ZenFencing markZenFencingTournamentsOrganizations
Sign in

Privacy Policy

Effective date: 27 July 2026

1. Who we are

The ZenFencing platform — the zenfencing.ru website and related services for the fencing community (the “Platform”) — is operated by Sole Proprietor Sergei Tikhomirov, registered in the Russian Federation (OGRNIP 317774600222831), referred to below as “we”, “us”, or the “Operator”.

This policy explains how we process the personal data of visitors and users, in line with the EU General Data Protection Regulation (GDPR) where it applies, and with Russian Federal Law No. 152-FZ “On Personal Data”.

Contact for privacy matters: info@zenfencing.ru.

The Platform is in beta (section 12): its feature set — and therefore the data it processes — is still evolving. This policy is updated as the Platform develops; the current version is always available on this page.

2. Controller and processor roles

The Platform lets users register themselves, keep an athlete, coach, or referee profile, join clubs, and apply to competitions, and lets organizers run competitions and publish their results.

For data that registered users enter about themselves (when creating an account, filling in a profile, or applying to a competition), we act as the data controller, on the basis of the user’s consent and of the contract (the Terms of Use).

For data of participants entered by a competition organizer or a club owner without the participation of the data subject (guest entry, adding an athlete to a club or training group, importing results of past competitions), the organizer or club is the data controller, and we act as a processor on their documented instructions (GDPR Art. 28; 152-FZ Art. 6(3)). The person who enters such data is responsible for its lawfulness and for any required consents (Terms of Use, sections 7 and 8).

3. What data we process

3.1. Account (all registered users): e-mail address (login); password (stored only as an irreversible hash); full name; date of birth; gender; country and region; interface language and time zone; a profile photo (avatar, optional); the date and fact of accepting the Platform’s documents.

3.2. Sports profile (athlete, coach, referee): weapons; sports rank / title and refereeing category; country and region represented; sports club / organization and coach; fencing hand (left / right).

3.3. Entries and participation: entry details and data refined for a specific competition (club, region, coach, rank), participant lists, and competition results (bout scores, placements, participation status).

3.4. Clubs and training: data of club owners and members, club contact details, training-group membership, schedule, and attendance.

3.5. Third-party data entered by a user. When applying to a competition, a user may add accompanying persons (full name) and vehicle details (number plate and, where needed, the owner’s name) to arrange venue passes. Such data is entered under the user’s responsibility (Terms of Use, section 7).

3.6. Technical data (all visitors): IP address (recorded in the audit trail of changes), records of significant actions, cookies and similar technologies (section 9).

3.7. We do not process special categories of data (health, biometrics, etc.). A medical withdrawal of an athlete is recorded only as a sporting status, without any health details. Profile photos are used for display only and are not used for biometric identification. We do not profile users, do not make automated decisions with legal effects, and do not sell personal data.

4. Purposes and legal bases

  • Registration and account functionality — Art. 6(1)(b) GDPR / 152-FZ Art. 6(1)(5), contract.
  • E-mail verification, password reset, and notifications about entry status and other significant events — contract, consent.
  • Entries, start lists, protocols, and running the competition — contract; for data entered by an organizer, processing on the controller’s instructions (Art. 28).
  • Public publication of competition progress and results (name, year of birth, region, club, rank, coach, results) — consent to publication (Art. 10.1 152-FZ, section 5), contract.
  • Athlete search and integration with competition-running services (section 6) — consent, contract.
  • Security, abuse prevention, and audit logs — Art. 6(1)(f) GDPR, legitimate interest.
  • Traffic measurement and improving the Platform (anonymous technical data) — legitimate interest.

5. Consent given on registration

When creating an account and when applying to a competition, the user gives consent covering: processing of personal data on the Platform for the purposes in section 4; sharing the data with the organizers of competitions applied to and with integrated competition-running services (section 6); and the public distribution of the data the subject permits for distribution (Art. 10.1 152-FZ) — full name, year of birth, region, club, sports rank, coach, and results — on zenfencing.ru and fencing.ru and on the competition organizer’s own channels.

Consent is given freely. It may be withdrawn at any time by contacting info@zenfencing.ru or by deleting the relevant data in your account. Withdrawal does not have retroactive effect and does not affect data already published in the final protocols of completed competitions to the extent needed to preserve the integrity of the sporting result. Publishing the minimum protocol data (name and results) is inherent to taking part in a public sporting competition.

