Rhythmic Gymnastics
Data processing
Agreement under Art. 28 GDPR between the organiser and Colourmatch.
Courtesy translation
This English text is provided for convenience only. The German version is the legally binding one; consent given when the organiser account is created refers to the German version.
Version of 09/09/2026
Anyone who consents when creating the organiser account concludes this agreement in this version; the version is stored together with the consent. Annex 1 describes the state of the technical and organisational measures as at the version date.
Agreement on the processing of personal data on behalf of a controller
The agreement is presented to the organiser before their organiser account is created and is concluded electronically; Art. 28(9) GDPR expressly permits the electronic format. Without a concluded agreement no organiser account is created — from the first online entry onwards, Kür processes children’s data on behalf of the organiser.
between
the organiser with the details they provide when creating their organiser account (name and legal form of the contracting party — club, federation, company or sole trader —, address and, unless a natural person, the authorised representative). These details are stored together with the consent and form part of this agreement.— hereinafter the “controller” —
and
Colourmatch, owner Sebastian LibudaCarlshöhe 29, 24340 Eckernförde
— hereinafter the “processor” —
§ 1 Subject matter and duration
1. The processor operates the “Kür” online platform for the controller (event page, online entry, music collection, competition planning, publication of start lists and results). In doing so it processes personal data on behalf of the controller.
2. Not covered by this agreement is the locally installed “Kür” competition software (desktop app). It runs exclusively on the controller’s devices; the data processed there on competition day (scores, start lists, music) remain under the controller’s control. The processor has no access to this local data. If the controller deliberately transfers data from the app to the platform (publication, cloud backup), this agreement applies to the transferred data.
3. The agreement applies for the duration of the platform usage agreement and ends with it.
§ 2 Nature, purpose and scope of the processing
1. Purposes: receiving and administering competition entries, receiving routine music files, presenting the event page, publishing start lists and results after release by the controller, sending entry confirmations, handing the planning state over to the controller’s competition software, cloud backup of competition states.
2. Nature of the processing: collection, storage, transmission to the controller, publication (only after release), erasure.
§ 3 Categories of data subjects
- Participants (gymnasts), predominantly minors
- Persons with parental responsibility and persons submitting entries (coaches, representatives of the entering clubs)
- Staff of the controller with platform access
§ 4 Categories of personal data
- Name, year of birth, club, competition category and apparatus choice of the participants
- Contact details of the person submitting the entry (email address)
- Routine music files (per participant and apparatus)
- Records of consent given by those with parental responsibility (time of the declaration)
- Start lists, results and scoring documents, to the extent the controller transfers them to the platform
- Account and sign-in data of portal users (email, password hash held by the sub-processor)
Special categories under Art. 9 GDPR are not processed as designed. The controller ensures that no health data or other Art. 9 data is entered in free-text fields.
§ 5 Obligations of the processor
1. Processing only on documented instructions from the controller (Art. 28(3)(a)). Use of the platform functions by the controller counts as an instruction.
2. Confidentiality: persons with access to the data are bound to confidentiality.
3. Technical and organisational measures in accordance with Annex 1; material changes are notified to the controller and the level of protection may not be reduced.
4. Assistance to the controller with data subject rights (Art. 12–23), with the security of processing (Art. 32) and with notification duties (Art. 33, 34).
5. Notification of any personal data breach to the controller without undue delay, and at the latest within 48 hours of becoming aware of it, with the information required by Art. 33(3).
6. On completion of the service: erasure or return of all data processed on behalf of the controller, at the controller’s choice (§ 8), unless a statutory retention obligation applies.
7. Rights of demonstration and audit: the processor makes available all information necessary to demonstrate compliance under Art. 28(3)(h). Audits are conducted primarily by means of information and existing evidence (e.g. the access log, audit reports of the sub-processors); on-site audits after reasonable notice.
§ 6 Obligations of the controller
1. The controller is responsible for the lawfulness of the processing, in particular for obtaining the necessary consent of those with parental responsibility (the platform records the consent at the entry; whether it is sufficient in substance is the organiser’s responsibility).
2. The controller decides on every publication (start list, results) themselves; the platform publishes nothing without their express action.
