Skip to content
Legal

Data Processing Agreement

How we process participant data on your behalf when you run an event — you are the controller, we are the processor.

Last updated ·
On this page
  1. 1. Parties & roles
  2. 2. Subject matter & duration
  3. 3. Our obligations as processor
  4. 4. Sub-processors
  5. 5. Security measures (Art. 32)
  6. 6. Data-subject requests
  7. 7. Personal-data breaches
  8. 8. International transfers
  9. 9. Deletion & return
  10. 10. General

01.Parties & roles

This Data Processing Agreement ("DPA") forms part of the agreement between you, the event organizer ("Host", the data controller), and HackathonHost ("we", the data processor).

It governs our processing of personal data on your behalf when you use HackathonHost to run an event. For our own account and billing data — where we are the controller — see the Privacy Policy.

02.Subject matter & duration

Subject matter. Processing of personal data that participants submit when they register for, and take part in, the events you create on the platform.

Duration. For as long as your host account is active and you keep the relevant events, plus the limited retention windows described in "Deletion & return" below.

Nature & purpose. Storing, organizing, displaying, and communicating event data so you can run registration, team formation, jury scoring, results, certificates, and participant communications.

Categories of data subjects. Event participants, team members, jury members, mentors, guests, and any other people whose details you enter.

Types of personal data. The fields you configure for your event — typically name, date of birth, government ID/CIF, email, phone, role, prior experience, plus any custom questions and free-text you add. You control which fields you collect.

03.Our obligations as processor

We commit that we will:

  • Process only on your instructions — we process participant data solely to provide the platform to you and as documented in this DPA and the app's features, not for our own purposes. We do not sell it or use it for advertising or profiling.
  • Keep it confidential — the people who operate the platform are bound by confidentiality and access data only where needed to run and support the service.
  • Secure it — we maintain the technical and organizational measures described in "Security" below (GDPR Art. 32).
  • Assist you — we provide features and, where needed, reasonable help so you can meet participants' rights requests and your own Art. 32–36 obligations (security, breach notification, impact assessments).
  • Delete or return — on termination or on your instruction, we delete or return the data as described below.
  • Support audits — we make available the information reasonably necessary to demonstrate compliance with Art. 28, including this DPA and our sub-processor list.

04.Sub-processors

You give us general authorization to engage the sub-processors below to deliver the service. Each sees only the slice of data it needs. We'll give notice of material changes (new or replacement sub-processors) through the app to active hosts, so you can object.

  • Railway — application & database hosting (EU / US).
  • Resend — outgoing transactional email (unless you configure your own SMTP).
  • Sentry — error monitoring (technical error details, which can incidentally include limited personal data).
  • Google & Apple — identity providers for optional social sign-in.
  • Polar & RevenueCat — payment processing for event credits.
  • Apple Push Notification Service — iOS push, when opted in.

The current, authoritative list lives in the Privacy Policy. Each sub-processor is bound by data-protection terms no less protective than those in this DPA.

05.Security measures (Art. 32)

Our technical and organizational measures include:

  • Encryption in transit — all traffic to the app and API is served over TLS.
  • Encryption at rest for backups — off-site database backups can be encrypted with AES-256 so a backup copy holds no readable personal data.
  • Access control — role-scoped logins (host, organizer, jury, mentor, guest); each host's data is isolated from every other host's.
  • Credential protection — passwords are stored only as bcrypt hashes; stored provider secrets are encrypted.
  • Hardening — rate limiting, bot protection on public actions, security headers, and error monitoring to detect issues.
  • Data minimization & retention limits — you choose which fields to collect, and long-ended events are automatically anonymized (see below).

06.Data-subject requests

The platform gives participants self-service tools — they can view their data and request erasure or withdrawal through links in their confirmation and notice emails. You, as the host, can also correct or remove any participant's data from the Registrations and Teams pages.

Where a request can't be resolved through those tools, we'll assist you in responding within the statutory timeframe. Participants who can't reach their host may write to contact@hackathonhost.com and we'll route the request to you or act on it where we're required to.

07.Personal-data breaches

If we become aware of a personal-data breach affecting data we process for you, we'll notify you without undue delay and provide the information you reasonably need to meet your own notification duties (Art. 33), including the nature of the breach, likely consequences, and the measures we've taken.

08.International transfers

Our infrastructure and sub-processors may process data in the EU and the US. Where personal data is transferred outside your jurisdiction, we rely on appropriate safeguards (such as Standard Contractual Clauses) offered by the relevant provider. The sub-processor list identifies who is involved.

09.Deletion & return

On account deletion. When you delete your host account, we cascade-delete every event you own and all teams, jury accounts, participant registrations, and associated email and billing logs under those events.

Automatic anonymization. Even while your account stays open, participant and event-staff personal data for events that ended more than 12 months ago is automatically anonymized in place — the aggregate records survive, the personal fields do not.

Export. Before deleting, you can export a full bundle of an event's data from the admin dashboard.

Backups. If off-site backups are enabled, a copy of deleted data can persist in an encrypted backup for a short rolling window (typically up to two weeks) before it ages out.

10.General

If there is a conflict between this DPA and the host terms on the subject of data protection, this DPA prevails. If any part is found unenforceable, the rest stays in effect.

This document is a template and not legal advice. For a countersigned agreement, or questions about our processing, contact contact@hackathonhost.com. We recommend your own legal review before relying on it.

Last updated:
Questions? Contact us →