Privacy Policy

International Dressage Officials Club (IDOC)

Last updated: 2 October 2026

GDPR-aligned notice for IDOC membership, website, payments, events, and communications

International Dressage Officials Club (IDOC) respects the privacy of members, applicants, event participants, website visitors, administrators, and other people who interact with IDOC. This Privacy Policy explains how IDOC processes personal data in connection with idoc.club, membership administration, member services, seminars and events, communications, payments, and related club operations.

This Policy is intended to satisfy the transparency requirements of the EU General Data Protection Regulation (GDPR), including Articles 12, 13, and 14, to the extent those provisions apply.

1. Data controller and contact details

The controller for the processing described in this Policy is International Dressage Officials Club (IDOC).

International Dressage Officials Club (IDOC)

Van De Reydtlaan 83, 2960 Brecht, Belgium

Email: accounts@idoc.club

Website: https://idoc.club

If IDOC is required to appoint a Data Protection Officer, the applicable DPO contact details will be published in this Policy or otherwise provided as required by law.

2. Personal data IDOC may collect

2.1 Account, identity, and contact data

  • First and last name.
  • Email address and account identifiers.
  • Postal address, city, state or province, postal code, and country.
  • Account, verification, and membership status.
  • Authentication and security data such as password-derived credentials, verification status, trusted-device records, multi-factor-authentication state, recovery evidence, sessions, and security-event records.

2.2 Professional and membership data

  • Membership category: Judge, Steward, Judge & Steward, or Veterinarian.
  • National Federation and IDOC region, where applicable.
  • FEI ID, where supplied.
  • Official role, level or status and Technical Delegate status, where applicable.
  • Membership start, paid-through, grace, expiration, suspension, renewal, and historical entitlement information.
  • Profile-change history and authorized administrator adjustments.

2.3 Payment and transaction data

  • Membership and seminar amounts, currency, payment date, source, and status.
  • Stripe customer, subscription, checkout, invoice, payment, refund, dispute, and related identifiers or summarized billing information.
  • Manual-payment references for approved non-Stripe methods where used.
  • Refund reason, amount, timestamp, authorization, and reconciliation records.

IDOC does not intend to store full payment-card numbers or card security codes; those details are handled by Stripe or another authorized payment provider.

2.4 Event, support, and communications data

  • Seminar or event registration, attendance, eligibility, payment, cancellation, wait-list, and related administrative data.
  • Support, membership, billing, and event communications with IDOC.
  • Information you voluntarily provide when contacting IDOC.

2.5 Website, device, security, and log data

  • IP address, browser and device information, request timestamps, and requested pages or endpoints.
  • Cookies, session identifiers, anti-bot or security signals, rate-limit information, and similar technical data.
  • Application, server, audit, security, and error logs.
  • Information used to investigate fraud, abuse, account compromise, failed or duplicate payments, and technical faults.

2.6 Marketing preferences

IDOC may record whether you affirmatively choose to receive optional updates about IDOC events, workshops, certifications, or similar activities, together with subscription and opt-out evidence needed to honor that choice.

3. Sources of personal data

IDOC obtains personal data directly from you when you create or use an account, complete onboarding, update your profile, pay, register for an event, contact IDOC, or choose communication preferences. IDOC may also obtain personal data indirectly from authorized administrators, legacy membership records, Stripe or other payment providers, authentication/security providers, hosting and email providers, National Federations, the FEI, event partners, or other relevant sources where there is a lawful basis.

Where Article 14 GDPR applies because personal data was not obtained directly from you, IDOC will provide the required information within the applicable Article 14 timeframe: generally within one month, at the time of the first communication with you if earlier, or before the first disclosure to another recipient if earlier, unless a lawful exception applies or you already have the information.

4. Purposes, legal bases, and legitimate interests

IDOC does not rely on a single legal basis for all processing. The basis depends on the purpose. In particular, acknowledging this Privacy Policy does not itself create consent for processing that is necessary to provide membership or comply with law.

