Privacy policy
How KALIBER Shooting Sports Club processes the personal data of its members, of applicants for membership and of visitors to this website.
Effective from 1 September 2026 · version 1.0
Who processes the data
The controller determining the purposes and means of the processing is the following civic association:
- Name
- Športovo-strelecký klub KALIBER
- Registered office
- Orlové 234, 017 01 Považská Bystrica
- Company ID
- 51890437
- Registration
- Registrácia: Ministerstvo vnútra Slovenskej republiky, číslo spisu VVS/1-900/90-54257
- klub@ssk-kaliber.sk
The club has not appointed a data protection officer — it does not process personal data on a large scale, carries out no large-scale systematic monitoring and processes no special categories of data. For anything concerning personal data, write to the e-mail address above.
What we process and why
Below is the complete overview of our processing. For each purpose you can see which data we need, the legal basis on which we process it and how long we keep it.
Answering a message sent through the contact form
- Data
- Name, e-mail, phone number, subject and body of the message
- Legal basis
- consent (Art. 6(1)(a) GDPR)
- Retention
- One year after the message is dealt with
Assessing an application for club membership
- Data
- Name, e-mail, phone number, date and place of birth, address, firearms licence number, requested type of membership and the reason for applying
- Legal basis
- performance of the membership relationship (Art. 6(1)(b) GDPR)
- Retention
- Until the board decides; a rejected application is deleted automatically after six months, an approved one becomes part of the member record
Keeping the register of members, administering membership and communicating with members
- Data
- Name, membership number, variable symbol, e-mail, phone number, date and place of birth, address, identity card number, firearms licence number including categories and validity, position on the board, membership status and internal note
- Legal basis
- performance of the membership relationship (Art. 6(1)(b) GDPR) + legal obligation (Art. 6(1)(c) GDPR)
- Retention
- For the duration of the membership and three years after it ends
Issuing a certificate of membership for a category E firearms licence
- Data
- Member data in the extent required by the certificate, captured as at the moment of issue, together with the number and date of issue
- Legal basis
- performance of the membership relationship (Art. 6(1)(b) GDPR)
- Retention
- Ten years from the date of issue — the club must be able to evidence what it certified
Registration for training sessions, competitions and club events
- Data
- Name, membership number, the event, registration status and position on the waiting list
- Legal basis
- performance of the membership relationship (Art. 6(1)(b) GDPR)
- Retention
- Three years after the event
Assessing membership fees, recording payments and matching bank transactions
- Data
- Name, membership number, variable symbol, amount and date of payment, the payer's account number and name and the message for the recipient taken from the bank transaction
- Legal basis
- performance of the membership relationship (Art. 6(1)(b) GDPR) + legal obligation (Art. 6(1)(c) GDPR)
- Retention
- Ten years, as required by the Accounting Act
Running the members' area and signing in to it
- Data
- Sign-in e-mail, hashed password, assigned roles and one-time password recovery codes
- Legal basis
- performance of the membership relationship (Art. 6(1)(b) GDPR)
- Retention
- For the duration of the membership
Security and operation of the website, protection of forms against abuse
- Data
- IP address, time of access, page address, browser type and application error logs
- Legal basis
- legitimate interest (Art. 6(1)(f) GDPR)
- Retention
- Twelve months at most
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Answering a message sent through the contact form | Name, e-mail, phone number, subject and body of the message | consent (Art. 6(1)(a) GDPR) | One year after the message is dealt with |
| Assessing an application for club membership | Name, e-mail, phone number, date and place of birth, address, firearms licence number, requested type of membership and the reason for applying | performance of the membership relationship (Art. 6(1)(b) GDPR) | Until the board decides; a rejected application is deleted automatically after six months, an approved one becomes part of the member record |
| Keeping the register of members, administering membership and communicating with members | Name, membership number, variable symbol, e-mail, phone number, date and place of birth, address, identity card number, firearms licence number including categories and validity, position on the board, membership status and internal note | performance of the membership relationship (Art. 6(1)(b) GDPR) + legal obligation (Art. 6(1)(c) GDPR) | For the duration of the membership and three years after it ends |
| Issuing a certificate of membership for a category E firearms licence | Member data in the extent required by the certificate, captured as at the moment of issue, together with the number and date of issue | performance of the membership relationship (Art. 6(1)(b) GDPR) | Ten years from the date of issue — the club must be able to evidence what it certified |
| Registration for training sessions, competitions and club events | Name, membership number, the event, registration status and position on the waiting list | performance of the membership relationship (Art. 6(1)(b) GDPR) | Three years after the event |
| Assessing membership fees, recording payments and matching bank transactions | Name, membership number, variable symbol, amount and date of payment, the payer's account number and name and the message for the recipient taken from the bank transaction | performance of the membership relationship (Art. 6(1)(b) GDPR) + legal obligation (Art. 6(1)(c) GDPR) | Ten years, as required by the Accounting Act |
| Running the members' area and signing in to it | Sign-in e-mail, hashed password, assigned roles and one-time password recovery codes | performance of the membership relationship (Art. 6(1)(b) GDPR) | For the duration of the membership |
| Security and operation of the website, protection of forms against abuse | IP address, time of access, page address, browser type and application error logs | legitimate interest (Art. 6(1)(f) GDPR) | Twelve months at most |
The club does not record birth numbers — data we do not hold cannot leak. A member is identified by name, date of birth and membership card number. The club processes no special categories of data under Article 9 GDPR (health, biometric or genetic data) and collects no criminal record data — that is assessed by the police in the firearms licence procedure, not by the club.
