Myrmic Build & Break
Challenge Privacy Notice
Last updated: September 09, 2026
This Privacy Notice explains how personal data is processed when you register for, participate in, or interact with the Myrmic Build & Break Challenge.
The challenge is operated by:
Peeriot GmbH
Peterssteinweg 14
04107 Leipzig
Germany
For privacy-related questions, contact:
1. What information we collect
Depending on how you participate in the challenge, we may process:
- your name or display name;
- email address;
- country of residence;
- GitHub handle;
- optional Discord handle;
- challenge preferences and participation status;
- first-run feedback and final submission information;
- repository, commit, demo, or project links;
- support messages and challenge-related communication;
- optional public attribution choices;
- prize eligibility and, for selected winners, information required to administer awards;
- technical website and security logs;
- analytics information from public challenge pages where you have consented to analytics.
Please do not submit passwords, API keys, secrets, unrelated personal information, or security vulnerability details through general challenge forms.
All personal data described in this notice is collected directly from you through registration, submission, and support forms, or through your voluntary use of Discord and GitHub in connection with the challenge. We do not receive participant data about you from the RustConf organizers, or any other third-party; RustConf serves only as the launch and promotional venue for the challenge and is not a data source or processor for Peeriot.
2. Why we use your information
We process your information to:
- register and administer your participation;
- send operational challenge communication;
- provide technical and community support;
- manage teams and challenge status;
- review and reproduce challenge submissions;
- evaluate submissions and administer awards;
- improve Myrmic, its documentation, and developer experience;
- protect our websites, systems, and participants from misuse or security threats;
- publish projects, names, handles, or attribution only where permitted or separately chosen;
- send general Myrmic product or community updates only if you separately opt in;
- understand aggregate use of public challenge pages where analytics consent has been provided.
Participation in the challenge does not require consent to general Myrmic marketing.
3. Legal basis for processing
Depending on the purpose, we expect to process personal data on the following legal bases:
Challenge administration and requested communication
Processing necessary to manage your participation and take steps requested by you in connection with the challenge.
Security and abuse prevention
Our legitimate interests in protecting participants, systems, websites, and services.
Optional marketing and analytics
Your consent.
Public attribution
Where required, your consent or another appropriate legal basis depending on how the publication is structured.
Prize, accounting, and legal records
Applicable legal obligations and administration of the challenge and awards.
4. Services we use
We use third-party service providers to operate the challenge and its websites.
Kinsta
Used for website hosting, infrastructure, security, logs, backups, and related hosting services.
Paperform
Used for challenge registration, feedback, and submission forms.
Zoho CRM
Used for participant administration, challenge status, jury-related records, and operational communication.
Zoho Mail
Used for transactional and operational challenge email.
Google Analytics
Used for optional analytics on public challenge pages, only after analytics consent has been provided.
We may also use Discord for optional community support and GitHub for source code, repositories, public Issues, contributions, and private security reporting.
Some providers may process personal data outside the European Economic Area. Where this occurs, appropriate safeguards depend on the provider, contractual arrangements, and actual technical configuration.
5. Discord and GitHub
We use the following third-party platforms to manage operational communications
Discord
Discord may be used for optional community support, discussion, office hours, and challenge communications.
Please do not post:
- confidential information;
- unnecessary personal information;
- passwords or credentials;
- potential security vulnerabilities.
GitHub
GitHub may be used for:
- public source repositories;
- challenge project links;
- public Issues;
- contributions;
- private vulnerability reports where available.
Potential security vulnerabilities must not be disclosed through public GitHub Issues.
Your use of Discord and GitHub is also subject to those services’ own terms and privacy policies.
6. Analytics and cookies
We use essential technologies where necessary to operate and secure our websites.
Google Analytics is optional.
For the challenge, Google Analytics should only load after you allow analytics cookies. We use analytics to understand aggregate interest in the challenge and how visitors interact with public challenge pages.
