GDPR

Last revised: 01/09/2026

Revised by: Ikechukwu


GDPR Notice (DRAFT)

This is a draft of the GDPR notice for OpenHack. It is not yet finalized and may be subject to change.

Introduction

This app (OpenHack) is a web-based code puzzle tool that allows students to solve coding challenges set by their organization coordinators or teachers. We are committed to protecting the privacy and personal data of our users and following the General Data Protection Regulation (GDPR).

Data Controller

OpenHack is operated by [name] and [name], who act as Joint Data Controllers under a Joint Controller Agreement. Contact is available under the "Contact Us" section below.

OpenHack data is stored on Postgres servers that are managed by OpenHack (us). We take sufficient measures to ensure data is only accessible by authorised users.

Hosting (currently) is on a home server, but we are planning to migrate to a GDPR-compliant cloud provider in the near future.

Data We Collect

As referenced by the "Children's Data" section below, this platform is designed for use in educational settings, and therefore minimises the collection of personal data.

1) Account data

We collect the following personal data when you create an account:

  • Name (only visible to you and your organization coordinators)
  • Randomly generated username
  • Email address (only visible to you and your organization coordinators)
  • Passwords (hashed and salted using secure cryptographic methods and are never stored in plain text)
2) Usage data

We collect data from usage:

  • Your solutions to coding puzzles (we require users to avoid submission of any personal data as part of their code)
  • Your progress and performance on coding puzzles
  • Last login time (for account activity tracking as per the deletion policy below)
3) Organization data

If you are part of an organization (e.g. a school), we may collect the following data about your organization:

  • Organization name
  • Your role within the organization (e.g. student, teacher, coordinator)
4) Telemetry data

In the event of a crash or error, we may collect telemetry data to help us diagnose and fix the issue. This data may include:

  • Error messages
  • Stack traces
  • Browser and operating system information
How We Use Your Data

We use the collected data for the following purposes:

  • Create and manage accounts
  • Allow participation in hackathons and coding assignments
  • Save and display code submissions
  • Enable teachers to manage students and their data
  • Maintain security, stability, and performance of the app

We do not sell or share your personal data with third parties for their marketing purposes.

Who We Share Your Data With

We may share your data with the following third parties:

  • Cloud hosting provider
  • Your organization (e.g. school) if you are part of one
  • Law enforcement or regulatory authorities if required by law

All third-party processors are required to process data in accordance with UK GDPR, and appropriate data processing agreements are in place.

Data Retention and Deletion

We retain your personal data for as long as your account is active. If a user has not logged in for 12 months, a warning will be sent to notify them that the account will be deleted within 30 days. After 30 days of inactivity, the account and all associated data will be permanently deleted.

Accounts that are not part of any organization will be automatically deleted after 1 month of not being enrolled in any organization.

When an account is deleted, submissions owned by that account will be deleted. However, if the submission is part of a group submission, the submission will be retained, with all metadata anonymized. If the user mistakenly puts personal data in their code submission, they can request deletion of that submission by contacting us.

Telemetry data is retained for a maximum of 30 days and is deleted after that period.

Lawful Basis

We use your data so that the platform can function, teachers can manage students, and accounts and progress can be saved securely. We use a minimal amount of personal data, and we do not use it for any purposes other than those necessary for the operation of the platform.

International Transfers

Where data is transferred outside the UK or EU, appropriate safeguards such as Standard Contractual Clauses are used.

Supabase acts as a data processor providing database and authentication services. Data is stored in the EU region (Sweden). Supabase may access data from outside the UK/EU where necessary to provide the service, and appropriate safeguards such as Standard Contractual Clauses are in place. // DEPRECATED

We act as our own data processor. We do not rely on any 3rd parties for data storage and/or authentication and authorisation services. Data may be stored on 3rd party systems, however the necessary measures are in place where they are unable to access data without our permission.

Rights of Data Subjects

You have the following rights regarding your personal data:

  • Right to access: You can request access to the personal data we hold about you.
  • Right to rectification: You can request that we correct any inaccurate or incomplete personal data we hold about you.
  • Right to erasure: You can request that we delete your personal data, subject to certain conditions.
  • Right to restrict processing: You can request that we restrict the processing of your personal data, subject to certain conditions.
  • Right to data portability: You can request that we provide your personal data in a structured, commonly used, and machine-readable format, and you have the right to transmit that data to another controller.
  • Right to object: You can object to the processing of your personal data, subject to certain conditions.
  • Rights related to automated decision-making and profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
  • Right to complain: You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data infringes the GDPR.
Children's Data

This platform is designed for use in educational settings by students, including those under the age of 18. We follow the principles of the UK Age Appropriate Design Code, including data minimisation, high privacy settings by default, and limiting data collection to what is necessary for educational purposes.

Data Security

We take appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. This includes HTTPS encryption, password hashing, and access controls to restrict data to authorized users.

Changes to This Notice

Any changes we make to this notice in the future will be posted on this page. Users will have to confirm they have read the updated notice before they can continue using the app.

Data Breaches

In the event of a personal data breach, we will assess the risk to users and, where required, notify the relevant educational institution and the Information Commissioner’s Office (ICO) within 72 hours. Affected users will be notified where there is a high risk to their rights and freedoms.

Contact Us

For all data protection requests (access, deletion, correction), please contact:
[email]

We will respond within one month as required under UK GDPR.

openhack