No Obstacle NO OBSTACLE

Privacy Policy

Last updated: 16 November 2023  ·  Effective date: 16 November 2023

1. Who we are (data controller)

No Obstacle a.s.b.l. is the data controller responsible for your personal data.

No Obstacle a.s.b.l.
L-1480 Luxembourg
RCS F13693
Email: no@obstacle.lu

2. Personal data we collect

We collect and process the following categories of personal data:

Account data

  • Email address (used as login identifier)
  • Full name and telephone number

Member licence data

Required to register athletes with the relevant sports federation and issue official licences:

  • First name, last name, date of birth
  • Luxembourg CNS (matricule / social-security) number
  • Postal address (street, postcode, city, country)
  • Emergency contact name and telephone number
  • Medical notes (only information you voluntarily provide)

Payment data

Membership payments are processed by Stripe, Inc. We never see or store your card details. We retain a reference (Stripe session ID) and the amount paid for our accounting records.

Communications

  • Messages submitted via the contact form
  • Trial sign-up details (name, email, phone)

Technical data

We use a strictly necessary session cookie to keep you logged in. See our Cookie Policy for details.

3. Legal basis for processing

We process your personal data on the following legal bases under the General Data Protection Regulation (GDPR):

  • Performance of a contract (Art. 6(1)(b) GDPR) — processing your account data, licence data, and payment records to provide and administer your club membership.
  • Legal obligation (Art. 6(1)(c) GDPR) — retaining accounting and payment records as required by Luxembourg law.
  • Legitimate interests (Art. 6(1)(f) GDPR) — communicating with you about your membership, keeping our website and systems secure.
  • Explicit consent (Art. 9(2)(a) GDPR) — processing your CNS/matricule number (a national identification number) and any medical notes, which are special-category data. You provide these voluntarily when completing the member registration form; you may withdraw consent at any time (see section 7).

4. How we use your data

  • Create and manage your member account
  • Issue annual sports licences to the relevant federation
  • Process membership fee payments via Stripe
  • Send you transactional emails (login links, payment confirmations)
  • Respond to contact form messages and trial sign-ups
  • Meet our legal and accounting obligations

We do not use your data for automated decision-making or profiling.

5. Data sharing and third parties

We share your data only when necessary:

  • Stripe, Inc. — payment processing. Stripe acts as an independent data controller for card payment data. See stripe.com/privacy.
  • Sports federation — licence data (name, DOB, CNS number) is submitted to the relevant federation as required for official registration.
  • Email provider — we use SMTP to send login and confirmation emails. Your email address is transmitted to our mail server.

We do not sell, rent, or otherwise share your personal data with any other third parties for marketing or commercial purposes.

6. Data retention

  • Member data: retained for the duration of your membership and for up to 5 years after your last active season, to allow re-registration and comply with federation requirements.
  • Payment records: retained for 10 years as required by Luxembourg accounting and tax law.
  • Contact messages and trial sign-ups: retained for up to 1 year.
  • Login tokens: single-use and expire after 30 minutes; deleted automatically once used or expired.

7. Your rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access — request a copy of the data we hold about you
  • Right to rectification — correct inaccurate or incomplete data (you can do this directly in your account)
  • Right to erasure — request deletion of your data, subject to our legal retention obligations
  • Right to restriction — ask us to restrict processing in certain circumstances
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — withdraw consent for the processing of special-category data (CNS number, medical notes) at any time; this will not affect the lawfulness of prior processing

To exercise any of these rights, please email us at no@obstacle.lu. We will respond within 30 days.

8. Security

We store all personal data on a secure server within the European Union. Passwords are never stored — we use magic-link email authentication. Data is protected by HTTPS in transit and stored in an encrypted-at-rest environment. Access to the admin area is password-protected.

9. International transfers

Stripe, Inc. is based in the United States. Data transfers to Stripe are covered by Standard Contractual Clauses (SCCs) approved by the European Commission, providing an adequate level of protection.

10. Cookies

We use only strictly necessary cookies. For details, please see our Cookie Policy.

11. Complaints

If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the Luxembourg supervisory authority:

Commission Nationale pour la Protection des Données (CNPD)
15, Boulevard du Jazz
L-4370 Belvaux, Luxembourg
cnpd.public.lu

12. Updates to this policy

We may update this Privacy Policy from time to time. The date at the top of this page indicates when it was last revised. Your continued use of the website after any changes constitutes acceptance of the updated policy.