Privacy Policy
Effective: 2026-07-05 · The Sports Registry (TSR)
1. Controller and processor
TSR (The Sports Registry) is a platform that any sports federation, in any country, can use (each, a federation) to manage its members, athlete licenses, documents, and competitions — the platform is not limited to Lithuanian federations. It is built and technically operated by 3T Media FZE, registration no. 20352/2026, United Arab Emirates (referred to as we or the Processor).
Although we (the Processor) are not established in the European Union, the EU General Data Protection Regulation (GDPR) applies to our processing of data of federations and members located in the EU or EEA, because we offer platform services to them (GDPR Art. 3(2)(a)). Federations and members may additionally be subject to their own country's local data protection laws — compliance with those is the federation's responsibility as the data controller.
Depending on the data category, the roles under the GDPR differ:
Federation — data controller
Each federation (e.g. LMF, LZSF, LKF in Lithuania, or any federation from another country using TSR) is an independent data controllerfor its own members', athletes', licenses', documents', and competitions' data. The federation decides who becomes a member, which licenses are issued, which documents are required, and how it communicates with members. Questions about your personal data should first be directed to your federation's administration.
3T Media FZE — data processor
We process member data on behalf of, and under instructions from, the federation— we provide the technical platform (website, mobile app, servers, document storage), but we do not decide who gets a license or how a member's documents are evaluated. We have, or are putting in place, a data processing agreement (DPA) with each federation.
Some data (technical logs, security records, the audit log, and correspondence with federations as our own clients) is processed by us as the data controller, on the basis of legitimate interest (platform security and operation) — described further in Section 4.
For data protection questions, see the contact details in Section 17.
2. What TSR is and your role
TSR brings together three groups of users: members (athletes, horse/animal owners), federation administrators(manage their federation's members, licenses, documents), and the platform operator (us — we maintain the infrastructure, fix technical issues, and, when necessary, act across several federations at once solely for support/security purposes).
This policy applies to all three surfaces — the website (tsr.lt), the federation admin panel, and the mobile app (iOS/Android) used by federation members.
3. What data we collect
We only collect data that is necessary to administer membership, licenses, and competitions.
Account data
First and last name, email, a cryptographic password hash (never plain text), phone number, date of birth, nationality, gender, address, city, country, profile photo, preferred language, last login time. An account can be created either by the member (self-registration) or by a federation administrator on the member's behalf (often the case for younger athletes — see Section 13).
License and qualification data
License/qualification/certificate number, type, status (active, suspended, expired), validity dates, payment status, unique QR verification code (qr_token).
Documents and data extracted from them
Uploaded documents: passport/ID document, medical certificate, insurance policy, consent form, registration document, photo, etc. Passport, medical certificate, and insurance documents go through an AI text-recognition feature — see Section 14 for a detailed description of what data (including health data) is extracted and stored this way.
Penalties and restrictions
Penalty type (warning/fine/suspension/disqualification), reason, amount, validity period, who issued it. Penalties are only valid within the federation that issued them.
Messages
Correspondence with your federation's administration (subject, text, read receipt). See Section 5 for who can see these messages.
Horse and other animal/equipment data
Some federations (e.g. equestrian sport) register not only athletes but also animals/equipment linked to an owner's account: name, breed, year of birth, color, gender, passport number, microchip number, photo. These identifiers belong to the animal, not a person, but are linked to the owner's (member's) account.
Technical data
IP address (for security and login-abuse protection), browser/device information, session cookie, an activity log (who did what, and when, in the admin panel).
4. Purposes and legal basis
| Purpose | Data category | Legal basis (GDPR) |
|---|---|---|
| Account creation and authentication | Account data | Art. 6(1)(b) — contract / federation membership |
| License issuance and administration | License, document data | Art. 6(1)(b) / Art. 6(1)(c) — federation rules and legal obligations |
| Verification of documents (passport, medical, insurance) | Document, health data | Art. 9(2)(a) — explicit consent (document upload) |
| Public license validity check (QR) | Name, photo, nationality, date of birth, penalties | Art. 6(1)(f) — legitimate interest (sport/competition integrity and safety) |
| Email notifications (license, document status, reminders) | Email, name | Art. 6(1)(b) — contract |
| Messages between member and federation | Message content | Art. 6(1)(b) — membership administration |
| Payment processing (being rolled out) | Payment/billing data | Art. 6(1)(b) — contract |
| Platform security and abuse prevention | Technical data, IP, activity log | Art. 6(1)(f) — legitimate interest |
| Accountability (audit log) | Administrator actions | Art. 6(1)(f) / Art. 5(2) — accountability principle |
| Dispute handling and defense of legal claims | All related data | Art. 6(1)(f) — legitimate interest |
Health data (e.g. a summary of a medical certificate's content) is a special category of personal data under GDPR Art. 9. We only process it with your explicit consent — you upload such a document voluntarily, knowing its purpose. You may withdraw consent at any time, though this may mean the license that requires the document cannot be issued or renewed.