We do not intentionally send the following information to Google Analytics:
- names;
- email addresses;
- Challenge IDs;
- GitHub or Discord handles;
- form answers;
- repository URLs;
- security-report references.
Analytics should be limited to approved aggregate events related to the public challenge journey.
You can change or withdraw analytics consent at any time through:
{{COOKIE_SETTINGS_URL}}
7. Marketing communications
General Myrmic product and community news are separate from challenge administration.
You will only receive these communications if you provide separate consent.
Marketing consent:
- is optional;
- is not required to participate in the challenge;
- is not pre-selected;
- can be withdrawn at any time.
Operational messages necessary to administer the challenge may still be sent even if you do not opt for general marketing.
8. How long we keep your information
The current working retention model is:
Registration and challenge feedback
Up to 12 months after the challenge closes, followed by deletion or anonymization unless a longer period is required.
Optional public showcase content
Retained according to the applicable publication basis and withdrawal rights.
Google Analytics user-level event data
Working default of 2 months.
Prize, tax, and accounting records
Retained for the applicable statutory period.
Security reports
Retained for as long as necessary for investigation, remediation, security, and legal protection.
9. Who can access your information
Challenge information is accessible only to Peeriot team members and service providers who require access for the purposes described in this notice.
Access should be limited according to role and operational needs.
Names, handles, project descriptions, quotes, repositories, or demonstrations are only published according to the challenge rules and the participant’s applicable attribution choices.
Jury members may receive access to information necessary to evaluate challenge submissions. Submission evaluation is carried out entirely by human jury members; we do not use automated decision-making or profiling that produces legal effects or similar significantly affects participants.
10. Security and vulnerability reports
Only test systems that you own or are explicitly authorized to test.
Do not publish potential security vulnerabilities through:
- Discord;
- public GitHub Issues;
- general challenge registration forms;
- general challenge feedback or submission forms.
If you believe you have identified a security vulnerability, report it privately to:
Please include enough information for the Myrmic team to understand and reproduce the issue, but do not include unnecessary personal information, credentials, or secrets.
A privately reported security finding may still be considered for an award where it is permitted by the Challenge Rules.
11. Your data protection rights
Subject to applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate information;
- request deletion of your personal data;
- request restriction of processing;
- receive certain information in a portable format;
- object to certain processing;
- withdraw consent at any time where processing relies on consent.
Withdrawing consent does not affect processing that occurred before the withdrawal. To exercise your rights, contact:
security@myrmic.dev
You may also lodge a complaint with a competent data protection supervisory authority.
12. International data transfers
Some service providers or their subprocessors may process information outside the European Economic Area.
Where personal data is transferred internationally, Peeriot uses appropriate safeguards where required, such as the European Commission’s Standard Contractual Clauses or an equivalent recognized transfer mechanism, as required by applicable law.
We do not claim that all challenge-related processing takes place exclusively within the European Union unless this has been verified across the complete technical setup and all relevant subprocessors.
13. Security of your information
We take reasonable technical and organizational measures to protect personal information used to operate the challenge.
These measures may include:
- limiting access according to role;
- using authenticated administrative systems;
- separating participant records from public analytics;
- restricting access to challenge and jury information;
- using private channels for security reports;
- reviewing service-provider access and integrations;
- avoiding personal information in analytics parameters, URLs, and tracking data.
No online service can guarantee absolute security. Participants should therefore avoid submitting information that is not required for participation.
14. Changes to this notice
We may update this Privacy Notice if:
- the challenge process changes;
- new service providers are introduced;
- existing services are removed;
- the purposes of processing change;
- legal or technical requirements change.
The current version and publication date will be shown on this page.
Contact
For questions about this Privacy Notice or how your personal data is handled:
Peeriot GmbH
Peterssteinweg 14
04107 Leipzig
Germany
For privacy and potential security vulnerabilities:
JOIN THE BUILD & BREAK CHALLENGE!
Try the starter project, build a use case, or bring us a break report. Registration takes about three minutes.