What the participant workspace collects about you, who it is shared with, and what you can ask us to do about it.
This notice covers the participant workspace at https://if-hackathon-workspace.pages.dev — the separate, sign-in-only service used by people taking part in an Innovation Forum × R1X hackathon. It is a different service from the public website at https://r1x.co.uk/public_hackathon/, which has its own Privacy Policy and Cookie Policy. This notice does not replace those; it sits alongside them.
The workspace exists so that a participant can sign in, see which team they are in, reach their team's code repository and task board, and see the deadline. It is deliberately small.
Global Innovation Forum Limited (company number 10010132), registered at Future Business Centre, Kings Hedges Road, Cambridge CB4 2HY, is the data controller. R1X is our technology and hosting partner. Questions and requests go to info@inno-forum.co.uk, or to [DATA PROTECTION CONTACT NAME] at [DATA PROTECTION EMAIL].
When you sign in with GitHub, we keep two things about you: your GitHub username and the display name on your GitHub profile. We also show which team you are in, which we read from GitHub each time you load the page rather than storing our own copy. We do not store your profile picture — the workspace draws a plain initial instead, so that your browser never has to fetch an image from GitHub while you are using it.
There is a difference between what we keep and what passes through, and it is fair to tell you about it. When we ask GitHub who you are, GitHub sends back your whole public profile in one response. Depending on what you have filled in, that can include a public email address, a biography, a company or a location. We read only the two fields above; the rest is not saved, not logged and not passed to anyone. Equally, when we check your team we ask GitHub for the teams you belong to, and GitHub's answer covers every organisation you are in — including ones that have nothing to do with this event. We keep only the teams belonging to this event's organisation and discard the rest immediately.
We do not collect, and the workspace has nowhere to put:
We deliberately do not record whether you are under 18 in this service. The event team holds that separately where it is needed for safeguarding.
Your work is not stored by us. When you build something during the event it goes into your team's repository on GitHub, using your own GitHub account, exactly as it would on any other project. The workspace shows you a link to that repository; it does not hold a copy.
Team repositories are public by default, which means the code and the commit history — including the name and email address recorded against your commits — can be seen by anyone. Please read the participant guidance before you commit for the first time. Deleting a repository later does not reach copies other people have already taken.
One cookie, named if_session. It holds your signed-in state and expires after eight hours. It is strictly necessary for the service to work — without it, the workspace cannot tell one signed-in person from another — so it does not require consent under PECR.
It is marked HttpOnly, so it cannot be read by scripts in your browser, and Secure, so it is only ever sent over an encrypted connection. We set no analytics, advertising or tracking cookies anywhere in the workspace.
What the cookie contains. Alongside your username it holds the access key GitHub issued when you signed in, which is what lets us ask GitHub which team you are in. It is kept in the cookie rather than in a database because we do not run one. Being HttpOnly, it is never visible to any script on the page, and it only ever grants the read-only permissions you approved when you signed in — it cannot be used to change anything in your account or your code.
One honest limit on signing out. Because there is no database, there is nothing on our side to switch off when you sign out. Signing out removes the cookie from your browser, which is what matters on a shared computer, but a copy taken beforehand would keep working until the eight hours run out. This is why the eight hours are short. If you want to end access immediately and everywhere, revoke this application in your GitHub settings under Applications — that works at once, because it stops GitHub honouring the key rather than asking us to forget it.
A short-lived second cookie, if_oauth_state, exists only during sign-in to protect against a cross-site request forgery attack, and is deleted immediately afterwards.
Two providers, and nobody else:
We do not sell your data, we do not use it for marketing, and we do not share it with sponsors.
Our lawful basis is contract: you have entered a hackathon, and we cannot run it — put you in a team, give you somewhere to work, judge what you built — without processing this. Where you are under 18 we take additional care in line with the ICO's Age Appropriate Design Code.
Your signed-in session lasts eight hours and then ends. We hold the record of which team you were in for [RETENTION PERIOD] after the event so that results can be checked and disputes resolved.
Your GitHub account, and anything you put in a repository, belong to you and are governed by GitHub's own terms. Closing your GitHub account is done with GitHub, not with us.
You can ask us for a copy of what we hold, ask us to correct it, ask us to delete it, or object to how we use it. Write to info@inno-forum.co.uk and we will respond within one month.
One honest limitation. Once you have pushed work to a public repository, other people may have copied, forked or archived it. We can remove our own copies and links, and we can help you ask GitHub, but neither we nor GitHub can reach copies other people already hold. This is why the guidance asks you to think before the first commit rather than after.
If you are not happy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk.
Please make sure a parent or guardian knows you are taking part. We take extra care with your information, we do not profile you, and we do not use your data for marketing. If a parent or guardian wants to exercise your rights on your behalf, they can write to info@inno-forum.co.uk.
Note that GitHub requires its users to be 13 or over, and is a separate company with its own terms and privacy policy.
If the workspace changes what it collects, this notice is updated before the change goes live, not after.