Legal

Privacy notice

Last updated 2026-10-08

This notice explains what personal data is processed when you visit cyrange.eu, contact us, or take part in a CTF on ctf.cyrange.eu, under the EU General Data Protection Regulation (GDPR).

1. Controller

[TODO(Dan): legal name and address of the controller; see also the imprint]
Contact for privacy requests: info@cyrange.eu

2. Visiting this website

This website sets no cookies, runs no analytics or trackers, and loads fonts, images and scripts only from cyrange.eu itself. Like every web server, ours records each request in an access log: time, IP address, requested address, response status, browser identification and referring page.

  • Purpose: security, abuse detection, fault finding.
  • Legal basis: legitimate interest, Art. 6(1)(f) GDPR.
  • Retention: log files on the web server are rotated and deleted after at most 30 days. Copies forwarded to our security monitoring system are kept for [TODO(Dan): retention period of the SIEM, must match the Wazuh setting].

3. Contacting us

The contact form on this site does not send data to us or to any server. It prepares an email in your own email application, and nothing leaves your device until you send it. If you email us (info@cyrange.eu) we process your name, email address, organisation and message to answer you (Art. 6(1)(b) or (f) GDPR). Retention: [TODO(Dan): how long enquiries are kept, e.g. until the matter is closed plus a fixed period].

4. CTF platform (ctf.cyrange.eu)

To take part you create an account. We process the data you enter (username, email address, team, and optional fields such as affiliation or country [TODO(Dan): confirm which registration fields are enabled in CTFd]), your password (stored only as a hash), your challenge submissions with timestamps, and the IP address used when you sign in and submit. The platform sets a session cookie that is strictly necessary to keep you signed in. Your username or team name and your score may appear on the public scoreboard.

  • Purpose: run the competition, prevent cheating and abuse, contact you about the event.
  • Legal basis: performance of the participation agreement (Art. 6(1)(b)) and legitimate interest in fair play and security (Art. 6(1)(f)).
  • Retention: [TODO(Dan): how long accounts and submissions are kept after an event; deletion process].

The platform access log has the same content and retention as described in section 2.

5. Recipients and processors

The websites run on a server we operate in a data centre of Hetzner Online GmbH [TODO(Dan): confirm hosting location, e.g. Helsinki, Finland, and that a data processing agreement is in place]. Email: [TODO(Dan): name of the email provider]. We do not sell personal data and do not use advertising or analytics services.

6. Transfers outside the EU/EEA

[TODO(Dan): confirm: none by CyRange; check the email provider]

7. Your rights

You may request access, rectification, erasure, restriction of processing and data portability, and object to processing based on legitimate interest (Art. 15 to 21 GDPR). Where processing rests on consent you may withdraw it at any time. Write to info@cyrange.eu.

8. Complaints

You have the right to complain to a supervisory authority. For Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon), aki.ee [TODO(Dan): confirm this is the competent authority for the controller].

9. Security

All traffic uses HTTPS. Access to systems is restricted and logged. To report a vulnerability see Security.

10. Changes

We update this notice when processing changes; the date above shows the latest version.