Home
·
Legal & Policies
Social FightIn – GDPR Processes
Purpose
This document outlines the operational processes required to ensure compliance with the General Data Protection Regulation (GDPR) for the Social FightIn platform.
1. Data Collection Process
Objective
Ensure only the minimum personal data required to deliver the service is collected.
Personal Data Collected
Name
Email address
Username
Profile photo
Date of birth (if required)
Gym affiliation
Weight class (if applicable)
Competition history (if applicable)
User-generated content
Messages
Device information
Analytics data
Principles
Collect only necessary data.
Clearly explain why each data field is collected.
Avoid collecting sensitive personal data unless absolutely necessary.
Review data collection annually.
2. Consent Management
Users must actively consent where required before:
Marketing emails
Push notifications
Analytics tracking (where applicable)
Location services
Consent must be:
Freely given
Specific
Informed
Unambiguous
Easy to withdraw
Consent records should be stored securely.
3. User Rights Process
Users may request:
Access to their personal data
Correction of inaccurate information
Deletion of their account
Data portability
Restriction of processing
Withdrawal of consent
Procedure
Request received through support email — socialfightin@gmail.com
Identity verified.
Request logged.
Request reviewed.
Response provided within one month.
Completion recorded.
4. Account Deletion Process
When a deletion request is received:
User identity verified.
Account disabled.
Personal information permanently deleted unless legally required to retain it.
User-generated content anonymised where appropriate.
Confirmation sent to the user.
Deletion recorded in the audit log.
5. Data Retention Policy
Data Type
Retention Period
User account
Until deletion request or prolonged inactivity
Support tickets
24 months
Analytics
26 months (or platform default)
Payment records
As required by applicable financial and tax legislation
Moderation records
24 months
Audit logs
24 months
Retention periods should be reviewed annually. See also Data Retention Policy .
6. Security Measures
The platform should implement:
Encryption in transit (HTTPS/TLS)
Encryption at rest where appropriate
Secure password hashing
Role-based admin permissions
Multi-factor authentication for administrators
Secure cloud hosting
Routine backups
Security monitoring
Software updates and patching
7. Third-Party Processors
Maintain a register of all providers processing personal data. Examples may include:
Authentication provider
Cloud hosting provider
Payment processor
Analytics provider
Customer support platform
Email service provider
Push notification provider
Each processor should have appropriate contractual safeguards in place. See the Third-Party Processor Register .
8. Data Breach Response
If a personal data breach occurs:
Identify and contain the breach.
Assess affected data.
Assess potential risk to individuals.
Notify senior management.
Notify the relevant supervisory authority where legally required.
Notify affected users where legally required.
Record: cause, impact, resolution, and preventative actions.
See also Data Breach Response Plan .
9. Content Moderation & Personal Data
Moderators may access personal information only where necessary to investigate:
User reports
Fraud
Harassment
Abuse
Community guideline violations
Moderator actions should be logged. See Content Moderation Policy .
10. Privacy by Design
New features should undergo a privacy review before release. Consider:
What data is collected?
Is all data necessary?
Can data collection be minimised?
What user controls are available?
Are privacy settings appropriate by default?
11. Staff Responsibilities
Anyone with access to user data must:
Follow confidentiality obligations.
Access only the data necessary for their role.
Report suspected data breaches immediately.
Complete privacy and security training where applicable.
12. Governance & Review
This document should be reviewed:
Annually
Following significant platform changes
Following legislative changes
After any major security incident
The platform should maintain records demonstrating compliance with applicable data protection obligations.