Privacy Policy

Last updated: 1 July 2026

This policy sets out the information regarding the processing of personal data which PaddockAI, in its capacity as data controller, is required to provide to data subjects pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation) and applicable national data protection legislation.

1. Data controller

PaddockAI is the data controller in respect of personal data collected in connection with the creation and use of the service. Enquiries concerning the processing of personal data shall be directed in writing to [email protected].

2. Categories of personal data

The following categories of ordinary personal data are processed, cf. Article 6 of the Regulation:

  • Identification and contact data (name, e-mail address and, where applicable, a profile picture).
  • Data concerning the user's use of the service (lists created and entries followed).
  • Subscription and payment-related references. Card data is not processed by PaddockAI but exclusively by the payment service provider.
  • Technical error reports, to the extent consent has been given, cf. section 8.

3. Purposes and legal basis

  • Creation and administration of the user account and provision of the service's functions: Article 6(1)(b) of the Regulation (performance of a contract).
  • Administration of subscriptions, including compliance with statutory bookkeeping obligations: Article 6(1)(b) and (c).
  • Technical error diagnostics via a third party: Article 6(1)(a) (consent).
  • Safeguarding the operation and integrity of the service and preventing misuse: Article 6(1)(f) (legitimate interest in operating a secure and functional service).

4. Recipients of personal data

Personal data is disclosed to data processors assisting with the operation of the service, which process such data solely on documented instructions. The following categories of data processors are engaged: providers of hosting and data-storage infrastructure, a provider of transactional e-mail delivery, a payment service provider and — to the extent consent has been given — a provider of technical error diagnostics.

Where third-party sign-in is used, only such data as the sign-in provider makes available upon authentication is transferred. Personal data is not disclosed to third parties for marketing purposes.

5. Transfers to third countries

Certain data processors are established in, or may process data from, countries outside the EU/EEA. Any such transfer takes place on the basis of an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework, or the European Commission's Standard Contractual Clauses, cf. Chapter V of the Regulation. Documentation of the transfer basis may be requested via the contact details in section 1.

6. Retention and erasure

  • Account data and user-generated content is retained until the user deletes their account, whereupon the data is erased without undue delay.
  • Accounting records are retained for the current and five subsequent financial years pursuant to applicable bookkeeping legislation.
  • Technical error reports are retained for a limited period and thereafter erased automatically.

7. Data collected from publicly accessible sources

The service reproduces start lists, results and scheduling information concerning riders and combinations. Such data originates from publicly accessible sources, cf. Article 14(2)(f) of the Regulation, having previously been published by event organisers through their event-administration platforms. No data concerning riders is processed beyond what has thus already been made public. The processing is based on Article 6(1)(f).

8. Cookies and local storage

The service employs strictly necessary browser storage for authentication and for preserving the user's settings, in accordance with the exemption for necessary storage under the applicable rules implementing the ePrivacy Directive. In addition — and solely subject to prior consent — storage is employed in connection with technical error reporting. Consent may be withdrawn at any time with effect for the future via the cookie settings below. No storage is employed for marketing or analytics purposes.

9. Rights of data subjects

Pursuant to Chapter III of the Regulation — subject to the conditions and limitations set out therein — the data subject has the following rights:

  • The right of access, cf. Article 15.
  • The right to rectification, cf. Article 16.
  • The right to erasure, cf. Article 17.
  • The right to restriction of processing, cf. Article 18.
  • The right to data portability, cf. Article 20.
  • The right to object, cf. Article 21, in respect of processing based on Article 6(1)(f).
  • The right to withdraw consent, cf. Article 7(3), without affecting the lawfulness of processing carried out prior to such withdrawal.

Requests shall be submitted via [email protected] and will be answered without undue delay and in any event within one month of receipt, cf. Article 12(3).

10. Right to lodge a complaint

The data subject may lodge a complaint concerning the processing of personal data with the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, DK-2500 Valby, cf. Article 77 of the Regulation. Further information is available at www.datatilsynet.dk.

11. Amendments

This policy is revised on an ongoing basis in accordance with changes to the service or to applicable law. The version in force at any given time is available on this page, stating the date of the most recent update.

Cookie settings

Necessary storage (sign-in and settings) can't be opted out of. Error reporting is optional and can be changed here anytime.

Your choice: Not decided yet