Privacy Notice

Version 1.0 — September 6, 2026

This Privacy Notice describes how personal data collected in connection with the MAX Authorization Challenge is processed.

1. Data Controller

The data controller is the organizer of the MAX Authorization Challenge.

For privacy-related requests or questions concerning personal data, participants may use the contact information published on the official challenge website.

2. Data Collected

The challenge collects only the data reasonably necessary to enable:

The data processed may include:

Personal data that is not necessary for the operation of the challenge is not intentionally collected.

3. Purposes of Processing

Personal data is processed exclusively for purposes related to the management and operation of the challenge, including:

4. Legal Basis for Processing

Personal data is processed to the extent necessary to enable participation in the challenge and to pursue the organizer’s legitimate interests in the management, security, integrity, and proper administration of the contest.

Where processing relies on the participant’s consent, that consent may be withdrawn in accordance with the applicable procedures.

5. Publication of Usernames and Results

Usernames, scores, and challenge results may be displayed publicly on leaderboards and challenge-related pages.

Real names, affiliations, write-ups, or additional identifying information will not be published by the organizer unless:

6. Technical Service Providers

External technical service providers may be used to operate the challenge, including services necessary for:

The remote verifier is currently hosted using Render, an external cloud service provider.

Technical service providers may process personal data and technical information only to the extent necessary to provide their respective services. This may include information such as IP addresses, connection data, request metadata, and network or access logs generated in the ordinary operation and security of the service.

Such processing is subject to the provider’s own applicable privacy and data-processing terms.

7. International Data Transfers

Some technical service providers may process data outside the European Economic Area.

Where applicable, such processing must take place subject to the safeguards required by applicable data protection law.

8. Data Retention

Personal data will be retained for as long as reasonably necessary to:

When personal data is no longer necessary for these purposes, it may be deleted, anonymized, or retained only in aggregated form.

9. Participants’ Rights

Subject to applicable data protection law, participants may request:

Requests may be submitted using the contact information published on the official challenge website.

10. Complaints

Participants have the right to lodge a complaint with the competent data protection authority if they believe that their personal data is being processed in violation of applicable data protection law.

11. Cookies and Technical Tools

The platform may use cookies or other technical tools that are strictly necessary for authentication, security, and operation of the service.

Any additional analytics, tracking, or profiling technologies will be described separately if they are actually used.

12. Commercial Profiling

Personal data collected in connection with the challenge is not used by the organizer for commercial profiling.

13. Updates to This Notice

This Privacy Notice may be updated when necessary to reflect technical, operational, or regulatory changes.

The version published on CTFd constitutes the current version of the Privacy Notice.