Privacy Policy

Last updated: 2026-04-24

This page is currently available in English only. Localised versions are coming.

This Privacy Policy explains how CyberLuka (“CyberLuka”, “we”, “our”, or “us”) collects, uses, and protects personal data when you use the services at cyberluka.com(the “Service”).

We are based in the Netherlandsand comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Dutch implementation act (UAVG), and the ePrivacy Directive.

1. Who we are

The data controller responsible for your personal data is:

We are a small organisation and are not required to appoint a Data Protection Officer (DPO) under GDPR Article 37. You can reach the person responsible for privacy matters at the address above.

2. What personal data we collect

We collect only the data we need to run the Service.

Game creators (paying customers)

  • Account: email address, password (stored as a bcrypt hash), preferred language, preferred currency, company name if you provide one.
  • Game configuration: the games, countries, teams, and challenges you create.
  • Payment: your Stripe customer ID, the amount paid, and the currency. We do not store card numbers or other full payment details — these stay with Stripe (see section 6).
  • Security logs: IP address and user-agent for authentication, registration, password-reset, and game-lifecycle events, retained for 90 days (legitimate interest — see section 3).

Players

  • Account within a game: username, display name, password (stored as a salted SHA3-512 hash), team membership.
  • Game activity: flag submissions, points, conquests, timing.

Player accounts are created at the invitation of the game creator for the duration of a specific game. The game creator is the controller for the personal data of players they invite; CyberLuka acts as processor on behalf of the game creator for that data (see section 6).

Visitors (not logged in)

  • Approximate country derived from your IP address by our edge network provider, used to detect your default currency and decide whether to show the cookie-consent banner. We do not store the IP itself for this purpose.
  • Anonymous performance telemetry (page load times, errors). No personal identifiers are attached.

3. Why we process data and on what legal basis

We rely on the legal bases in GDPR Article 6:

  • Performance of a contract (Art. 6(1)(b)): creating and managing your account, deploying games, processing payments, delivering the Service.
  • Legitimate interests (Art. 6(1)(f)): keeping security and audit logs to detect fraud and protect the Service; preventing abuse. We have balanced these interests against your rights; you can object at any time (see section 9).
  • Legal obligation (Art. 6(1)(c)): keeping invoices and tax records for the period required by Dutch law (currently 7 years).
  • Consent (Art. 6(1)(a)): non-essential cookies, if and when we introduce them (we do not currently use analytics or marketing cookies).

4. Cookies

We use only cookies that are strictly necessary or functional. We do not currently use analytics or marketing cookies.

CookiePurposeCategoryDuration
authjs.session-tokenKeeps you signed inEssential30 days
NEXT_LOCALERemembers your language choiceFunctional1 year
CL_CURRENCYRemembers your currency choiceFunctional1 year
CL_COOKIE_CONSENTStores your cookie preferencesEssential1 year
cl_live_locale_*Projector view language (per game)Functional30 days
Stripe Checkout cookiesFraud prevention during paymentEssential (third-party)See Stripe

Visitors in the EU, EEA, UK, and Switzerland see a cookie-consent banner on first visit. You can change your choice at any time using the “Cookie preferences” link in the footer.

5. How long we keep your data

  • Account data: for as long as your account is active, plus 30 days after you request deletion.
  • Game data: up to 3 years after a game ends, so results remain accessible for re-sharing. You can request earlier deletion.
  • Security and audit logs: 90 days.
  • Invoices and tax records: 7 years (Dutch statutory retention).
  • Vouchers: until redeemed, plus 1 year.
  • Application Insights telemetry: 30 days, aggregated and without personal identifiers.

6. Who we share data with

We use a small number of processors under written agreements (Article 28 GDPR). We do not sell your personal data to anyone. By function, these include:

  • Cloud infrastructure provider — hosting of the platform, databases, and transactional email delivery. All primary data is stored in a European Union data-centre region.
  • Edge network provider — DNS, content delivery, and network-layer security. Limited technical data (IP address, request metadata) is processed to deliver the Service.
  • Payment processor Stripe Payments Europe Limited (Ireland), PCI-DSS certified. Stripe is the controller for card details; we never store card numbers.
  • AI inference provider — only for CTF labs that include AI features, and only in an EU region. Prompts submitted by players in those labs are processed by this provider for the duration of the response.
  • Source-code hosting — used for our own codebase and lab content. No personal data is shared with this provider.

Named sub-processor list: a current list of the specific companies we use for each of the functions above is available on request from privacy@cyberluka.com. Enterprise customers can request it as part of a Data Processing Agreement.

Game creator as controller: when you, as a game creator, invite players, you become the controller for your players’ personal data. CyberLuka acts as your processor and only processes that data on your instructions to deliver the Service. Our Terms of Service include the processing terms required by Article 28 GDPR; enterprise customers may request a separate Data Processing Agreement.

7. International data transfers

All primary data is stored in the European Union. A small number of our sub-processors are based in or operate from the United States. These transfers are covered by:

  • the EU–US Data Privacy Framework, for processors certified under it; and/or
  • EU Standard Contractual Clauses as a backup safeguard.

8. Security

We protect personal data with:

  • TLS encryption on all network traffic.
  • Passwords stored as bcrypt hashes (game creators) or salted SHA3-512 hashes (players). We never store plaintext passwords.
  • Role-based access control and least-privilege principles.
  • Automated monitoring and security logging.
  • Regular dependency and platform patching.

No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and you without undue delay, as required by Articles 33–34 GDPR.

9. Your rights

Under GDPR and Dutch law you have the right to:

  • Access the personal data we hold about you (Art. 15).
  • Rectify inaccurate or incomplete data (Art. 16).
  • Eraseyour data in the situations listed in Article 17 (“right to be forgotten”).
  • Restrict processing (Art. 18).
  • Receive a portable copy of your data in a machine-readable format (Art. 20).
  • Object to processing based on legitimate interests (Art. 21).
  • Withdraw consent at any time where processing is based on consent.
  • Not be subject to automated decisions with legal effect. We do not carry out such decisions.

To exercise any of these rights, email privacy@cyberluka.com. We will respond within one month, as required by GDPR.

10. Complaints

If you believe we have handled your personal data improperly, you have the right to lodge a complaint with your local supervisory authority. The Dutch authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We appreciate the chance to address your concern first, but this is your right under GDPR Art. 77.

11. Children

The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be announced by email to account holders at least 30 days before they take effect. The date at the top of this page always reflects the current version.

13. Contact

Questions about this Policy or how we handle your personal data: privacy@cyberluka.com.

We value your privacy

We use only cookies that are strictly necessary for the site to work, plus functional cookies you have chosen. We do not use analytics or marketing cookies today. Read more.