Sports Timing Brasil

Legal

Privacy Policy

Applies to sportstimingbrasil.com, to the SwimSystemApp platform (swimsystem.app), to the coach, official and athlete portals, to the desktop competition modules and to our support channels.

Last updated: September 17, 2026 · version 2.1

Sports Timing Brasil (STB) values the privacy of its users and is firmly committed to the protection of personal data, guided by the principles of transparency, security, necessity and purpose. This Privacy Policy explains how we collect, use, store, share, transfer and protect information provided by athletes, legal guardians, event organizers, sports federations, service providers and everyone else who interacts with our systems and platforms.

Our operations comply with the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018). Where our services reach data subjects located in the European Union or the United Kingdom, we also follow the standards of the General Data Protection Regulation (GDPR, Regulation EU 2016/679), ensuring lawful and secure processing in cross-border environments.

The short version. We process the data required to register athletes, run competitions, charge entry fees and publish results. We do not sell personal data and we do not use competition data for third-party advertising.

Sports results are public information by nature: name, club, category, event and time appear in bulletins, on the venue scoreboard and on the results portal; see the section on public disclosure. For any request about your data, write to support@sportstimingbrasil.com.

1. Who we are and who this policy applies to

STB Sistemas e Tecnologia Esportiva LTDA, trading as Sports Timing Brasil, registered under Brazilian company number (CNPJ) 47.816.373/0001-07, with offices in Curitiba/PR, Brazil, is a Brazilian company specialized in digital solutions for sports event management, with a strong focus on swimming, open water swimming and artistic swimming.

Our systems support every stage of an event: membership and registration of athletes, coaches and officials, entries, event programmes, seeding, document checking and validation, accreditation and venue access control, timing, officials rosters, payment processing and real-time publication of results.

Covered surfaces

  • sportstimingbrasil.com: this corporate website.
  • swimsystem.app: the SwimSystemApp platform, with the public competition and results portal, the administrative panel used by sports bodies, and the coach, official and athlete portals.
  • Desktop competition modules (SW Module, OW Module and others), used at the poolside or at the race venue, including over a local network with no internet access.
  • Support channels: support centre, e-mail, WhatsApp and the service status page.

This policy does not apply to the websites, regulations and in-house systems of the confederations, federations, clubs and organizers that use our solutions. Each of those bodies has its own policy and is responsible for the processing it carries out outside our platforms.

2. Definitions

  • Personal data: any information relating to an identified or identifiable natural person.
  • Sensitive personal data: data on health, racial or ethnic origin, religious belief, political opinion, genetic or biometric data, among others listed in the LGPD.
  • Data subject: the natural person the data relates to.
  • Controller: the party that decides on the processing of personal data.
  • Processor: the party that processes personal data on behalf of the controller.
  • Data Protection Officer (DPO): the person appointed to act as the channel between the controller, data subjects and the data protection authority.
  • Processing: any operation carried out with personal data, such as collection, use, access, reproduction, transmission, storage and deletion.
  • Consent: a free, informed and unambiguous statement by which the data subject agrees to the processing of their data for a specific purpose.
  • Sports body: in this policy, the confederation, federation, league, club, school or organizer that contracts our solutions and registers people in them.

3. When we are controller and when we are processor

Our platforms are multi-tenant: every confederation, federation, club or organizer has its own area and decides who to register, which documents to require and which competitions to run. That distinction defines who is responsible for each processing activity.

SituationOur role
Login account data, the corporate website, support interactions, billing of our own subscriptions and platform securityController. We define the purpose and the means of processing.
Data of athletes, coaches, officials and other participants entered by a sports body to manage memberships, entries, rosters and resultsProcessor. The sports body is the controller; we process such data according to its instructions and the contract in place.
Data the data subject enters in a portal (coach, official, athlete) to link themselves to a sports bodyProcessor for the sports affiliation and controller for the login account and the security logs.

When we receive a request about data for which we are only a processor, we forward the request to the controlling sports body, provide the technical support needed to fulfil it and let the data subject know that the request was forwarded.

4. Legal bases and principles

All processing we carry out relies on at least one of the legal bases set out in the LGPD (art. 7 and, for sensitive data, art. 11) and, where applicable, in the GDPR (art. 6 and 9):

  • Performance of a contract or of preliminary steps: competition entry, membership, use of the platform, issuing of charges.
  • Compliance with a legal or regulatory obligation: tax, accounting and employment obligations, and retention of access logs.
  • Legitimate interest: platform security, fraud prevention, service improvement and publication of sports results.
  • Consent: marketing communications, non-essential cookies and sensitive data processing that depends on specific authorisation.
  • Exercise of rights in judicial, administrative or arbitration proceedings, and credit protection.
  • Protection of life and physical safety of the data subject or a third party, for example relevant medical information during an open water race.

