LEGAL
Privacy Policy
Version 1.1 — Last updated: 29 August 2026
1. Introduction
This Privacy Policy explains how personal data is collected, used, stored and protected in connection with the website noxrt.com and the NOXRT Team Portal (together, the “Site”).
It is written to meet the requirements of Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), and Spanish Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights (“LOPDGDD”). Where a member of the team or a visitor is located in the United Kingdom, the equivalent provisions of the UK GDPR and the Data Protection Act 2018 apply, and the same standard of protection is applied in either case.
NOXRT competes internationally and its drivers are not all resident in the same country. It is our policy to apply the protections set out below to every individual whose data we hold, regardless of where they live, rather than only to those whom the GDPR strictly obliges us to protect.
2. Data Controller
The data controller responsible for the processing described in this Policy is:
- Sergi Lozano Bellette, acting in a personal capacity and not as a company or registered association
- Operating under the name NOXRT (NOX Racing Team)
- Located in Barcelona, Spain
- Contact for all data protection matters: infonoxrt@gmail.com
NOXRT is an amateur sim racing team. The Site is not a commercial service, nothing is sold through it, and personal data is never sold, rented, traded or made available to third parties for marketing purposes.
Because of the limited scale and nature of this processing, we are not required to appoint a Data Protection Officer under Article 37 GDPR. The contact address above is the single point of contact for every matter covered by this Policy.
3. Scope and categories of data subject
This Policy covers three distinct groups, and what applies to you depends entirely on which of them you fall into:
- Visitors — anyone who reads the public pages of the Site.
- Team members — individuals for whom an account has been created on the NOXRT Team Portal.
- Event participants — team members who take a seat in a race line-up.
4. Personal data we process
4.1 Visitors
We do not collect, store or process any personal data about visitors to the public Site.
To be specific, and because these are the things a reader is entitled to be sceptical about: the Site contains no web analytics of any kind, no advertising network, no advertising or social media tracking pixels, no behavioural profiling, and no cookies that identify you.
Every asset on this Site is served from our own server. Web fonts are hosted here rather than loaded from Google Fonts. Avatars are generated here rather than fetched from Gravatar. The national flags on our team page are stored here rather than requested from a flag CDN. This is deliberate: each of those, had we taken the convenient option, would have handed your IP address to a company you never chose to visit. Loading a page of this Site causes your browser to contact nobody but us.
One form of processing nevertheless occurs at a technical level, and we consider it more honest to state it than to claim a purity the architecture does not have. Our hosting provider records standard web server data, including IP address, timestamp, requested resource and browser user agent. These logs are generated automatically by the server, are used solely for the operation, availability and security of the Site, and are retained in accordance with the provider’s retention schedule.
4.2 Browser storage
If you switch the Site between its light and dark appearance, that preference is recorded in your browser’s local storage under the key noxrt-theme, with a value of either light or dark.
This is not a cookie. It is never transmitted to our server, it is not readable by us, it contains no identifier, and it cannot be used to recognise or track you. It exists only so that the Site opens the way you last left it. Clearing your browser’s site data removes it.
4.3 Team Portal accounts
Portal accounts are created by us for individuals who are part of the team. Registration is not open to the public and no account can be created by self-service. For each account we process:
- Username, display name and email address
- A cryptographically hashed password, which cannot be read or recovered by us
- The team role assigned to the account, which determines the material that account may access
- Session cookies issued by WordPress while the account is signed in, the sole function of which is to maintain the authenticated session
Authenticated team members may access private team material — car setups, race briefings and telemetry. These files are stored outside the publicly accessible area of the server and are released only after both authentication and role authorisation have been verified for each individual request.
4.4 Event participation
Where a driver takes a seat in an event line-up, we record which account occupies which seat and, once the event has been run, the classification recorded against that seat. This information is stored with the event record and is what makes it possible to field and account for a grid.
4.5 Data we do not process
We do not process special categories of personal data within the meaning of Article 9 GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning a person’s sex life or sexual orientation. We do not process data relating to criminal convictions or offences. We do not request or hold payment card details, government identification numbers, or physical addresses of team members.
5. Purposes and legal bases
Every processing operation described above rests on one of the legal bases in Article 6(1) GDPR, as follows:
- Portal accounts — Article 6(1)(f), legitimate interests: the administration of the team and the operation of a members-only area. Without an account there is no way to identify who is entitled to access private team material. The interest is balanced against the rights of the individual by holding the minimum data required to operate an account and nothing further.
- Event participation — Article 6(1)(f), legitimate interests: organising, entering and recording competitive events, which is the purpose for which the team exists and for which members join it.
- Hosting access logs — Article 6(1)(f), legitimate interests: maintaining the availability, integrity and security of the Site, and investigating abuse or attack.
- Browser storage of appearance preference — strictly necessary to provide the function explicitly requested by the user, and accordingly exempt from the consent requirement under Article 22.2 of Spanish Law 34/2002 (LSSI).
