Privacy Policy
Privacy Policy
Last updated: 6 July 2026
This Privacy Policy explains how protoledger.org (the "Site") handles personal data. We are committed to processing personal data lawfully, fairly, and transparently, in accordance with the EU General Data Protection Regulation (GDPR) and applicable national law.
1. Who is responsible (data controller)
The controller responsible for personal data processed through the Site is Oleh Bezuhlyi, operator of protoledger.org. You can reach us about any privacy matter, or to exercise your rights, through the contact form on our About page.
2. What we collect and why
We keep data collection to a minimum. We process:
- Contact form data — the name, email address, and message you provide when you contact us. Used to receive and respond to your enquiry.
- Challenge submissions — the challenge level, subject, summary, and any optional contact detail you provide when submitting a challenge. Used to review the challenge and, where accepted, to publish it in the public challenge log with attribution as described in the challenge process.
- A hashed record of your IP address — when you submit a form, we store a one-way cryptographic hash (SHA-256) of your IP address, not the address itself. Used only to rate-limit submissions and prevent abuse.
- Server and technical data — like most websites, our hosting provider processes standard server log data (such as IP address, date and time of request, and browser user-agent) as part of delivering the Site and keeping it secure.
- Cookies and analytics data — see Section 5 and our Cookie Policy.
We do not operate user accounts, we do not sell personal data, and we do not use third-party advertising or cross-site tracking.
3. Legal bases for processing
We rely on the following legal bases under Article 6(1) GDPR:
- Consent — Article 6(1)(a) — for any analytics cookies, which are set only after you accept them. You may withdraw consent at any time (Section 5).
- Legitimate interests — Article 6(1)(f) — for responding to enquiries you send us, for securing the Site, and for rate-limiting form submissions to prevent abuse. Our legitimate interest is the safe and effective operation of the Site; strictly-necessary cookies are also covered here (and by applicable e-privacy rules).
- Compliance with a legal obligation — Article 6(1)(c) — where we must retain or disclose data to comply with the law.
4. Who processes data on our behalf
- Hosting: the Site is hosted by Hetzner Online GmbH (Germany), which processes server data on our behalf within the EU.
- Analytics (only when enabled and only with your consent): Google Analytics 4, provided by Google. Analytics is loaded only after you accept analytics cookies; IP anonymisation is enabled. If analytics is not configured or you decline, no analytics data is sent to Google.
We enter into appropriate data-processing terms with our processors.
5. Cookies and analytics
The Site uses a small number of cookies. Strictly-necessary cookies (for your session and to remember your cookie choice) are always set because the Site cannot function without them. Analytics cookies are set only if you click "Accept" in the cookie banner, and no analytics script loads before then. Full details of each cookie — name, purpose, and duration — are in our Cookie Policy. You can withdraw or change your consent at any time by clearing the Site's cookies or using the banner when it reappears.
6. International transfers
Our hosting is located in the EU. If analytics is enabled and you consent, some data may be processed by Google outside the European Economic Area; in that case such transfers are made under appropriate safeguards (such as the EU Standard Contractual Clauses and applicable adequacy frameworks).
7. How long we keep data
- Contact messages and challenge submissions are retained for as long as necessary to review and respond to them, to operate the challenge process, and to keep a record of published challenges; we delete or anonymise them when they are no longer needed.
- Hashed IP records used for rate-limiting are short-lived and retained only as long as needed for that purpose.
- Server logs are retained by our hosting provider for a limited period for security and diagnostics.
8. Your rights
Subject to the conditions in the GDPR, you have the right to:
- access the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure ("right to be forgotten");
- request restriction of processing;
- data portability — receive your data in a structured, machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal; and
- lodge a complaint with a supervisory authority — in particular the data-protection authority of your country of residence or of the operator's establishment.
To exercise any of these rights, contact us via the About page. We will respond within the time limits set by the GDPR.
9. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects concerning you.
10. Children
The Site is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Security
We use reasonable technical and organisational measures to protect personal data, including transport encryption (HTTPS), input validation, CSRF protection on forms, and storing IP addresses only in hashed form. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
12. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above shows when it last changed. Material changes will be reflected on this page.
13. Contact
For any question about this policy or your personal data, use the contact form on our About page.