Principles that guide our decisions

  • Purpose, adequacy and necessity: we ask for the minimum data the competition and the sports rules require, and each sports body may reduce the required fields further.
  • Transparency and free access for the data subject.
  • Data quality and the ability to have data corrected.
  • Security, prevention and non-discrimination.
  • Accountability.

5. Data we process

Data provided by you or by your sports body

  • Identification: full name, social name, date of birth (or the year only, where the exact date is not required), sex/gender, nationality and place of birth, photograph for accreditation.
  • Documents: Brazilian taxpayer number (CPF), identity card, passport for foreign nationals, company numbers of clubs and providers, and the documents required by the sports body for membership.
  • Professional and sports records: licence or registration number, coach professional council registration, officiating level and grade, club affiliation and transfer history.
  • Contact details: e-mail addresses, phone numbers and postal address.
  • Legal guardian data where the data subject is a minor.
  • Functional classification and health data strictly necessary for para-sport events or for race safety.
  • Payment data: billing details and receipts. Full card numbers are entered directly in the payment provider environment and never pass through or remain in our systems.

Data generated by the use of the platforms

  • Entries, entry times, heats and lanes, results, splits, outcomes (disqualification, no-show, did not finish), rankings, points and records.
  • Officials rosters, roles performed, attendance and issued credentials.
  • Accreditation and venue entry records, where the sports body uses access control.
  • Support requests, messages, attachments and the interaction history.

Data collected automatically

  • IP address, date and time of access and approximate location derived from the IP address.
  • Browser type, operating system, language, theme and device or desktop module installation identifier.
  • Pages visited, actions taken and application failures, for diagnosis and security.
  • Cookies and similar technologies, as described in the dedicated section.

Data received from third parties

  • Data sent by the sports body you are linked to, including through imports of competition files (LENEX, SDIF, spreadsheets) and of sports management systems.
  • Taxpayer number checks against official databases and authorised lookup providers, to confirm the name and registration status.
  • Payment confirmations and updates sent by the payment provider.

6. What we use each type of data for

PurposeLegal basis
Create and maintain login accounts and authenticate usersContract performance
Process memberships and entries, check documents and apply competition rules (age, category, deadlines, quotas)Contract performance and legitimate interest
Issue charges, reconcile payments, issue invoices and receiptsContract performance and legal obligation
Run the competition: seeding, timing, scoreboard, results, points and recordsContract performance and legitimate interest
Publish event programmes, results, rankings and recordsLegitimate interest and applicable sports rules
Issue credentials and control access to the venueContract performance and legitimate interest
Provide technical support and answer requestsContract performance and legitimate interest
Keep the platforms secure, investigate incidents and prevent fraudLegitimate interest and legal obligation
Retain application access logsLegal obligation (Brazilian Internet Civil Framework)
Send operational notices about the competition, the entry and the accountContract performance
Send news, content and invitations that are not operationalConsent, revocable at any time
Measure website audience and performance with aggregated metricsConsent, for non-essential cookies

We do not use data of athletes, coaches and officials for third-party advertising, we do not sell it and we do not license it for the building of commercial databases.

7. Public disclosure of sports data

A competition is a public event, and a sports result is the record of a public fact. For that reason, certain data appears without login on the competition portal, in bulletins, on the venue scoreboard, in broadcasts and in official documents issued by the organizing body.

  • Usually public: participant name, sports body or club, category and age group, functional class where applicable, event, heat and lane, time, splits, outcome, ranking, points and records.
  • Never public: taxpayer and identity numbers, postal address, phone number, e-mail address, legal guardian data, health information, payment data and the content of support interactions.

The organizing body controls disclosure: it decides when the result of a heat becomes official and it can take the results of a competition off the air. Until a heat is made official, outcomes such as disqualification and the corresponding reason are not shown publicly.

Photographs and video recorded at the event are the responsibility of whoever organizes and broadcasts the competition, under the regulations and participation terms of that event.

If you believe the display of your data goes beyond what the sports purpose requires, you may object to the processing through the channels in the rights section. We will assess the request together with the controlling body; in some cases publication of the result is required by the rules of the sport and cannot be suppressed.

8. Children and adolescents

A significant part of aquatic sport is practised by children and adolescents, and their data is processed in their best interest.

