Golf P'la Fresquinha (GPF) · Last updated 2025
Golf P'la Fresquinha (GPF) is a private web application used by a closed group of golf friends to run an annual competition. It is not a commercial service. The data controller is the committee of Golf P'la Fresquinha (GPF). Contact: committee@gpf.golf.
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Name, email address, password (hashed) | Account creation and authentication | Contract (6.1.b) |
| Handicap index (declared and calculated) | Competition scoring and leaderboard | Contract (6.1.b) |
| Round data (course, gross score, date, Stableford points, hole-by-hole scores) | Leaderboard ranking and handicap calculation | Contract (6.1.b) |
| Scorecard images (uploaded voluntarily) | Automatic score extraction via AI vision; images are processed transiently and never permanently stored on our servers | Consent (6.1.a) |
| Audit log entries (name, action, timestamp) | Integrity checks and dispute resolution; retained for 12 months then automatically deleted | Legitimate interest (6.1.f) |
| Password reset tokens (hashed, time-limited) | Secure password recovery; expire after 1 hour | Contract (6.1.b) |
Session cookie (__Secure-next-auth.session-token) | Keeping you logged in during your visit; functional cookie, no tracking | Legitimate interest (6.1.f) |
When you upload a scorecard image, it is sent over HTTPS to Anthropic (anthropic.com) for text extraction. Anthropic processes the image under a zero-data-retention policy for API calls — it is not used to train models and is not stored after processing. The extracted data is shown to you for confirmation before anything is saved to our database. The original image file is never stored on our servers.
Anthropic is a sub-processor under our data processing arrangement. By uploading a scorecard you consent to this transient processing.
We use one functional cookie only:
__Secure-next-auth.session-token — a secure, HTTP-only, same-site session cookie set by NextAuth when you log in. It expires when you close your browser or after a configured period. It contains no personal data (only an encrypted session reference) and is not used for tracking or advertising.We do not use analytics cookies, advertising cookies, or any third-party tracking scripts.
Fonts are self-hosted: no request is made to Google Fonts or any external font CDN from your browser.
We do not sell or share your personal data with third parties for commercial purposes. Your data may be shared only with:
As a data subject you have the right to:
To exercise any right, email committee@gpf.golf. We will respond within 30 days.
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Portuguese data protection authority: CNPD (Comissão Nacional de Proteção de Dados) — cnpd.pt.
Passwords are hashed with bcrypt (cost factor 10). All connections are encrypted with TLS/HTTPS (HSTS enforced). Session cookies are HTTP-only, Secure, and SameSite=Lax. Security headers (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy) are applied to all responses. The database connection uses SSL.
We may update this policy when we change how we process data. The date at the top of this page will reflect the latest revision. For significant changes, we will notify members by email if SMTP is configured.