← Darkroom

Privacy Policy

Darkstar Darkroom registration. Effective: August 2026

In short: your registration data is encrypted by our application before it is stored, kept exclusively on cloud infrastructure in the European Union, used only to validate and approve attendees for this event, and deleted within 30 days after the event. Questions: [email protected].


1. Who we are

Darkstar is the data controller for personal data processed through this registration site. We organise defence technology events, camps, and related programmes. If you need the registered legal entity behind Darkstar, for example to exercise your rights or to lodge a complaint, contact us at [email protected] and we will provide it.


2. What this policy covers

This policy applies to personal data submitted through the Darkroom registration form and to technical data collected when you visit this site. For our other programmes and websites, see the privacy policy published on darkstar.ee.


3. What data we collect

When you register, we collect exactly what you enter into the form:

For abuse prevention we additionally process your IP address (stored only as a keyed, irreversible hash), your browser user-agent string, and a bot-detection score. We do not collect anything else, and the form has no hidden tracking.


4. Why we process your data and on what legal basis

PurposeData usedLegal basisRetention
Validate and approve attendees for the eventAll registration dataConsentDeleted within 30 days after the event
Communicate approval status, entry credential (QR code), venue, and timingName, emailConsentDeleted within 30 days after the event
Event-day entry control (QR scan at the door)Name, entry credentialConsent / legitimate interest (event security)Deleted within 30 days after the event
Abuse and spam preventionHashed IP, user-agent, bot-detection scoreLegitimate interestDeleted within 30 days after the event

That is the complete list. Your data is used only for attendee validation and approval for this event and the directly related logistics above. We do not use it for marketing, we do not sell it, we do not share it with sponsors or partners, and we do not use it for automated decision-making or profiling. Approval decisions are made by people.


5. How your data is protected

We treat event registration data as sensitive and apply the following technical and organisational measures:


6. Deletion after the event

All registration data, including approved-attendee records, entry credentials, and abuse-prevention metadata, is deleted within 30 days after the event takes place. If you are not approved, or the event is cancelled, your data is deleted on the same schedule or earlier. You can also request deletion at any time before that (see your rights below).


7. Service providers (sub-processors)

We keep the list of providers deliberately short, and we describe them here by category rather than by name:

CategoryWhat it is used for
Cloud hosting and infrastructureServing this site, storing encrypted registration records, and sending transactional email such as approvals, credentials and reminders
Internal review toolingVetting and approving registrations
Bot and abuse detectionBlocking automated submissions to the registration form
Aggregate traffic measurementCounting page views, with IP anonymisation and never linked to your registration

Registration records are stored on EU infrastructure. The review tooling above is provided from the United States and receives your registration so that the team can vet it; that transfer is covered by the EU-US Data Privacy Framework or by Standard Contractual Clauses approved by the European Commission, and we will confirm which on request. No advertising scripts are used.

We do not publish the names of our providers, or which data sits with which one. Naming the services behind our events narrows the search for anyone trying to reach the people who take part, and that is the one thing we will not make easy. This changes nothing about your rights. The full list, naming each provider, its role, the data it handles and where it processes it, is available on request: email [email protected] and we will send it to you. We provide it in full, and without needing to be asked, to supervisory authorities and to anyone else legally entitled to it, including the Estonian Data Protection Inspectorate.


8. Your rights

Under the EU General Data Protection Regulation (GDPR) and Estonian data protection law, you have the right to:

To exercise any of these rights, email [email protected]. We respond within 30 days.

If you believe we have not handled your data correctly, you can lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee, or with the supervisory authority in your country of residence.


9. Cookies and analytics

This site sets no cookies of its own. Our bot-detection and aggregate traffic-measurement providers may set cookies required for those functions, with IP anonymisation enabled, and those cookies are governed by their own privacy policy. Analytics data is aggregate usage measurement only and is never combined with your registration data.


10. Children

This event and site are not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors.


11. Changes to this policy

Material changes will be posted on this page and the effective date above will be updated. Since data is deleted after the event, this policy has a naturally limited lifespan.


12. Contact

Darkstar
Email: [email protected]
Web: darkstar.ee