  • The registration of an underage athlete is carried out by the sports body or by the legal guardian, who declares to be aware of and to agree with the processing described in this policy.
  • Our services are not intended for self-service account creation by children under 13 without the express authorisation of a legal guardian.
  • Sports bodies and operators using our platforms must keep the consent form for the processing of minors data, signed by the legal guardian, and present it on request.
  • We ask only for the data that is necessary; non-operational communications are not addressed to minors.

If improper or unauthorised processing of a minor data is identified, we take immediate steps to delete that data and, where necessary, notify the guardians and the competent authorities.

9. Sensitive personal data

We process sensitive data only where the sport, race safety or the law require it, and always limited to the minimum necessary:

  • Para-sport functional classification and the reports the sports body requires to place the athlete in the correct class.
  • Health information relevant to safety in open water events and to emergency care.
  • Medical or fitness certificates, where the event regulations require them.

Such data is restricted to the people who need it for the role they perform, does not appear in public listings and is never used for commercial purposes.

10. Who we share data with

Sports bodies and organizers

We share participant data with confederations, federations, leagues, clubs and organizers only where there is a direct link to the membership, the entry or the participation in an event, under the contracts, regulations and cooperation terms in place. Each body access is limited to its own scope and to the bodies affiliated to it.

No personal information is made available to third parties without a proper legal basis, even where different bodies enter or request conflicting data in our systems. In case of inconsistency, we apply technical and administrative measures to protect data integrity and to give priority to the security and privacy of the data subject.

Processors and service providers

We rely on suppliers that process data on our behalf, under contract and with security and confidentiality obligations:

SupplierPurpose
Asaas Gestão Financeira Instituição de Pagamento S.A. (CNPJ 19.540.550/0001-21)Issuing and settlement of charges by PIX, bank slip and card, transfers to sports bodies and management of receiving accounts
Cloudflare, Inc.Application hosting and network protection
Supabase, Inc.Storage of platform data and account authentication
Amazon Web Services, Inc.Cloud infrastructure used by Supabase
Google CloudCloud services and AI-assisted reading of event documents
Google AnalyticsAggregated audience metrics for the public portal, subject to your consent
MailerSendService e-mail, such as invitations, password resets and receipts
Atlassian (Statuspage)Public status page and communication of incidents and maintenance
Authorised registration lookup providersChecking of taxpayer numbers and registration status against official databases

Authorities and other cases

  • Public, judicial, administrative and regulatory authorities, where there is a legal obligation or a formal request.
  • Lawyers and auditors, for the exercise of rights and compliance with obligations.
  • In the event of corporate reorganisation, merger, acquisition or sale of assets, with notice and keeping the safeguards of this policy.

Sports Timing Brasil does not sell personal data. All third parties we work with are contractually bound to appropriate privacy and information security standards.

11. International data transfers

Some of the suppliers above operate servers and teams outside Brazil. Whenever there is an international transfer, we apply the applicable legal mechanisms to ensure an adequate level of protection:

  • Standard contractual clauses, including those approved by the European Commission and the standard clauses of the Brazilian data protection authority (ANPD).
  • Adequacy decisions recognised by the ANPD or by the European Commission.
  • Prior assessment of the supplier, requiring security measures equivalent to our own.

Wherever possible we prefer processing regions in Brazil or in the Americas, to reduce latency and to simplify the applicable regime.

12. Cookies and similar technologies

We use cookies, browser local storage and equivalent identifiers in the desktop modules. Essential ones cannot be switched off without breaking the service; the others depend on your choice.

CategoryWhat it does
EssentialKeep your session authenticated, protect forms, balance load and remember the selected sports body
PreferenceStore language, light or dark theme, filters and form drafts in your browser
Performance and diagnosticsIdentify application errors and slow pages, with technical data about the access
Audience metricsMeasure visits in aggregate on the public portal; enabled according to your consent

You can configure your browser to refuse or delete cookies and withdraw the consent given to non-essential categories. Some features may be limited; for instance, you will have to sign in again on every visit.

13. How long we keep data

We retain each piece of data only for as long as necessary for the purposes in this policy or for the period the law requires. After that it is deleted or anonymised.