5. Who can see your data
Your federation's administrators
Your federation's administrators (role federation_admin) see your full profile, all your licenses, qualifications, uploaded documents (including AI-extracted data from them), penalties, and messages with the federation — this is necessary to administer your membership. They cannotsee another federation's members' data.
Platform operator (super admin)
A limited number of 3T Media FZE staff have platform-administrator (super_admin) access across all federations — used only for technical support, security incident investigation, and fulfilling legal obligations. This access is not used for day-to-day review of member data.
Other members
Another member cannot access your photo or documents — access to files (photos, documents) is strictly restricted by federation and ownership: you can only view your own files, and administrators can only view files belonging to their own federation's members.
6. Public license verification (QR)
Every license, qualification, and certificate has a unique, random QR code intended for public verification — e.g. a competition organizer or official scanning the code on a physical license card or document. This verification page is accessible without logging in and is a core feature that allows checking license validity in real time.
What is shown publicly when the QR code is scanned
- For an athlete license: first name, last name, photo, nationality, age (calculated from date of birth), license type/status/validity, federation name and logo, active penalties (type and reason, if any), and up to 5 active qualifications.
- For an animal (e.g. horse) license: the animal's name, breed, year of birth, color, passport and microchip numbers, photo, and the owner's first and last name.
- For a qualification or certificate: the holder's first and last name and the relevant document number/type/validity.
This data is shown by design — it mirrors the logic of checking a physical license/ID card: anyone checking the physical card would see the same information. The QR token is random and unguessable, and requests are rate-limited (no more than 60 requests per minute per IP address).
Important: if a physical license card or a PDF containing a QR code ends up in the wrong hands, anyone can view the information listed above. Treat your license card with the same care as an identity document.
7. Processors (sub-processors)
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Anthropic, PBC (Claude AI) | Automatic recognition of document data (passport, medical certificate, insurance) | USA | Data Processing Agreement (DPA); EU–US Data Privacy Framework (DPF) / SCC |
| Brevo SAS (Sendinblue) | Transactional emails (license, document status, reminders) | France (EU) | GDPR DPA |
| Hetzner Online GmbH | Server infrastructure and database | Germany (EU) | EU data center; DPA |
| QR Server / goqr.me (api.qrserver.com) | QR code image generation for the downloadable license PDF card | Not publicly stated | Only the verification link (URL) with a random token is sent — no names or other personal fields are sent directly |
| Stripe, Inc. / Stripe Payments Europe Ltd. | Payment processing (feature currently being rolled out) | USA / Ireland (EU) | PCI DSS Level 1; EU–US DPF / SCC |
We aim to have a data processing agreement (DPA) in place with every processor. You can request the list and copies of these agreements by contacting us — see Section 17.
License fee status (paid/unpaid/waived) is currently marked manually by the federation administrator, but we are currently rolling out automated payment processing via Stripe. Once this feature is enabled, card payment data will be handled exclusively by Stripe (a PCI DSS Level 1 certified platform) — we will not store full card data ourselves. This policy will be updated if the scope or terms of Stripe usage change.
8. International data transfers
Core data is stored within the EU/EEA (Germany, Hetzner). For AI document recognition, document content (including personal data and, where applicable, a summary of health data) is sent to Anthropic, PBC (USA) for processing.
- EU–US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCC) — depending on the processor's certification status.
- Technical measures — TLS 1.2+ encryption in transit; uploaded documents (passport, medical certificate, insurance, etc.) are additionally encrypted at rest with AES-256; every access to such a document is recorded in an audit log.
You can request more information about specific safeguards by contacting us — see Section 17.
If your federation or you personally are located outside the EU/EEA, your data is still transferred into the EU/EEA (Germany), where the platform runs — this is not an "international transfer out of the EU", but data collection directly on a server located within EU territory.
9. Retention periods
| Data category | Retention period | Basis |
|---|---|---|
| Account and profile data | While you are an active federation member | Membership administration |
| Licenses, qualifications | Validity period + an archival period in case of disputes | Legitimate interest |
| Documents (passport, medical certificate, insurance) and AI-extracted data | Approved — as long as the related document/license. Rejected — automatically deleted after 90 days | Consent / legitimate interest |
| Messages with the federation | Until deletion is requested (no automatic deletion at this time) | Membership administration |
| Activity log (audit log) | Indefinitely, entries are immutable | Accountability principle (GDPR 5(2)) |
| Deactivated account | Data remains in the database (account marked inactive) | Accounting, dispute handling |
You can delete a rejected document (passport, medical certificate, insurance, etc. that a federation administrator did not approve) yourself at any time — the file is removed from the server immediately and irreversibly. If you don't, such documents are automatically and irreversibly deleted 90 days after rejection. An administrator can also delete any of your documents at your request.
For other data (account, licenses, messages, etc.) we do not currently have an automated data-erasure mechanism — removing an account means deactivating it (the data is no longer used but physically remains in the database). If you would like this data fully deleted, contact your federation administrator or us — see Section 17 — we will carry out the deletion manually within the timeframes given in Section 10, while taking into account legitimate reasons to retain data (e.g. ongoing disputes or legal requirements).
