TRYKA Privacy Policy
Effective date: 8 July 2026
This Privacy Policy explains how Tryka Fitness Limited, trading as TRYKA, collects, uses, shares and protects personal data when you use our website, create an account, register for an event, attend an event, buy products or services, contact support, appear in event media, volunteer, work with us, or otherwise interact with TRYKA.
We have written this policy for athletes, spectators, volunteers, staff, event crew, website visitors and other people whose personal data we process. It applies to our website at https://tryka.fit, our event registration and race administration platform, our customer account services, our event operations, our photography and results services, and related support and marketing activities.
This policy should be read together with our Terms & Conditions and any event-specific notices, waivers or participant information we provide. The Terms & Conditions govern participation in TRYKA events. This policy explains how personal data is handled in connection with those services.
1. Introduction
TRYKA organises sporting events and operates technology used to manage event entries, athlete registrations, race administration, timing, results, photography, customer accounts, purchases and support.
To provide those services, we need to process personal data. Some of that information is ordinary contact or account information. Some information relates to sporting participation, such as date of birth, race category, timing information and published results. Some information may be more sensitive, such as adaptive category information used to support fair competition and inclusive participation.
We are committed to handling personal data lawfully, fairly and transparently. We collect only what we need for defined purposes, apply appropriate safeguards, and keep personal data only for as long as it is needed.
This policy is intended to meet our transparency obligations under the EU General Data Protection Regulation, the Data Protection Act 2018 and the Irish ePrivacy Regulations (S.I. No. 336/2011, as amended).
2. Definitions
In this policy:
“TRYKA”, “we”, “us” and “our” means Tryka Fitness Limited, trading as TRYKA.
“Personal data” means information relating to an identified or identifiable person. Examples include a name, email address, customer account details, photograph, timing record or payment reference.
“Processing” means any operation performed on personal data, including collection, storage, use, disclosure, deletion, publication, restriction or anonymisation.
“Controller” means the organisation that decides why and how personal data is processed. For the activities described in this policy, Tryka Fitness Limited is generally the controller.
“Processor” means a service provider that processes personal data for us under our instructions, such as hosting, payment, email, support or monitoring providers.
“Athlete” means a person who registers for or participates in a TRYKA event.
“Adaptive category information” means information about an athlete’s adaptive competition category or classification, such as hearing impairment, visual impairment, upper limb impairment, lower limb impairment, short stature impairment, neurological impairment or seated classifications. We use this term deliberately. TRYKA does not collect detailed medical records for this purpose.
“Event media” means photographs, video, audio, livestreams, social media content, editorial content, promotional material and other media captured at or in connection with a TRYKA event.
3. Who We Are
The controller of your personal data is:
Tryka Fitness Limited
Trading as TRYKA
132 Baggot Street Lower
Dublin
D02 AE12
Ireland
Website: https://tryka.fit
TRYKA has appointed a Data Protection Officer. You can contact our Data Protection Officer and privacy team at:
privacy@tryka.fit
You may also write to us at our registered office address above.
4. Scope
This policy applies when we process personal data in connection with:
visits to the TRYKA website;
customer accounts and profiles;
athlete registrations and event entries;
ticket purchases and product purchases;
event administration, event operations and race timing;
adaptive divisions and participant support;
event photography, filming and media;
race results and leaderboards;
customer support and enquiries;
volunteer, staff and crew administration;
marketing communications;
fraud prevention, security and legal compliance.
This policy does not cover websites, services or platforms operated by third parties, even if they are linked from the TRYKA website. Those third parties are responsible for their own privacy notices.
5. Personal Data We Collect
The personal data we collect depends on how you interact with TRYKA.
Identity And Contact Information
We may collect:
name;
email address;
telephone number;
postal address;
account login details;
customer identifiers;
communication preferences;
records of your communications with us.
We use this information to create and manage accounts, process registrations, communicate about events, provide support, issue receipts, deal with queries and meet our legal obligations.
