Privacy Policy & Data Processing Agreement

Part IV — Privacy Policy

Last Updated: 21 May 2026.

This Policy details how IHFP Sports and Technologies Ltd processes, secures, and routes data across its global digital sports architecture. It is written to be consistent with the UK GDPR, the EU GDPR, the California Consumer Privacy Act (as amended by the CPRA), and the data protection regimes of Pakistan, the UAE, Saudi Arabia, Canada, and Australia.

1. Controller Identity and Contact

For data protection purposes, IHFP Sports and Technologies Ltd is the Controller of personal data processed through the Platform. The Controller may be contacted at [email protected] or by post at its registered office in England & Wales. The Data Protection Lead is the company officer responsible for privacy matters and routes queries to the Executive Management Committee where escalation is required.

2. Data Categories Collected and Processed

2.1 Account Identifiers: Name, contact telephone numbers, email addresses, residential addresses, social platform authentication tokens, and cross-border location profiles.

2.2 Geospatial Data: High-precision GPS coordinates of competition lofts, Judge check-in locations, and continuous automated geofence tracking data of officiating staff during active racing windows.

2.3 Avian and Heritage Records: High-definition pigeon photographs, eye-pigmentation data, ring sequence indexes, lineage maps, health compliance certifications, and historical flight performance timelines.

2.4 IoT Device Data Streams: High-definition video recordings captured by the IHFP Loft Guard camera module, motion-sensor triggers, IP addresses, and hardware network connection logs.

2.5 Payment and Commercial Data: Card last-four digits, billing addresses, transaction history, payout records, and tax information where applicable.

2.6 Special Category Data: The Platform does not seek to collect special category personal data. Where biometric facial data is captured for Judge check-in, processing relies on explicit consent at registration and may be withdrawn at any time.

3. Legal Bases for Processing

The Company relies on the following legal bases under the UK and EU GDPR: Contractual performance, Legitimate interests, Consent, and Legal obligation.

4. Data Subject Rights

Users have the rights to access, rectification, erasure (in limited circumstances), restriction, objection, and data portability. Requests may be submitted to [email protected].

5. Information Sharing

Personal data is shared only with cloud infrastructure providers, payment service providers, communications providers, accredited Judges, and regulators where required. Public tournament leaderboards and historical score-card archives are accessible globally without authentication.

6. International Transfers

As a platform operating globally, personal data is transferred across borders utilizing UK and EU Standard Contractual Clauses and other recognised mechanisms.

7. Retention

Standard user accounts, biometric tracking logs, and geofence histories are retained for the active lifecycle of the Platform account plus an archiving period of five years.

Part VI — Data Processing Agreement

This Data Processing Agreement (DPA) forms an integrated part of the Platform's core legal architecture and governs the relationship between IHFP Sports and Technologies Ltd, acting as Data Controller, and external partners, acting as Data Processors.

1. Scope, Duration and Processing Parameters

This DPA governs the systematic processing of first-party sports data, including user profiles, geospatial coordinates, automated IoT landing telemetry, and Referee tracking metrics.

2. Mandatory Security Controls

2.1 Encryption: All geospatial telemetry, payment parameters, and verification video uploads must be encrypted both in transit and at rest.

2.2 Tamper-Proof Timestamps: Telemetry logs originating from the IHFP Loft Guard must bypass local user device clocks, routing instead through secure network servers synchronised directly to authoritative NTP sources.

3. Breach Management

In the event of a verified database intrusion or unauthorised access, the Processor must notify the Company within 24 hours of becoming aware of the incident.

4. Cross-Border Telemetry and Regulatory Compliance

Processors acknowledge that the Platform serves a highly connected international user base and agree to maintain strict regulatory compliance across all data movements.