CategoryRetention
Registration and sports affiliationWhile the affiliation is active and for the applicable limitation periods after it ends
Results, rankings, points and recordsIndefinitely, for the historical and statistical interest of the sport, including the determination of records
Membership documents and evidence required by the sports bodyFor the period defined by the controlling body and by the rules of the sport
Tax, accounting and financial dataFor the statutory retention period of tax and accounting documents
Application access logsAt least 6 months, under the Brazilian Internet Civil Framework, and longer where there is an ongoing request or investigation
Support interactionsWhile necessary to resolve the case and thereafter for the applicable limitation period
Data processed on the basis of consent (marketing, metrics)Until consent is withdrawn

14. Information security

We apply technical and administrative measures to protect data against unauthorised access and accidental or unlawful destruction, loss, alteration or disclosure, with practices aligned to international information security management standards (ISO/IEC 27001):

  • Encryption of data in transit and at rest.
  • Role-based access control, with segregation between sports bodies and least privilege; each user access is limited to their own body and its affiliates.
  • Managed authentication, with secure password reset and passkey support.
  • Application event logging and monitoring of errors and outages.
  • Backup and recovery routines, tested periodically.
  • Edge protection against denial-of-service attacks and malicious requests.
  • Contractual confidentiality with our team and our suppliers.

No system is absolutely impenetrable. If you suspect misuse of your account or identify a vulnerability, please tell us immediately at support@sportstimingbrasil.com.

15. Security incidents

We maintain an internal procedure to detect, contain and investigate security incidents involving personal data. Once an incident with relevant risk to data subjects is confirmed, we notify the Brazilian data protection authority and the affected data subjects within a reasonable period, describing what happened, the data involved, the measures taken and the recommended protective steps.

Where we act as processor, we immediately notify the controlling body and provide the information it needs to meet its own notification duties.

16. Automated decisions and artificial intelligence

We do not take solely automated decisions producing legal effects on you, such as accepting or refusing a membership, based on behavioural profiling.

Our systems do perform automatic checks and calculations: taxpayer number validation against official databases, age and category checks, time processing, points, rankings and records, and seeding suggestions. These are objective sports and registration rules, always reviewable by whoever runs the competition.

We use artificial intelligence for one bounded task: reading event documents, such as a PDF event programme, to turn them into structured data. The output is reviewed by a person before it takes effect. We do not use participants personal data to train artificial intelligence models.

You may request a review of any automated decision affecting you through the channels in the next section.

17. Your rights and how to exercise them

You have the following rights under the LGPD and, where applicable, the GDPR:

  • Confirmation that processing exists and access to your data.
  • Correction of incomplete, inaccurate or outdated data.
  • Anonymisation, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law.
  • Portability of your data to another provider, subject to trade and industrial secrets.
  • Deletion of data processed on the basis of consent.
  • Information about who we share your data with.
  • Information about the possibility of refusing consent and the consequences of that refusal.
  • Withdrawal of consent and objection to processing based on legitimate interest.
  • Restriction of processing and review of automated decisions.
  • Lodging a complaint with the data protection authority (the ANPD in Brazil, or the competent authority in the European Union).

How to ask

Write to support@sportstimingbrasil.com describing your request. To protect you, we may ask for additional information confirming your identity or your status as legal guardian. We answer within 15 days under the LGPD; in cases governed by the GDPR, within 1 month, extendable under the terms of the regulation.

If the data is under the control of a federation, club or organizer (the most common case for memberships and entries), we forward your request to the controlling body and let you know that we did. Requests that depend on sports regulations, such as removing an official result, are decided by that body.

18. Changes to this policy

This policy may change to reflect legal, technical or service developments. The date of the last update and the version appear at the top of the page. Material changes are announced through our official channels or prominently on the platforms, and we recommend reading this page periodically.

Where a change requires new consent, it will be requested before the new processing begins.

19. Data Protection Officer, contact and jurisdiction

Questions, requests and complaints about privacy should be addressed to our Data Protection Officer (DPO), João Pedro Marin Vieira Cordeiro, who answers in Portuguese and English:

  • E-mail: support@sportstimingbrasil.com
  • Phone and WhatsApp: +55 (41) 99175-1337
  • Address: Rua Silveira Peixoto, 1062, Sala 92, Água Verde, Curitiba/PR, ZIP 80240-120, Brazil

This policy is governed by Brazilian law. The courts of Curitiba/PR are elected to settle disputes arising from it, without prejudice to the data subject right to apply to the data protection authority or to the courts of their own domicile, where the law so provides.

STB Sistemas e Tecnologia Esportiva LTDA. (Sports Timing Brasil) · CNPJ 47.816.373/0001-07

Rua Silveira Peixoto, 1062, Sala 92, Água Verde, Curitiba/PR, ZIP 80240-120, Brazil

Data Protection Officer: João Pedro Marin Vieira Cordeiro · support@sportstimingbrasil.com