Athlete And Event Information
When you register for or participate in an event, we may collect:
date of birth;
gender;
nationality;
gym, club, company or team name;
event, heat, wave, division and category;
emergency contact details;
bib number or participant number;
check-in and attendance status;
race timing data;
rankings, placings and results;
event history and participation records.
We use this information to administer events, manage eligibility, organise heats and divisions, support safety, operate timing systems, produce results and preserve sporting records.
Adaptive Category Information
Where relevant, we may collect adaptive category information so that athletes can participate in appropriate adaptive divisions and receive reasonable participant support.
Examples of adaptive category information include:
hearing impairment;
visual impairment;
upper limb impairment;
lower limb impairment;
short stature impairment;
neurological impairment;
seated classifications.
TRYKA stores adaptive categories. We do not collect detailed medical records as part of this process. We ask athletes to provide only the information needed for eligibility, adaptive divisions, fair competition and participant support.
Payment Information
Payments are processed by Revolut. TRYKA does not store your payment card number, CVV or card expiry date.
We may store payment-related records such as:
payment reference;
payment ID;
transaction status;
order value;
event, ticket or product purchased;
billing contact details;
refund or chargeback information where relevant.
We use this information for order fulfilment, reconciliation, customer support, accounting, fraud investigation and legal compliance.
Photography And Video Information
TRYKA events may be photographed and filmed. Event media may include images or recordings of athletes, spectators, volunteers, staff and other attendees.
More information is set out in the “Event Photography” section below.
Website, Device And Technical Information
When you use our website or online services, we may collect:
IP address;
browser type and version;
device type;
operating system;
referring URL;
pages visited;
time and date of visits;
approximate location derived from technical information;
log data;
security and error information.
We use Plausible Analytics, configured to be privacy friendly and not to use cookies. We also use Meta Pixel for advertising, conversion measurement and remarketing, but only where required consent has been obtained before it loads.
Support And Communications Information
If you contact us, we may process:
name and contact details;
order or registration details;
support messages;
attachments or screenshots you provide;
call, email or ticket history;
internal notes needed to resolve your query.
Support services may be provided through tools such as Freshdesk and Google Workspace.
Volunteer, Staff And Event Crew Information
For volunteers, staff, contractors and crew, we may process contact details, role information, availability, event assignment, attendance records, communications, access permissions and operational notes needed to run events safely and effectively.
Where employment or contractor relationships apply, additional privacy information may be provided separately.
6. Sources Of Data
We collect personal data from:
you directly, when you create an account, register, buy a ticket, contact us, complete a form or attend an event;
parents or guardians, where they register or authorise participation for a child;
team captains, gym representatives, company representatives or group organisers, where they submit information for participants;
event staff, timers, officials, photographers and support teams;
our website, systems and service providers;
payment providers, where they confirm payment status or provide payment references;
publicly available sources, where relevant to event administration, fraud prevention, safety or dispute handling.
If you provide personal data about another person, such as an emergency contact, team member or child, you should make sure you have authority to do so and that the person understands how their data will be used.
7. How We Use Personal Data
We use personal data for the purposes below.
To Provide Accounts, Registrations And Purchases
We process personal data to create and manage customer accounts, process event entries, issue tickets, manage product purchases, personalise registration details, process payments, provide receipts, support refunds where applicable, and administer account settings.
To Run Sporting Events
We use personal data to plan and operate events, verify registrations, allocate athletes to heats and divisions, manage check-in, support safety, administer rules, communicate event information, manage volunteers and staff, operate timing systems, handle incidents and respond to participant needs.
To Manage Adaptive Divisions And Participant Support
We use adaptive category information only where needed for eligibility, adaptive divisions, fair competition and participant support. We do not use adaptive category information for unrelated marketing, profiling or advertising.
To Publish Race Results
Race results are an essential part of sporting competition. We may publish and maintain results that include athlete name, club or company, category, event, placing, finish time, rankings and related performance information.
Publication allows athletes, spectators, organisers and the sporting community to verify outcomes, compare performance, preserve event history and maintain the integrity of the competition.
