RecceGrid is operated by Sabiedrība ar ierobežotu atbildību “Consulting Art”. We apply the General Data Protection Regulation and other applicable data-protection law when we determine why and how personal data is processed.
1. Controller and scope
This Policy applies to RecceGrid websites, mobile applications, account and organization workspaces, event tools, route-survey features, live services, notifications and support interactions. It does not govern an external website or service linked from RecceGrid.
Consulting Art is the controller for platform accounts, security, billing administration, service communications and operation of RecceGrid. An event organizer or team may be a separate controller for participant, staff, guest or event data that it chooses to collect and manage.
2. Identity and account data
When you register or sign in, we may receive your name, email address, verified-email status, user identifier, preferred username, language, organization and role claims from the configured identity provider. We also store account settings and authentication-session information needed to keep you signed in securely.
You may add profile details such as display name, nationality, languages, biography, profile image, contact-visibility settings and emergency-contact information. Required fields and visibility depend on the feature and the choices made by you or your organization.
3. Organizations, profiles and invitations
We process organization and team names, memberships, assigned roles, invitation email addresses, invitation status and ownership or profile-claim evidence so workspaces can be created, administered and protected.
Organization owners and administrators can see relevant member identity, role and invitation information. They are responsible for inviting the correct people, maintaining appropriate access and explaining any additional processing they perform through their workspace.
4. Rally, uploaded and imported data
Event operations may include schedules, entries, crew and vehicle details, staff assignments, guest and safety zones, checkpoints, timing, results, penalties, incidents, notices, photos, files and other content submitted by authorized users.
RecceGrid may also store rally records, profiles, images, results, source links and external identifiers obtained from public or licensed sources. We use provenance information to distinguish imported records, support corrections and avoid presenting a third-party identifier as a RecceGrid account identity.
5. Routes, telemetry and live location
Route surveys and event use may produce precise GPS coordinates, timestamps, device accuracy, heading, speed, route points, markers, warnings, speed limits, danger zones, timing splits, control checkpoints and recorded or calculated run information.
Live operations may process participant positions, device freshness, checkpoint passage, timing confidence, incidents, penalties and replay evidence. Organizer views may be more precise than public views; public positions can be delayed, rounded or removed when a live session ends according to event settings and safety policy.
6. Technical, communication and billing data
We process IP address, browser and device information, application version, request and error logs, security events, cookie or local-storage identifiers, connectivity state and usage interactions needed to operate, troubleshoot and protect the service.
We store support messages, notification status and transactional-email delivery information. Billing providers process payment credentials under their own privacy terms; RecceGrid may retain customer, plan, invoice, transaction status and tax-related records without storing full card details.
7. Purposes and legal bases
We process data to create accounts and workspaces; provide routes, events, timing, live operations and profile features; deliver invitations and notices; provide support and billing; maintain reliability; prevent abuse; investigate incidents; enforce agreements; and comply with legal duties.
Depending on the context, the legal basis is performance of a contract, steps requested before a contract, compliance with a legal obligation, our legitimate interests or those of users in operating and securing the service, or consent where law requires it. You may withdraw consent at any time without affecting earlier lawful processing.
8. Organizer roles and visibility
An organization decides who may access its workspace and which event information is shared with members, participants, staff, guests or the public. Public event pages, leaderboards and live maps display only information configured and eligible for that audience.
When an organization determines the purpose and means of processing event data, it must provide its own notices, establish a legal basis, respect participant rights and configure access, public visibility and retention appropriately. Separate contractual data-processing terms may further allocate responsibilities.
9. Sharing and service providers
We share data with authorized workspace members and intended event audiences as needed for the selected feature. We may also use providers for identity, hosting, databases, object storage, content delivery, mapping, email, payments, monitoring, support, analytics or advertising, subject to contractual and legal safeguards where required.
We may disclose information when required by law, to protect people, rights or service integrity, to investigate abuse, or as part of a corporate transaction subject to appropriate confidentiality and data-protection measures. A third-party service processes data under its own terms when it acts as an independent controller.
10. International transfers
Some service providers may process data outside Latvia or the European Economic Area. Where required, we use an adequacy decision, standard contractual clauses or another lawful transfer mechanism and assess supplementary safeguards appropriate to the transfer.
11. Retention and deletion
We keep personal data only as long as needed for the purposes described here, the active account or workspace, event operations, contractual commitments, dispute resolution, security, audit and legal obligations. Retention depends on the data category, organization settings and the sensitivity and operational value of the record.
Precise raw telemetry may have a shorter lifecycle than approved route, timing, incident or penalty evidence. Deleting an account does not necessarily remove records an organization must retain, public or imported historical results, backups awaiting rotation, or information needed to establish, exercise or defend legal claims.
12. Security
We use proportionate technical and organizational measures intended to protect data, including authenticated access, role-based permissions, transport protection, service isolation, logging, backups and incident response. No online system can guarantee absolute security.
Protect your account and devices, assign the least access needed, remove obsolete memberships and promptly report suspicious activity. Organizers should limit precise live-location access and avoid publishing information that could create a safety risk.
13. Cookies, analytics and advertising
RecceGrid uses cookies or similar device storage for sign-in, security, language, theme and other requested functionality. Disabling essential storage may prevent parts of the service from working.
If analytics or advertising is enabled, providers may process device, usage or advertising identifiers under their privacy terms. We request consent where required and provide available controls; browser settings and provider choices may also limit non-essential cookies or personalized advertising.
14. Your rights and choices
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection; withdraw consent; and ask about the source, recipients and retention of your data. Some profile and visibility details can be corrected directly in RecceGrid, while organization-managed data may require contacting that organization.
Contact us to exercise a right. We may need to verify your identity and may retain or refuse information where law permits or requires it. You may lodge a complaint with the Latvian Data State Inspectorate or the competent supervisory authority in your country.
15. Children, changes and contact
RecceGrid is not directed to children who cannot lawfully provide their own data. Organizers handling data about minors must obtain any required authorization, provide age-appropriate notices and limit collection and visibility. Contact us if you believe a child’s data was provided without a valid basis.
We may update this Policy as RecceGrid, providers or legal requirements change. We will publish the revised version, update the effective date and provide additional notice where required. Privacy questions and requests can be sent to the contact below.
Controller and contact information
- Legal name
- Sabiedrība ar ierobežotu atbildību “Consulting Art”
- Registration number
- 40103285272
- Registered
- 9 April 2010, Commercial Register of the Republic of Latvia
- VAT number
- LV40103285272
- Legal address
- Austuves iela 3A, Rīga, LV-1063, Latvia
- Privacy contact
- [email protected]