Privacy Policy
This privacy policy informs you about the nature, scope and purpose of processing personal data on Roxzone pursuant to the GDPR.
1. Data Controller
The controller for data processing on this platform is:
Roxzone Performance UG (haftungsbeschränkt)
Ulmenweg 49
53809 Ruppichteroth, Germany
Email: info@roxzone-performance.de
Managing Director: Jonathan Faber
No data protection officer has been appointed because the conditions (fewer than 20 persons engaged in ongoing data processing, no special categories of data under Art. 9 GDPR) are not met. Should the conditions change, a DPO will be appointed and listed here.
2. Data Collected
We process only the data you provide when using the platform or that is technically necessary to operate it:
- Account data: email address, display name, password hash (Argon2id, never plain text).
- Profile data: gender (for race matching), HYROX experience level, preferred language, optional avatar.
- Race-partner searches: event date, format, free-form search description.
- Ticket listings: race identifier, ticket ID (HYROX-external), price, free-form description.
- Messages: 1:1 conversation content between registered users (max. 2,000 characters per message), timestamps, read status.
- Logs and technical data: truncated IP address, user agent, request ID, error stack trace (on errors).
3. Purpose and Legal Basis per Data Category
- Account, profile, searches, listings, messages: performance of the user contract (matching race partners and start-place transfers) — Art. 6(1)(b) GDPR.
- Admin audit log, anti-fraud mechanisms, reports (RPT-*): legitimate interest in platform safety and abuse prevention — Art. 6(1)(f) GDPR.
- Server logs and error tracking: legitimate interest in operational security and error analysis — Art. 6(1)(f) GDPR.
- Cookieless analytics (Matomo): legitimate interest in aggregated reach measurement — Art. 6(1)(f) GDPR; cookieless configuration requires no consent under TTDSG.
4. Recipients / Data Processors
We use carefully selected data processors. The complete list with legal bases is available in our subprocessor register (see "Last updated:" below for the version date). External data processors at the time of publication:
- Strato AG, Germany — hosting of the entire application infrastructure (application server, Postgres database, offsite backups). Legal basis: Art. 6(1)(b) GDPR. DPA pending signature.
- Resend (EU/Ireland) — transactional email delivery (account verification, match digest, ticket and message notifications) and processing of bounce/complaint webhooks. Legal basis: Art. 6(1)(b) GDPR. DPA pending signature.
Additionally, we operate the following services self-hosted on our own infrastructure. No data is transmitted to third parties:
- Matomo — web analytics in cookieless mode, self-hosted on our infrastructure. No cookies, no cross-site trackers, no outbound connection to Matomo Cloud / InnoCraft Ltd.
- GlitchTip — error tracking (Sentry-API-compatible), self-hosted on our infrastructure. No outbound connection to the Sentry cloud / Sentry GmbH.
5. Data Transfer to Third Countries
None. All external data processors used (Strato, Resend) are based in the European Union and process data exclusively within the EU/EEA. Self-hosted services (Matomo, GlitchTip) run on the same EU infrastructure.
6. Retention
Retention is governed by our retention policy, versioned in config/retention.yml and enforced by automated background jobs (Phase 6):
- Unconfirmed accounts: 30 days after registration, then auto-deletion.
- Race-partner searches: 90 days after event date.
- Ticket listings in terminal state (sold / expired): 24 months.
- Admin audit log: 3 years.
- Postgres backups: 14 days rolling.
- Application logs: 7 days.
- Error events (GlitchTip): 90 days.
- Analytics (Matomo, cookieless): 180 days aggregated, no PII.
Upon account deletion, personal profile data (name, email, avatar, bio) is immediately and irreversibly overwritten (PII-scrub tombstone per LEGL-06). Messages already sent remain in the database because the conversation partner has a legitimate interest in the conversation history (Art. 17(3)(b) GDPR); the sender ID is set to NULL and the partner sees the sender as "deleted user".
7. Your Rights
Under the GDPR you have the following rights:
- Access (Art. 15 GDPR) — to the data stored about you.
- Rectification (Art. 16 GDPR) — directly in your profile at /en/settings.
- Erasure (Art. 17 GDPR) — self-service via /en/settings; profile PII is deleted immediately.
- Restriction (Art. 18 GDPR) — by email to the privacy contact address listed above.
- Data portability (Art. 20 GDPR) — on request, as a JSON export of your personal data.
- Objection (Art. 21 GDPR) — to processing based on legitimate interests (Art. 6(1)(f) GDPR).
8. Cookies and Tracking
We use only strictly necessary cookies (session, CSRF, language preference, cookie consent). Optional embeds (e.g. videos) are blocked by default and only activated after your consent.
Our web analytics (Matomo) runs in cookieless mode: no cookies are set, no fingerprinting is performed and IP addresses are anonymized. Consent under TTDSG is therefore not required.
You can review or change your cookie settings at any time:
9. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR. The competent authority is the supervisory authority of the German federal state where we are based:
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
10. Monthly prize draw after a successful ticket handover
Roxzone runs a monthly prize draw among users who took part in a ticket handover confirmed through the platform. The rules are set out in the terms of participation.
The data required to run the draw is processed for that purpose. This includes in particular the user account, the ticket handover in question, the trading partner involved, the time and status of the mutual confirmation, and the number of entries counted for the calendar month.
Where processing is necessary for participation in and the running of the draw, it is based on Art. 6(1)(b) GDPR.
To keep the draw fair and to prevent fabricated handovers or other abuse, confirmed handovers may additionally be checked for irregularities and flagged internally. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in preventing manipulation and ensuring a fair draw.
Technical flags never lead to an automatic exclusion from the draw. Exclusion follows a manual review only.
If you win, the data needed to notify you and to hand over the prize is processed.
Personal data relating to the draw is stored only for as long as it is needed to run the draw, to carry out any necessary review, and to prevent abuse. After that it is deleted or anonymised, unless statutory retention obligations apply. Anonymised statistics, in particular the total number of successfully confirmed ticket handovers, may be kept indefinitely for statistical purposes.
11. Changes to This Privacy Policy
We update this privacy policy when the legal situation, the services we use, or our processing activities change. There is no automatic mass-email broadcast on changes; the "Last updated:" date below is updated on every content change. We recommend reviewing this page before sensitive actions (e.g. account creation, listing publication).
Last updated: 2026-08-21