Myrmic Build & Break
Challenge Privacy Notice

Last updated: September 09, 2026

This Privacy Notice explains how personal data is processed when you register for, participate in, or interact with the Myrmic Build & Break Challenge.

The challenge is operated by:

Peeriot GmbH
Peterssteinweg 14
04107 Leipzig
Germany

For privacy-related questions, contact:

security@myrmic.dev

1. What information we collect

Depending on how you participate in the challenge, we may process: 

  • your name or display name; 
  • email address; 
  • country of residence; 
  • GitHub handle; 
  • optional Discord handle; 
  • challenge preferences and participation status; 
  • first-run feedback and final submission information; 
  • repository, commit, demo, or project links; 
  • support messages and challenge-related communication; 
  • optional public attribution choices; 
  • prize eligibility and, for selected winners, information required to administer awards; 
  • technical website and security logs; 
  • analytics information from public challenge pages where you have consented to analytics. 

  

Please do not submit passwords, API keys, secrets, unrelated personal information, or security vulnerability details through general challenge forms. 

All personal data described in this notice is collected directly from you through registration, submission, and support forms, or through your voluntary use of Discord and GitHub in connection with the challenge. We do not receive participant data about you from the RustConf organizers, or any other third-party; RustConf serves only as the launch and promotional venue for the challenge and is not a data source or processor for Peeriot. 

2. Why we use your information

We process your information to:

  • register and administer your participation;
  • send operational challenge communication;
  • provide technical and community support;
  • manage teams and challenge status;
  • review and reproduce challenge submissions;
  • evaluate submissions and administer awards;
  • improve Myrmic, its documentation, and developer experience;
  • protect our websites, systems, and participants from misuse or security threats;
  • publish projects, names, handles, or attribution only where permitted or separately chosen;
  • send general Myrmic product or community updates only if you separately opt in;
  • understand aggregate use of public challenge pages where analytics consent has been provided.

 

Participation in the challenge does not require consent to general Myrmic marketing.

3. Legal basis for processing

Depending on the purpose, we expect to process personal data on the following legal bases:

Challenge administration and requested communication

Processing necessary to manage your participation and take steps requested by you in connection with the challenge.

Security and abuse prevention

Our legitimate interests in protecting participants, systems, websites, and services.

Optional marketing and analytics

Your consent.

Public attribution

Where required, your consent or another appropriate legal basis depending on how the publication is structured.

Prize, accounting, and legal records

Applicable legal obligations and administration of the challenge and awards.

4. Services we use

We use third-party service providers to operate the challenge and its websites.

Kinsta

Used for website hosting, infrastructure, security, logs, backups, and related hosting services.

Paperform

Used for challenge registration, feedback, and submission forms.

Zoho CRM

Used for participant administration, challenge status, jury-related records, and operational communication.

Zoho Mail

Used for transactional and operational challenge email.

Google Analytics

Used for optional analytics on public challenge pages, only after analytics consent has been provided.

We may also use Discord for optional community support and GitHub for source code, repositories, public Issues, contributions, and private security reporting.

Some providers may process personal data outside the European Economic Area. Where this occurs, appropriate safeguards depend on the provider, contractual arrangements, and actual technical configuration.

5. Discord and GitHub

We use the following third-party platforms to manage operational communications 

Discord

Discord may be used for optional community support, discussion, office hours, and challenge communications. 

Please do not post: 

  • confidential information; 
  • unnecessary personal information; 
  • passwords or credentials; 
  • potential security vulnerabilities. 

GitHub

GitHub may be used for: 

  • public source repositories; 
  • challenge project links; 
  • public Issues; 
  • contributions; 
  • private vulnerability reports where available.  


Potential security vulnerabilities must not be disclosed through public GitHub Issues. 

Your use of Discord and GitHub is also subject to those services’ own terms and privacy policies. 

6. Analytics and cookies

We use essential technologies where necessary to operate and secure our websites. 

Google Analytics is optional. 

For the challenge, Google Analytics should only load after you allow analytics cookies. We use analytics to understand aggregate interest in the challenge and how visitors interact with public challenge pages. 

We do not intentionally send the following information to Google Analytics:  

  • names; 
  • email addresses; 
  • Challenge IDs; 
  • GitHub or Discord handles; 
  • form answers; 
  • repository URLs; 
  • security-report references. 