3. The controller maintains their own mandatory disclosures (legal notice, privacy notice) on the event page, as soon as the platform provides the fields for this.
§ 7 Sub-processors
1. The controller authorises the sub-processors listed in Annex 2(general authorisation under Art. 28(2) sentence 2).
2. The processor gives notice of intended changes in text form at least 30 days in advance. The controller may object on important data protection grounds; if no agreement is reached, the controller may terminate for cause.
3. A contract under Art. 28(4) is in place with every sub-processor.
§ 8 Erasure and return
1. The controller can remove their competition data from the platform themselves (“Take offline” — removes entries, start lists, publications, competition states, scoring documents as well as music and document files of that competition). If the controller’s access is suspended (for instance because of late payment), this self-service route is not available; erasure is then carried out by the processor on request without undue delay, and at the latest within 14 days of receipt of the request. The right to erasure under Art. 17 GDPR is unaffected by a suspension.
2. Independently of this, the processor erases entries, answers to additional forms including uploaded files, routine music and individual score sheets of a competition automatically at the latest 90 days after its last competition day (a daily, logged deletion run — Annex 1, section 5). Content deliberately published by the controller (event page, start lists, results lists) remains until they “take it offline”.
3. On termination of the agreement the processor erases all remaining data processed on behalf of the controller within 30 days of termination, unless the controller requests its return (data export) beforehand.
4. Excluded from the scope of erasure is evidence data which the processor keeps in order to meet its own legal obligations (e.g. the access log of entry data retrievals, which contains no entry content).
§ 9 Liability, final provisions
1. Art. 82 GDPR applies to liability; otherwise the provisions of the main agreement apply.
2. Amendments and additions require text form.
3. German law applies.
4. The agreement is concluded electronically (Art. 28(9) GDPR). Conclusion consists of the controller’s consent when creating their organiser account and the provision of this version by the processor. The time of consent, the version and the controller’s details are stored and made available to them as evidence on request; a handwritten signature is not required.
Annex 1 — Technical and organisational measures
This annex names only measures that were demonstrably in place in the system on 31/07/2026 (verified against the code and the live database). Planned measures are listed separately at the end and are not warranted.
1. Access control and tenant separation
- Row level security on every data table. Tables without an express release rule are fully locked for application accounts; this applies in particular to the administrative tables (customers, licences, activations, device accounts, access log).
- Tenant separation: every competition-related row carries the identifier of its organiser. Access exists only through a verified membership with the respective organiser. The server itself derives the assignment of new entries from the announcement; a value sent by the client is overwritten and cannot falsify the assignment.
- Entry data cannot be queried freely. Neither anonymous nor signed-in users can read entry lists; coaches see only their own entries. The organiser and the competition software receive entry data only through server functions which check the authorisation, limit the fields to what is necessary and log every retrieval.
- Password policy and rate limiting: account passwords need at least 12 characters with upper and lower case letters and digits and are checked against known password breaches when set (compromised passwords are rejected); a change of email address must be confirmed via both addresses. The sign-in, registration and mail endpoints are rate-limited on the server.
2. Device-bound access instead of a master key
- Every activated device running the competition software receives its own technical account with rights limited to that organiser. The account is created with a one-time password which is immediately exchanged for a session and is stored nowhere; the device register holds no secret.
- When a device is signed out its account is deleted, which ends its access.
- The former full-access key has been rotated and is, as a rule, no longer issued to devices. Limitation: for the transitional period a fallback route still exists which issues a full-access key if account creation fails; it will be closed before further organisers are taken on (see “Planned”).
3. Logging
- Access log for entry data: every retrieval of entry data by organisers or by the competition software is recorded — who, when, which competition, how many records. The log deliberately contains no content (no names, no entry data) and outlives the deletion of the retrieving account, so that the trace of the access does not disappear with the account. It is immutable for application accounts (only the operator reads and writes it) and is automatically truncated after 365 days (daily run, section 5).
4. Transmission and storage
- All connections are TLS-encrypted (HTTPS).
- Data is held with the sub-processor Supabase in the EU region Frankfurt (eu-central-1).
