This is a draft of the GDPR notice for OpenHack. It is not yet finalized and may be subject to change.
This app (OpenHack) is a web-based code puzzle tool that allows students to solve coding challenges set by their organization coordinators or teachers. We are committed to protecting the privacy and personal data of our users and following the General Data Protection Regulation (GDPR).
OpenHack is operated by [name] and [name], who act as Joint Data Controllers under a Joint Controller Agreement. Contact is available under the "Contact Us" section below.
OpenHack data is stored on Postgres servers that are managed by OpenHack (us). We take sufficient measures to ensure data is only accessible by authorised users.
Hosting (currently) is on a home server, but we are planning to migrate to a GDPR-compliant cloud provider in the near future.
As referenced by the "Children's Data" section below, this platform is designed for use in educational settings, and therefore minimises the collection of personal data.
We collect the following personal data when you create an account:
We collect data from usage:
If you are part of an organization (e.g. a school), we may collect the following data about your organization:
In the event of a crash or error, we may collect telemetry data to help us diagnose and fix the issue. This data may include:
We use the collected data for the following purposes:
We do not sell or share your personal data with third parties for their marketing purposes.
We may share your data with the following third parties:
All third-party processors are required to process data in accordance with UK GDPR, and appropriate data processing agreements are in place.
We retain your personal data for as long as your account is active. If a user has not logged in for 12 months, a warning will be sent to notify them that the account will be deleted within 30 days. After 30 days of inactivity, the account and all associated data will be permanently deleted.
Accounts that are not part of any organization will be automatically deleted after 1 month of not being enrolled in any organization.
When an account is deleted, submissions owned by that account will be deleted. However, if the submission is part of a group submission, the submission will be retained, with all metadata anonymized. If the user mistakenly puts personal data in their code submission, they can request deletion of that submission by contacting us.
Telemetry data is retained for a maximum of 30 days and is deleted after that period.
We use your data so that the platform can function, teachers can manage students, and accounts and progress can be saved securely. We use a minimal amount of personal data, and we do not use it for any purposes other than those necessary for the operation of the platform.
Where data is transferred outside the UK or EU, appropriate safeguards such as Standard Contractual Clauses are used.
Supabase acts as a data processor providing database and authentication services. Data is stored in the EU region (Sweden). Supabase may access data from outside the UK/EU where necessary to provide the service, and appropriate safeguards such as Standard Contractual Clauses are in place. // DEPRECATED
We act as our own data processor. We do not rely on any 3rd parties for data storage and/or authentication and authorisation services. Data may be stored on 3rd party systems, however the necessary measures are in place where they are unable to access data without our permission.
You have the following rights regarding your personal data:
This platform is designed for use in educational settings by students, including those under the age of 18. We follow the principles of the UK Age Appropriate Design Code, including data minimisation, high privacy settings by default, and limiting data collection to what is necessary for educational purposes.
We take appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. This includes HTTPS encryption, password hashing, and access controls to restrict data to authorized users.
Any changes we make to this notice in the future will be posted on this page. Users will have to confirm they have read the updated notice before they can continue using the app.
In the event of a personal data breach, we will assess the risk to users and, where required, notify the relevant educational institution and the Information Commissioner’s Office (ICO) within 72 hours. Affected users will be notified where there is a high risk to their rights and freedoms.
For all data protection requests (access, deletion, correction), please contact:
[email]
We will respond within one month as required under UK GDPR.