To Provide Event Photography And Media
We photograph and film events for photography packages, event coverage, website content, social media, marketing, editorial use and historical archive. We may use photography services to organise event photographs and make relevant images available to athletes.
To Communicate With You
We send service and transactional communications such as registration confirmations, receipts, ticket information, event updates, schedule changes, safety notices, support responses and administrative messages.
These communications are not marketing. They are necessary for our services, for event safety, or for our contractual relationship with you.
To Send Marketing Communications
Where permitted, we may send marketing about TRYKA events, products, services and similar offerings. We do this only where we have a valid legal basis, such as explicit consent or the Irish ePrivacy soft opt-in for existing customers where the legal conditions are met.
More information is set out in the “Marketing Communications” section below.
To Improve And Secure Our Services
We use technical, log, diagnostic and support information to maintain our website and systems, detect errors, monitor performance, prevent abuse, investigate incidents, protect accounts, maintain security, debug problems and improve user experience.
For Legal, Accounting And Business Administration
We process personal data to keep accounting records, comply with tax and company law obligations, manage insurance, handle disputes, respond to legal requests, investigate fraud, enforce our Terms & Conditions, protect legal rights and maintain appropriate business records.
8. Legal Bases
The GDPR requires us to identify a legal basis for processing personal data. Depending on the activity, we rely on one or more of the following legal bases under Article 6 GDPR:
Contract: processing is necessary to perform a contract with you or to take steps at your request before entering into a contract.
Legal obligation: processing is necessary to comply with a legal obligation that applies to us.
Legitimate interests: processing is necessary for our legitimate interests or those of another party, provided those interests are not overridden by your rights and freedoms.
Consent: you have given clear consent for a specific purpose.
Vital interests: processing is necessary to protect someone’s life or physical safety in an emergency.
Where we process special category data, we also need a condition under Article 9 GDPR. For adaptive category information, where it may reveal information about health or disability, we generally rely on explicit consent and, where relevant, processing needed to establish, exercise or defend legal claims or to support substantial public interest safeguards recognised by applicable law. We keep this processing limited and proportionate.
Purpose Examples of data Article 6 legal basis Article 9 condition, where relevant
Account creation and management Name, email, login details, account settings Contract; legitimate interests Not usually applicable
Event registration and ticketing Identity, contact details, event entry, order details Contract Not usually applicable
Payment processing and reconciliation Payment reference, payment ID, order value, billing records Contract; legal obligation; legitimate interests Not usually applicable
Event operations and race administration Athlete details, category, heat, check-in, emergency contact Contract; legitimate interests; vital interests in emergencies Not usually applicable unless information reveals special category data
Adaptive divisions and participant support Adaptive category information Consent; contract; legitimate interests Explicit consent; legal claims where needed
Race timing and results Bib number, times, placing, rankings, category, club/company Contract; legitimate interests Not usually applicable
Publication and maintenance of race results Athlete name, event, category, placing, finish time, rankings Legitimate interests Not usually applicable
Event photography and filming Images, video, event media Legitimate interests; consent where required for specific uses Explicit consent where a specific use requires it
Transactional communications Confirmations, receipts, event updates, safety notices Contract; legitimate interests; legal obligation Not usually applicable
Marketing communications by consent Email, preferences, consent record Consent Not usually applicable
Marketing communications under soft opt-in Email, purchase history, opt-out record Legitimate interests, with ePrivacy soft opt-in conditions Not applicable
Meta Pixel advertising and remarketing Cookie IDs, online identifiers, event data Consent Not usually applicable
Cookie consent management Consent choices, technical identifiers Legal obligation; legitimate interests Not applicable
Support and complaints Contact details, messages, order or event records Contract; legitimate interests; legal obligation Depends on content of request
Security, logging and fraud prevention IP address, logs, account activity, payment references Legitimate interests; legal obligation Not usually applicable
Accounting, tax and legal compliance Invoices, payment references, transaction records Legal obligation; legitimate interests Not usually applicable
Legal claims and disputes Relevant account, order, event, communications and evidence records Legitimate interests; legal obligation Legal claims
When we rely on legitimate interests, we consider the purpose, necessity of the processing, and potential impact on individuals. Our legitimate interests include running safe and fair sporting events, protecting the integrity of results, preventing fraud, securing our systems, resolving disputes, improving services, promoting TRYKA events, and maintaining a historical sporting archive.