PurposeTypical legal basisLegitimate interest where relied upon
Create and authenticate an account; process onboardingContract / steps before contract; legitimate interestsSecurely operating accounts, preventing abuse, and maintaining reliable identity records
Administer membership, entitlement, professional profile, renewals, and member accessContract; legitimate interests; legal obligations where applicableAccurate club administration, member eligibility, continuity of records, and prevention of entitlement errors
Process payments, subscriptions, refunds, disputes, and reconciliationContract; legal obligation; legitimate interestsCollecting amounts due, preventing duplicate or fraudulent transactions, maintaining accurate accounting and membership records
Operate seminars, events, applications, and wait listsContract / steps before contract; legitimate interestsEfficient event administration, eligibility management, participant communications, and capacity planning
Provide the paid member directory and professional networking functionsContract; legitimate interestsEnabling legitimate professional networking and club functions among current eligible members
Send account, security, membership, payment, renewal, and event-service messagesContract; legal obligation; legitimate interestsKeeping members informed about services, security, payments, and membership standing
Send optional promotional updatesConsent, where consent is the chosen basisNot applicable when processing is based on consent
Protect systems, prevent abuse, investigate incidents, and maintain audit evidenceLegitimate interests; legal obligation where applicableCybersecurity, fraud prevention, accountability, service integrity, and defense of legal claims
Comply with accounting, tax, regulatory, legal, or dispute obligationsLegal obligation; legitimate interests; legal claimsCompliance, evidence preservation, dispute resolution, and protection of legal rights

5. Required versus optional information and consequences of not providing it

Certain data is required to create and administer an IDOC account or membership. Required data includes the identity, contact, membership-classification, and other profile fields designated as required for the selected membership category, plus information necessary to authenticate the account and record payment or another authorized entitlement.

If you do not provide required data, IDOC may be unable to create the account, complete onboarding, verify eligibility, process payment, activate or renew membership, provide member-only services, or register you for a service that requires that information.

Fields identified as optional may be left blank without preventing membership unless the field later becomes necessary for a service you specifically request. Optional promotional marketing consent is not required for membership and must not be a condition of receiving the core service.

6. Essential communications and optional marketing

IDOC may send operational communications necessary to administer your account or membership, including verification, password and security notices, membership status, payment confirmations, failed-payment notices, renewal or expiration reminders, refunds, event administration, and important service notices. These are not optional marketing communications.

Optional marketing about events, workshops, certifications, or similar activities is separate. Where consent is relied upon, the choice must be freely given, specific, informed, unambiguous, and made by a clear affirmative action. IDOC will not treat silence, inactivity, or a pre-selected marketing checkbox as consent. You may withdraw marketing consent at any time without affecting membership or essential service messages.

IDOC should retain evidence of the marketing-consent event, including the account, consent status, date/time, source, and applicable wording or policy version, so that the choice can be demonstrated and later honored or withdrawn.

7. Member directory and public aggregate information

For currently entitled members, IDOC may provide a limited professional directory to other eligible members. It may include first and last name, country, professional role and level, National Federation, and IDOC region. It is not intended to expose email addresses, exact street addresses, payment data, authentication data, or raw internal database identifiers.

Where directory processing relies on legitimate interests, members retain the right to object under Article 21 GDPR. IDOC will assess an objection in accordance with applicable law and will cease processing where required unless compelling legitimate grounds or legal-claims grounds permit continuation.

IDOC may publish aggregate membership counts designed not to identify individual members. Public aggregate features should apply appropriate minimum thresholds and data-minimization safeguards.

8. Recipients and categories of recipients

IDOC may disclose personal data only where reasonably necessary for the purposes described in this Policy, including to authorized IDOC administrators and service personnel; Stripe and other payment providers; hosting, deployment, database, email, security, anti-abuse, logging, monitoring, and technical providers; relevant event organizers, instructors, venues, National Federations, the FEI, or other bodies where necessary and lawful; professional advisers; public authorities or courts where legally required; and a lawful successor organization in connection with an organizational transfer.

IDOC does not sell personal data to advertisers.

9. International transfers

Because IDOC serves an international membership and uses external service providers, personal data may be processed outside Belgium or the European Economic Area. Where Chapter V GDPR applies, IDOC will use a lawful transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, or another legally recognized safeguard, and supplementary measures where required.

You may contact IDOC using the details in Section 1 to request information about the transfer mechanism applicable to your data and, where required by law, obtain a copy of or access to the relevant safeguards, subject to lawful redactions for confidential or security-sensitive information.

10. Data retention

IDOC retains personal data only for as long as reasonably necessary for the purposes for which it was collected, including membership and event administration, accurate payment and entitlement history, legal and accounting obligations, security, dispute resolution, and legal claims.

Retention is determined by data category and purpose rather than a single universal period. Financial, refund, audit, and membership-history records may need to be retained after membership ends; temporary verification challenges, expired sessions, failed signup attempts, transient logs, and migration files should be deleted or anonymized sooner when no longer necessary.