- Routine music is held in a non-public storage area. Retrieval by the competition software runs through short-lived, signed addresses which a server function issues only after an authorisation check.
- Staged publicity: the event page initially shows only the announcement and entry counts. Names appear only once the organiser publishes the start list or the results by a deliberate action of their own.
5. Routes to erasure
- Self-deletion: every portal user can delete their own account (Art. 17). This removes open entries, the profile, the club, the roster of athletes and the music files in storage. Entries from competitions already taken over (frozen) remain as the organiser’s competition records and are detached from the account.
- Data export: every portal user can export their data as a file themselves (Art. 15/20).
- Recycle bin with a fixed period: anything deleted from the roster of athletes stays in the recycle bin for 30 days; a daily automatic run deletes it permanently.
- “Take offline”: the organiser can remove a competition completely from the platform; the deletion run covers all seven competition-related tables including the cloud backup as well as music and document files, and verifies success against the rows actually deleted (not merely against a success message).
- Automatic retention period for entry data: a daily run erases entries, answers to additional forms including uploaded files, routine music and individual score sheets at the latest 90 days after the last competition day — including orphaned files with no link to an entry, and with a re-check after clearing. Every run is logged per competition with the number of rows. Deliberately published content (event page, start lists, results lists) is excluded (§ 8(2)).
6. Availability and integrity
- Competition day does not depend on the platform. The competition software works locally and offline; an outage of the platform cannot stop a competition in progress.
- Signed software delivery: updates to the competition software are cryptographically signed (Ed25519) and verified locally before installation.
7. Data minimisation
- Online entry is possible without an account; only what is needed for the entry is collected (name, year of birth, club, category, apparatus choice, contact email of the person submitting the entry).
- Technical device accounts carry no real names and no reachable email addresses.
Planned or open — not warranted
- Two-factor sign-in for organiser accounts.
- Automatic retention periods for the remaining data (planning states never collected, cloud backups) — for entry data (90 days, section 5) and the access log (365 days, section 3) they already run automatically.
- Closing the transitional fallback route described in section 2.
Annex 2 — Sub-processors
| Sub-processor | Service | Place of data processing | Basis of the transfer |
|---|---|---|---|
| Supabase Inc., USA | Database, sign-in/accounts, file storage (music, documents), server functions | EU, Frankfurt region (eu-central-1) | Standard contractual clauses (Art. 46(2)(c) GDPR), agreed in the Supabase DPA, section 12 and Annex 2 |
| Vercel Inc., USA | Delivery of the event pages and the portal | USA and worldwide delivery nodes | Standard contractual clauses (Annex 3 of the Vercel DPA); in addition certified under the EU-US Data Privacy Framework |
| Resend, Inc., USA | Sending the entry confirmation emails | USA | Certification under the EU-US Data Privacy Framework and standard contractual clauses (sections 6.2 and 11.1 of the Resend DPA) |
Changes to this list are announced 30 days in advance in accordance with § 7; the list currently in force is kept publicly available.
Annex 3 — Transfers to third countries
1. The competition and entry data is held in the European Union (Supabase, Frankfurt region). A transfer to the USA takes place to the extent that the providers named in Annex 2 are established there and can access data in the course of their service — when entry confirmations are sent, additionally in the form of the transmitted email content.
2. For each of these transfers appropriate safeguards under Art. 46(2)(c) GDPR are in place: the standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914), agreed in the data processing agreements linked in Annex 2. Vercel Inc. and Resend, Inc. are additionally certified under the EU-US Data Privacy Framework; for certified companies an adequacy decision of the Commission of 10/07/2023 applies. Should the adequacy decision cease to apply, the standard contractual clauses continue to carry the transfer.
3. The processor has assessed and documented the effectiveness of these safeguards; the assessment is made available to the controller on request. The controller can inspect the current agreements of the sub-processors at any time through the links in Annex 2.
4. The processor arranges the processing so that as little data as possible leaves the territory of the European Union: entry data, music files and competition states are stored exclusively in the EU; the pages are delivered without entry data, and entry confirmations contain no details about third parties.
Version of 09/09/2026 · Terms of use · Privacy · Legal notice