Privacy Policy

Last updated: May 2026

1. Introduction

The Autonomous Cyber Defense Challenge 2026 (“the Challenge”, “we”, “our”, or “the organisers”) respects the privacy of participants, judges, mentors, sponsors, researchers, and visitors to the platform.

This Privacy Policy explains how information may be collected, processed, stored, and used in connection with participation in the Challenge, access to the website, submission of projects, operational simulations, and related activities.

By accessing the platform or participating in the Challenge, users acknowledge and agree to the practices described in this policy.

2. Information We Collect

The organisers may collect limited information necessary to operate the Challenge securely and effectively, including:

Account & Registration Information

  • Full name
  • Email address
  • Country or region
  • Professional or academic affiliation
  • Team information
  • Public profile links (optional)

Technical & Operational Information

  • IP address
  • Browser and device metadata
  • Authentication logs
  • Platform interaction telemetry
  • Submission metadata
  • API usage logs
  • Infrastructure access records

Submission Materials

Participants may voluntarily submit:

  • source code,
  • technical documentation,
  • architecture diagrams,
  • presentations,
  • videos,
  • model outputs,
  • detection logic,
  • research findings,
  • automation workflows,
  • or related materials.

3. Purpose of Data Collection

Information may be used for:

  • participant authentication,
  • competition administration,
  • infrastructure security,
  • fraud prevention,
  • operational monitoring,
  • evaluation and judging,
  • communication regarding the event,
  • sponsor coordination,
  • platform reliability,
  • legal and compliance obligations,
  • and improvement of future challenge operations.

Security telemetry and infrastructure logs may also be collected to detect abuse, unauthorised access attempts, malicious activity, or violations of the event rules.

4. Operational Security & Monitoring

Given the cybersecurity nature of the Challenge, participants acknowledge that:

  • challenge environments may be monitored,
  • infrastructure activity may be logged,
  • sandbox behaviour may be analysed,
  • and automated abuse-detection systems may be used.

Monitoring is conducted solely for operational integrity, infrastructure protection, competition fairness, and responsible security management.

The organisers do not authorise real-world attacks, unauthorised scanning, or malicious activity outside approved challenge environments.

5. Confidentiality of Submissions

Not all submissions, rankings, demonstrations, or project materials will be published publicly.

Certain projects may involve:

  • sensitive defensive methodologies,
  • dual-use security research,
  • infrastructure simulations,
  • sponsor-provided datasets,
  • or operational detection workflows.

The organisers reserve the right to withhold, redact, anonymise, or restrict publication of technical artefacts, participant identities, evaluation details, or demonstrations where disclosure may create security, legal, ethical, or reputational concerns.

6. Data Sharing

The organisers do not sell participant data.

Limited information may be shared with:

  • judges,
  • mentors,
  • operational partners,
  • infrastructure providers,
  • or sponsors directly involved in Challenge operations,

strictly where necessary for evaluation, logistics, infrastructure access, or event administration.

Information may also be disclosed where required by applicable law, regulation, legal process, or security obligations.

7. Third-Party Services

The platform may use trusted third-party infrastructure or services for:

  • hosting,
  • authentication,
  • analytics,
  • communication,
  • cloud infrastructure,
  • telemetry,
  • or submission management.

Such providers may process limited data in accordance with their own privacy and security policies.

8. Data Retention

Information is retained only for as long as reasonably necessary to:

  • administer the Challenge,
  • maintain operational security,
  • resolve disputes,
  • comply with legal obligations,
  • or support future editions of the event.

The organisers may anonymise or aggregate certain operational datasets for research, statistical, or reporting purposes.

9. Participant Responsibilities

Participants are responsible for ensuring that:

  • submitted materials do not violate applicable laws,
  • proprietary information is shared only with proper authorisation,
  • third-party intellectual property rights are respected,
  • and submissions comply with the Challenge rules and ethical guidelines.

Participants should avoid including unnecessary personal, confidential, or sensitive information within submissions.

10. Security

The organisers implement reasonable technical and organisational measures intended to protect platform integrity and participant information.

However, no internet-connected system can be guaranteed fully secure. Participation in the Challenge is undertaken at the participant’s own risk.

11. International Participation

The Challenge may involve international participants, infrastructure providers, judges, and sponsors. By participating, users acknowledge that information may be processed across multiple jurisdictions where operationally necessary.

12. Changes to This Policy

This Privacy Policy may be updated periodically to reflect operational, legal, or platform changes. Continued use of the platform after updates constitutes acceptance of the revised policy.

13. Contact

For privacy, operational security, or policy-related inquiries, participants may contact the organising team through the official communication channels listed on the platform.