Privacy Policy

Last updated: August 9, 2026

This Privacy Policy explains how personal data are processed when you use the OCR Europe application or visit the OCR Europe website.

Personal data are processed only where necessary to provide the website and application, operate their technical functions, maintain security, provide optional synchronization and notification functions, or where you have consented to the processing.

1. Controller

The controller responsible for processing personal data under the General Data Protection Regulation (GDPR) is:

Norman Rath
c/o OCR Europe
Thomas-Müntzer-Str. 10
04207 Leipzig
Germany
E-mail: Click to write
Website: www.ocr-europe.com

2. Website access and server log files

When you visit the OCR Europe website, the web server may automatically process technical information transmitted by your browser.

This may include:

These data are processed to deliver the website, ensure its stability and security, detect technical errors, and prevent misuse or attacks.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable, and technically functional operation of the website and the protection of our systems against misuse and attacks.

Server log data are deleted when they are no longer required for these purposes, unless further storage is necessary to investigate a security incident, comply with a legal obligation, or establish, exercise, or defend legal claims.

3. Data processing when using the OCR Europe application

When using the OCR Europe application, certain technical information may be transmitted to servers operated for OCR Europe in order to provide app functions, manage notification registrations, and ensure technical compatibility.

The following data may be processed:

The device token is used exclusively to address and deliver push notifications to the respective installation of OCR Europe.

The application version, build number and operating system version are used to manage notification registrations, ensure technical compatibility and prevent notifications from being sent to outdated or incompatible application installations.

The configured language is used to select the appropriate language for notifications and related app functions.

These technical data are not combined with a name, e-mail address, user account or other information that would directly identify the user.

The data are not used for advertising, profiling, cross-app tracking or purposes of data brokers. The data are not sold.

4. Push notifications

OCR Europe may send push notifications relating to events, application content, event reminders and notification categories activated by the user.

Push notifications are only sent if the user has granted the required notification permission of the respective operating system.

For this purpose, the application receives a device token from the respective push notification service. This token serves as a technical delivery address for the respective installation of OCR Europe.

On iOS, push notifications are delivered through Apple Push Notification service (APNs).

On Android, push notifications may be delivered through Google Firebase Cloud Messaging (FCM).

For the delivery of a notification, the device token and the notification content are transmitted to the respective push notification service of the platform provider.

The legal basis for processing in connection with voluntarily activated push notifications is Article 6(1)(a) GDPR.

The notification permission can be withdrawn at any time with effect for the future. Push notifications can be disabled in the settings of OCR Europe or in the system settings of the respective device.

Disabling notifications prevents future push notifications from being delivered.

Technical registration data that are no longer required are deleted or deactivated when:

Apple and Google process transmitted data in accordance with their own applicable privacy provisions.

5. Local notifications and event reminders

OCR Europe may offer local reminders for events or other application content.

Local notifications are scheduled and managed on the user's device. Scheduling a local notification does not require the corresponding reminder data to be transmitted to servers operated by OCR Europe.

Users can manage reminder options within the application and can disable notification permission at any time in the system settings of the respective device.

6. Locally stored application data

OCR Europe allows users to store application data such as:

These data may be stored locally on the user's device.

Locally stored application data are not transmitted to servers operated by OCR Europe unless transmission is expressly required for a particular synchronization or technical function described in this Privacy Policy.

Users can modify or delete locally stored data using the corresponding functions provided within the application.

Deleting the application may remove locally stored application data, subject to the storage and backup mechanisms of the respective operating system or platform provider.

7. Optional synchronization via iCloud and CloudKit (iOS)

On iOS, if iCloud is available and enabled for OCR Europe, locally stored application data may be synchronized between the user's Apple devices through Apple's iCloud and CloudKit services.

Depending on the application functions used, synchronized data may include:

These synchronized data are associated with the user's Apple Account within Apple's infrastructure.

OCR Europe does not create a separate user account for this purpose and does not receive the user's Apple Account password.

Data transmitted through iCloud or CloudKit are processed by Apple in accordance with the agreements and privacy provisions applicable to the user's Apple Account and iCloud services.

Users can manage or disable iCloud access for OCR Europe through the iOS settings.

Disabling synchronization does not necessarily delete data that have already been stored locally or in iCloud.

8. Location data

OCR Europe may request access to the user's current location to provide functions such as:

The current location is processed on the user's device and is not transmitted to servers operated by OCR Europe.

Location access can be managed or withdrawn at any time in the privacy and location settings of the respective device.

If the user opens an event location in Apple Maps, Google Maps or another map or navigation application, the destination and any location data required for the requested map or navigation function are processed by the selected provider in accordance with that provider's privacy policy.

9. Calendar access and event export

OCR Europe may allow users to add an event to the calendar available on their device.

Calendar access is only requested where necessary to perform the function selected by the user and where required by the respective operating system.

When an event is added to the device calendar, information such as the event name, date, time, location and related event details may be transferred to the calendar selected by the user.

OCR Europe does not transmit the user's existing calendar contents to servers operated by OCR Europe.

Depending on the calendar selected by the user, calendar data may be synchronized by Apple, Google, Microsoft or another calendar provider.

Such synchronization is controlled by the user's device and account settings and is subject to the privacy policy of the respective calendar provider.

10. Event data and external registration links

OCR Europe provides information about obstacle course racing and other sporting events throughout Europe.

Event information may include, for example:

This information generally relates to events and organizations rather than individual users of OCR Europe.

