a small file which asks permission to be placed on your computer’s hard drive. Cookies help analyse web traffic or notify you when you visit a site. We use cookies for the following purposes:

  • Session Management: To keep you logged in while using our services
  • Analytics: To understand application traffic and improve functionality.
  • Preferences: To remember your preferences, such as language or region settings.

Overall, cookies help us provide a better website by enabling us to monitor which pages are useful to you. A cookie does not give us access to your computer or any information other than what you choose to share. You can choose to accept or decline cookies, but declining may prevent you from taking full advantage of the website.

Links to Other Websites

Our services may contain links to other websites of interest. Once you use these links to leave our site, we do not have control over the other site. Therefore, we cannot be responsible for the protection and privacy of any information you provide while visiting such sites, which are not governed by this privacy statement.

Your Data Protection Rights Under the General Data Protection Regulation (GDPR)

If you are a resident of the EEA, you have the following rights:

  • You can access,correct, update, or request deletion of your personal information at any time by emailing privacy@alphatiming.co.uk. A small fee may be payable. If you believe any information we hold is incorrect or incomplete, email us to correct the information.
  • In addition, you can object to the processing of your personal information, ask us to restrict the processing of your personal information, or request portability of your personal information by emailing privacy@alphatiming.co.uk.
  • You have the right to opt-out of marketing communications at any time. You can exercise this right by clicking on the "unsubscribe" link in the marketing emails sent to you.
  • Similarly, if we have collected and process your personal information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
  • You have the right to complain to a data protection authority about our collection and use of your personal information. For more information, please contact your local data protection authority.

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.

Changes To This Privacy Policy

This policy may be modified from time to time, so please review it frequently. Changes to this policy will be posted on our website. If we materially change the ways in which we use or share personal information previously collected from you with our customers, we will notify you by email or other communication