LEGAL
Privacy policy
Última actualización: July 24, 2026
This policy explains how Eccox Business Group, LLC (“we”) processes personal data when you use the website, the Open Sports System (OSS) platform, and the OSS Arena and OSS Display apps. We do not sell personal data.
1. Controller and contact
Data controller: Eccox Business Group, LLC, developer of Open Sports System. Website: https://opensportsystem.com. Privacy contact: legal@opensportsystem.com.
To exercise rights or ask privacy questions, email legal@opensportsystem.com or use the contact page.
2. Scope
This policy applies to the commercial website, OSS Platform (cloud sports management), and the OSS Arena (control/operator) and OSS Display (visualization) apps, including local connectivity features and, when configured by the event operator, OSS backend services.
It does not apply to third-party websites, apps, or services that have their own privacy policies.
3. Principles
We process only what is needed (minimization), for limited purposes (operation, connectivity, security, and support), with transparency, reasonable security measures, and without selling personal or sensitive data.
4. Data we process
Website and platform: data you provide (name, email, organization, role, country, sport, and messages in forms or when using an account); usage and technical browsing data (pages visited, device, aggregated performance) via cookies and similar technologies — see the Cookie Policy.
Arena / Display apps — event and operational data: event/area labels, discipline/format configuration, scoreboard and timer state, operational messages, and connection parameters (for example local port or pairing URL with token).
Arena / Display apps — technical and local data: local network data to pair controller and display (local IP, port, session token), connection status, minimal compatibility data (e.g. resolution), and preferences/configuration stored on the device.
Camera (optional): only if you choose to scan a QR code for LAN pairing. Permission is requested at runtime. We do not use the camera for biometrics, surveillance, or advertising.
5. Data we do not process by default
In the current base implementation we do not sell personal data, do not include advertising SDKs for ad personalization, do not perform commercial user profiling, and do not request SMS, call log, or precise location permissions for the apps’ core functionality.
If future versions introduce new practices or third-party SDKs, we will update this policy and store disclosures before release.
6. Purposes and legal basis
We use data to: respond to inquiries and demos; provide and improve the service; operate events (control and display); pair devices and maintain sessions; operational continuity (local configuration); security and misuse prevention; and comply with legal obligations.
Where required by law, the legal basis is performance of the service/contract, consent, and/or legitimate interest in operating and protecting the service, depending on context.
7. Permissions and consent
When a feature needs potentially sensitive access (e.g. camera for QR), we request permission at runtime, only on your action, with a contextual explanation of the purpose.
If a future feature involves processing outside reasonable expectations, we will implement prominent disclosure and consent as required by the platform and applicable law.
8. Sharing
We may share data only as needed: between devices in the same deployment (controller and display); with OSS backend infrastructure configured by the operator; with providers acting on our behalf (hosting, analytics, security, monitoring) under processing agreements; or when required by law.
We do not share data for sale.
9. International transfers
If data is processed outside your country, we apply appropriate transfer safeguards as required by applicable law.
10. Retention and deletion
We retain data only as long as needed for operation, technical continuity, security, support, and legal compliance.
Local app configuration can be removed by reset/clear or uninstalling the app. For formal access or account/personal data deletion requests, use the form at https://opensportsystem.com/en/privacy/data-deletion or email legal@opensportsystem.com. We process those requests within 30 days, unless a legal obligation requires otherwise.
11. Security
We apply reasonable technical and organizational measures against unauthorized access, alteration, disclosure, or loss. No system can guarantee absolute security.
12. Children
The website and platform are oriented to organizations and adults managing federated sport. Arena and Display are intended for authorized event personnel (organizers, technical staff, table officials). They are not designed to intentionally collect personal data from children as a primary audience.
13. Your rights
Depending on your jurisdiction, you may request access, rectification, deletion, restriction or objection to processing, portability, withdraw consent where applicable, and lodge a complaint with a competent authority.
To exercise them: legal@opensportsystem.com, the contact page, or https://opensportsystem.com/en/privacy/data-deletion for account or data deletion.
14. Cookies and changes
Cookie use on the website is described in the Cookie Policy (/cookies).
We may update this policy for legal, technical, or product changes. We will publish the current version at this URL and update the “Last updated” date.
15. Store listing consistency
Google Play disclosures (Data safety / Ads, if applicable) and Apple App Store privacy labels should match this policy.