GDPR Compliance

Your data protection rights under EU regulations, applied consistently for every user

Last updated: August 7, 2026

01Introduction to GDPR

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018, across the European Union. GDPR applies to any organization worldwide that processes personal data of EU residents, regardless of where the organization is located. As Formula-Timer serves users globally, including within the EU, we apply GDPR-aligned data protection standards to all users.

Global application

While GDPR is an EU regulation, it applies worldwide to any service that processes data of EU residents. Formula-Timer follows GDPR standards for all users, regardless of location, to keep data protection consistent.

02Data controller information

Data controller

  • Entity: Formula-Timer
  • Website: formula-timer.com
  • Email: [email protected]
  • Purpose: F1 timing and analytics services

Contact for data protection

  • GDPR inquiries: [email protected]
  • Subject line:"GDPR Data Request"
  • Response time: Within 30 days
  • Languages: English, Spanish

03Your GDPR rights

Under GDPR, all users — particularly EU residents — have the following rights regarding their personal data:

Right to information

Be informed about how your personal data is collected and used.

Right of access

Request access to your personal data and how it is processed.

Right to rectification

Have inaccurate or incomplete personal data corrected.

Right to erasure

The "right to be forgotten" — request deletion of your data in certain circumstances.

Right to restrict processing

Restrict the processing of your personal data in certain circumstances.

Right to data portability

Obtain and reuse your personal data across different services.

04Legal basis for processing

Formula-Timer processes personal data based on the following legal grounds under GDPR Article 6:

Primary legal bases

  • Legitimate interest: providing F1 timing services and website functionality
  • Consent: for analytics, cookies, and marketing communications where applicable
  • Contract performance: when providing specific services to users

Additional considerations

  • Legal obligation: compliance with applicable laws and regulations
  • Vital interests: protection of life or physical safety, rarely applicable
  • Public task: not applicable to our commercial services

05How to exercise your rights

To exercise any of your GDPR rights, please follow this process:

Step 1 — Contact us

Send an email to [email protected]with the subject line "GDPR Data Request."

Step 2 — Verification

We'll verify your identity to protect your personal data from unauthorized access.

Step 3 — Response

We'll respond within 30 days as required by GDPR, which may extend to 60 days for complex requests.

06International transfers

When transferring personal data outside the EU, we rely on:

  • Adequacy decisions or appropriate safeguards
  • Standard contractual clauses where applicable
  • Compliance with GDPR transfer requirements

07Data retention

We retain personal data only as long as necessary for:

  • Providing our services
  • Legal compliance requirements
  • Legitimate business purposes

08Data Protection Officer

At our current scale of operations, we do not require a formal Data Protection Officer. Data protection inquiries are handled directly by:

Contact: [email protected]
Role: Data protection compliance

09Complaints

You have the right to lodge a complaint with your local supervisory authority if you believe we have violated GDPR.

Find your local authority via the EDPB member list.

10Policy updates

We may update this GDPR compliance information to reflect:

  • Changes in GDPR interpretation
  • Service improvements
  • Changes in legal requirements

11Related information