IDOC will maintain documented retention criteria or schedules for material data categories and implement deletion, anonymization, or archival processes so data is not kept indefinitely merely because storage is available.

11. Security and data protection by design

IDOC uses technical and organizational safeguards designed to protect personal data against unauthorized access, alteration, disclosure, loss, or misuse. Safeguards may include server-side authorization, membership access controls, encrypted network connections, password hashing, email verification, multi-factor authentication for privileged accounts, purpose-bound step-up authentication, secure cookies, anti-bot protections, rate limiting, validation, append-only audit evidence, restricted database access, verified payment webhooks, backups, and monitoring.

Access should follow least-privilege principles, and application functions should collect, expose, and log only the personal data reasonably necessary for their stated purpose.

12. Cookies and similar technologies

IDOC uses cookies and similar technologies that are strictly necessary to authenticate users, maintain secure sessions, remember permitted device state, protect forms and login flows, prevent abuse, and operate requested website features. These essential technologies are not used for advertising and are required for the requested service or its security.

IDOC does not currently use non-essential analytics or advertising cookies. The site may show a compact informational notice about its essential-cookie use; dismissing that notice is not treated as consent because no consent is requested for strictly necessary technologies.

If IDOC introduces non-essential analytics, advertising, profiling, or similar tracking technologies for which consent is required under applicable law, those technologies must remain disabled until the user has made the required choice, and the site must provide a mechanism to later withdraw or change that choice. The cookie interface must not use pre-selected consent for non-essential categories.

13. Your GDPR rights

Subject to applicable conditions and exceptions, you may have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Request erasure.
  • Request restriction of processing.
  • Object to processing based on legitimate interests.
  • Object at any time to direct marketing.
  • Receive qualifying data in a portable format.
  • Withdraw consent where consent is relied upon.
  • Lodge a complaint with a competent supervisory authority.

IDOC may verify identity before acting on a request. Rights are not absolute; for example, IDOC may retain financial, audit, security, or legal records where another lawful basis requires or permits continued retention.

14. Handling rights requests

IDOC will provide a practical method for submitting privacy-rights requests. In accordance with Article 12 GDPR, IDOC will respond without undue delay and in principle within one month of receiving a valid request. Where permitted because of complexity or number of requests, that period may be extended by up to two additional months, with notice of the extension and reasons within the initial one-month period.

If IDOC does not act on a request, it will provide the reasons and information about the right to complain to a supervisory authority and seek a judicial remedy, as required by applicable law.

15. Automated decision-making and profiling

IDOC does not intend to make decisions producing legal or similarly significant effects about members solely by automated processing without appropriate human involvement, except where lawful and properly disclosed. Automated controls may be used for security, anti-abuse, rate limiting, payment reconciliation, account routing, and membership-entitlement enforcement. If Article 22-significant automated decision-making is introduced, IDOC will provide the additional information and safeguards required by law before using it.

16. Personal-data breaches

IDOC maintains incident-response processes for security events involving personal data. Where a personal-data breach triggers GDPR notification duties, IDOC will notify the competent supervisory authority and, where required because of high risk, affected individuals within the applicable legal timeframes.

17. Children

IDOC membership and professional services are directed to dressage officials and related professionals rather than children. IDOC does not knowingly design the membership service for children. If data from a child is processed in circumstances requiring parental authorization or another legal basis that is absent, IDOC will take appropriate steps consistent with applicable law.

18. Third-party websites and independent controllers

The website may link to the FEI, National Federations, event platforms, venues, payment services, publications, or other third parties. Those organizations may act as independent controllers for data they collect directly from you. Their privacy practices are governed by their own notices.

19. Changes to this Privacy Policy

IDOC may update this Policy when services, providers, legal obligations, or processing activities change. The current version will be posted with its last-updated date. If a material change makes information previously provided obsolete or incomplete, IDOC will provide additional notice where required by the GDPR.

20. Complaints and supervisory authority

If you have a concern about IDOC handling of personal data, you may contact IDOC using the details in Section 1. You also have the right to lodge a complaint with the Belgian Data Protection Authority or another competent EEA supervisory authority, particularly in the country of habitual residence, place of work, or place of the alleged infringement.

21. Contact

International Dressage Officials Club (IDOC)

Van De Reydtlaan 83, 2960 Brecht, Belgium

Email: accounts@idoc.club

Website: https://idoc.club