9. Adaptive Category Information
TRYKA supports adaptive divisions so that athletes can compete fairly and receive appropriate participant support. To do this, we may ask athletes to provide adaptive category information.
Adaptive category information is limited to the category or classification needed for event eligibility, fair competition and support. We do not collect detailed medical records. We do not require athletes to upload broad medical histories for ordinary event registration.
We may use adaptive category information to:
confirm eligibility for adaptive divisions;
allocate athletes to appropriate categories;
administer fair competition rules;
support event planning and safety;
communicate with athletes about participant support;
resolve category, eligibility or results queries.
Access to adaptive category information is restricted to people who need it for event administration, participant support, compliance, dispute handling or system maintenance.
Where adaptive category information is no longer needed, we delete it or anonymise it in line with our retention rules. If you ask us to delete your account or registration data, we aim to delete adaptive category information within 30 days of the deletion request, unless we need to retain limited information for legal, safety, dispute, fraud prevention or accounting reasons.
10. Event Photography
TRYKA events are public or semi-public sporting events where photography and filming are expected. We capture event media to document the event, provide photography packages, promote TRYKA, engage the sporting community and maintain a historical archive.
Event media may be used for:
athlete photography packages;
website content;
social media;
event highlights;
marketing and advertising;
press and editorial coverage;
sponsor or partner materials where appropriate;
internal training and operational review;
historical archive.
Our usual legal basis for event photography and filming is legitimate interests. Those interests include documenting sporting events, promoting TRYKA, enabling athletes to access event photographs, supporting event coverage and preserving the history of competitions.
We recognise that people may have concerns about particular images. If you have a concern about an image or recording, contact us at privacy@tryka.fit and provide enough detail for us to identify the material. We will review concerns fairly, taking account of privacy, safety, safeguarding, freedom of expression, contractual rights, event context and our legitimate interests.
In some situations, we may rely on consent for a particular image use. Where we rely on consent, you may withdraw that consent at any time. Withdrawal will not affect processing that took place before withdrawal.
11. Race Results
Race results are a central part of sporting competitions. TRYKA publishes results so athletes, spectators and the wider sporting community can understand and verify event outcomes.
Results may include:
athlete name;
club, gym or company;
category or division;
event;
placing;
finish time;
rankings;
other performance information relevant to the competition.
We publish and maintain results on the basis of legitimate interests. Our interests include transparency, fairness, sporting integrity, accountability, athlete recognition, historical record keeping and preventing disputes or manipulation of event outcomes.
If you ask us to delete personal data that appears in historical results, we will consider the request carefully. Where deletion is appropriate, we may anonymise results rather than remove them entirely. For example, we may replace a name with an anonymous label while preserving timing, placing and event structure.
This approach helps protect individual privacy while preserving the integrity and historical value of the competition record.
12. Children
The minimum athlete age for TRYKA events is 9.
Where required, registrations for athletes under 16 must be completed or authorised by a parent or guardian. Parents and guardians should ensure that information provided for a child is accurate and that the child understands, in an age-appropriate way, how TRYKA will use their information.
We take particular care with children’s data. We use children’s personal data only for purposes connected with registration, event administration, safety, results, support, photography, legal compliance and communications with the parent, guardian or athlete where appropriate.
We do not knowingly use children’s personal data for behavioural advertising without any consent required by law.
Parents or guardians can contact privacy@tryka.fit with questions about a child’s personal data.
13. Marketing Communications
TRYKA sends two broad types of email: transactional communications and marketing communications.
