Organiser terms

Version 1.1 · 8 September 2026

The agreement

These terms are between Wiltech Solutions (Pty) Ltd, a company registered in South Africa ("Marshal", "we", "us"), and you, the person who creates an account and runs events on it ("you", "the organiser").

You accept them when you create an account. If you are doing this for a club, school, employer or other organisation, you confirm you are allowed to accept on its behalf, and "you" means that organisation too.

The sections Who is responsible for what, Your obligations, Our obligations, Who else is involved and Retention and deletion together also serve as the written processing agreement that data protection law requires between us — Article 28 of the UK and EU GDPR, and section 21 of South Africa's POPIA.

What Marshal is

Marshal shows you where the people in your event are and how they are doing, while it is running. Participants install a Connect IQ data field on their own Garmin device and enter the join code you give them.

It is not a safety system. Marshal depends on a watch, Bluetooth, a participant's phone, a mobile network and our servers. Any of those can fail, and coverage in the places people run and ride is often poor. A participant showing green does not mean they are well, and a participant showing red usually means a dropped signal rather than an emergency. Do not use Marshal as your means of detecting that someone is in trouble, and do not present it to participants as one.

Your account

  • Keep your password to yourself, and tell us promptly if you think someone else has it.
  • You are responsible for what happens under your account.
  • One human per account. Do not share a login around a committee.
  • You must be old enough to enter a contract where you live.

Who is responsible for what

Two different sets of personal information pass through Marshal, and we are not in the same role for both.

Your event's participant data
positions, heart rate, pace, display names
You are the controller. You decide that the event exists, who is invited to join it, who gets the dashboard link, and when it is closed and deleted. We are your processor — we hold and move that data on your instructions and for no purpose of our own.
Your account
email address, authentication, the events you create
We are the controller. We decide what we need in order to run the service, keep it secure and reach you.

POPIA calls a controller the responsible party and a processor the operator. The roles are the same either way.

This matters in practice: a participant who wants their data removed can be answered by you immediately, from your portal. If they come to us instead, we will point them to you and help where we can, but the decision about your event's data is yours.

Your obligations

As the controller for your event, you agree to:

  • Get each participant's consent before they join. Not a formality: heart rate is health data, which most privacy laws treat as a special category needing clear, explicit, freely given consent. Location plus identity is sensitive in its own right.
  • Tell participants what actually happens — what is collected, that it appears on a live map, who will be watching it, and that it is deleted 48 hours after the event closes. Our privacy policy is written to be handed straight to them.
  • Make joining genuinely optional. Do not make Marshal a condition of taking part, and do not put pressure on employees, students or members to enable it.
  • Leave heart rate to the participant. The data field has a Send heart rate toggle; anyone may turn it off and send position only. Do not require it, and do not treat someone who declines as not taking part. If your event genuinely needs it, explain why and let people choose.
  • Treat the join code as a key. Anyone who has it can send readings into your event. Give it only to participants, and close the event when it is over.
  • Share the dashboard narrowly. Anyone you give access to can see every participant's live position and vitals.
  • Decide about public viewing deliberately. Each event has a public viewing switch, off by default. Turning it on means anyone holding the event code can watch without an account — which includes every participant you gave the code to, and anyone they pass it to. Before you turn it on, tell participants that is what will happen, and treat it as part of what they are consenting to. Codes are short and human-chosen, so do not rely on one being hard to guess. Closing the event ends public viewing at once.
  • Handle under-18s properly. If any participant is a child, get consent from a parent or guardian, in whatever form the law where you are requires. School and youth club events are exactly the case to slow down on.
  • Deal with participants' requests. Access, correction and deletion requests about your event come to you first. Tell us if you need help.
  • Only give us instructions that are lawful where you and your participants are.

Our obligations

As your processor for your event's participant data, we agree to:

  • Process it only to provide Marshal to you, and on your instructions — not for our own purposes, not to train anything, never sold.
  • Keep it confidential, and impose the same duty on anyone who can reach it.
  • Apply the security measures described in our privacy policy, and keep them under review.
  • Tell you without undue delay if we become aware of a breach affecting your event, with what we know at the time.
  • Help you, so far as we reasonably can, to answer participants' requests and to meet your own obligations.
  • Delete your event data on the schedule below, or sooner if you tell us to.
  • Make available the information you need to satisfy yourself we are doing the above.
  • Use sub-processors only as set out next, and remain answerable to you for them.

Separately, as controller of your account data, we handle it as described in the privacy policy.

Who else is involved

Google — Firebase Realtime Database, Authentication and Hosting. Event data is stored in Google's europe-west1 region, in Belgium. You authorise this sub-processor by accepting these terms. If we add another, we will tell account holders by email before it starts handling event data, so you have a chance to object.

Map tiles are rendered from OpenStreetMap data. Your browser requests those tiles directly; the tile server sees the area you are looking at, not who is in it.

Retention and deletion

  • Positions and vitals are deleted 48 hours after the later of: the event being closed, or the last reading received.
  • You can delete an event's data, or all of your events and data, at any time from your portal. That is immediate and permanent.
  • Account details are kept until you delete the account.
  • Deletion is deletion. We do not keep an archive copy for ourselves.

Acceptable use

Do not use Marshal to:

  • track anyone who has not knowingly agreed to it, or who has asked you to stop;
  • monitor staff performance, attendance or whereabouts outside a genuine event;
  • build a profile of anyone's movements or health over time;
  • do anything unlawful, or anything that puts a participant at risk;
  • attack, probe or overload the service, or work around its access controls.

Covert tracking is the thing we care most about. If you would not be comfortable showing a participant this page and their own live trace, do not run the event.

Availability

Marshal is provided as it is, with no promise of uptime, accuracy or fitness for a particular purpose, to the extent the law where you are allows that. There is no guaranteed service level. We may change or withdraw features, and will give reasonable notice for changes that materially reduce what you get.

Liability

We are not liable for indirect or consequential loss, lost profit, or loss arising because Marshal did not show something — a dropped signal, a stale position, a participant who never appeared. See what Marshal is: plan your event's safety on the assumption Marshal is not there.

Nothing here limits liability that cannot lawfully be limited, including for death or personal injury caused by negligence, or for fraud.

Because Marshal is currently provided free of charge, our total liability to you is limited to ZAR 1,000.

Ending the agreement

You can stop at any time by deleting your data and your account. We may suspend or close an account that breaches these terms — immediately where participants are at risk, otherwise with notice and a chance to put it right. When the agreement ends, your event data is deleted on the schedule above.

Changes

We may update these terms. The version and date at the top will change, and for anything significant we will email account holders and ask you to accept the new version before continuing. Carrying on using Marshal after a minor change means you accept it.

Governing law

These terms are governed by the law of South Africa, and the South African courts have jurisdiction. If you are a consumer somewhere else, this does not take away rights or protections your local law gives you that cannot be contracted out of, and it does not stop you bringing a claim where you live if your law says you may.

Contact

tristan@alasia.co.za
Wiltech Solutions (Pty) Ltd, South Africa

Our registered address is available on request, including for service of any formal notice under these terms.