Legal
Privacy Policy
1. Data Controller
The data controller for ARCH CHALLENGE is MGM Cape Verde, reachable at [email protected]. All personal data collected through this website is processed in accordance with the EU General Data Protection Regulation (GDPR) and applicable national legislation.
2. Data We Collect
We collect the following categories of personal data:
- Registration data: first name, last name, email address, country of residence, profession, university or studio name, registration type (individual or team).
- Team member data: names, emails and countries of additional team members provided during registration.
- Payment data: payment status and registration fee amount. We do not store payment card details — payments are handled by third-party processors.
- Submission data: files uploaded through the participant dashboard.
- Technical data: session identifiers, IP address, browser type, and access timestamps collected automatically when you use the website.
- Cookie consent data: a record of your cookie consent choices (accept, reject, or custom preferences), including an anonymised session identifier, a one-way hash of your IP address (non-reversible), browser type, and timestamp. This data is collected to comply with our legal obligation to demonstrate valid consent under GDPR Art. 7(1).
3. Purposes and Legal Basis
We process your personal data for the following purposes:
- Competition management (legal basis: contract performance) — to register you as a participant, manage your submission and communicate competition updates.
- Payment processing (legal basis: contract performance) — to manage registration fees and confirm payment status via PayPal.
- Transactional communication (legal basis: contract performance) — to send registration confirmations, dashboard access links and competition-related notices via Resend.
- Newsletter and marketing (legal basis: consent) — to send competition news, announcements and future challenge notifications via Mailchimp, only if you have explicitly subscribed.
- Legal obligations (legal basis: legal obligation) — to comply with applicable laws and regulations, including recording cookie consent choices as required by GDPR Art. 7(1).
- Website analytics (legal basis: consent) — to understand how visitors interact with the website via Google Analytics, only if you have given explicit consent through the cookie banner.
4. Data Retention
Registration and submission data is retained for the duration of the competition and for a period of 3 years thereafter for legal and administrative purposes. Session data is deleted after 7 days of inactivity. If you withdraw your registration, your personal data will be deleted within 30 days, except where retention is required by law.
5. Data Sharing
We do not sell or rent your personal data. We may share data with:
- Jury members — anonymised submission data only, without identifying participant information.
- Resend — transactional email service used to deliver registration confirmations and competition updates. Acts as a data processor under GDPR. Resend Privacy Policy.
- Mailchimp (Intuit Inc.) — newsletter and marketing communication platform, used only if you have explicitly subscribed to our mailing list. Data transferred to the US under Standard Contractual Clauses. Mailchimp Privacy Policy.
- PayPal (PayPal Holdings, Inc.) — payment processing for registration fees. When you complete a payment, you are redirected to PayPal's platform; we receive only payment confirmation and transaction reference. We do not store card or bank details. PayPal Privacy Policy.
- Google Analytics (Google LLC) — website analytics service, active only with your explicit consent. Collects anonymised usage data (pages visited, session duration, device type). Data transferred to the US under Standard Contractual Clauses. IP anonymisation is enabled. Google Privacy Policy.
- Cloudflare — website hosting, security and content delivery network. Cloudflare Privacy Policy.
- Legal authorities — where required by law or court order.
6. International Transfers
Your data may be processed on servers located outside the European Economic Area (EEA), including in the United States. Where this occurs, we ensure adequate safeguards are in place through Standard Contractual Clauses or other GDPR-compliant mechanisms.
7. Your Rights
Under the GDPR, you have the following rights:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may request correction of inaccurate data.
- Right to erasure — you may request deletion of your data, subject to legal obligations.
- Right to restriction — you may request that we restrict processing of your data in certain circumstances.
- Right to data portability — you may request your data in a structured, machine-readable format.
- Right to object — you may object to processing based on legitimate interest.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Cookies
We use cookies and similar technologies on this website. For full details on the types of cookies we use and how to manage your preferences, please refer to our Cookie Policy.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration or destruction. Passwords are stored as salted cryptographic hashes and are never stored in plain text. All data in transit is encrypted via HTTPS.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The date at the top of this page indicates the most recent revision. We will notify registered participants of material changes by email.
11. Newsletter Unsubscribe
If you have subscribed to our newsletter, you can unsubscribe at any time by clicking the unsubscribe link at the bottom of any newsletter email, or by contacting us at [email protected]. Unsubscribing from the newsletter does not affect processing of data related to your competition registration.
12. Cookie Consent Audit Log
To comply with GDPR Art. 7(1), we maintain an audit log of all cookie consent events. Each time you interact with the cookie banner (accept, reject or customise), we record:
- A one-way hash (SHA-256, truncated) of your IP address — this is not reversible and does not constitute personal data under GDPR Recital 26.
- An anonymous session identifier generated in your browser (random value, not linked to your account).
- Your browser's User-Agent string (device and browser type).
- Timestamp of the consent event (server time).
- The specific choices made (which cookie categories were accepted or rejected).
- The version of the cookie banner displayed at the time.
This data is stored on Cloudflare D1 (our database infrastructure) and is used solely for the purpose of demonstrating valid consent to supervisory authorities if required. The legal basis for this processing is legal obligation (GDPR Art. 6(1)(c)). Consent audit records are retained for 3 years from the date of collection, in line with standard GDPR enforcement limitation periods.
13. Contact
For any privacy-related queries, please contact us at:
MGM Cape Verde — ARCH CHALLENGE
[email protected]
