Hackathon and Event Privacy Notice
AI BEAVERS hackathons and event programs
Last updated: June 27, 2026
Scope
This notice explains how AI BEAVERS processes personal data for hackathons, founder events, build nights, event check-in, team submissions, judging, public voting, attendee verification, sponsor/API-key perks, public winner pages, recaps, and event media.
It supplements the main Privacy Policy. If the two notices conflict for a hackathon or event flow, this event notice applies to that flow.
Controller
Alexander Zakharov
Turmweg 31
20148 Hamburg, Germany
Email: [email protected]
Data We Process for Event Programs
1. Registration, Attendance, and Check-In
- Data: Name, email, company, role, registration source, Luma or Meetup attendee fields, event ticket status, check-in timestamp, checked-in attendee status, and venue access notes where needed.
- Purpose: Manage event access, capacity, safety, attendance verification, logistics, participant communication, and eligibility for submissions or perks.
- Legal basis: Contract or pre-contract steps under Art. 6(1)(b) GDPR; legitimate interests under Art. 6(1)(f) GDPR for venue operations, safety, fraud prevention, and audit.
- Required or optional: Required registration and check-in fields are needed to attend or claim event benefits. Optional profile, company, or communication fields improve event operations.
2. Team and Project Submissions
- Data: Team name, participant names, contact email, project name, description, category, repo or demo links, images, logos, pitch materials, track eligibility answers, submitted files, timestamps, and review status.
- Purpose: Accept submissions, organize projects by track, prepare judging, verify eligibility, publish approved project information, and maintain an event record.
- Legal basis: Contract under Art. 6(1)(b) GDPR for participation; legitimate interests under Art. 6(1)(f) GDPR for event integrity, moderation, public documentation, and dispute handling.
- Required or optional: Fields marked required in a submission form are needed for judging or publication. Optional links, images, and supporting material can improve the project page or judging context.
3. Judging and Winner Selection
- Data: Judge assignments, project eligibility data, scores, notes, rankings, finalist status, winner categories, disqualification notes, and audit records.
- Purpose: Support judges, apply event rules, select finalists and winners, resolve disputes, and publish results.
- Legal basis: Contract under Art. 6(1)(b) GDPR and legitimate interests under Art. 6(1)(f) GDPR in fair judging, event integrity, and public result documentation.
- Required or optional: Judging data is required for participants who submit a project for judged tracks.
4. Social Voting
- Data: Voter name, email, selected project, verification token, verification timestamp, IP address, user agent, referrer, vote status, duplicate prevention signals, and optional newsletter opt-in.
- Purpose: Verify votes, prevent duplicate or fraudulent voting, calculate aggregate results, publish leaderboards, and contact opted-in newsletter subscribers.
- Legal basis: Legitimate interests under Art. 6(1)(f) GDPR for voting integrity and fraud prevention; consent under Art. 6(1)(a) GDPR for optional newsletter subscription.
- Required or optional: Name, email, and verification are required to cast a counted vote. Newsletter opt-in is optional.
- Public display: Individual voter identities are not shown publicly. Aggregate counts, rankings, and project results may be public.
5. Sponsor Perks, API Keys, Credits, and Benefits
- Data: Participant email, checked-in attendee status, perk eligibility, sponsor or API provider, redemption status, claim timestamp, support notes, and related identifiers.
- Purpose: Confirm eligibility, distribute perks, prevent duplicate claims, resolve support issues, and report aggregated redemption activity to sponsors.
- Legal basis: Contract under Art. 6(1)(b) GDPR for benefit delivery and legitimate interests under Art. 6(1)(f) GDPR for fraud prevention, support, and sponsor accountability.
- Required or optional: Eligibility and contact data is required to claim a perk. Sharing data directly with a sponsor or API provider may be required for some external redemptions and will be controlled by that provider.
6. Public Winners, Recaps, and Media
- Data: Team names, participant names where approved or event-relevant, project summaries, winner categories, rankings, images, videos, quotes, social posts, sponsor acknowledgements, and recap materials.
- Purpose: Publish winner pages, event recaps, public galleries, newsletters, social posts, sponsor reports, and community archive pages.
- Legal basis: Consent under Art. 6(1)(a) GDPR for optional media and quoted personal attribution where requested; contract under Art. 6(1)(b) GDPR for public project participation terms; legitimate interests under Art. 6(1)(f) GDPR in documenting and promoting community events.
- Required or optional: Public winner, finalist, team, and approved project details may be part of participation in public tracks. Close-up media, testimonials, and optional attribution can be limited or removed on valid request where feasible.
Processors and Recipients
We may use or share event data with the following recipients where needed for the purposes above:
- Firebase, Firestore, Firebase Storage, Firebase Auth, and Google Cloud.
- Resend for transactional and newsletter email.
- Luma, Meetup, venues, and event platforms used for registration or calendars.
- Judges, mentors, and limited event staff for submission review and event operations.
- Sponsors or API providers when needed to verify or deliver a perk.
- Telegram for limited organizer notifications where configured.
- Website visitors and search engines for public winner, recap, and project pages.
International transfers may occur through these providers. Where required, we rely on adequacy decisions, the EU-US Data Privacy Framework where applicable, standard contractual clauses, or other legally recognized transfer safeguards.
Retention
- Registration, check-in, and attendee verification data is kept while needed for event operations, eligibility, support, audit, safety, and legal claims.
- Submission, judging, winner, leaderboard, and recap records may be kept as part of the public event archive and to preserve result integrity.
- Voting verification tokens are short-lived and commonly expire within 24 hours. Vote audit records may be kept longer to maintain leaderboard integrity and investigate fraud.
- Sponsor perk and API-key claim records are kept while needed to verify eligibility, prevent duplicate claims, support participants, and satisfy sponsor accountability.
- Payment, tax, or accounting records connected with paid event products are retained for statutory periods where applicable.
Your Rights
Subject to GDPR conditions and limits, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent for future optional media, newsletter, or optional public attribution processing.
Email [email protected] to exercise rights. We may need to verify your identity and may retain limited data where required for event integrity, public archives, legal claims, accounting, or safety.
Contact
For event privacy questions, contact Alexander Zakharov at [email protected].