Taikai NAGATO ESPAÑA 2027
1. Basic Information on Data Protection
This Privacy Policy governs the processing of personal data provided by individuals registering for the Taikai organized by the “Bujinkan Collado Dojo” Association.
For the purposes of this Privacy Policy, “Taikai” shall mean the event organized by the “Bujinkan Collado Dojo” Association, an association integrated into the Spanish Kickboxing and Muaythai Federation — FEKM — (FEKM), consisting of a martial arts, educational, and associative gathering led by Nagato Sensei (Daishihan of the Bujinkan Dojo and Soke of Shindenfudo Ryu), intended for the practice, teaching, dissemination, and improvement of martial arts related to the Bujinkan, as well as the participation of attendees and instructors.
The Association shall process the personal data of attendees and instructors for these purposes, in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights (“LOPDGDD”), and other applicable regulations.
2. Data Controller
The controller responsible for processing personal data is ASSOCIATION BUJINKAN COLLADO DOJO – NINJUTSU BUDO TAIJUTSU. Registration number (Valladolid): No. 361.
Contact: legal@taikainagatospain2027.com
3. Categories of Personal Data Processed
The Association may process the following categories of personal data, depending on the specific relationship with the data subject and the information provided in the registration form or through other means enabled for event management:
a) Identification data: first name, surname(s), ID card/NIE/passport number, date of birth, nationality, and signature, where applicable.
b) Contact details: postal address, email address, and telephone number.
c) Sports or associative data: dojo affiliation and Bujinkan rank.
d) Registration and event management data: participation category, registration date, supporting documentation, communications, authorizations, organizational notes, and data necessary for proper participation in the Taikai.
e) Financial or payment data: proof of payment, amount paid, and payment method used.
f) Data required for insurance contracting or management: identification and contact data of attendees or participants, to the extent necessary for the contracting, management, or activation of insurance coverage related to the event.
g) Image and voice: photographs, videos, or recordings taken during the event, where applicable, for informational, promotional, historical, or associative dissemination purposes, always in accordance with the applicable legal basis and the information provided in each case.
h) Health data or special circumstances: only when strictly necessary to address organizational needs, safety, risk prevention, medical assistance, or reasonable accommodation during the event. Such data shall be processed with particular care and limited to what is strictly necessary.
4. Purposes of the Processing
Personal data shall be processed for the following purposes:
4.1. Registration and Participation Management
The Association shall process data to manage registration applications, verify participants’ identities, prepare attendee lists, manage accreditation, control access to the event, and enable proper participation in the Taikai.
4.2. Administrative, Financial, and Accounting Management
Data may be processed to manage payments, issue receipts or supporting documents, verify paid registrations, process refunds where applicable, comply with accounting, tax, or administrative obligations, and retain documentation for legally required periods.
4.3. Communication of Event-Related Information
The Association may use contact details to send necessary information regarding the Taikai, such as registration confirmations, schedules, participation rules, organizational changes, venue information, required documentation, safety instructions, urgent communications, or follow-up information directly related to the event.
4.4. Event Security, Organization, and Control
Data may be processed to ensure attendee safety, manage venue capacity, prevent incidents, handle emergencies, address medical or safety situations, coordinate organizing staff, and comply with applicable legal obligations.
4.5. Management of Event-Related Insurance
Attendee or participant data may be disclosed to the relevant insurance provider, particularly REALE Seguros, for the purpose of contracting, managing, and, where applicable, activating refund insurance or other insurance coverage related to the event, with the Association acting as the policyholder.
Such disclosure shall be limited to the data strictly necessary for the relevant insurance purpose.
4.6. Dissemination of the Association’s Activities
The Association may capture and use images from the event to document activities, report on the event, and promote associative activities through websites, social media, posters, reports, internal or external communications, and other customary channels.
5. Legal Basis for Processing
The legal basis for processing shall depend on each specific purpose:
a) Performance of a contract or pre-contractual measures — Article 6(1)(b) GDPR — for managing registration, participation, payments, accreditations, and the provision of event-related services.
b) Compliance with legal obligations — Article 6(1)(c) GDPR — to comply with tax, accounting, administrative, safety, claims-handling, or lawful authority requirements.
c) Consent of the data subject — Article 6(1)(a) GDPR — for certain processing activities not necessary for event registration, such as specific communications, individualized image capture or dissemination, or other processing activities requiring consent.
d) Legitimate interests of the Association — Article 6(1)(f) GDPR — for ensuring event security and preventing incidents, always balancing the rights and interests of affected individuals.
e) Public interest or protection of vital interests, where applicable — Articles 6(1)(d) and 9(2)(c) GDPR — in emergency situations, medical assistance, or circumstances requiring action to protect the physical integrity of participants.
f) Processing of special categories of personal data, where applicable — Article 9 GDPR — only where strictly necessary and when an applicable exception exists, such as explicit consent, protection of vital interests, or medical assistance.