OCR Europe may provide links to event organizers, ticketing or registration providers and other external services.

No personal data are transmitted to an external provider merely because a standard link is displayed.

When the user actively opens a registration link or another external service, the respective provider may process technical information and any information subsequently provided by the user.

The external provider is responsible for this processing and its own privacy policy and terms apply.

11. External websites and services

The website and application may contain links to external websites or services, including:

No personal data are transmitted to an external provider merely because a standard link is displayed.

When the user actively opens an external link or service, data may be transmitted to the respective provider. The provider is responsible for the subsequent processing and its own privacy policy and terms apply.

Where content from an external provider is directly embedded rather than merely linked, technical data may be transmitted to that provider when the embedded content is loaded. Where applicable, such processing is governed by the privacy provisions of the respective provider.

12. Matomo website analytics

The OCR Europe website uses Matomo, an open-source web analytics platform, to obtain statistical information about the use of the website and to improve its content, usability, and technical performance.

Matomo is operated on infrastructure controlled by or provided for OCR Europe.

Matomo is configured without analytics cookies. No Matomo tracking cookies are stored on the user's device.

Matomo may process technical and usage information such as:

The data are used to create website statistics, identify technical problems, and improve the website.

They are not combined with user accounts, names, e-mail addresses, or other information directly identifying a visitor.

The data are not used for advertising or cross-website tracking and are not transmitted to advertising networks or data brokers.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are:

Analytics data are stored only for as long as they are required for these purposes and are subsequently deleted or anonymized.

Further information about Matomo is available in the Matomo Privacy Policy.

13. Recipients and service providers

Personal data are disclosed only where necessary for the stated purposes, where disclosure is legally required, or where the user has consented.

Recipients may include:

Service providers acting on our behalf process personal data only in accordance with applicable data protection requirements and contractual instructions.

14. International data transfers

The use of services provided by Apple, Google or other international providers may involve the processing of data outside the European Economic Area.

Where personal data are transferred to a country for which the European Commission has not adopted an adequacy decision, the transfer is based on an appropriate legal safeguard where required, such as the European Commission's standard contractual clauses.

15. Legal bases for processing

Depending on the individual processing activity, personal data are processed on one or more of the following legal bases:

16. Legitimate interests

Where processing is based on Article 6(1)(f) GDPR, our legitimate interests include:

17. Storage and deletion

Personal data are stored only for as long as necessary for the respective processing purpose.

Data may be retained for a longer period where:

Technical push notification registration data are stored only for as long as required to provide the notification service or related technical functions.

Locally stored data remain on the user's device until they are deleted by the user, removed by the application, or removed through mechanisms provided by the operating system.

Data stored through an optional synchronization service may remain within the infrastructure of the respective platform provider until deleted in accordance with that provider's functionality and policies.

Once the relevant purpose no longer applies and no legal retention obligation or other lawful reason for continued storage exists, data processed by OCR Europe are deleted, anonymized or otherwise rendered unusable for the respective purpose.

18. Data security

Appropriate technical and organizational measures are used to protect personal data against accidental or unlawful:

However, data transmission over the internet cannot be guaranteed to be completely secure. Absolute protection against all risks is therefore not possible.

19. Rights of data subjects

Subject to the applicable legal requirements, data subjects have the following rights:

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

To exercise these rights, data subjects may contact the controller using the contact details provided in Section 1.

20. Right to object under Article 21 GDPR

Where personal data are processed on the basis of Article 6(1)(f) GDPR, the data subject has the right to object to the processing at any time on grounds relating to their particular situation.

Following an objection, the personal data will no longer be processed unless compelling legitimate grounds for the processing can be demonstrated which override the interests, rights, and freedoms of the data subject, or unless processing is required for the establishment, exercise, or defence of legal claims.

21. Right to lodge a complaint

Data subjects have the right to lodge a complaint with a data protection supervisory authority if they believe that the processing of their personal data infringes applicable data protection law.

A complaint may be submitted to the supervisory authority responsible for the controller or to another competent supervisory authority, particularly in the EU Member State of the data subject's habitual residence, place of work, or place of the alleged infringement.

The supervisory authority responsible for the controller's location is:

Sächsische Datenschutz- und Transparenzbeauftragte
Maternistraße 17
01067 Dresden
Germany
E-mail: post@sdtb.sachsen.de
Website: www.datenschutz.sachsen.de

22. Automated decision-making and profiling

OCR Europe does not use personal data for decisions based solely on automated processing that produce legal effects or similarly significantly affect users.

OCR Europe does not use personal data for advertising profiles or tracking profiles.

23. Obligation to provide data

Users are not legally required to provide the technical data described in this Privacy Policy.

However, certain technical data are required to provide specific functions.

For example, a valid push notification device token is required to deliver remote push notifications. If notification permission is not granted or is withdrawn, the application can still be used, but remote push notifications cannot be delivered.

Location permission is optional. If location access is not granted, the application can still be used, but functions that require the user's current location, such as nearby-event searches, distance calculation or distance-based sorting, may not be available.

Calendar access is optional. If calendar access is not granted, OCR Europe can still be used, but events may not be added directly to the user's calendar where such permission is required.

Synchronization is optional. If synchronization is disabled or unavailable, OCR Europe can still be used, but synchronized application data may not be available across multiple Apple devices.

24. Changes to this Privacy Policy

This Privacy Policy may be updated where application functions, website functions, legal requirements, or processing activities change.

The current version of this Privacy Policy is made available through OCR Europe and/or the OCR Europe website.