Privacy policy

How SwimNexus uses personal information.

This notice explains what we collect, why we use it, who may see it, and the choices and rights available to you.

Last updated: 15 July 2026

SwimNexus provides development and invited-testing services for swimming clubs, meet hosts, league organisers, officials, volunteers, competitors, families, and platform users. This notice covers the SwimNexus website and the SwimMeetOS, SwimClubOS, and SwimLeagueOS product family.

No data salesWe do not sell personal information.
No ad trackingWe do not currently use advertising or analytics cookies.
Invitation accessWorking product areas are currently restricted.

Who we are

SwimNexus is the name used for this United Kingdom-based service. For privacy questions, requests, or the current operator's legal contact details, email [email protected].

Our privacy roles

Responsibility depends on why information is being used:

  • SwimNexus is a controller for account administration, product testing relationships, support enquiries, website security, service audit, and our own business records.
  • A club, meet host, or league organiser is normally the controller for member, competitor, official, volunteer, entry, result, billing, or league information it chooses to enter, import, manage, or publish through a product.
  • SwimNexus normally acts as that organisation's processor when we store or handle its operational information under its instructions. We may also need to use limited records as a controller to secure the service, investigate faults, or meet legal obligations.

If your information came from a club, meet, or league, that organisation should usually be your first contact. We will help it respond where appropriate.

Information we use and where it comes from

Depending on the product and your role, we may use:

  • account information such as name, email address, password hash, club or organisation, role, product access, login history, and password-reset records;
  • organisation information such as club codes, contacts, billing contacts, participating teams, and user permissions;
  • meet and competitor information such as names, dates or years of birth where required, age groups, sex or competition category, membership or registration numbers, clubs, entries, seed times, results, disqualifications, awards, scores, and reports;
  • team contact and finance information such as contact name, email, phone number, entry totals, fees, invoice status, and payment status;
  • officials information such as name, email, phone, club, governing-body membership number, qualifications, availability, duty preferences, mentoring requests, allocations, and coordinator notes;
  • optional dietary, parking, or accessibility information where a meet host enables and needs those fields;
  • support, testing, and contact information you send through our forms or by email; and
  • technical and security information such as session identifiers, IP address, browser or device details, service logs, imports and exports, audit events, and email delivery status.

We receive information directly from individuals, from authorised club or meet users, from league organisers, through entry or officials forms, and from files imported from swimming software or governing-body formats.

Why we use information and our lawful bases

We use personal information to provide and secure accounts; administer invited testing; respond to enquiries; build and operate meets; receive and validate entries; coordinate officials; seed and run races; calculate and publish results; create reports and exports; support club and league workflows; send necessary service messages; diagnose problems; prevent misuse; and maintain audit records.

Depending on the context, the lawful basis is usually:

  • contract, where processing is necessary to provide an account or service requested by an organisation or user;
  • legitimate interests, including operating and improving the service, supporting swimming administration, keeping accurate event records, responding to enquiries, and protecting the platform—balanced against people's rights;
  • legal obligation, where records or disclosures are required by law; or
  • consent, where a genuinely optional use relies on consent. Consent can be withdrawn, but this does not affect processing already carried out lawfully.

Clubs, meet hosts, and leagues must choose and document the appropriate lawful basis for the operational information they control. SwimNexus does not currently use personal information for solely automated decisions that produce legal or similarly significant effects.

Your right to object: where processing relies on legitimate interests, you can object. We will consider your circumstances and stop unless there are compelling lawful reasons to continue.

Children and sensitive information

Competitive swimming involves children and young people, whose information deserves particular protection. We design for restricted access, data minimisation, clear publication choices, and straightforward explanations. We do not use children's information for advertising or behavioural profiling.

A club or meet host should collect only the information it needs, explain the use in age-appropriate language, and avoid recording unnecessary medical, welfare, or safeguarding detail in general operational fields. Information that may reveal health needs, such as some dietary or accessibility details, must be handled with extra care and only where an appropriate UK GDPR condition has been identified.

Children have data protection rights of their own. Depending on age and understanding, a child may exercise those rights directly or a parent or guardian may help them.

Sharing, processors, and public publication

We do not sell personal information. Information may be available to authorised users of the relevant club, meet host, or league; SwimNexus administrators who need access for support or security; and suppliers providing hosting, database, backup, and authenticated email delivery. We require service providers to protect information and use it only for the agreed service.

Where an organisation chooses an export or integration, information may be shared with timing systems, results or rankings systems, payment or communication services, governing bodies, or other recipients selected by that organisation.

Public live results and published reports may include a competitor's name, club, age or age group, event, time, place, points, and disqualification status. Officials' contact details, membership numbers, availability, mentoring, dietary, accessibility, and allocation details are not published on the public meet portal. Meet hosts control when operational results are made public and should publish only what is necessary.

If a supplier processes information outside the UK, we will use an applicable UK adequacy regulation or another recognised safeguard, such as approved contractual clauses, where required. You can ask us for more information about relevant safeguards.

Cookies and technical data

SwimNexus uses a strictly necessary session cookie to keep forms secure and keep signed-in users authenticated. The service may also use local browser storage for a meet operator who deliberately prepares the Meet Run screen for temporary offline continuity. That data remains on the operator's device until cleared by the browser or the operator.

We do not currently use advertising, behavioural-tracking, or third-party analytics cookies. If this changes, we will update this notice and provide any consent controls required by law.

How long we keep information and how we protect it

We keep personal information only while it is needed for the purpose for which it was collected, and for any reasonable legal, safeguarding, financial, security, dispute, backup, or audit period. The relevant club, meet host, or league sets retention requirements for its operational data. We periodically review testing and support information and delete or anonymise it when it is no longer needed.

Account and session records are retained while access is active and for a proportionate security or audit period afterwards. Password links expire automatically. Contact enquiries and email delivery records are retained while the enquiry or delivery issue is handled and for a reasonable follow-up period. Meet results may need longer retention as part of the sporting record, while unnecessary contact, availability, dietary, or accessibility information should normally be removed sooner.

Protection measures include access controls, organisation and product permissions, password hashing, session protection, audit histories, restricted public routes, backups, and review of deliberately generated exports. No internet service can promise absolute security, but suspected security issues can be reported to [email protected].

Your rights

Depending on the circumstances and lawful basis, you may have the right to:

  • ask for access to your personal information;
  • have inaccurate or incomplete information corrected;
  • ask for information to be erased or processing restricted;
  • object to processing based on legitimate interests;
  • receive certain information in a portable format; and
  • withdraw consent where consent is the lawful basis.

Some rights are not absolute. We may need to verify identity and may refer a request to the club, meet host, or league that controls the information.

Contact, complaints, and updates

To ask a privacy question, exercise a right, or report a concern, email [email protected]. Please identify the relevant club, meet, league, or account where you can do so safely.

You also have the right to complain to the UK Information Commissioner's Office. Visit ico.org.uk/make-a-complaint for current contact options. We would appreciate the opportunity to address the concern first.

We will update this notice when products, suppliers, public access, or legal requirements change. Material changes will be highlighted here and, where appropriate, communicated to account holders or partner organisations.