6. Sharing and recipients

We share personal data only with:

  • competition organizers — entry data is shared with the organizer of the competition applied to, for eligibility, protocols, and running the event;
  • the fencing.ru competition service — when a competition is run live and results are exchanged, the Platform shares the relevant start lists and final results; athlete search lets an organizer on fencing.ru find an athlete and add them to a competition;
  • our e-mail provider — to deliver e-mails (verification, password reset, notifications): the recipient’s address and the message content;
  • public authorities, where required by applicable law.

Start lists and competition progress and results are public by design and visible to anyone — this is the core function of the Platform. The same public data may also be published on the partner platform fencing.ru. An organizer may additionally publish results on their own channels (website, social media, etc.) as an independent controller. These channels are covered by the consent to distribution (section 5).

We do not transfer personal data to servers outside Russia. There are no advertising networks and no third-party tracking. Russia is not covered by an EU adequacy decision; if you access the Platform from the EU/EEA or take part in a competition run on it, your data is processed on servers in Russia, in reliance on Art. 49(1)(b) GDPR (transfer necessary to perform the contract) and the safeguards in section 11.

7. Children

Many fencing competitors are minors. Registration and consent for a participant under 14 are provided by their parent or legal guardian; for a participant aged 14 to 18, registration is done with the awareness and consent of a parent or legal guardian. In the EU/EEA, parental consent applies below the age set by local law under Art. 8 GDPR. By creating a minor’s account or entering their data, the user confirms that they have the necessary authority and the legal guardian’s consent, including for publication in competition protocols.

8. Storage location and retention

The Platform’s databases for personal data of Russian citizens are located in the Russian Federation (152-FZ Art. 18(5)). Account and profile data is kept for the life of the account; competition data (including participant data and results) is kept for as long as the competition exists in the Platform, as results have lasting sporting and archival value; technical logs (IP, action records) are kept for no longer than 12 months, then deleted or anonymized. Processing ends when its purposes are met, on expiry of retention periods, on withdrawal of consent (absent another legal basis), or where unlawful processing is found.

9. Cookies and analytics

We use only functional and session cookies needed for the Platform to work; there are no advertising cookies. These include refreshToken (an HttpOnly session cookie that keeps you logged in), hasSession (a flag indicating an active session), and NEXT_LOCALE (interface language). The account access token is held in browser memory only and is not written to persistent storage. For traffic measurement we may use our own self-hosted analytics (Umami), which works without cookies, collects only anonymous data, does not profile individual users, and is not shared with third parties. You can delete or block cookies in your browser; some features (login, language) may then stop working.

10. Your rights

Subject to applicable law (GDPR Articles 15–21; 152-FZ Chapter 3), you have the right to access your data; rectify inaccurate data; erase your data; restrict or object to processing; data portability; withdraw consent at any time (without affecting prior processing); and lodge a complaint with a supervisory authority (in the EU — your local data protection authority; in Russia — Roskomnadzor). To exercise your rights, contact info@zenfencing.ru. If your request concerns data entered by an organizer or a club, we will forward it to that controller or fulfil it in coordination with them. We respond within one month (GDPR) or 10 business days (152-FZ), whichever applies.

11. Security

We use HTTPS encryption in transit; passwords stored only as hashes; HttpOnly session cookies; access controls; rate limiting and brute-force protection on login (account lockout after repeated failed attempts); strict input validation; audit logs of significant actions; and internal monitoring.

12. Beta period

The Platform is in beta. As a result:

  • the feature set and therefore the categories of data processed may change; where a new purpose or a new category of data is introduced, this policy is updated before that processing begins;
  • during maintenance, migrations, and bug fixing, data may be moved between technical environments, recalculated, restored from backups, or deleted; retention is governed by section 8;
  • some operations on data — correcting incorrectly entered records, merging duplicate athlete profiles, importing results of past competitions, restoring data — may during this period be carried out manually by authorised staff of the Operator; such actions are written to the audit log;
  • the beta status of the Platform does not limit data subjects’ rights: requests are handled and consent is withdrawn in the manner and within the time limits set out in section 10 and by applicable law, regardless of the Platform’s stage of development.

13. Changes

We may update this policy. The current version is always available on this page; material changes are announced on the Platform. Matters not covered here are governed by the laws of the Russian Federation.

© 2026 ZenFencing. All rights reserved.
Privacy PolicyTerms of Service