10. Your rights under the GDPR
As a TSR account holder, you have the following rights:
| Right | What it means | GDPR article |
|---|---|---|
| Right of access | Obtain a copy of your data and information about how it is processed | Art. 15 |
| Right to rectification | Request correction of inaccurate or incomplete data | Art. 16 |
| Right to erasure | Request deletion of data when there is no legal basis to retain it | Art. 17 |
| Right to restriction | Request that processing be temporarily suspended | Art. 18 |
| Right to portability | Receive your data in a structured, commonly used format | Art. 20 |
| Right to object | Object to processing based on legitimate interest | Art. 21 |
| Withdrawal of consent | Withdraw consent to AI processing of documents at any time | Art. 7(3) |
You can submit a request to your federation administrator (as the data controller) or to us — see Section 17 — and we will forward it to the relevant federation. We respond within 30 days. In complex cases the deadline may be extended to 90 days — we will notify you if this applies.
If you believe your rights have been violated, EU/EEA residents may lodge a complaint with their own country's data protection supervisory authority.
11. Cookies
We use a minimal, strictly necessary set of cookies. We do not use any marketing or analytics tracking cookies.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| tsr_session | Login session authentication | 30 days | Necessary |
| NEXT_LOCALE | Remembers your selected language | 1 year | Necessary |
The mobile app has no cookies — the login token is stored in the device's secure storage (iOS Keychain / Android Keystore), see Section 15.
12. Security measures
We apply the following technical and organizational measures under GDPR Art. 32:
- Encryption in transit: TLS (HTTPS) for all traffic between the browser/app and the server.
- Passwords: stored using bcrypt with an individual salt; plain text is never stored.
- Sessions: the authentication token (JWT) is stored in an httpOnly cookie (not accessible to JavaScript) or, in the mobile app, in the device's secure storage.
- Access control: files (photos, documents) are accessible only to the owner, their federation's administrator, or the platform operator — strictly scoped by federation and ownership.
- Activity log: all administrator actions (viewing, changing data) are recorded in an immutable log.
- Breach notification: in the event of a security breach, we will notify the supervisory authority within 72 hours, and affected individuals without undue delay.
We do not yet have two-factor authentication (2FA) — we recommend using a strong, unique password for your account.
13. Minor members
Sports federations using TSR often have younger (minor) athlete members. In such cases, the member account and personal data are usually created and managed on the platform by the federation administrator— based on a membership agreement/application physically signed by a parent or legal representative under the federation's own internal process (this consent is obtained outside the TSR platform, through the federation's membership process).
If you are a parent, guardian, or legal representative and wish to review, correct, or request deletion of a minor member's data — contact the relevant federation or us — see Section 17.
14. AI use and automated decisions
When you upload a passport, medical certificate, or insurance policy document through the website, its content is automatically sent to an AI service (Anthropic Claude), which reads and structures data from the document image/PDF:
- Passport/ID document: first name, last name, document number, date of birth, expiry date, issuing authority.
- Medical certificate: first name, last name, expiry date, the issuing doctor/institution, and a brief summary of the findings (health data within the meaning of GDPR Art. 9).
- Insurance policy: first name, last name, policy number, expiry date, insurer.
The system also automatically compares the AI-recognized name against your account data (a match flag) so an administrator can more easily spot discrepancies. The same AI processing applies regardless of whether you upload a document through the website or the mobile app.
No automated decision-making within the meaning of GDPR Art. 22 takes place — AI only assists with transferring data; the final decision to approve or reject a document is always made by a federation administrator (a human). The one automated consequence in the system: when an administrator issues a suspension-type penalty, all of your active licenses in that federation are automatically marked as suspended — this is a direct consequence of the administrator's decision, not an independent decision made by AI or an algorithm.
15. Mobile app
The TSR mobile app (iOS/Android) uses the same server and database as the website. It requests the following permissions:
- Camera — to scan QR codes (license verification).
- Photo library — to upload documents and a profile photo.
The login token is stored in the device's secure storage (iOS Keychain / Android Keystore), not in cookies. The app has a push-notification permission prompt, but this feature is not yet implemented — we currently do not collect or store any push notification tokens.
16. Policy updates
We may need to update this policy due to new features, changes in law, or organizational changes.
- Material changes (new processing purposes, new processors, a change in legal basis) — we will notify you by email or through the platform at least 30 days in advance.
- Editorial changes (typo fixes, clarified wording) — take effect immediately; the date at the top is updated.
By continuing to use the platform after material changes take effect, you confirm that you have reviewed the new policy.
17. Contact and supervisory authority
Data processor (platform)
3T Media FZE
Registration no. 20352/2026
United Arab Emirates
info@esolutions.ltSupervisory authority
As we are established outside the European Union, EU/EEA residents may lodge a complaint with their own country's data protection supervisory authority.
For everything described in this policy (data protection, exercising your rights, the sub-processor list, deletion requests), please use a single contact — info@esolutions.lt (a temporary contact until a dedicated tsr.lt domain mailbox is set up).
If you are outside the EU/EEA, you may also contact your federation or the relevant local authority, depending on your country's laws.
We respond to data subject requests within 30 days. If a request is complex, this may extend to 90 days, and we will inform you in advance.