Effective Date: April 9, 2026
1. Introduction
This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit or interact with our website at https://wimaworld.com/. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection laws. By using our website, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for the processing of your personal data through this website is WIMA – Women’s International Motorcycle Association (“WIMA”), the operator of https://wimaworld.com/. If you have any questions about this Privacy Policy or wish to exercise your rights under the GDPR, please contact us using the details provided in Section 12 below.
3. Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Comments. When you leave a comment on our website, we collect the data shown in the comments form (such as your name, email address, and website URL), as well as your IP address and browser user agent string. We collect your IP address and browser user agent string for the purpose of spam detection. An anonymized string (hash) created from your email address may be provided to the Gravatar service to determine whether you use that service. The Gravatar service privacy policy is available at https://automattic.com/privacy/. Upon approval of your comment, your profile picture will be visible to the public alongside your comment.
3.2 Media. If you upload images to the website, you should be aware that images may contain embedded location data (EXIF GPS). Visitors to the website may download and extract location data from images hosted on the website. We recommend that you remove any embedded location data before uploading images.
3.3 Cookies. Our website uses cookies in the following ways: If you leave a comment on our site, you may opt in to saving your name, email address, and website in cookies. These cookies are stored for your convenience so that you do not need to re-enter your details when leaving subsequent comments. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine whether your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will set several cookies to save your login information and screen display preferences. Login cookies last for two days, and screen options cookies last for one year. If you select “Remember Me,” your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you edited. It expires after one day.
3.4 Embedded Content from Other Websites. Articles on this site may include embedded content such as videos, images, and articles from other websites. Embedded content from other websites behaves in the same way as if you had visited those websites directly. These third-party websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with the embedded content, including tracking your interaction if you have an account and are logged in to those websites.
4. Legal Basis for Processing
Under the GDPR, we process your personal data on the following legal bases:
4.1 Consent (Article 6(1)(a) GDPR). Where you have given your explicit consent to the processing of your personal data for one or more specific purposes, such as opting in to store your details in cookies when leaving a comment.
4.2 Legitimate Interests (Article 6(1)(f) GDPR). We may process your personal data where it is necessary for our legitimate interests, provided that such interests are not overridden by your fundamental rights and freedoms. Our legitimate interests include spam detection and prevention, website security, and the proper administration of our website.
4.3 Legal Obligation (Article 6(1)(c) GDPR). We may process your personal data where it is necessary for compliance with a legal obligation to which we are subject.
5. Who We Share Your Data With
We do not sell your personal data to third parties. We may share your personal data in the following limited circumstances:
Your anonymized email hash may be shared with the Gravatar service as described in Section 3.1. If you request a password reset, your IP address will be included in the reset email. Visitor comments may be checked through an automated spam detection service. We may also disclose your personal data where required to do so by law, regulation, or court order.
6. International Data Transfers
Some of the third-party services we use, such as the Gravatar service and automated spam detection services, may process your data outside the European Economic Area (“EEA”). Where such transfers occur, we will ensure that appropriate safeguards are in place in accordance with Article 46 of the GDPR, such as standard contractual clauses approved by the European Commission, or that a valid adequacy decision under Article 45 of the GDPR applies.
7. Data Retention
If you leave a comment, the comment and its associated metadata are retained indefinitely. This is so that we can recognise and approve follow-up comments automatically without holding them in a moderation queue.
For users who register on our website, we store the personal information they provide in their user profile for as long as their account remains active. All users can view, edit, or delete their personal information at any time, with the exception that usernames cannot be changed. Website administrators may also view and edit user profile information.
We retain other personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law.
8. Your Rights Under the GDPR
Under the GDPR, you have the following rights with respect to your personal data:
8.1 Right of Access (Article 15). You have the right to request a copy of the personal data we hold about you, including any data you have provided to us, in a structured, commonly used, and machine-readable format.
8.2 Right to Rectification (Article 16). You have the right to request that we correct any inaccurate personal data we hold about you without undue delay.
8.3 Right to Erasure (Article 17). You have the right to request that we erase any personal data we hold about you. Please note that this right does not extend to data we are obliged to retain for administrative, legal, or security purposes.
8.4 Right to Restriction of Processing (Article 18). You have the right to request that we restrict the processing of your personal data in certain circumstances.
8.5 Right to Data Portability (Article 20). You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
8.6 Right to Object (Article 21). You have the right to object to the processing of your personal data where we rely on legitimate interests as our legal basis for processing.
8.7 Right to Withdraw Consent. Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
8.8 Right to Lodge a Complaint. You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes the GDPR. You may do so with the supervisory authority of the EU Member State in which you habitually reside, work, or in which the alleged infringement occurred.
9. Automated Decision-Making
Visitor comments may be checked through an automated spam detection service. This processing is carried out on the basis of our legitimate interest in preventing spam and maintaining the security of our website. You have the right to contest any decision made solely by automated means that significantly affects you.
10. Security of Your Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
11. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time. Any changes will be posted on this page with an updated effective date. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your data.
12. Contact Us
If you have any questions about this Privacy Policy, wish to exercise any of your rights under the GDPR, or wish to make a complaint, please contact us at:
president@wimaworld.com