Where processing is based on legitimate interests, you have the right to object to it. Section 9 explains how.
6. Automated decision-making
We do not carry out automated decision-making producing legal or similarly significant effects, and we do not carry out profiling, within the meaning of Article 22 GDPR. Selection for a race line-up is a decision taken by people, on sporting grounds, and is not made by any automated process.
7. Recipients and international transfers
Personal data is not disclosed to third parties. There is exactly one party other than ourselves involved in the operation of this Site:
Hostinger International Ltd, our hosting provider, which stores the Site and its database and acts as a data processor on our behalf, processing personal data only on our documented instructions and under a data processing agreement, as required by Article 28 GDPR. The server hosting this Site is located in France and its backups are stored in Lithuania. Both are within the European Union, and no personal data held in the Site or its database is stored outside it.
There is no content delivery network, no analytics provider, no advertising network and no embedded third-party content. No personal data leaves the European Union.
Should any provider in future process personal data outside the European Economic Area, such transfers will be made only under a transfer mechanism recognised by Chapter V GDPR — an adequacy decision of the European Commission, or the Commission’s Standard Contractual Clauses together with any supplementary measures the transfer requires, and this Policy will be updated to say so before the transfer begins.
Our footer links to Discord, Instagram, Twitch and TikTok. These are ordinary hyperlinks. No content, script or tracker from those platforms is embedded in the Site, and no information about you is transmitted to them unless and until you choose to follow the link. Once you do, you are on a service operated by a separate controller, governed by that platform’s own privacy policy, over which we have no control and for which we accept no responsibility.
8. Retention
| Data | Retention period |
|---|---|
| Portal account and its personal data | For the duration of the individual’s membership of the team. Deleted when membership ends, unless a specific and stated reason requires otherwise. |
| Event line-ups and classifications | Retained as a record of the team’s competitive history. On request, an individual can be dissociated from these records. |
| Hosting access logs | As determined by the hosting provider’s retention schedule. |
| Correspondence about a data protection request | Retained for as long as necessary to evidence that the request was handled, and no longer. |
9. Your rights
Subject to the conditions and exceptions in the GDPR, you have the right to:
- Access the personal data we hold about you, and obtain a copy of it (Article 15)
- Rectification of data that is inaccurate or incomplete (Article 16)
- Erasure of your data (Article 17)
- Restriction of processing in the circumstances set out in Article 18
- Data portability, in a structured, commonly used and machine-readable format (Article 20)
- Object to processing carried out on the basis of legitimate interests (Article 21)
To exercise any of these rights, write to infonoxrt@gmail.com. We will respond within one month of receipt, as required by Article 12(3) GDPR. That period may be extended by a further two months where a request is complex, in which case we will tell you within the first month and explain why. Exercising these rights is free of charge.
We may ask you to confirm your identity before acting on a request. This is not an obstacle placed in your way; it is to ensure that we do not disclose your personal data to somebody else who has asked for it in your name.
10. Complaints
If you believe your data has been handled improperly, we would prefer that you raise it with us first, so that we have the opportunity to put it right.
You are nevertheless entitled at any time to lodge a complaint with a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. If you are resident in another EEA member state or in the United Kingdom, you may instead complain to the supervisory authority of your own country of residence.
11. Minors
Sim racing is a sport with young competitors, and some members of the team may be minors.
Under Article 7 LOPDGDD, a person aged 14 or over may consent to the processing of their own personal data in Spain. Below that age, consent must be given by a parent or legal guardian. Where a Portal account is to be created for a person under 14, we obtain the agreement of a parent or legal guardian before the account is created.
A parent or legal guardian may exercise any of the rights in section 9 on behalf of a child in their care by writing to the address above.
12. Security
We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR, including:
- Encryption of all traffic in transit over HTTPS
- Storage of private team files outside the public web root, retrievable only through an authenticated and role-checked request
- Passwords stored as salted cryptographic hashes, which are not reversible and are not readable by us
- Role-based access control, so that each account can reach only the material its role permits
- Restriction of administrative functions to the smallest number of accounts that can operate the team
No system is perfectly secure and we will not claim otherwise. In the event of a personal data breach likely to result in a risk to the rights and freedoms of individuals, we will notify the AEPD within 72 hours in accordance with Article 33 GDPR, and will inform the affected individuals directly where Article 34 requires it.
13. Changes to this Policy
This Policy is versioned and dated at the top of the page. Where what we do with personal data changes, this Policy is updated to match before or at the time the change takes effect, and the version number and date are revised accordingly. We will not broaden the scope of our processing while leaving this text as it stands.
Where a change materially affects team members, we will inform them directly rather than relying on their noticing an amended page.
14. Contact
Any question, request or complaint concerning this Policy or the processing of your personal data should be addressed to infonoxrt@gmail.com.