Where the data comes from
Most of the data comes directly from you — in the membership application, in a request to change your data, when registering for an event or when contacting the club. Data about fee payments comes from the bank notifications and statements for the club's account: the payer's name, account number, amount, variable symbol and the message for the recipient. We do not enrich your record from public sources.
Who we share the data with
We do not provide the data to third parties for their own purposes, we do not sell it and we do not publish it. It is accessible to board members to the extent their role requires, and to the following processors:
- the web hosting provider whose servers run the club's website and database (processing the data under a data processing agreement);
- the provider of the mailbox and outgoing mail server through which notifications and certificates are sent;
- the bank holding the club's account — we take payment data from its statements;
- Google (reCAPTCHA), where protection of the public forms is switched on — it processes the IP address and browser behaviour in order to tell a human from a bot.
We do not transfer data outside the European Economic Area, with the exception of reCAPTCHA, where the transfer is covered by the European Commission's standard contractual clauses. The certificate of membership is handed to the police by you — the club sends it to no authority.
Cookies
The website uses strictly necessary cookies only. Without them you could not stay signed in and we could not remember your cookie choice:
front-uid— the members' area sign-in cookie, valid for 30 days;ssk_cookie_consent— your cookie choice, valid for one year.
The club uses no analytics, statistics or marketing tools and does not track your behaviour on the website. Should it ever deploy them, it will ask for your consent beforehand and this list will be extended.
Your rights
In relation to your personal data you have the following rights:
- Right of access
- You may ask for confirmation of whether we process data about you, for a copy of it and for information about the processing.
- Right to rectification
- We will correct any inaccurate or incomplete data. Members can start it themselves by filing a change request in the members' area.
- Right to erasure
- We will erase data once it is no longer needed, once you withdraw consent, or once you object and we have no overriding grounds. Data we must keep by law — accounting records above all — cannot be erased.
- Right to restriction
- While we verify the accuracy of a record or the merits of an objection, we will only store it.
- Right to portability
- Data you have given us and that we process by automated means on the basis of consent or a contract will be provided in a machine-readable format.
- Right to object
- You may object at any time to processing based on a legitimate interest.
- Right to withdraw consent
- Where we process data on the basis of consent, you may withdraw it at any time. This does not affect the lawfulness of the processing before the withdrawal.
- Right to lodge a complaint
- If you believe your data is processed unlawfully, you may turn to the supervisory authority.
You can exercise these rights by e-mail at the club address above. We will reply within one month at the latest; where a request is complex we will tell you within that period that the deadline has been extended. To avoid handing data to the wrong person we may verify your identity. The supervisory authority is:
Office for Personal Data Protection of the Slovak RepublicHraničná 12, 820 07 Bratislava 27, Slovakia dataprotection.gov.skAutomated decision-making
The club carries out no automated individual decision-making and no profiling. Applications, change requests and the issuing of certificates are all decided by the board. The only automated step is matching a bank payment to a member by its variable symbol — if a payment is matched to the wrong member, the board will correct it on request.
Changes to this policy
We will amend this policy when the scope of the processing or the law changes. The current wording is always on this page and its effective date is shown at the top. Members are notified by e-mail of any substantial change.