This document describes the organisation's data handling policy: what personal data is collected by the DCA registration application, why it is collected, how long it is retained and what data is removed after its operational purpose has been fulfilled. In the event of a data breach that may affect your rights or freedoms, we will notify you as required by applicable law.
Dutch Contender Association (DCA)
Contact: dca@contenderzeilen.nl
Personal data is collected under Article 6(1)(b) GDPR: processing is necessary for the performance of a contract (event registration and payment). Emergency contact data is collected under Article 6(1)(f) GDPR: legitimate interest (participant safety during the event).
Financial records (invoices, payments) are retained under Article 6(1)(c) GDPR: compliance with a legal obligation (Dutch tax law: 7-year invoice retention requirement).
The registration process collects personal identification and contact details, eligibility and equipment data, emergency contact information, event logistics preferences, and compliance documents. Invoice data, communication logs, and cancellation records are created as a result of the registration and payment process. The specific fields requested are presented to the registrant during sign-up.
No bank account or credit card details are collected or stored by this application. Payments are processed directly through external providers (Stripe, PayPal, etc.), which handle all sensitive financial data under their own security standards and privacy policies. Only the transaction outcome, payment reference, and anonymised provider response are recorded here.
When an event is archived, personal registration data is no longer operationally required and is permanently deleted. The minimum data necessary for financial accountability and future event participation is retained.