Darkstar Darkroom registration. Effective: August 2026
In short: your registration data is encrypted by our application before it is stored, kept exclusively on cloud infrastructure in the European Union, used only to validate and approve attendees for this event, and deleted within 30 days after the event. Questions: [email protected].
Darkstar is the data controller for personal data processed through this registration site. We organise defence technology events, camps, and related programmes. If you need the registered legal entity behind Darkstar, for example to exercise your rights or to lodge a complaint, contact us at [email protected] and we will provide it.
This policy applies to personal data submitted through the Darkroom registration form and to technical data collected when you visit this site. For our other programmes and websites, see the privacy policy published on darkstar.ee.
When you register, we collect exactly what you enter into the form:
For abuse prevention we additionally process your IP address (stored only as a keyed, irreversible hash), your browser user-agent string, and a bot-detection score. We do not collect anything else, and the form has no hidden tracking.
| Purpose | Data used | Legal basis | Retention |
|---|---|---|---|
| Validate and approve attendees for the event | All registration data | Consent | Deleted within 30 days after the event |
| Communicate approval status, entry credential (QR code), venue, and timing | Name, email | Consent | Deleted within 30 days after the event |
| Event-day entry control (QR scan at the door) | Name, entry credential | Consent / legitimate interest (event security) | Deleted within 30 days after the event |
| Abuse and spam prevention | Hashed IP, user-agent, bot-detection score | Legitimate interest | Deleted within 30 days after the event |
That is the complete list. Your data is used only for attendee validation and approval for this event and the directly related logistics above. We do not use it for marketing, we do not sell it, we do not share it with sponsors or partners, and we do not use it for automated decision-making or profiling. Approval decisions are made by people.
We treat event registration data as sensitive and apply the following technical and organisational measures:
All registration data, including approved-attendee records, entry credentials, and abuse-prevention metadata, is deleted within 30 days after the event takes place. If you are not approved, or the event is cancelled, your data is deleted on the same schedule or earlier. You can also request deletion at any time before that (see your rights below).
We keep the list of providers deliberately short, and we describe them here by category rather than by name:
| Category | What it is used for |
|---|---|
| Cloud hosting and infrastructure | Serving this site, storing encrypted registration records, and sending transactional email such as approvals, credentials and reminders |
| Internal review tooling | Vetting and approving registrations |
| Bot and abuse detection | Blocking automated submissions to the registration form |
| Aggregate traffic measurement | Counting page views, with IP anonymisation and never linked to your registration |
Registration records are stored on EU infrastructure. The review tooling above is provided from the United States and receives your registration so that the team can vet it; that transfer is covered by the EU-US Data Privacy Framework or by Standard Contractual Clauses approved by the European Commission, and we will confirm which on request. No advertising scripts are used.
We do not publish the names of our providers, or which data sits with which one. Naming the services behind our events narrows the search for anyone trying to reach the people who take part, and that is the one thing we will not make easy. This changes nothing about your rights. The full list, naming each provider, its role, the data it handles and where it processes it, is available on request: email [email protected] and we will send it to you. We provide it in full, and without needing to be asked, to supervisory authorities and to anyone else legally entitled to it, including the Estonian Data Protection Inspectorate.
Under the EU General Data Protection Regulation (GDPR) and Estonian data protection law, you have the right to:
To exercise any of these rights, email [email protected]. We respond within 30 days.
If you believe we have not handled your data correctly, you can lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee, or with the supervisory authority in your country of residence.
This site sets no cookies of its own. Our bot-detection and aggregate traffic-measurement providers may set cookies required for those functions, with IP anonymisation enabled, and those cookies are governed by their own privacy policy. Analytics data is aggregate usage measurement only and is never combined with your registration data.
This event and site are not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors.
Material changes will be posted on this page and the effective date above will be updated. Since data is deleted after the event, this policy has a naturally limited lifespan.
Darkstar
Email: [email protected]
Web: darkstar.ee