Transactional Communications
Transactional communications include:
registration confirmations;
account messages;
receipts;
ticket information;
event information;
schedule changes;
safety notices;
operational updates;
support replies.
These messages are sent because they are necessary to provide services, administer events, perform our contract with you, protect safety or meet legal obligations. They are not marketing emails, even if they refer to the event or service you purchased.
Marketing Emails By Consent
We may ask for explicit consent to send marketing emails, for example during profile or account creation. Where we rely on consent, you can withdraw it at any time by using the unsubscribe link in a marketing email or by contacting privacy@tryka.fit.
Withdrawing consent does not affect the lawfulness of marketing sent before withdrawal.
Soft Opt-in Marketing
Where permitted by Irish ePrivacy law, we may use the soft opt-in for existing customers. This applies only where:
you gave us your email address during a purchase or checkout;
the marketing relates only to TRYKA’s own similar products or services;
you were given a clear chance to opt out during checkout;
you are given a clear chance to opt out in every marketing email;
you have not opted out.
We do not treat the soft opt-in as blanket consent. It is limited to TRYKA’s own similar events, products and services. It does not allow unrelated third-party marketing.
Mailchimp
We use Mailchimp to help manage marketing emails, subscription lists, unsubscribe records and campaign delivery. Mailchimp may process limited personal data such as email address, name, marketing preferences, email engagement information and unsubscribe status.
14. Cookies And Tracking Technologies
We use cookies and similar technologies on the TRYKA website. Some are essential for the website and services to function. Others, such as Meta Pixel, are used for advertising, conversion measurement and remarketing and require consent before loading.
Plausible Analytics is configured not to use cookies. We mention it here because it helps us understand website usage in a privacy-friendly way, but it is not treated as a cookie for the purposes of our Cookie Policy.
For more detail, see our separate Cookie Policy.
15. Third-party Providers
We use trusted third-party providers to operate our website, events, payments, communications, support, security and administration. These providers may act as processors, independent controllers, or both, depending on the context.
Our providers may include:
Amazon Web Services, for cloud hosting, infrastructure and related services;
Revolut, for payment processing;
Mailchimp, for marketing email management;
Google Workspace, for business communications and document management;
Freshdesk, for customer support;
Sentry, for error monitoring and diagnostics;
photo management providers, for event photography services;
other event, timing, photography, logistics, professional, legal, accounting and technical providers.
This list may change over time. It is not intended to be exhaustive.
Where a provider acts as our processor, we require it to process personal data under appropriate contractual terms and to apply suitable security measures. Where a provider acts as an independent controller, its own privacy notice may also apply.
We may also share personal data with:
event venues and operational partners where needed for event delivery;
timing and results providers;
photographers and media providers;
insurers, lawyers, accountants and professional advisers;
regulators, law enforcement, courts or public authorities where required or appropriate;
purchasers, investors or advisers in connection with a business transaction, subject to appropriate safeguards.
We do not sell personal data.
16. International Transfers
Most personal data is processed within the European Union or European Economic Area.
Some providers may process limited personal data outside the EEA. For example, Mailchimp may involve transfers to the United States or other countries.
Where personal data is transferred outside the EEA, we rely on appropriate safeguards where required, such as:
an adequacy decision adopted by the European Commission;
the EU-US Data Privacy Framework, where applicable to the recipient and the transfer;
Standard Contractual Clauses approved by the European Commission;
supplementary measures where needed;
derogations permitted by GDPR for specific situations.
We assess international transfers in light of the data involved, the provider, the destination country, the safeguards available and applicable legal requirements.
17. Data Security
We use technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, misuse, alteration and disclosure.
Our measures may include:
encryption where appropriate;
secure cloud infrastructure;
access controls and least-privilege permissions;
authentication controls;
logging and monitoring;
backup and recovery processes;
vulnerability management;
environment separation;
supplier due diligence;
staff access management;
incident response processes;
security review of important systems and changes.
No system can be guaranteed to be completely secure. We work to apply safeguards proportionate to the nature of the data, the processing and the risks involved.
