Privacy notice
Last updated: 6 September 2026
This notice explains how personal data is processed when you visit the E.A.E Golf website, register an application, use the API, purchase a paid plan or contact us.
1. Controller
The controller responsible for processing is:
Dipl.-Ing. Patricio Alfonso Guerrero
c/o GAM
Pappelallee 64
10437 Berlin
E-Mail: [email protected]
2. Website and server logs
When the website or API is accessed, the hosting infrastructure may process technical information required to deliver and secure the service. This can include:
- IP address
- Date and time of the request
- Requested URL and HTTP method
- Response status and transferred data volume
- Referrer, where transmitted
- Browser, operating system or client user agent
- Request identifier and security events
The purposes are reliable delivery, troubleshooting, abuse prevention, rate limiting and security monitoring. Processing is based on our legitimate interests in operating and protecting the service under Article 6(1)(f) GDPR.
Operational logs are normally deleted or anonymized after 7 days unless a longer period is required to investigate abuse, preserve evidence or comply with a legal obligation.
3. Hosting
The service is hosted by:
Hetzner Online GmbH
Processing location: Germany
The hosting provider processes data on our behalf where required. A data processing agreement is concluded when Article 28 GDPR applies.
4. Application registration and API keys
When an application is registered, we may process:
- Name and contact details of the applicant
- Company or organization
- Application name and description
- Registered domains or browser origins
- Requested plan, scopes and rate limits
- API-key identifier, status and usage information
- Communication relating to approval and support
The API key itself is shown only as required for activation. The service may store a cryptographic representation rather than the plain key.
Processing is necessary to provide the requested service and manage the contractual relationship under Article 6(1)(b) GDPR. Where an applicant acts for an organization rather than personally, processing may also be based on our legitimate interest in managing business contacts under Article 6(1)(f) GDPR.
5. API usage and security
We process request metadata associated with an API client to authenticate requests, enforce scopes and rate limits, measure usage, prevent abuse, troubleshoot failures and administer the service.
Do not transmit personal data through query parameters or API fields unless an endpoint explicitly requires it. The public golf-data endpoints are not intended for uploading personal profiles or sensitive personal data.
6. Contact and support
When you contact us, we process the information in your message and the contact details required to respond. The legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual communication and Article 6(1)(f) GDPR for other legitimate business communication.
We retain correspondence for as long as necessary to handle the request and comply with applicable retention obligations.
7. Billing and payment
Payments for paid plans are processed by Stripe. When you purchase a paid plan, Stripe processes the payment and billing information required to complete the transaction. Depending on the payment method, this may include your name, billing address, payment method details and transaction information.
We do not receive or store complete payment card details. We may receive and process billing-related information from Stripe, such as customer and subscription identifiers, invoice details, payment status and transaction references, where necessary to manage your subscription, provide the service and comply with legal accounting and tax obligations.
The legal bases for our processing of this information are Article 6(1)(b) GDPR for the performance of the contract and Article 6(1)(c) GDPR for compliance with legal obligations.
Payment services are provided by Stripe. Stripe may process personal data as an independent controller for certain activities, including payment processing, fraud prevention and compliance with its own legal obligations. Further information about how Stripe processes personal data is available in Stripe's privacy policy.
Accounting and tax-relevant records are retained for the periods required by applicable German commercial and tax law.
8. Cookies and local storage
The documentation website operates without non-essential tracking by default. Technically necessary storage may be used to remember settings such as the selected language or to maintain security-related state.
If analytics, marketing tools or other non-essential technologies are introduced, they will not be activated until this notice and, where required, the consent mechanism have been updated.
9. Recipients
Personal data may be disclosed to the following categories of recipients where necessary:
- Hosting and infrastructure providers
- Technical service providers acting on our instructions
- Stripe and other providers involved in payment, subscription and billing processing
- Accounting and tax service providers
- Professional advisers
- Public authorities where disclosure is required by law
Service providers acting as processors are engaged in accordance with Article 28 GDPR where applicable.
We do not sell personal data.
10. International transfers
Some service providers, including Stripe, may process personal data in countries outside the European Economic Area or make data accessible from such countries.
Where personal data is transferred to a country for which the European Commission has adopted an adequacy decision, the transfer may be based on that decision. Where no adequacy decision applies, transfers are made using an appropriate transfer mechanism under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses, together with supplementary safeguards where required.
Stripe provides information about the transfer mechanisms and safeguards applicable to its processing in its privacy documentation.
11. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected or for as long as required by applicable law.
In particular:
- Website and API logs are normally deleted or anonymized after 7 days, subject to the exceptions described in Section 2.
- Application, account and API-client data is generally retained for the duration of the contractual relationship. Data may be retained for a limited period afterwards where necessary to handle claims, prevent abuse or comply with legal obligations.
- Billing and transaction information received from Stripe is retained where required for subscription administration and statutory accounting and tax obligations.
- Accounting and tax-relevant records are retained for the retention periods required under applicable German commercial and tax law.
- Support and other correspondence is retained for as long as necessary to handle the matter and, where applicable, for subsequent legal or contractual purposes.
When personal data is no longer required and no statutory retention obligation applies, it is deleted or anonymized.
12. Your rights
Subject to the applicable legal conditions, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request erasure
- Restrict processing
- Receive data in a portable format
- Object to processing based on legitimate interests
- Withdraw consent with effect for the future
Where processing is based on Article 6(1)(f) GDPR, you have the right to object to the processing on grounds relating to your particular situation in accordance with Article 21 GDPR.
You also have the right to lodge a complaint with a data protection supervisory authority.
13. Automated decisions
We do not make decisions producing legal or similarly significant effects solely through automated processing unless explicitly stated for a particular service.
14. Changes to this notice
We may update this notice when the service, providers or legal requirements change. The current version is published on this page.