Legal
Privacy Policy
How personal information is used, protected, retained and controlled across EAF services.
Effective 20 July 2026
Who is responsible for your data
The European Airsoft Federation (EAF) is the controller for personal data processed through this website, the administrator dashboard and the User Portal. Privacy questions and requests can be sent to office@airsofteurope.com or through the contact page.
What we collect
Depending on how you use the website, the EAF may process your name, date of birth, federation or organisation, country, email addresses, telephone numbers, postal addresses, position, user group, social-media handles, website address, account credentials in hashed form, event-submission details, uploaded files, consent records and administrative audit information. Date of birth is used to verify that an account applicant is at least 13 years old; it is not displayed publicly. When an authenticated federation representative submits news, the EAF also processes the proposed article text and image together with the user’s account identity and federation attribution. Basic technical security information, such as IP address, request time and rate-limit records, may also be processed.
Optional audience measurement
If an authorised EAF administrator enables first-party analytics and you affirmatively allow analytics in Cookie settings, the EAF may process a randomly generated pseudonymous visitor identifier, a session identifier, visit and page times, page URL and title, content type, website language, referring website and broad traffic source, coarse country, device category, browser family, operating-system family, estimated session duration, document downloads, clicks to external federation websites and contact-form submission counts. The analytics record does not store a raw IP address, complete user-agent string, name, email address or message content. Country is derived only from a trusted hosting indication or a local privacy-preserving lookup when configured; otherwise it is recorded as unknown. The public site remains available if you refuse.
Why we use it and our legal bases
- To answer enquiries, deliver authenticated User Portal messages to the recipient selected by the user, and administer event submissions requested by you.
- To receive federation news proposals, verify their source, enable authorised news administrators to review and edit them, contact the submitter where clarification is needed, and publish approved articles with appropriate federation attribution.
- To create, review, secure and administer EAF user and administrator accounts and protected services. This includes using date of birth only to apply the minimum-age rule and protect younger users. These steps are necessary to provide the requested account service and support the EAF’s legitimate interest in operating an age-appropriate, secure portal.
- To operate the federation, communicate with representatives and staff, maintain accurate records, prevent abuse and protect the website. These are legitimate interests of the EAF, balanced against the rights of the people concerned.
- To measure public website use only after an affirmative analytics choice. Consent can be refused or withdrawn without losing access to public content.
- To retain records where European or national law requires this.
- To maintain optional User Portal contact details that a user chooses to add for federation administration and communication. The separate consent choice and its timestamps are recorded honestly and can be changed without affecting processing that occurred before withdrawal. An unticked choice is not consent; the EAF may use those details only where another stated lawful basis applies.
Required and optional information
Fields marked as required are needed to create or secure an account, apply the 13-year minimum age, respond to a request, or review an event submission. A submission cannot be handled without them. Applicants younger than 13 cannot register through this service. Private contact details in the User Portal are optional and can be saved whether the separate consent box is selected or not. The box is not selected in advance, its stored value reflects the user’s actual choice, and leaving it unticked must not be treated as consent.
Who can receive the data
Access is limited to authorised EAF administrators, staff and service providers that host, secure, back up or deliver the website and email on the EAF's instructions. Authenticated User Portal messages and their attachments are delivered only to the fixed Board, Delegates or Office mailbox selected by the user. A protected copy of public and User Portal contact-form text, sender and recipient details, delivery status/reference and attachment filenames is available only to top-tier EAF administrators; attachment files themselves are not copied to that archive. Federation news proposals are available to authorised news coordinators and administrators for moderation; after approval, the article content, image and stated federation attribution become public, while private account and contact details remain protected. Approved event information may be published, but private contact information is not published unless this is separately agreed. Detailed first-party analytics and exports are restricted to authorised top-tier administrators. The EAF does not sell personal data or disclose analytics to advertising networks. Information may be disclosed to an authority when legally required.
Public gallery videos are not connected to an external platform until you choose to play one. Playing a video may disclose your IP address, browser details and viewing request to YouTube, Vimeo or Dailymotion under that platform's own privacy terms.
International transfers
If a service provider processes personal data outside the European Economic Area, the EAF will use an applicable adequacy decision or appropriate safeguards, such as approved standard contractual clauses, and provide information about those safeguards on request.
How long we keep it
- Detailed audience-measurement records: no longer than 12 months. Anonymous monthly totals may be kept after visitor- and session-level details are deleted.
- Public and authenticated User Portal contact-form archive records: up to 24 months, capped at 2,000 records. These records include submitted text, sender/recipient details, delivery status/reference and attachment filenames; User Portal attachment files remain temporary and are not copied to the archive.
- Event-submission contact records: up to 24 months after the event has ended.
- Rejected or withdrawn federation news submissions: up to 12 months after the moderation decision, so the EAF can manage follow-up and demonstrate responsible review. Published articles and their public federation attribution may remain in the EAF news archive while they retain organisational or historical value; associated private submission and moderation records are normally retained for up to 24 months after publication.
- Rejected or abandoned event submissions: up to 12 months after submission.
- User and administrator account records, including the date of birth used for minimum-age verification: while the account is active and normally up to 12 months after closure, unless a shorter period is appropriate or a longer period is legally required.
- Optional user-profile contact details: until the user deletes them, the account is closed, or a longer period is legally required. Consent selections and change timestamps may be retained as accountability records.
- Security and rate-limit records: normally no longer than 12 months. Routine backups are overwritten within 90 days.
Your rights
Subject to the conditions in data-protection law, you may request access, correction, deletion, restriction or portability of your personal data, and you may object to processing based on legitimate interests. You can withdraw optional analytics consent through Cookie settings and change or withdraw the recorded User Portal consent choice by clearing its checkbox. Withdrawal does not affect processing that was lawful before withdrawal. You may delete optional profile details separately or contact the EAF Office. You also have the right to complain to the data-protection authority in your country of residence, place of work or the place of the alleged infringement.
Privacy self-service
Submit a privacy request
Use this protected form to exercise a data-protection right. The EAF may ask for proportionate identity verification before disclosing, changing or deleting personal information.
Security and automated decisions
The EAF uses access controls, encryption in transit, password hashing, upload validation, audit records and protected storage to reduce risk. Member-message attachments are allowlisted and structurally checked but those controls cannot guarantee that a valid-looking file is malware-free; recipient mail security remains necessary. No internet service can guarantee absolute security. The EAF does not use this website to make decisions about people solely by automated means.
Updates
This notice may be updated when the service or legal requirements change. The effective date above will be changed when a material update is published.