If we become aware of a personal data breach, we will assess it and notify affected individuals and the Data Protection Commission where required by law.
18. Data Retention
We keep personal data only for as long as needed for the purposes described in this policy, including legal, accounting, tax, insurance, fraud prevention, dispute resolution and sporting integrity purposes.
Our retention periods vary depending on the type of data and the context.
Data category Retention approach
Accounts Deleted or anonymised within 30 days after a valid deletion request, unless retention is required for legal, accounting, fraud prevention, dispute or safety reasons
Registrations Deleted or anonymised within 30 days after a valid deletion request, unless retention is required for legal, accounting, fraud prevention, dispute, safety or sporting integrity reasons
Adaptive category information Deleted within 30 days after a valid deletion request, unless limited retention is required for legal claims, dispute handling or other legally permitted reasons
Race results Anonymised within 30 days where a valid request is granted and anonymisation is appropriate; historical results may be preserved for sporting integrity
Payment references and payment IDs Retained only as long as required for legal obligations, accounting, reconciliation, customer support, fraud prevention, chargebacks and dispute handling
Support records Kept for as long as needed to resolve the issue and maintain appropriate business, dispute and legal records
Marketing records Kept until you unsubscribe or withdraw consent, plus suppression records needed to honour opt-outs
Security logs Kept for a limited period appropriate to security, fraud prevention, diagnostics and legal needs
Deletion may not be immediate from backups, logs or archival systems, but backup copies are protected and removed or overwritten in line with normal retention cycles.
19. Your Rights
You have rights under GDPR. These rights are subject to conditions and exceptions, but we will always consider requests fairly.
To exercise your rights, contact privacy@tryka.fit.
We may need to verify your identity before acting on a request. We will respond without undue delay and, in any event, within one month of receiving your request. If a request is complex or you have made multiple requests, we may extend this by up to two further months. If we extend the period, we will tell you within one month and explain why.
Access
You can ask for confirmation of whether we process your personal data and request a copy of that data.
Rectification
You can ask us to correct inaccurate personal data or complete incomplete personal data.
Erasure
You can ask us to delete personal data in certain circumstances. This is sometimes called the “right to be forgotten”.
We may not be able to delete data where we need it for legal obligations, accounting, fraud prevention, legal claims, safety, dispute handling or sporting integrity. Where appropriate, we may anonymise race results instead of deleting the underlying sporting record.
Restriction
You can ask us to restrict processing in certain circumstances, for example while we assess a dispute about accuracy or an objection.
Portability
Where processing is based on consent or contract and carried out by automated means, you can ask to receive certain personal data in a structured, commonly used and machine-readable format.
Objection
You can object to processing based on legitimate interests, including certain uses of event media or publication of personal data. We will consider your objection and balance it against our legitimate grounds for processing.
You can object to direct marketing at any time. If you object to direct marketing, we will stop sending it.
Withdrawal Of Consent
Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing that took place before withdrawal.
Automated Decision Making
TRYKA does not make decisions producing legal or similarly significant effects solely through automated processing.
20. Complaints
We encourage you to contact us first at privacy@tryka.fit so we can try to resolve your concern.
You also have the right to complain to the Irish Data Protection Commission:
Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland
Website: https://www.dataprotection.ie
If you live outside Ireland, you may also have the right to contact your local EU or EEA data protection authority.
21. Changes To This Policy
We may update this policy from time to time to reflect changes in our services, technology, legal requirements or business operations.
If we make material changes, we will take appropriate steps to bring them to your attention. This may include website notices, account notices, email updates or additional event-specific information.
The effective date at the top of this policy shows when this version applies from.
22. Contact Details
For privacy questions, rights requests or concerns about your personal data, contact:
Tryka Fitness Limited
Trading as TRYKA
132 Baggot Street Lower
Dublin
D02 AE12
Ireland
Data Protection Officer and privacy contact: privacy@tryka.fit
Website: https://tryka.fit