6. Data Recipients
Personal data may be disclosed, where necessary, to the following recipients:
a) REALE Seguros, for the contracting, management, and, where applicable, activation of refund insurance or other insurance coverage related to the Taikai, with the Association acting as policyholder.
b) Banks, payment platforms, or payment service providers, for payment processing, refunds, or financial supporting documentation.
c) Service providers necessary for event organization, such as IT services, web hosting providers, communication management services, printing companies, accreditation providers, accommodation providers, logistics providers, venue operators, or auxiliary services.
d) Public administrations, law enforcement authorities, courts, tribunals, or competent authorities, where required by law or lawful request.
e) Professionals or collaborating entities, where necessary for the organizational, medical, insurance-related, logistical, or security management of the event.
7. International Data Transfers
Personal data shall be processed within the European Economic Area (“EEA”).
However, if technological providers located outside the EEA are used for event management purposes, or if data access from third countries is involved, the Association shall implement the safeguards required under applicable legislation, such as European Commission adequacy decisions, standard contractual clauses, binding corporate rules, or other valid mechanisms under the GDPR.
8. Data Retention
Personal data shall be retained for the time necessary to manage registration, participation, and the development of the Taikai.
Once the event has concluded, data shall be securely blocked and retained for the periods necessary to address potential legal, contractual, tax, accounting, insurance-related, or administrative liabilities.
In particular:
a) Registration and participation data shall be retained during the organization and holding of the event and subsequently for the limitation period applicable to any potential legal claims.
b) Once the applicable limitation period has expired, attendee data shall be deleted unless another legal basis justifies its retention.
c) Financial, accounting, or tax-related data shall be retained for the periods required under tax and accounting regulations.
d) Data disclosed to insurance entities shall be retained for the time necessary for the contracting, validity, management, and potential claims related to the insurance policy, as well as for the legally established limitation periods.
e) General event images may be retained for as long as reasonably necessary to document historical, informational, or associative activities, unless the data subject validly objects where applicable.
f) Data processed based on consent shall be retained until such consent is withdrawn or for as long as the purpose for which the data was collected remains applicable.
9. Rights of Data Subjects
Data subjects may exercise the following rights:
- Right of access to their personal data.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure where one of the legally established grounds applies.
- Right to object to processing, particularly where based on legitimate interest.
- Right to restriction of processing.
- Right to data portability, where applicable.
- Right to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
To exercise these rights, the data subject may contact the Association via email at legal@taikainagatospain2027.com.
The request must clearly specify the right being exercised and, where necessary, include documentation enabling verification of the requester’s identity.
Data subjects also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos) through AEPD, particularly where they consider that they have not obtained satisfaction in the exercise of their rights.
10. Mandatory or Voluntary Nature of the Data
Data marked as mandatory in the registration form are necessary to manage participation in the Taikai. Failure to provide such data may prevent registration or participation in the event.
Data marked as voluntary shall not condition participation unless necessary for a specific purpose requested by the data subject.
Individuals providing data guarantee that such data are accurate, current, and truthful, and undertake to communicate any modifications.
11. Data of Minors
In the case of participation by minors, registration must be completed or authorized by their parents, legal guardians, or legal representatives, as applicable.
The Association may request documentation or authorization necessary to verify such representation and ensure the safe participation of the minor.
The processing of minors’ data shall be limited to what is strictly necessary for registration, participation, safety, insurance, sports management, and compliance with applicable legal obligations.
12. Security Measures
The Association shall implement appropriate technical and organizational measures to protect personal data against loss, unauthorized access, alteration, improper disclosure, or destruction.
Such measures shall include, among others, restricting access to data to personnel or collaborators who need such access, ensuring the proper custody of lists and forms, using secure communication and storage systems, and reviewing providers involved in event management.
13. Updates to the Privacy Policy
The Association may update this Privacy Policy whenever necessary to adapt it to regulatory, organizational, technical, or event-management-related changes.
The version in force shall be the one published or otherwise provided by the Association at the relevant time.