 

Analytics should be limited to approved aggregate events related to the public challenge journey.  

You can change or withdraw analytics consent at any time through: 

{{COOKIE_SETTINGS_URL}} 

7. Marketing communications

General Myrmic product and community news are separate from challenge administration. 

You will only receive these communications if you provide separate consent. 

Marketing consent: 

  • is optional; 
  • is not required to participate in the challenge; 
  • is not pre-selected; 
  • can be withdrawn at any time. 

 

Operational messages necessary to administer the challenge may still be sent even if you do not opt for general marketing. 

8. How long we keep your information

The current working retention model is:

Registration and challenge feedback

Up to 12 months after the challenge closes, followed by deletion or anonymization unless a longer period is required.

Optional public showcase content

Retained according to the applicable publication basis and withdrawal rights.

Google Analytics user-level event data

Working default of 2 months.

Prize, tax, and accounting records

Retained for the applicable statutory period.

Security reports

Retained for as long as necessary for investigation, remediation, security, and legal protection.

9. Who can access your information

Challenge information is accessible only to Peeriot team members and service providers who require access for the purposes described in this notice. 

Access should be limited according to role and operational needs. 

Names, handles, project descriptions, quotes, repositories, or demonstrations are only published according to the challenge rules and the participant’s applicable attribution choices. 

Jury members may receive access to information necessary to evaluate challenge submissions. Submission evaluation is carried out entirely by human jury members; we do not use automated decision-making or profiling that produces legal effects or similar significantly affects participants. 

10. Security and vulnerability reports

Only test systems that you own or are explicitly authorized to test. 

Do not publish potential security vulnerabilities through: 

  • Discord; 
  • public GitHub Issues; 
  • general challenge registration forms; 
  • general challenge feedback or submission forms.  

 

If you believe you have identified a security vulnerability, report it privately to: 

security@myrmic.dev

Please include enough information for the Myrmic team to understand and reproduce the issue, but do not include unnecessary personal information, credentials, or secrets.  

A privately reported security finding may still be considered for an award where it is permitted by the Challenge Rules. 

11. Your data protection rights

Subject to applicable law, you may have the right to:  

  • request access to your personal data; 
  • request correction of inaccurate information; 
  • request deletion of your personal data; 
  • request restriction of processing; 
  • receive certain information in a portable format; 
  • object to certain processing; 
  • withdraw consent at any time where processing relies on consent. 

 

Withdrawing consent does not affect processing that occurred before the withdrawal. To exercise your rights, contact: 

security@myrmic.dev

You may also lodge a complaint with a competent data protection supervisory authority. 

12. International data transfers

Some service providers or their subprocessors may process information outside the European Economic Area. 

Where personal data is transferred internationally, Peeriot uses appropriate safeguards where required, such as the European Commission’s Standard Contractual Clauses or an equivalent recognized transfer mechanism, as required by applicable law. 

We do not claim that all challenge-related processing takes place exclusively within the European Union unless this has been verified across the complete technical setup and all relevant subprocessors. 

13. Security of your information

We take reasonable technical and organizational measures to protect personal information used to operate the challenge.

These measures may include:

  • limiting access according to role;
  • using authenticated administrative systems;
  • separating participant records from public analytics;
  • restricting access to challenge and jury information;
  • using private channels for security reports;
  • reviewing service-provider access and integrations;
  • avoiding personal information in analytics parameters, URLs, and tracking data.

 

No online service can guarantee absolute security. Participants should therefore avoid submitting information that is not required for participation.

14. Changes to this notice

We may update this Privacy Notice if:

  • the challenge process changes;
  • new service providers are introduced;
  • existing services are removed;
  • the purposes of processing change;
  • legal or technical requirements change.

 

The current version and publication date will be shown on this page.

Contact

For questions about this Privacy Notice or how your personal data is handled:

Peeriot GmbH
Peterssteinweg 14
04107 Leipzig
Germany

For privacy and potential security vulnerabilities:

security@myrmic.dev

ARE YOU READY?

JOIN THE BUILD & BREAK CHALLENGE!

Try the starter project, build a use case, or bring us a break report. Registration takes about three minutes.